When the EU Council and Parliament reached political agreement on the "AI omnibus" package on 7 May 2026, most compliance teams updated their calendars and exhaled. The rules for high-risk AI systems embedded in critical infrastructure — the kind that powers aircraft navigation, ground vehicle automation, and defense logistics — were extended. Systems used in critical infrastructure areas now have until 2 December 2027 to comply with the full high-risk obligations.
That's a meaningful runway extension. But if you're a defense OEM, treating December 2027 as your actual deadline is a governance trap.
The Part That Didn't Move
While the AI omnibus deal extended the embedded-AI deadline, the EU AI Act's transparency obligations stayed exactly where they were. The European Commission's own regulatory page is unambiguous: "The transparency rules of the AI Act will come into effect in August 2026."
August 2, 2026 is 25 days away.
Transparency rules cover more than chatbot disclosure banners. They govern when users must be informed they're interacting with AI, when AI-generated content must be labeled, and — critically for defense contractors — disclosure requirements around AI systems that surface recommendations to human operators. An AI-assisted intelligence summary presented to an analyst is not a product embedded in a machine. It's an AI output in a human decision chain. The August 2 deadline applies.
Two Tiers, Two Clocks
The omnibus deal created a clear two-tier compliance timeline:
Tier 1 — Transparency and disclosure: August 2, 2026 (unchanged)
This covers AI systems where humans interact with AI outputs — recommendations, generated content, decision aids. Every defense AI tool that puts an LLM-generated output in front of an operator is in scope. Twenty-five days.
Tier 2 — Stand-alone high-risk systems (Annex III), including critical infrastructure: December 2, 2027
The Commission specifically called out "AI safety components in critical infrastructures (e.g. transport), the failure of which could put the life and health of citizens at risk" as the category that falls here. The AI stack that controls physical systems, optimizes routing, or takes autonomous action on sensor data gets 17 months.
If your AI system is a stand-alone high-risk system under Annex III — critical infrastructure, employment, essential services — you're in Tier 2. If it is a safety component embedded in a regulated product under Annex I, you're in Tier 3 and have until 2 August 2028. If your engineers use AI tools that surface outputs to humans before action, you're in Tier 1.
Tier 3 — High-risk AI embedded in regulated products (Annex I): August 2, 2028
Safety components inside products already covered by EU product legislation — machinery, aviation, medical devices — move on the later date.
Most defense prime programs have both.
The Data Boundary Is the Common Thread
Here's the governance problem the timeline extension didn't solve: both tiers require you to know where AI is touching your data.
Tier 1 transparency requirements assume you can document what AI systems are in use and where their outputs enter human decision chains. Tier 2 risk assessment requirements assume a complete inventory of what data feeds each embedded system. Neither assumption holds at a defense prime with thousands of engineers who have a frontier model open in a browser tab alongside their program work.
The EU AI Act omnibus extended the compliance deadline for the AI stack you've already inventoried. It didn't extend any relief for AI usage that's invisible to your governance program — the model queries that carry context about schedules, designs, and technical specifications outside your perimeter every day.
That's not a December 2027 problem. It's an August 2026 problem. And it's the gap that no GRC platform's AI framework extension covers, because closing it requires enforcement at the point where data crosses the boundary — before it reaches the model.
What Evidence Looks Like Under Both Tiers
Both the August 2 transparency obligations and the December 2027 high-risk requirements converge on the same evidence standard: a documented record of what AI was used, on what data, under what policy, by whom, and when. The difference is urgency, not architecture.
For defense primes with EU program exposure, the governance layer that satisfies both tiers isn't a compliance checklist. It's a real-time control point that generates a signed, immutable receipt at every enforcement boundary — the kind of audit trail that answers a regulator's inquiry with a retrieval, not a reconstruction.
The omnibus deal bought time on the embedded-AI stack. The data boundary — the layer that governs what your engineers send to models they don't own — is on the August clock.
Containment.AI builds deterministic, policy-enforced AI governance for defense and aerospace environments. If you're assessing your EU AI Act posture for programs with EU exposure, start with a conversation about your data boundary.