Regulatory Deadlines Are Slipping. International Standards Are Not.
One of the most closely watched compliance regimes stepped back from its own enforcement timeline. In Europe, the co-legislators of the EU AI Act adopted the Digital Omnibus on AI in late June, a package that will defer the compliance dates for high-risk AI systems once it is published in the Official Journal.
A reasonable leader could read that as a signal to slow down, but that would be a mistake. A pause in enforcement mechanics doesn’t mean the underlying requirements have gone away, and that is the difference between treating a regulatory pause as a reprieve and recognizing it as a runway.
Regulators defer the timeline, not the obligation
The Digital Omnibus defers enforcement dates. It does not change what the law requires. The European Parliament approved it on June 16, 2026, and the Council formally adopted it on June 29, 2026. The amendment still has to be published in the Official Journal before taking effect, which is expected in the weeks around the original deadline.
Once in force, it moves the compliance date for standalone high-risk systems under Annex III from August 2, 2026, to December 2, 2027, and for high-risk AI embedded in regulated products under Annex I to August 2, 2028.
The change does not reclassify a single system. A recruitment screening tool or a credit-scoring model that qualified as high-risk before the amendment still qualifies after it.
Two points hold regardless of the amendment:
- Until the Omnibus is published in the Official Journal, the original August 2, 2026 high-risk date remains in force as written.
- The obligations the Omnibus does not touch are unaffected, including the Article 50 transparency duties that apply from August 2, 2026, and the general-purpose AI model obligations that have applied since August 2025.
The market keeps its own calendar
Regulation is one source of demand for assurance, but for most organizations it is not the most pressing one.
Buyers, insurers, boards, and investors have to price the risk of the counterparties they depend on, and that need does not stall because a regulator moved a date. A procurement team still has to decide whether an organization can be trusted with its data. An enterprise customer still has to answer its own auditors, its own regulators, and its own board.
When a mandate slips, the private demand it was meant to formalize does not slip with it. In many cases, it sharpens. A deferred deadline removes the comfortable assumption that every competitor will hold the same credential. The organization that can demonstrate independent assurance while its peers wait for the compliance date is no longer meeting a baseline, it is holding a competitive differentiator.
Why ISO 27001 and ISO 42001 hold their value through a delay
This is where ISO 27001 and ISO 42001 do work that a moved regulatory deadline cannot undo.
Both are management system standards rather than point-in-time attestations built on the same harmonized high-level structure, certified by an accredited certification body, and maintained across an annual surveillance cycle. The evidence they produce is continuous and independently validated, which is precisely the assurance value the market actually wants.
ISO 27001 is the established information security management system, recognized in procurement across nearly every market. Its control set maps closely to major security compliance frameworks, since most build from the same core practices: access control, risk assessment, incident response, continuous monitoring. When a regulatory verification mechanism is suspended or deferred, a certified organization still holds an internationally recognized, independently audited attestation that its security management system functions.
ISO 42001 is the counterpart for artificial intelligence, the first certifiable AI management system standard. An organization certified to it already operates the governance structures, risk processes, and many of the lifecycle controls that the EU AI Act’s high-risk obligations will require when they apply. A deferral to 2027 does not lower that bar. It converts a delay into runway. A certified organization will spend the additional months compounding maturity, while others treat the new date as a reason to wait and then compress the same work into a shorter window closer to enforcement.
Certification does more than satisfy a regulator
Most discussion of these standards stops at the internal benefit, but an accredited certificate is also an external instrument:
It clears procurement. An accredited certificate is a portable claim that a buyer’s vendor-risk function can accept without re-auditing an organization from the ground up. It shortens sales cycles and clears the security review that stalls most enterprise deals.
It establishes category position. Legitimacy accrues to whoever moves first. A firm certified while its peers wait for a deadline becomes the trusted option in its segment by default, a standing that is difficult for a latecomer to reclaim.
It substantiates claims and reduces exposure. Independent, evidence-based validation gives an organization documented support for the assurances it makes to customers and regulators, no matter which enforcement calendar is in effect.
It outlasts the cycle. A management system is structural, so it survives leadership turnover, regulatory reversal, and shifting market conditions. It does not depend on a single champion or a news cycle to stay in place.
Governance, audits, and assessments are distinct disciplines
Certifying to ISO 42001 assures an organization’s AI governance and responsible AI management practices. It is not a model audit, and on its own, it is not an impact assessment.
A mature program runs all three as distinct, but integrated, disciplines. The management system provides accountability, algorithm and model audits test the behavior of specific systems, and Impact assessments, now supported by ISO/IEC 42005, evaluate consequences for the people a system affects. Certification gives an organization the frame that the other two hang on. A-LIGN’s AI Governance practice is built around keeping these disciplines distinct while making them work together.
What to do during a regulatory pause
A moving deadline changes the enforcement calendar. It does not change the underlying work. Companies positioned to benefit from the next enforcement wave should:
- Keep building the management system. ISO 27001 and ISO 42001 implementation supports every plausible regulatory outcome because the controls address the underlying risk rather than a specific deadline.
- Pursue or maintain certification now. A delay is the lowest-pressure window to complete an assessment, before competition for assessor capacity and executive attention returns.
- Treat the delay as runway. Use the additional time to reach real maturity, not to defer the effort into a shorter and more expensive window later.
- Keep evidence current. Certification is sustained through annual surveillance cycles. Maintaining accurate, objective evidence between audits is what keeps the credential meaningful.
- Hold assurance investment steady. Reducing security or governance spend because a program review has not concluded, or because an amendment is not yet published, trades a durable advantage for a short-term saving.
How A-LIGN can help
A-LIGN is an accredited certification body that supports organizations across ISO 27001 and ISO 42001, from initial scoping and readiness through certification and ongoing surveillance. Our teams can help evaluate how a regulatory delay affects a scheduled engagement, sequence a multi-framework program, and turn an enforcement pause into your maturity advantage.
Organizations weighing how to position their assurance strategy through a shifting regulatory calendar are encouraged to contact A-LIGN today.


