The Trilogue Failed. The Deadline Did Not.

  • Hook type: Breaking regulatory event (Brussels trilogue failure, 28 April 2026)
  • Opening stat: EU AI Act Annex III deadline 2 August 2026: 94 days from publication date
  • Strategic intent: Reframe EU AI Act compliance from regulatory overhead to production investment; establish Sovereignty Agility as the correct response posture for NZ practitioners
  • Cross-series callbacks: Part 9 (Sovereignty Agility, executed); EA Thursday Ch 12 (agentic asset register as implementation layer, executed inline)
  • NTP claim scan: 18 e-type claims (17 confirmed, 1 Likely: UK £500M fund -- "reportedly" framing applied); 3 n-type claims (Sovereignty Agility framework; agentic asset register compliance pattern; Heaven/Skynet structural application). No unverified entities. Existence-Predication Firewall: clear.
  • PSC flag summary: Four NZ government sources (MBIE, GCDO, OPC, DPMC) used descriptively. Validation Trap check applied to NZ light-touch posture framing: descriptive throughout, no adequacy evaluation. DPMC regime framed as proposed and not enacted.

Gen AI Tuesday -- Part 16 of 35

Navigation: [Part 15: The Agentic Enterprise Has Arrived] | [Part 17: Coming 12 May]


On 28 April 2026, after approximately twelve hours of negotiations in Brussels, the political trilogue on the EU Digital Omnibus on AI collapsed. Three parties: the European Parliament, the Council of the EU, and the European Commission. One unresolved issue. Zero agreement.

The immediate consequence for anyone managing EU AI Act compliance: the planning assumption that has underpinned most enterprise AI governance conversations since late 2025 is no longer valid. The Digital Omnibus was the vehicle for pushing the Annex III high-risk AI compliance deadline from 2 August 2026 to 2 December 2027. That extension has not passed. Until it does, and until agreement is published in the Official Journal of the European Union, 2 August 2026 is the only legally operative deadline under Regulation (EU) 2024/1689.

Ninety-four days from the date this article publishes. For organisations treating the extension as a planning certainty, this is not a regulatory development to monitor on a watchlist. It is a posture change to make this week.

It applies to New Zealand businesses too.


What Broke Down

The Digital Omnibus on AI, proposed 19 November 2025, had a specific technical and political purpose: simplifying the EU AI Act's overlapping obligations with existing product safety directives covering medical devices, in-vitro diagnostics, machinery, and toys.

The dispute that collapsed the 28 April talks came down to Annex I conformity assessment architecture. For AI systems embedded in regulated products, Parliament and Council could not agree on the assessment structure. Parliament pushed to move these systems to Section B, meaning compliance governed entirely by the relevant sector-specific safety law. Council wanted dual requirements: compliance with both the AI Act and the applicable sector directive. Twelve hours of negotiations produced no resolution.

A follow-up trilogue is scheduled for approximately 13 May 2026. The Cypriot Council Presidency ends 30 June; Lithuania takes over 1 July. If agreement is reached in May and the Official Journal publishes promptly, the extension could still apply before August. That is the optimistic path. It is also the path that cannot be planned against until it is in print.

As the IAPP stated on 1 May: "Until then, it's status quo. The AI Act was already passed into law and enforcement of high-risk systems starting 2 Aug. 2026 still stands." DLA Piper's assessment, published 29 April, advised that organisations deploying AI in employment-related contexts should treat the existing August deadline as the operative planning horizon and continue compliance preparations accordingly.

The organisations now at risk are those that interpreted "the Omnibus is likely to pass" as equivalent to "the extension is confirmed." It was never confirmed. The original law applies until the amendment is published.


What 2 August 2026 Actually Requires

The EU AI Act's compliance architecture is staged. Most of it is already in force.

The Article 5 prohibitions on unacceptable-risk AI, including subliminal manipulation and real-time biometric identification in public spaces for law enforcement, have applied since 2 February 2025. Obligations for providers of general-purpose AI models have applied since 2 August 2025.

What arrives on 2 August 2026 is the full compliance burden for Annex III high-risk AI systems. This is the category that matters for most enterprise practitioners.

