General Counsel and the New Centre of Gravity in AI Governance
ArticleWe explore how General Counsel have become the most operationally literate professionals in the legal AI governance conversation.

Across our conversations with General Counsel over recent months, a consistent assumption has taken hold: that the EU AI Act's most significant obligations have been pushed comfortably into the future, and that compliance planning can now be deprioritised as a result.
That assumption is half right, and the half that is wrong matters. The high-risk deadline has genuinely moved — but the move is now confirmed law, with fixed new dates, not an open-ended reprieve. This briefing sets out exactly what has changed, what has not, and where organisations are most likely to misjudge the position, including organisations based entirely outside the EU.
The EU AI Act's scope is broader than many UK and internationally headquartered organisations appreciate. It applies not only to providers and deployers established within the EU, but to providers and deployers located anywhere in the world where the output of an AI system is used within the EU. It applies to importers, distributors and authorised representatives dealing with AI systems placed on the EU market. For any organisation with EU clients, EU operations, EU subsidiaries, or AI-generated output that ultimately reaches EU end users, the Act is not a foreign regulatory development to be monitored from a distance. It is a live compliance obligation.
The AI Act entered into force on 1 August 2024, with a staggered implementation timetable. Chapters I and II, covering general provisions and prohibited AI practices, have applied since 2 February 2025. Provisions on general-purpose AI models, governance and penalties have applied since 2 August 2025. Neither of these dates has changed.
What has changed is the timetable for high-risk AI systems under Annex III — historically the obligations that matter most for the majority of corporates, covering conformity assessments, risk management systems, human oversight requirements and documentation obligations. Concern about implementation readiness across the market — incomplete harmonised standards, unfinished Commission guidance, and Member States still designating national supervisory authorities — led the European Commission to table a Digital Omnibus proposal in November 2025. The Council and Parliament reached political agreement on the package in May 2026, and formally adopted it shortly afterwards.
That agreement is no longer a proposal. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal of the European Union on 24 July 2026 and entered into force on 27 July 2026 — six days ahead of the original 2 August 2026 deadline. It is enacted EU law.
This matters because the deferral agreed is a fixed backstop, not an open-ended one. Earlier drafts of the mechanism would have tied the new application date to a future Commission decision confirming that standards and conformity assessment infrastructure were genuinely ready — a formulation that left the effective timeline contingent and unpredictable. The final text instead sets firm new dates that apply regardless of further Commission action.
The substantive requirements for high-risk AI systems under Annex III have not been cancelled, reduced or rewritten. What has changed is when they take effect:
“The deferral is enacted law, not a live proposal, and it sets fixed dates rather than a conditional trigger. The open question for boards is no longer whether the deadline moved — it is whether the additional runway gets used well.”
It is worth noting, for completeness, that several obligations are proceeding on schedule irrespective of the high-risk systems question. The Omnibus package introduces a new prohibited practice banning AI systems that generate non-consensual intimate imagery, alongside a parallel prohibition on AI-generated child sexual abuse material, taking effect on 2 December 2026. At the same time, the grace period for providers to implement transparency solutions for AI-generated content has been shortened from six months to three, with the revised deadline also landing on 2 December 2026. Neither of these is affected by the high-risk deferral, and organisations should continue tracking them on an unchanged, near-term timetable.
The overall regulatory picture is not one of general relief. It is one of redistributed urgency.
The most consequential change in the Omnibus is not the new date — it is what organisations do with the sixteen months (for Annex III) or twenty-five months (for Annex I) of additional time. A deferral of the application date is not a deferral of the underlying obligations: conformity assessment, risk management systems, human oversight design and technical documentation still need to be built, and the market infrastructure that prompted the deferral in the first place — harmonised standards, notified bodies, national market surveillance authorities — is still catching up.
Organisations that treat the extension as a reason to stand down compliance resourcing, rather than as additional time to do the work properly, are likely to find themselves in the same position in late 2027 that they would otherwise have faced in mid-2026 — except with less institutional urgency behind the effort by then. We would recommend against reallocating budget or headcount away from Annex III readiness on the strength of this deferral.
We recommend re-baselining Annex III high-risk compliance planning to 2 December 2027, and Annex I planning to 2 August 2028, treating both as confirmed dates rather than provisional ones. We recommend using the additional time deliberately — to complete conformity assessment preparation, finalise technical documentation and human oversight design, and track the maturing landscape of harmonised standards — rather than as a basis for deprioritising the work. We also recommend keeping the 2 December 2026 obligations relating to prohibited practices and transparency on an unchanged, near-term timetable, since these are proceeding independently of the high-risk deferral. For organisations operating across the UK, EU and other jurisdictions simultaneously, we would recommend a short internal audit of which entities, systems and use cases actually fall within the Act's territorial scope — a question that is frequently assumed rather than properly tested.
General Counsel are, once again, the professionals expected to translate a shifting regulatory timetable into a defensible position for their boards. We would welcome the opportunity to discuss what this means for your organisation specifically, including a review of your current AI systems against the Act's territorial scope, high-risk classification, and revised compliance runway.
If this would be useful, please reach out to Melina Efstathiou, Managing Director of Legal Data Intelligence and AI Governance Expert at Grant Thornton, to arrange a conversation.
We explore how General Counsel have become the most operationally literate professionals in the legal AI governance conversation.