Imagine you are the compliance lead at a mid-sized European manufacturer. Eighteen months ago your board, reading the headlines, told you to get the company ready for three things: the EU Deforestation Regulation, the new sustainability reporting rules, and the AI Act. You did what good compliance leads do. You hired two people. You bought a reporting tool. You commissioned a consultancy to map your value chain. You built a project plan with the deadlines circled in red.
This spring, every one of those red circles moved.
The EU Deforestation Regulation? Postponed on 23 December 2025 (one week before it was due to apply), pushing large operators to December 2026. The sustainability reporting you’d staffed up for? Your company probably just fell out of scope entirely. The AI Act obligations you were racing toward an August 2026 deadline to meet? Deferred to December 2027, maybe, pending a text that at the time of writing still isn’t formally law. Your two new hires are now working against deadlines that may move again. Your board wants to know why you spent the money.
This post is about that compliance lead, and the argument that the real cost of Europe’s recent regulatory turn isn’t found in any single rule, but in the churn itself.
What actually happened
Two big “omnibus” packages reshaped the European rulebook in a matter of months, both flowing from the same source: the Competitiveness Compass, the Commission’s January 2025 roadmap built on the Draghi report, which set an explicit target of cutting reporting burdens by 25%. Deregulation stopped being an instinct and became a KPI.
The Sustainability Omnibus (Omnibus I) entered into force on 18 March 2026. It did three dramatic things. It narrowed CSRD scope to companies with over 1,000 employees and €450M turnover, cutting a regime originally designed to cover roughly 50,000 companies down to a fraction of that. It raised the CSDDD due-diligence threshold to 5,000 employees and €1.5bn turnover and pushed application to 2029. And it stripped out substance: the EU-wide civil liability regime was deleted, the Paris-aligned transition-plan obligation removed, and the reporting standards themselves cut by a 61% reduction in mandatory data points.
The Digital (AI) Omnibus reached provisional agreement on 7 May 2026, the first amendment to the AI Act since it passed. It deferred high-risk obligations on a staggered schedule (standalone Annex III systems from August 2026 to December 2027, embedded systems to August 2028) and gave standards bodies like CEN-CENELEC more time because implementation was, in the regulators’ own words, visibly off track.
Here is the part that matters most for our compliance lead, and the part the headlines bury: the delay is not permission to stop. Until the AI Omnibus is formally published in the Official Journal, 2 August 2026 remains a live compliance date: lawyers are explicitly telling clients to keep preparing against the old deadline. And the political agreement itself underscores the expectation that implementation efforts should already be underway. So the organisation is asked to hold two contradictory futures in its head at once: prepare as if the deadline is August 2026, but plan as if it’s December 2027. That is not relief. That is whiplash.
The hidden cost isn’t the rule, it’s the churn
Most commentary treats each of these moves as a win or a loss: industry cheers the lighter load, civil society mourns the gutted ambition. Both miss the governance point. A rule that is stable, even a demanding one, is something an organisation can build around. A rule that keeps moving imposes a different and underexamined cost: the cost of the moving target itself.
Think about what our compliance lead actually lost. Not the rule. The sunk investment: the hires made against a timeline that vanished, the tool bought for a regime the company no longer falls under, the consultancy fees for a value-chain map now larger in scope than the law requires. Economists call this stranded capital. In compliance, it shows up as a function built for a world that was legislated out of existence between the planning and the execution.
And the deeper cost is informational. You cannot price compliance capex when the rulebook is in motion. Do you staff up now or wait for the final text? If you wait and the deadline holds, you’re exposed. If you build and the scope narrows, you’ve wasted the budget. Either way you are making a capital-allocation decision under rules that are themselves a variable rather than a constant, and the rational response to that uncertainty is often to do nothing, which is precisely the opposite of what a regulation is supposed to induce. Paradoxically, a deregulatory agenda pursued through constant amendment can leave organisations less prepared and more paralysed than a stable but stricter regime would.
The thesis hiding in here
This is the live-events version of a question I’ve been working through academically: how organisations should structure themselves under uncertainty, and where decisions should sit when the environment keeps shifting. The omnibus saga is a near-perfect natural experiment in it.
Faced with regulatory churn, an organisation has two instincts. Centralise: pull compliance into a single function that tracks every moving deadline, absorbs the volatility, and shields the business units from it. This is efficient when rules change often, because you’re not duplicating the horizon-scanning effort across the company, but it creates a bottleneck and a single point of failure, and it distances the people who know the operational reality from the people interpreting the rule. Decentralise: push compliance ownership into the business units that live closest to the risk. This keeps interpretation grounded in operational reality and is more resilient to any one function being overwhelmed, but it multiplies the cost of every rule change, because now twelve teams each have to re-learn the new deadline instead of one.
Regulatory whiplash sharpens the trade-off brutally. The more often rules move, the stronger the case for centralising the tracking (so you scan the horizon once, not twelve times), but the stronger the case for decentralising the judgment (because a narrowed-scope rule means the question “does this even apply to us now?” can only be answered unit by unit). The interesting answer isn’t centralise-or-decentralise; it’s that the two functions of compliance, monitoring and deciding, may want to live in different places, and a turbulent regulatory environment is exactly what forces you to separate them. Layer AI on top (automated regulatory-change tracking, which genuinely lowers the cost of the monitoring half) and the calculus shifts again, because the thing that used to justify a big central function gets cheaper, while the judgment half stubbornly doesn’t.
Why it matters beyond the compliance team
Zoom out and the irony is structural. The whole point of the omnibus packages, per the Compass, was to make Europe more competitive by cutting red tape. But competitiveness depends on firms being able to plan: to commit capital with some confidence about the rules they’re committing it under. If the method of cutting red tape is itself a source of unpredictability, the cure carries a dose of the disease. A 25%-lighter rulebook that arrives via three years of amendments, postponements, and provisional agreements may cost more in planning uncertainty than it saves in reporting hours.
None of this is an argument against simplification. The original CSRD genuinely was heavy, the AI Act timelines genuinely were unworkable, and reasonable people wanted both fixed. It’s an argument that how you change rules is itself a governance choice with real costs, and that “we made it simpler” and “we made it more predictable” are not the same claim. Europe has, this year, delivered the first while arguably undermining the second.
So spare a thought for the compliance lead with the moving red circles. Their problem is not that the rules are too strict or too lax. It’s that they keep moving, and nobody is putting a number on what that motion costs.
What I’m reading
- Gibson Dunn, “EU AI Act Omnibus Agreement”. The cleanest statement of the “2 August 2026 remains a live compliance date” point: essential for understanding why the delay creates work rather than removing it.
- Clifford Chance, “Omnibus I: the EU concludes CSDDD and CSRD reforms”. Best on the substance removed (civil liability, transition plans) and the EUDR’s week-before-the-wire postponement.
- Etifor, “Omnibus I: what changes for the CSRD and CSDDD”. Connects the cuts explicitly back to the Competitiveness Compass and the 25% burden-reduction target: the political-economy through-line.
- TechPolicy.Press, “What the EU AI Omnibus Deal Changes”. Useful counterweight: notes that both industry and civil society came away frustrated, and that the Data Omnibus is the bigger fight still coming.