TWINLADDER
TwinLadder logoTwinLadder
Atpakaļ uz apskatu

Izdevums #35

The Duty Softens. The Exposure Does Not Move.

On 6 May the trilogue reached political agreement on the Digital Omnibus on AI: high-risk obligations deferred to December 2027 and August 2028, the Article 4 literacy duty softened, Member State sandboxes pushed to August 2027. The following day the Institute of Student Employers reported that 29% of 144 employers now see increased performance problems in early-career hires, against 12% in 2022, and that 52% have lengthened induction. This issue reads the week as a vacated rung on the name-loss-regulation ladder, and asks the board question the deferral forces: if the deadline moved, what were we doing it for?

EU AI Act
Digital Omnibus
board governance
entry-level formation
judgment
2026. gada 9. maijs12 min read
The Duty Softens. The Exposure Does Not Move.

TwinLadder Weekly

Issue #35 — The Duty Softens. The Exposure Does Not Move.

9 May 2026 · Weekly intelligence on judgment, governance, and the boards accountable for both


Editor's Note

From Alex —

On 6 May the European co-legislators reached provisional agreement on the Digital Omnibus on AI. The high-risk obligations move out: stand-alone Annex III systems to 2 December 2027, AI embedded in regulated products under Annex I to 2 August 2028. The AI literacy duty in Article 4 is softened. The deadline for Member States to stand up their regulatory sandboxes goes to 2 August 2027.

If your organisation built an AI competence programme because a statute set a date, the date has moved and the article that carried the demand has been eased.

The following day, the employers published their own numbers. The Institute of Student Employers surveyed 144 organisations and found that 29% now report increased performance problems among early-career hires. In 2022 that figure was 12%. Over the same four years, 52% have lengthened induction to cover professional conduct.

Two things happened in one week, in opposite directions. The reason written into law got weaker. The reason visible in the intake got stronger.

So the question I would put to a board this month is short, and it takes a minute to answer out loud. If the deadline moved, what were we doing it for? A programme that can only answer "the deadline" has told you what it was.

Liga has the analysis.

— Alex


What Moved on 6 May, and What Held

The Digital Omnibus on AI is a package of targeted amendments to the AI Act, and the trilogue reached political agreement on it on 6 May. Gibson Dunn's read of the deal records the deferrals precisely: "High-risk obligations for stand-alone Annex III systems are deferred to 2 December 2027; for AI embedded in regulated products under Annex I, to 2 August 2028." The Member State sandbox deadline goes to 2 August 2027. Article 4, the AI literacy obligation binding since February 2025, is softened. A new Article 5 prohibition on AI-generated non-consensual intimate imagery and child sexual abuse material is added, with a transitional period to 2 December 2026.

Now the part that stayed where it was. The same analysis records that "2 August 2026 remains an active compliance date" and that "the Article 50 transparency obligations for AI systems largely remain on the original schedule." So a board reading the headline as a general reprieve is reading it too widely. The transparency duties arrive on the original clock, and 2 August 2026 stays live.

The same day, the Commission published its draft Delegated Act revising the European Sustainability Reporting Standards under the CSRD. DLA Piper's note on the consultation is the single source we have for the date, and it puts it plainly: "On 6 May 2026, the European Commission published its draft Delegated Act revising the European Sustainability Reporting Standards (ESRS) under the CSRD." A four-week consultation runs to 3 June.

One day, two reporting regimes rewritten under the boards already working to them. The audit committee that approved a CSRD assurance plan in 2024 is now aiming at a target that is being redrawn. The risk committee that scheduled an AI programme against 2 August 2026 has just watched most of that date walk into 2027 and 2028.

Read those two together and a governance fact comes out of them. A date set in Brussels is an input controlled by someone outside the building. It can be extended, compressed or rewritten by a negotiation held elsewhere, on a timetable set elsewhere. Any internal programme whose only load-bearing member is that date inherits the same instability.


Name, Loss, Regulation — and the Rung That Just Emptied

A board's risk register is a sediment. Every line on it was once absent, and became a standing obligation on a particular date, for a particular reason, almost always in the same order. Someone names a mechanism while holding no power to compel anything about it. Then a loss makes the mechanism expensive and legible. Then a regulator, reading the loss, forces the category onto the register with an owner, a cadence and a date by which the board must be able to say it is being managed. Name, loss, regulation.