Annex III classifies AI systems as high-risk based on the context of use, not the technology. The categories: biometric identification; critical infrastructure management; education and vocational training; employment and worker management; access to essential services including private credit, public benefits, and emergency services; law enforcement; migration, asylum, and border control; administration of justice. If your system operates in one of these domains, the technology stack is secondary. The use case triggers the obligation.

The obligations that apply to providers from 2 August include:

Article 9: Risk management as an ongoing, documented, evidence-based process. Not a one-time assessment. Not a point-in-time checklist. A continuous process with documented outputs.

Articles 10 to 12: Data governance for training and validation data; technical documentation completed before market placement; record-keeping and logging of high-risk system operation.

Articles 13 to 14: Transparency and information provision to deployers; and human oversight as native architecture. The human oversight requirement is the one most often misunderstood. It does not mean a human reviews outputs occasionally. It means the system is designed from the start so that a human can understand, intervene, and correct the system's operation. Bolted-on review processes do not satisfy Article 14.

Article 15: Accuracy, robustness, and cybersecurity requirements appropriate to the intended purpose.

For deployers, not only providers, the obligations are real. If you are an organisation deploying a third-party high-risk AI system for use by EU residents, Articles 26 to 28 apply: follow provider instructions; ensure intended use is maintained; designate a responsible person; register in the EU database; report serious incidents to national market surveillance authorities.

Article 50 deserves separate attention. The transparency obligations were not in substantive dispute in the trilogue, and they apply from 2 August 2026 regardless of whatever the Omnibus eventually does. If your organisation is launching any AI system that generates synthetic content visible to EU users on or after 2 August, disclosure obligations, content labelling, and deepfake identification requirements apply from day one. Modulos confirmed on 30 April that as of that date, no delay had been adopted and the original deadlines in Regulation 2024/1689 continue to apply. Content marking and watermarking capabilities need to be production-ready before 2 August, not after.


Who Is Actually in Scope

The EU AI Act's territorial reach mirrors the GDPR logic most NZ exporters and technology vendors have been managing for years. The compliance obligation follows the user, not the vendor. Any organisation whose AI system is used within the EU, or that produces outputs affecting EU residents, is in scope regardless of headquarters location.

For NZ practitioners, this is not a theoretical exposure.

Consider a NZ SaaS vendor running an AI-assisted HR platform. If that platform is used by an EU customer to make hiring, promotion, or performance management decisions affecting EU residents, the system may fall within Annex III's employment and worker management category. No EU offices required. No EU legal entity required. The obligation attaches to the use case and the user location.

Consider a NZ healthcare AI provider with clinical decision-support tools deployed in EU health systems. Access to essential services, and depending on the use case, education and vocational training may both apply.

Consider a NZ manufacturer exporting AI-assisted equipment subject to EU machinery directives. This is precisely the Annex I category that broke the trilogue. Until the Omnibus resolves the dual-compliance question, the conservative and legally defensible position is to assume both the AI Act and the relevant product safety directive apply.

The NZ domestic picture adds another compliance layer. The algorithmic transparency obligations that took effect 1 May 2026 mean that agentic AI systems aggregating personal information from third-party sources now carry a domestic compliance obligation alongside any EU AI Act exposure. These are separate legal requirements with separate compliance architectures. They share a common root: the need to know what your AI systems are doing, what data they are processing, and who is affected.

NZ's national AI strategy, as set out in the MBIE "Investing with Confidence" document published July 2025, maintains a principle-based approach relying on existing legislation: the Privacy Act, the Fair Trading Act, the Commerce Act, and the Human Rights Act, aligned with OECD AI Principles. There is no bespoke NZ AI legislation on the current legislative programme. This creates a practical asymmetry for NZ exporters: no domestic high-risk AI compliance obligation comparable to the EU's, but real EU-market exposure for any NZ business placing AI systems or outputs in scope.

A further development worth noting for risk-aware practitioners: the DPMC's proposed regime for critical infrastructure cyber security, with consultation that closed in April 2026, includes mandatory risk management programme requirements. If enacted, a requirement to meet an internationally recognised framework would functionally push designated entities toward governance practices structurally similar to EU AI Act Article 9 standards, independent of direct EU exposure. NZ practitioners managing compliance timelines for EU AI Act and the proposed DPMC regime simultaneously are working toward the same architectural destination from different starting points: documented, auditable, ongoing risk management with human oversight as a design requirement rather than a policy aspiration.

