Brussels Just Moved the Deadline. Sovereignty Moved the Goalposts.
- By Winston Thomas
- August 10, 2026

On Aug. 2, 2026, every chatbot in Europe had to start confessing. Deepfakes needed labels. Machine-generated content needed machine-readable marks. Skip it, and the bill runs to EUR15 million or 3% of worldwide annual turnover, whichever is higher.
The algorithm screening résumés and scoring credit? It got 16 more months.
That is the E.U. AI Act now: two clocks, running at different speeds. Regulation (EU) 2026/1744 (the AI Digital Omnibus) was published July 24 and entered into force July 27, 2026, five days before the deadline it was rewriting. Annex III high-risk obligations moved to Dec. 2, 2027. AI baked into regulated products moved to Aug. 2, 2028. Article 50 transparency did not move at all.
Kalliopi Spyridaki watched that negotiation up close. As chief privacy strategist for EMEA and Asia Pacific at SAS, she sits on the company’s internal AI oversight committee. She also leads AI policy for DIGITALEUROPE, the association representing the technology industry in Brussels.
She was not surprised. “It was expected that they would agree actually to push back the high-risk deadline,” she says in a recent interview with CDOTrends on the sidelines of SAS Innovate On Tour in Singapore. “And that is the reason why you may have also heard of the data omnibus that came at the same time. They split the data and the AI omnibus because they really wanted to push back the deadline for high risk.”
Transparency was never the hard part. “I don’t think that transparency was as much of an operational complexity,” she says. "The focus was on high risk.”
The delay is runway for the regulator
So, CDOs have a breather — or do they? Spyridaki explains that the 16 months are not really a gift to industry; they are time for Brussels to finish the guidance it has not finished writing.
Her team ran into that while preparing input for the consultation on the high-risk guidelines. “A number of times we went back and forth because what we actually wanted to be clarified was the law itself,” she says. “We would have wanted the AI definition to be different. We would have wanted the intention to be used in certain ways, and that is in the law — that cannot change. So I don’t know how much the guidelines can do to clarify what has already been put in hard law.”
CDOs also need to pay attention to the lack of vocabulary. “Frontier AI” and “generative AI” appear nowhere in the AI Act. Both, along with “AI agent,” turn up in the Cloud and AI Development Act the Commission tabled on June 3. Brussels wrote sharper definitions for a law that does not exist yet than for the one it started enforcing this month.
“It’s not easy to regulate AI and keep pace with what’s happening from the technology perspective,” Spyridaki says.
She is not writing off the framework, though. The durable parts, she argues, were never in dispute: "Some of the fundamental principles around data governance, around model governance, around transparency, accuracy of outcomes, and monitoring throughout the entire life cycle, those are not going to change, whether it’s frontier AI or quantum AI in five years’ time."
That is the sentence to build a roadmap on and not the deadline.
What Article 50 actually looks like on Monday
The obligation that landed is the one most CDOs underestimated, because it reaches nearly everyone. Any system that interacts with a person has to disclose that it is a machine. This includes synthetic audio, image, and video, which need labeling. Generative output needs machine-readable marking. Generative systems already on the E.U. market get until Dec. 2, 2026 for the marking piece; new ones do not. And open-source systems are not exempt.
Spyridaki’s framing is the one to carry into a board meeting, because it strips out the mystique.
“Things like nutrition labeling are kind of the equivalent,” she says. “You have a product, or you have a process; you have to be able to describe ‘this is what’s here’ and make sure that people are not mistaken.”
“You have a product, or you have a process; you have to be able to describe ‘this is what’s here’ and make sure that people are not mistaken.” – Kalliopi Spyridaki @ SAS
For CDOs who are mostly the AI deployers, the technical burden is lighter than it sounds and the process burden is heavier. “Perhaps the technology isn’t there, and the standards around watermarking aren’t out there,” she says, “but it’s the question of putting processes in place to make sure that you are transparent about the use of AI.”
In other words, the law makes it a disclosure inventory problem before it is an engineering problem. Which customer-facing systems touch a human? Which ones generate content? Who signs off that the label is there? If you cannot answer that in a morning, Article 50 is already a live exposure. It means that the AI Office gained the power to compel documentation and issue fines on the same day the rule landed.
Get closer to counsel — and keep moving
Ask Spyridaki what a data chief should change because of the Omnibus, and the answer is bracing. “I wouldn’t really think about it that way if I was a CDO. Not at all.”
The Omnibus did soften Article 4, converting AI literacy from a duty to ensure competence into a duty to support its development. That matters to lawyers, but it should change nothing operationally. “For a responsible company, they will have already started putting that obligation in place like we did,” she says. “There is no reason to not continue with that obligation because it’s useful for your organization, it’s useful for the ecosystem, and it creates trust with your customer.”
Her practical advice is to get closer to legal counsel as a partner in adoption, and not as a gatekeeper. The distinction matters, and her own career is the argument for it. Two decades running public policy and legal counseling side by side have taught her that a CDO and legal counsel should be a team. A CDO who waits for the regulatory picture to resolve fully will wait past the point where adoption is worth anything; one who moves without counsel in the room inherits the liability alone.
“I truly don’t think that organizations were waiting for this extension,” she says. “They have already been preparing.”
