Token-OPEX: Inference Controls, Not the Seat Budget
Angelika Beierlein
9 Min. read time Token costs aren’t a line item in SaaS contracts. They’re variable OPEX per workflow-and ...
6 Min. Read
On 7 May 2026, the Council, Parliament and Commission reached a provisional agreement on the Digital Omnibus to the AI Act, pushing back the strictest obligations for high-risk AI. Once the package is formally confirmed, the core requirements for application-layer high-risk systems will not take effect until 2 December 2027 instead of August 2026. For many organisations, that sounds like room to breathe. But that is precisely where the trap lies: anyone who freezes their governance work now is accumulating compliance debt that will come due with interest in 2027.
Key Takeaways
Related:Improvised AI Strategy: What the Supervisory Board Must Demand / BlackRock and Morgan Stanley Assess AI Governance
The agreement is the first amendment to the AI Act since its adoption in 2024. It does not postpone the law as a whole, but specifically targets the deadlines for high-risk systems. That is an important distinction that tends to get lost in the initial sense of relief.
What is the AI Act Omnibus? The Digital Omnibus to the AI Act is an amendment package that EU institutions provisionally agreed on 7 May 2026. It shifts several compliance deadlines, allows the Commission to suspend duplicate requirements where existing sectoral rules already cover the same ground, and introduces new prohibitions. The provisional agreement still needs to be formally confirmed and published in the Official Journal.
Two groups are directly affected. Application-based high-risk systems under Annex III receive an additional 16 months – their obligations now take effect on 2 December 2027. Product-regulated systems under Annex I, such as those in medical devices or lifts, are pushed back by one year to 2 August 2028. The obligation on member states to establish national AI regulatory sandboxes is also delayed to August 2027.
The reflex to pause an AI governance programme when more time appears is understandable – and expensive. The requirements themselves do not change with the delay, only their deadline. Organisations that wait until late 2027 to tackle risk classification, documentation, and human oversight will face exactly the same workload, only under time pressure and in a market where consulting capacity is at a premium.
There is also a market-concentration effect to consider. When every company shares the same December 2027 deadline, they will ultimately compete for the same scarce auditing and advisory resources. Starting early sidesteps that bottleneck and means not negotiating at the most expensive possible moment.
The postponement is only one side of the package. On the other, the Omnibus introduces a new prohibition in Article 5 targeting AI-generated child sexual abuse material – one that takes effect immediately when the package enters into force, with no transition period. The list of banned practices is therefore getting longer, not shorter.
There is also a simplification with consequences: the Commission will be able to suspend duplicate requirements by implementing act where sectoral rules already cover the same subject matter. That reduces red tape, but it requires organisations to map their AI systems cleanly to the correct regulatory framework. Losing track of that mapping does not eliminate compliance obligations – it merely moves them to a different file.
At its core, the decision is binary. Either the company freezes its compliance program and scrambles to catch up in 2027 under pressure – or it uses these 16 months as a structured head start. The second option is not only lower risk; it is usually cheaper.
Three steps are worth taking regardless of the deadline. First, the AI inventory: which systems in the organization actually fall into a high-risk category? Second, the gap analysis: where is documentation, risk management, and human oversight – as required by the AI Act – still missing? Third, accountability: AI governance belongs at the leadership level, not in a project that dies with the first budget round. The extended deadline is a gift for those who treat it as preparation time, and a trap for those who mistake it for a pause.
On 7 May 2026, the Council, Parliament, and Commission reached a provisional agreement. It is the first amendment to the AI Act since its adoption in 2024. Formal confirmation and publication in the Official Journal are still pending.
High-risk obligations under Annex III move from August 2026 to 2 December 2027; those under Annex I shift from August 2027 to 2 August 2028. The requirement for national AI regulatory sandboxes is pushed back to August 2027.
No. Only the high-risk deadlines have been deferred. The prohibition tier remains active, and the Omnibus even adds a new prohibition in Article 5. The fundamental requirements for high-risk AI are unchanged – only their deadline has moved.
Because the workload does not shrink – it merely shifts. Organizations that set up risk classification, documentation, and oversight only shortly before December 2027 will be working under time pressure and competing for scarce advisory capacity. Deferred obligations become compliance debt.
Build an AI inventory, analyze gaps in documentation and oversight, and elevate responsibility for AI governance to the executive level. That turns the extended deadline into preparation time rather than a missed milestone.
Read more on Digital Chiefs
Digital ChiefsAI Agents: ROI or Pilot Graveyard?Digital ChiefsAutonomous AI: How CIOs Can Manage Black-Box RisksDigital ChiefsDGX Cost Trap: Power OPEX DivMore from the MBF Media Network
cloudmagazinPlatform Engineering for Compliance: IDPs Enforce NIS2 and DORA mybusinessfutureEU AI Act from August 2026: What SMEs Must Label Now securitytodaySelf-Replication: AI Agents Jump from 6 to 81 PercentImage source: AI-generated (June 2026), C2PA certificate embedded in image