Model risk climbed those rungs. In 1983, in Automatica, Lisanne Bainbridge published a five-page paper called "Ironies of Automation" describing a trap that has not dated since: the more of a system you automate, the more critical becomes the human left to catch it when the automation fails, and the less that human practises the skill on which catching it depends. Nobody put it on a register. It took losses in bank trading books through the 1980s and 1990s, and then, on 4 April 2011, the joint Federal Reserve and OCC guidance known as SR 11-7, which named model risk as a category, required independent validation and an owner, and gave the discipline its organising phrase: effective challenge.

Operational resilience climbed the same rungs a decade later, and the loss that moved it is dated. In April 2018 the British bank TSB moved the records of 5.2 million customers onto a new platform over a single weekend, and the weekend did not end; normal service was not restored until December. Weeks after the migration failed, the Bank of England, the PRA and the FCA published a joint discussion paper. The policy statements followed on 29 March 2021, the rules took effect on 31 March 2022, and firms had to be operating inside their stated tolerances by 31 March 2025. Seven years, paper to signed obligation, with the loss at the start of it.

Europe has broken that sequence once. The General Data Protection Regulation was adopted in April 2016 and applied from May 2018, and no single dated catastrophe wrote it. There was a named mechanism, a mounting and diffuse unease, and a deliberate decision to raise the standard ahead of the worst case. That is the whole significance of GDPR for a board reading this week's news: it is the proof that the pre-loss rung can be occupied.

Article 4 of the AI Act was Europe's second attempt at standing on that rung. A literacy duty, written before any documented mass failure, aimed at the people operating the systems. On 6 May the co-legislators softened it, and moved the sandbox deadline — the supervised place where a firm could have built and tested competence under a regulator's eye — out to August 2027.

The rung is now empty. It can still be occupied, and one party is in a position to do it: the institution that carries the exposure. That removes the external clock and leaves the board holding the calendar.


What the Employers Said the Next Day

On 7 May the Institute of Student Employers published its 2026 Student Development Survey, drawn from 144 employer responses collected in January and February. The headline is reassuring on its face. "Nearly nine in ten (87%) of employers expect AI adoption to reshape graduate and apprentice roles," with 58% expecting minor task adjustments and 29% expecting significant change. Displacement is a minority expectation: "Forty per cent of employers don't expect to replace any entry-level roles by AI and 42% believe only a small number (1–10%) will be affected."

Roles survive. That is the finding, and it deserves to be taken at face value.

Then read what the same survey says about the people arriving into those roles. Times Higher Education's coverage carries the numbers. 35% of employers rated graduates below expectations at adapting to workplace demands. 42% named candidate quality as a concern. 29% reported increased performance-related issues among early-career hires, against 12% in 2022. 52% have increased induction time to cover professional conduct. A further 67% are concerned that graduates use AI during selection in ways that misrepresent what they can do.

Set the two halves beside each other. The employers expect the roles to survive and to be reshaped. 43% report that roles have already evolved without anyone formally redesigning them. And the readiness of the people entering those reshaped roles has been deteriorating on a four-year trend that the survey measures directly.

The survey asks about roles. Formation is a separate question, and it stays open: whether the reshaped job still contains the repetitions out of which a professional is built. Where the reps have gone, the cost shows up somewhere, and 52% of these employers have already found where: it arrives as induction time, and it gets booked as onboarding.

There is a second route by which the entry-level bench thins, and the firm that counts the cuts described it in the same week. Challenger, Gray & Christmas published its April job-cut report on 7 May: 83,387 announced cuts, 21,490 of them attributed to AI. Andy Challenger, the firm's chief revenue officer, drew a distinction most reporting collapses: "Regardless of whether individual jobs are being replaced by AI, the money for those roles is." A budget line moved into AI spend removes the same junior seat as an automated task, and it does so without producing any statement that a capability was given up.


Four Days Earlier, in Georgia

On 5 May the Supreme Court of Georgia handed down its decision in Hannah Renee Payne v. The State, No. S26A0459, on appeal from the Superior Court of Clayton County.

An assistant district attorney had used AI software to draft the State's briefs. She had also drafted the trial court's proposed order, and the court adopted it. The court's finding is one sentence: "In an order largely prepared by ADA Leslie, the trial court denied Payne's motion for new trial. That order contained citations to non-existent cases and cases that do not stand for the proposition asserted in the order."