The two S’s
Enforcement is already running ahead of the rulebook. The new Article 5 ban on AI-generated intimate imagery does not apply until Dec. 2, 2026, yet Hugging Face landed on the Commission’s radar on July 30, 2026.
Spyridaki reads that through a wider lens. “A lot of these announcements and, to a certain extent, enforcement of the E.U. AI Act when it comes is driven by sovereignty and geopolitical developments,” she says. She calls them the two S’s — simplification and sovereignty — and says they now shape every move out of Brussels. She is careful to add that this is not a crackdown: “It’s not purely enforcement and restriction.”
For CDOs in Asia Pacific, that doctrine matters more than the deadline. “What we see now is digital sovereignty, which is wider,” she says. “It is sovereignty around the entire digital infrastructure: hardware, software, networks, platform services, and not just data.”
The proposed Cloud and AI Development Act would turn that into procurement architecture with a four-level sovereignty assurance framework governing which cloud services may handle sensitive public-sector workloads. Vendors demonstrate assurance levels, and buyers assess them. Spyridaki notes the framework is already extending beyond public procurement: banking authorities are asking the same questions, and so are enterprises in the Middle East, where no such rule exists at all.
Asia is running the same play for different reasons. Indonesia is treating sovereignty as a market access condition, i.e., bring your AI, leave behind technology transfer and local talent. Vietnam’s AI Law took effect March 1, 2026, and requires foreign providers to appoint a local legal representative. ASEAN concluded DEFA negotiations in Manila in May 2026, with signing targeted for November.
Do not expect DEFA to dissolve the fragmentation. “Sovereignty is inherently a national policy,” she says. Governments cooperate on security, cyber resilience, and physical safety. “But they would not sit together to discuss digital sovereignty or their sovereign policies.” Privacy had shared terminology and a common operational framework. Sovereignty drags supply chain dependencies, raw materials and national security in with it. DEFA, in her framing, is “a framework for dialogue” and she means it as genuine praise, particularly with Singapore pushing openness inside the debate.
One change deserves a line item, and it is not in the Omnibus at all. The data package creates a single ENISA-operated entry point routing incident reports across NIS2, GDPR, DORA, eIDAS and CER, with the GDPR breach window stretched from 72 to 96 hours.
“In our sector, this will be fundamental,” Spyridaki says. “One incident could also be reportable under different types of legislation. It could be the GDPR, it could be the E.U. AI Act, it could be the NIS Directive — and it could be all three of them.”
Where SAS is placing its bet
Every obligation above, from Article 50 disclosure and Article 4 literacy to the December 2027 documentation regime, sovereign assurance levels, and incident reporting, resolves to the same prerequisite. You need to know what AI you are running, who owns it, and which rule applies to it. Most enterprises cannot produce that list.
That is the gap SAS AI Navigator is built for. Announced in April 2026 and shipping this quarter on the Microsoft Azure Marketplace, it inventories AI at the use-case level rather than the model level, then maps internal policies and external regulatory frameworks onto each one. It is deliberately model-agnostic, governing whatever an organization already runs, whether it's third-party LLMs, agents, or open source and SAS models, across the full arc from experimentation through deployment to retirement.
For a CDO facing a fragmented Asia Pacific rulebook, such an architecture is the point. One inventory answers Brussels, Hanoi and Jakarta with different policy overlays, instead of three parallel compliance builds.
Reggie Townsend, who runs AI ethics, governance and social impact at SAS, frames it as offense, rather than defense. “AI governance is too often thought of as a compliance measure,” he says. “It’s a growth driver.”
The numbers behind that claim are better than the genre usually offers. Gartner projects more than 40% of enterprises will experience a security or compliance incident linked to unauthorized shadow AI by 2030. IDC’s SAS-commissioned Trust Imperative report found 78% of organizations claim to fully trust AI, while only 40% have invested in governance, explainability, or ethical safeguards. It also discovered that organizations prioritizing trustworthy AI are 60% more likely to double their AI ROI. Europe, with the loudest regulator on earth, still has 46% sitting in that gap.
Navigator sits alongside a widening Viya governance layer built to pair copilots and autonomous agents with human oversight, especially vital as we build and work with agentic systems that act rather than merely answer. In February 2026, Gartner named SAS a Leader in its inaugural Magic Quadrant for Decision Intelligence Platforms for Viya, citing strengths in explainability, auditing and model governance for regulated industries.
The honest test is whether an inventory becomes a discipline or another dashboard. But the regulatory shape now favors the discipline. When December 2027 lands, the first thing a regulator asks for is a register.
The seat on both sides
Spyridaki has spent SAS’s entire AI Act journey watching the law get argued into existence since 2020, through every draft and every amendment that did not survive.
“When you follow that throughout that length, and our company has that insight, I think your understanding of the law and how it applies becomes much more granular and also pragmatic,” she says. “It’s not just something that somebody thought of and now it came, it’s the law, and we have to enforce it. There’s some history that helps you interpret it.”
That history is the asset. “Regulators do want that insight, and companies do want the insight of the regulators,” she says. “In my opinion, it should be a fixed function in every single company in the world.”
Twenty years in, she still refuses to choose between the two. Neither should your CDO.
Image credit: iStockphoto/Unaihuiziphotography
Winston Thomas
Winston Thomas is the editor-in-chief of CDOTrends. He likes to piece together the weird and wondering tech puzzle for readers and identify groundbreaking business models led by tech while waiting for the singularity.