The UK contrast clarifies the landscape without simplifying it. In the same week as the trilogue failure, the UK government reportedly announced a £500 million sovereign AI fund and a national semiconductor plan, framing AI development as a national industrial sovereignty imperative. The EU and UK are not two governments taking different positions on the same question. They are answering different questions. The EU: AI as regulated risk requiring mandatory compliance architecture. The UK: AI as industrial sovereignty requiring public investment. NZ: AI as a productivity tool with an existing legislative backstop and growing export exposure.

For NZ practitioners assessing which regulatory environment to plan for: given NZ's export patterns and the scale of EU-market exposure for SaaS vendors and manufacturers, the EU compliance architecture is likely the more immediately material planning question.


The Sovereignty Agility Response

Part 9 of this series introduced Sovereignty Agility: the ability to adapt AI architectures quickly to regulatory changes or vendor shifts. The Omnibus failure is exactly the stress test that concept was built for.

Organisations that maintained compliance readiness, rather than deferring against the Omnibus, are protected. They have not wasted the past six months. They have built governance infrastructure that serves two purposes: it satisfies the 2 August obligations if the Omnibus does not pass in time, and it accelerates production deployment regardless of what the Omnibus does.

The production case for compliance investment is now empirically supported. Databricks' State of AI Agents research, drawing on data from more than 20,000 customers, found that organisations with AI governance tools push twelve times more AI projects to production than those without. Twelve times. Not a marginal improvement. A structural one.

The governance infrastructure that EU AI Act compliance demands, specifically Article 9's ongoing risk management documentation and Article 14's native human oversight architecture, is not separable from the infrastructure that makes agentic AI deployments succeed in production. The compliance discipline and the production discipline are the same discipline.

This is the reframe that boards and technology leaders need. Every procurement cycle involving AI governance tooling faces the same challenge: the cost is visible today, the benefit is a future state that may or may not materialise. The EU AI Act changes that calculation. The compliance benefit arrives on a specific date with legal certainty. The production benefit, per the Databricks data, is not hypothetical: it is the current operating reality of organisations that have already built governance infrastructure. Both benefits are on the table simultaneously.

EU AI Act compliance is not a cost imposed by Brussels on organisations that happen to have EU customers. It is governance investment that makes AI deployments safer, more auditable, and more scalable, with EU compliance certification as a byproduct. Build the governance infrastructure to the production standard. Annex III compliance becomes a byproduct of doing the work properly.


The Technical Baseline: What Compliance Infrastructure Looks Like

For practitioners assessing what compliance work actually involves, the agentic AI case is instructive because it makes the requirement concrete.

The operational compliance pattern converging around Articles 9 and 13 for agentic systems involves several components: unique agent identifiers linked to documented capabilities and permission boundaries; cryptographic action signing producing an immutable audit trail; centralised verbose logging that is distinct from the per-platform text logs native to most orchestration tools; role-based permission enforcement at the action level rather than at the session level; rapid revocation capability that can be exercised without redeploying the system; and human oversight gates built into the architecture, not added as a review layer around it.

The last point is where Article 14 becomes operationally specific. The regulation requires that high-risk AI systems are designed so that natural persons can monitor the system's operation and can intervene to correct or halt it. This is a design requirement, not an operational policy. A policy that says "a human will review outputs weekly" does not satisfy Article 14. The standard is a system designed so that a human can see what the system is doing, understand why, and intervene in real time.

A recent technical audit of five major AI frameworks, scanning more than 19,000 files across each codebase, found one leading agentic framework carrying 56 instances of autonomous operation loops without native confirmation gates. According to Regula's technical audit, published 26 April 2026, under Article 14 the compliance burden for any system deployed without human oversight built natively shifts entirely to the end-implementer. If the vendor platform has not built oversight into the architecture, your organisation carries that compliance requirement. The vendor's Annex III conformity assessment does not indemnify your deployment.

This is the practical consequence of the provider-deployer distinction. Annex III compliance is not solely a vendor problem. It is a deployment-layer problem. The question for every organisation deploying agentic AI in any Annex III category is whether the oversight is built in or bolted on. Article 14 requires the former.

EA Thursday this week examines what the agentic asset register looks like as enterprise architecture: agent identifiers, permission boundaries, and action signing as deployable patterns. This article provides the compliance demand that makes that architecture non-optional.


