Zero-Day Dawn

Zero-Day Dawn

Standards Delay, Omnibus "Simplification": Cui Bono?

Why the legislator needs the delay more than you do

Violeta Klein, CISSP, AIGP's avatar
Violeta Klein, CISSP, AIGP
May 17, 2026
∙ Paid

Executive Summary

The European Commission has framed the Digital Omnibus as a simplification package — competitiveness, red-tape reduction, alignment with the Draghi agenda. The framing is accurate at the level it operates on. It is also incomplete.

The infrastructure required to enforce the EU AI Act does not exist in its intended form. The harmonized standards underpinning the high-risk obligations are not ready. None has been cited in the Official Journal. FprEN 18286 on quality management is closest, at Formal Vote, with publication possible in July 2026 and citation later. prEN 18282 on cybersecurity and prEN 18228 on risk management are at Enquiry. prEN 18229-2 on accuracy and robustness trails behind. Adam Leon Smith’s tracking of the JTC 21 process documents the pipeline status in detail. The earliest realistic citation lands in the second half of 2026, and several standards will not be cited before the new delayed entry into force.

The certification market has been selling around this gap for two years. “Aligned to prEN 18286.” “Compliant with the harmonized cybersecurity standard.” “ISO 42001 certified.” Each of these phrases describes work that does not, in fact, deliver presumption of conformity under the AI Act. Presumption of conformity applies the moment the European Commission cites a harmonized standard in the Official Journal of the European Union, and not a day before. ISO 42001 is not a harmonized standard. ISO 42001 is structurally incompatible with the AI Act's product-conformity architecture — a gap analyzed in JRC 139430.

By delaying high-risk obligations to December 2027 and August 2028, the Omnibus frames this delivery failure as a procedural adjustment. The recital lists the missing standards and the missing national infrastructure as the reasons. The framing is accurate. It is also doing political work.

That is the procedural read of the situation. It is the comfortable one. The structural read is harder to publish, so it does not get published at all.

This post is for paid subscribers

Already a paid subscriber? Sign in
© 2026 Quantum Coherence LLC · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture