Six days in July

Two dates tell the story of AI governance in 2026, and they are six days apart.

On 27 July 2026, the Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force, having been published in the Official Journal on 24 July. It deferred the EU AI Act's high-risk obligations for standalone Annex III systems from 2 August 2026 to 2 December 2027, and for AI embedded in regulated products under Annex I to 2 August 2028.

On 2 August 2026, the date that had sat in compliance calendars for two years as the moment the Act would substantially apply, only the Article 50 transparency obligations switched on, requiring providers and deployers to disclose AI interaction and label AI-generated content, backed by penalties of up to €15 million or 3% of worldwide turnover.

The heaviest compliance regime in the EU's flagship AI law moved sixteen months, with less than a week to spare. The stated reasons are honest ones: the harmonised standards that make high-risk compliance workable were not ready, and many member states had not yet named the authorities that would enforce the rules.

Hold that thought, because in the same summer, one of the technology industry's most establishment figures published an essay arguing that the risks those obligations were designed to manage are no longer approaching. They have arrived.

The shrillest voice in the room

Bill Gates is not a doomer. He spent five decades arguing that technology is a net good, and he still believes AI will transform health, agriculture and education. Which is what makes his intervention, in an essay and an accompanying MIT Technology Review interview, so uncomfortable.

His argument is simple. For years, the industry's answer to AI risk was a promise: when we get close to the dangerous thresholds, we will act. Restrict access. Stop models being copied. Put monitoring in place. Gates's charge is that the thresholds in bio-capability, cyber-capability, psychosocial dependence and job-market disruption have now been crossed, and the promised response has not materialised. In his words, "You can't count on an industry to self-regulate."

The detail that should stop every operations director mid-scroll is his account of the coding threshold. Gates describes being stunned by the leap in AI coding capability, agentic approaches, long context, autonomous execution, and then realising only months later that a coding threshold is also, by definition, a cyberattack threshold. The same capability that writes your integration scripts can conduct reconnaissance, harvest credentials and move laterally through a network. The skill barrier that once separated a curious adversary from a capable one has largely gone.

He is not speculating. In November 2025, Anthropic reported disrupting what it assessed as the first largely AI-orchestrated cyber espionage campaign, attributed to a Chinese state-sponsored group. The AI executed an estimated 80 to 90% of the tactical work across roughly 30 targets, among them technology companies, financial institutions, government agencies and chemical manufacturers. Some security researchers have questioned how much the AI genuinely did versus how much the report claims, and that scepticism is fair. But even the sceptics' version, familiar attacks run faster, cheaper and at greater scale with minimal human labour, is a changed threat model for anyone defending an estate.

The corroboration nobody wanted

If Gates were a lone voice, you could discount him. He is not. The research published across 2026 describes the same gap from every angle, and while the Schellman data is US-only, the IBM and Deloitte studies span more than twenty countries between them, so this is not a local pattern.

IBM's Institute for Business Value found that 77% of CIOs and CTOs report AI adoption already outpacing their governance capabilities. Deloitte's State of AI in the Enterprise research found 23% of companies already making at least moderate use of agentic AI, autonomous systems that act with minimal human oversight, while only one in five has a mature governance model for them.

The most telling number comes from Schellman's 2026 State of AI Governance report: 74% of organisations believe they could pass an AI compliance audit today, while only 27% describe their governance programmes as fully mature.

Read those together and the pattern is unmistakable. Confidence is high, spend is high, deployment is accelerating, and the control environment is a fraction of the way there. That is the enterprise-scale version of what Gates describes at the industry scale: everyone agreed to act at the threshold, and the threshold passed quietly while the paperwork was still in draft.

Deadline management is not governance

Which brings us back to those six days in July.

The Omnibus deferral is defensible as lawmaking. Regulating without workable standards or appointed enforcers helps nobody. But the date move ran a quiet test on every AI governance programme in Europe, and the result is worth knowing.

A programme built on risk barely noticed, because its controls were calibrated to what its AI systems could actually do and actually break. A programme built on a countdown noticed immediately. If yours changed pace in July, that is information about what it was: not governance, but deadline management wearing governance's clothes.

The distinction matters because the risks did not read the Official Journal. The cyber threshold Gates describes was crossed on the capability curve, not the compliance calendar. The agentic systems Deloitte counts are already in production. December 2027 changed none of that. Risk arrived early, and the regulation agreed to arrive later.

Why asset-intensive operators carry the gap

For most businesses, the governance gap is reputational and financial exposure. For asset-intensive, regulated operators, defence estates, NHS trusts, power and water utilities, transport networks, major manufacturers, it carries physical consequence, and three features of these environments concentrate the risk.

First, the estate sits on the IT/OT boundary. EAM and IWMS platforms touch work orders, permits to work, isolation records, building management systems and, increasingly, live condition data from operational technology. When the barrier to entry for a capable cyberattack collapses, every CMMS integration, remote access path and ageing middleware layer becomes part of the attack surface. Chemical manufacturers were among the targets in the first reported AI-orchestrated campaign.

Second, assurance is a supply chain problem, not a platform one. Every major EAM and IWMS vendor is shipping agentic and copilot features, and each arrives with a governance promise attached, while the contractors and SMEs delivering work on your estate are using whatever tools they have. The governed end of a supply chain and the ungoverned end sign the same clauses. Vendor and supplier assurances are inputs to your governance, never substitutes for it.