Thirteen Weeks: What to Do Now

The follow-up trilogue is scheduled for approximately 13 May 2026. If agreement is reached and the Official Journal publishes promptly, the extension could still apply before 2 August. That is the scenario to plan toward, not plan against.

Three questions worth working through this week.

First: scope assessment. Which of your AI systems are potentially in scope under Annex III? Run the assessment against use-case categories, not the technology stack. An AI system used in employment decision-making is potentially in scope regardless of whether it runs on a major platform or a purpose-built model. The category question is about what the system does, not how it works.

Second: documentation readiness. For systems potentially in scope, do you have the documentation that Articles 9 and 11 require? Risk management documentation and technical specifications are not documents produced overnight. They reflect an ongoing process. If you cannot demonstrate the process, the deadline finds you exposed.

Third: Article 50 launch inventory. Which of your AI systems generate content visible to EU users and are launching on or after 2 August 2026? The transparency and labelling obligations attach to the launch date. Systems launched before 2 August have different transition arrangements; systems launching on or after are immediately subject to Article 50 requirements from day one of operation.

The Omnibus may still pass. The May trilogue may reach agreement, Lithuania may move quickly, and the Official Journal may publish before 2 August. But until agreement is published, the only legally operative deadline is 2 August 2026.

Planning against a confirmed extension that has not been confirmed is not a risk strategy. It is exposure.

What compliance gap would your organisation discover if you ran this assessment today?


The views expressed in this article are entirely my own, informed by more than 30 years of professional experience in architecture, security, and technology leadership in New Zealand. They do not represent the views of my employer, any government agency, or the New Zealand government. My commentary on legislation and policy is analytical, drawing on publicly available sources and my professional expertise in architecture, security, and AI governance. I follow the Public Service Commissioner's Code of Conduct for the Public Sector and social media guidance.


Andreas Hamberger is an enterprise architect and technology leader based in Wellington, Aotearoa New Zealand, with more than 30 years of experience in mission-critical platforms, open-source deployment, and responsible AI governance. He holds TOGAF, IAPP, and AMInstD credentials and is a publicly identified New Zealand leader in architecture and security. The Hamberger Report: Generative AI 2026 provides enterprise leaders with evidence-based analysis of the AI landscape.


I use AI tools, including Sudowrite, Claude, Perplexity AI, DeepSeek AI, ChatGPT, Grok, Copilot, Openart and Gemini, as deliberate production tools, not ghostwriters. This is consistent with my position: AI amplifies human judgement; it does not replace it. The frameworks, arguments, and editorial decisions in this series are original work. AI accelerated the process. The thinking is mine.


[1] IAPP. "EU AI Act Digital Omnibus Breakdown: What It Means for Practitioners." 1 May 2026. https://iapp.org (search: Digital Omnibus AI Act April 2026)

[2] DLA Piper GENIE. "EU AI Act Digital Omnibus: Trilogue Talks Collapse." 29 April 2026. https://www.dlapiper.com/genie

[3] Modulos. "EU AI Act Update: Omnibus Talks Fail, Original Deadlines Stand." 30 April 2026. https://modulos.ai

[4] The Next Web. "EU AI Act Omnibus Fails in Trilogue." 29 April 2026. https://thenextweb.com

[5] European Union. Regulation (EU) 2024/1689 (EU AI Act). Official Journal of the European Union, 12 July 2024. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R1689

[6] Databricks. "State of AI Agents." January 2026. https://databricks.com

[7] Regula. "AI Framework Security Audit: v1.7.0 Findings." 26 April 2026. https://regulaforensics.com

[8] MBIE New Zealand. "Investing with Confidence: New Zealand's National AI Strategy." July 2025. https://www.mbie.govt.nz

[9] DPMC New Zealand. "Critical Infrastructure Cyber Security: Consultation Document." February 2026. https://www.dpmc.govt.nz

[10] Pearl Cohen. "EU AI Act Annex III Compliance Guide for Deployers." December 2025. https://www.pearlcohen.com

Previous
Previous

Adoption Theatre: Why 67% of Executives Already Know AI Has Caused a Breach

Next
Next

THE AGENTIC ENTERPRISE HAS ARRIVED: WHAT APRIL 2026 TELLS US ABOUT THE IMPLEMENTATION GAP