EU legislators gave final approval to the Digital Omnibus in late June, deferring the AI Act’s high-risk obligations for standalone (Annex III) systems from August 2, 2026 to December 2, 2027, with AI embedded in regulated products pushed to August 2028. Security teams shouldn’t read this as a pause. First, August 2, 2026 remains live: Article 50 transparency obligations for AI-generated content largely proceed on schedule. Second, the high-risk obligations themselves are unchanged, dictating continuous risk management, adversarial-attack resilience, human oversight, and audit logging. All will apply to AI systems your SOC both defends and operates. Auditors, insurers, and enterprise customers are already using the framework as a due-diligence baseline, deadline or not. The practical move for 2026: inventory where AI systems touch your security operations, and confirm you can reconstruct and evidence what any AI system did and why. That capability takes longer to build than a compliance memo.