Third, the deferral is not a UK shelter. The UK has no AI Act, and its approach runs through existing sector regulators and security frameworks; none of those clocks moved in July. NHS information governance, the NCSC's Cyber Assessment Framework, defence security conditions and CNI regulatory expectations continue on their own schedules, and they will judge an AI-enabled failure in your estate against duties you already hold today. Worth checking which calendar your programme is actually anchored to, because a Brussels timetable now points sixteen months in the wrong direction.

There is a fourth risk that sits underneath all three, and it is the one that makes deferral so dangerous in these sectors. A predictive-maintenance model trained on incomplete asset records does not produce conservative outputs; it produces confident ones. The failure mode is not silence: it is false assurance. Nothing alerts, nothing escalates, and a maintenance plan built on a partial view of the estate looks exactly like a maintenance plan built on a complete one. Every month of deferred foundational work is another month of decisions taken on that basis.

What the calendar cannot tell you

The conclusion is not to panic, and certainly not to freeze AI adoption. The productivity case in asset management is real, and this newsletter has argued from issue one that the organisations winning with AI are the ones that did the unglamorous work first. The conclusion is to change what your programme is calibrated to.

Calibrate to capability, not to compliance dates. The question is not "what must we evidence by December 2027" but "what can the systems we are deploying, and the adversaries now equipped with the same class of tools, actually do to our estate this quarter". Asset data quality, identity hygiene, boundary controls and human oversight of autonomous actions are not AI Act deliverables to be scheduled. They are the foundations that decide whether AI in your operation is an asset or an exposure, and they were worth building before the Act existed. That includes the unglamorous question of whether your people, and your suppliers' people, have a governed route to AI that they actually choose when the deadline is real.

Treat the sixteen months as runway, not relief. The high-risk regime was deferred, not dismantled. Organisations that use the window to build inventory, documentation and control maturity deliberately will meet December 2027 as a formality.

The thought piece: promises at the threshold

Every level of this system made the same promise, and every level renegotiated it when the moment came.

The frontier labs said that when the dangerous thresholds approached, they would hold back. Gates's account is that the thresholds arrived and the holding back did not. The regulators said the rules would be ready by August 2026. The date arrived, the standards were unwritten, so the date moved. The enterprises say they are governance-ready, and 74% believe it, while 27% have built it.

The same mechanism each time: a future commitment stood in for present work, and when the future arrived, the commitment was renegotiated. Gates is uncomfortable to read precisely because he refuses the renegotiation. The thresholds, he insists, are behind us, whatever the calendars say.

Which is the same failure mode, scaled up. A deferred deadline does not make an organisation cautious. It makes it confident. Nothing alerts, nothing escalates, and a programme running on a promise looks exactly like a programme running on controls. False assurance is not a data problem that happens to appear in AI systems. It is what an ungoverned system produces at every level, from a maintenance plan to a compliance calendar.

And here is the version that matters most inside an organisation. The frontier crossed thresholds it had promised to act on. In most organisations, no threshold was ever set. Nothing registers, nothing triggers, nothing has a line to cross, so the governance question never arrives at all.

Asset-intensive operators are the one group that cannot afford the renegotiation, because their failure modes are not press releases and fines. They are stopped production lines, unavailable clinical estates and interrupted power. In these sectors, the gap between risk arriving and governance arriving is measured in downtime, in safety cases, and occasionally in lives.

Which is why the oldest argument in this newsletter is also the most current one. Foundations are the only part of AI readiness that no deadline can defer and no vendor can promise on your behalf. The data you can trust, the access you can control, the decisions a human still owns, these do not become urgent when a regulation lands. They were urgent the day the capability shipped.

The thresholds have been crossed. The deadlines have been deferred. Only one of those facts should be setting your agenda.

So: what in your AI programme would change if every regulatory deadline moved two years, and what would not? The second list is your actual governance.

References

  • Regulation (EU) 2026/1744, the Digital Omnibus on AI, Official Journal 24 July 2026, in force 27 July 2026: https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng
  • MIT Technology Review, "Bill Gates says we've passed AI's danger thresholds. Now what?", 26 August 2026: https://www.technologyreview.com/2026/08/26/1142946/bill-gates-ai-danger-threshold/
  • Anthropic, "Disrupting the first reported AI-orchestrated cyber espionage campaign", November 2025: https://www.anthropic.com/news/disrupting-AI-espionage
  • IBM Institute for Business Value with Oxford Economics, CIO and CTO study, June 2026 (2,000 respondents, 33 geographies): https://newsroom.ibm.com/2026-06-08-new-ibm-study-finds-cios-and-ctos-face-growing-ai-control-gap-as-enterprise-deployment-scales
  • Deloitte, State of AI in the Enterprise 2026 (3,235 business and IT leaders, 24 countries): https://www.deloitte.com/global/en/issues/generative-ai/state-of-ai-in-enterprise.html
  • Schellman, 2026 State of AI Governance, 29 July 2026 (525 US-based professionals): https://www.schellman.com/whitepaper/2026-state-of-ai-governance

Foundations First is written by Alex Brain, Founder and Managing Director of Brainwave Asset Intelligence, a platform-agnostic EAM and IWMS and AI governance consultancy led by an SC-cleared founder, serving ten UK regulated sectors.

© 2026 Brainwave Asset Intelligence Ltd. All rights reserved. · Registered in England & Wales No. 17135517 · 3 Victoria Parade, Urmston, Manchester, M41 9BP