Nine fabricated or misused authorities were identified by the court. The prosecutor then identified twelve more herself and withdrew reliance on nine further citations in her appellate brief. The Supreme Court admonished her and the Clayton County District Attorney's office, suspended her privilege to practise before that court for six months, and imposed twelve hours of continuing legal education. It vacated the trial court's order denying a new trial. The underlying case is a murder conviction carrying a life sentence.

Follow where the check happened. The only human positioned to catch the fabrications was the trial judge, and the text in front of that judge had been drafted by the person who had already delegated the drafting to a machine. So the error travelled through the one review point in the process without meeting a reader who could test it. An appellate court caught it, at the cost of vacating the order that denied a new trial.

Georgia has no AI Act. No literacy article applies there, no deadline moved, no omnibus was negotiated. The exposure arrived anyway, through professional discipline, a vacated order and a case that has to be done again. Nothing agreed in Brussels on 6 May would have prevented it, and nothing agreed in Brussels on 6 May makes it less likely.

The capability, meanwhile, kept its own timetable. On the same 6 May, Anthropic moved multiagent orchestration into public beta on its managed-agent platform, alongside a research preview of an agent that reorganises its own memory store: "duplicates merged, stale entries replaced, and new insights surfaced." Vendors ship on release cycles. Legislatures ship on political ones. Those two clocks have now visibly diverged, and the interval belongs to whoever is deploying.


A Date Someone Else Controls, and a Date You Set

The resilience regime is worth borrowing here, because it shows what a board-set clock looks like when it is built properly. Strip it to four obligations, in the order the rules state them.

Identify. A firm must identify its important business services — the things the outside world depends on it to keep doing. The unit of analysis is what would be missed.

Quantify. For each service the board sets an impact tolerance: the maximum tolerable level of disruption, measured by a length of time. The PRA's supervisory statement requires a time-based metric in every case, and its own example is disarmingly plain — after 24 hours, or at the end of the day. A number, with a clock in it, chosen in advance, against which failure can later be measured by anyone.

Test. Against a severe but plausible disruption. Not the worst case, which excuses everything, and not the likely case, which tests nothing.

Sign. The board must approve and regularly review the written self-assessment. Approve, and regularly review — a record carrying the board's name, discoverable afterwards, renewed on a cadence.

That machinery was built for services going dark for a weekend. Its object was service continuity. The mechanics are what travel: a named service, a stated tolerance, a scheduled test, an approved record. Those four survive the removal of any external deadline, because the board set them.

The instrument the omnibus week calls for is the same four applied to a different service — the institution's own capacity to judge the output of its systems. Name the decisions where a fluent, well-formatted, plausibly reasoned document reaches a customer, a court or a regulator. State who reads them before they leave the building. Set a date on which the board asks again whether those readers can still tell. Approve the answer.

Investors have started asking for the chartered version of this. On 5 May, SHARE, Parnassus Investments and PFA Pension co-filed a proposal asking Alphabet's board to update its Audit Committee charter to cover the responsible development and deployment of AI. The filing's own language is about location: Alphabet is expanding AI "without clear chartered Board-level oversight, which ultimately reduces transparency and diffuses accountability across the Board." A charter amendment is a cheap instrument. It costs a revision and a calendar slot, and it buys a place where the question has to be asked on a date the board owns.


What This Means for Boards Right Now

One. Separate the two calendars in your AI programme, this quarter, on one page. On the left, every milestone that exists because a statute named a date — those milestones now move to 2 December 2027 and 2 August 2028, and they will move again if the next negotiation says so. On the right, every milestone that exists because the institution decided the exposure was real. If the right-hand column is empty, the programme was a compliance schedule, and the 6 May agreement has just dissolved most of it.

Two. The near dates are the ones to work against. 2 August 2026 remains an active compliance date, and the Article 50 transparency obligations largely stay on the original schedule. A programme stood down on the strength of the deferral will meet those in twelve weeks with a team that has been told the subject was postponed.

Three. Put a number with a clock in it against the reading capacity, not against the tooling. The failure in Payne happened where a person read a document and could not tell. For each class of AI-assisted output that leaves your organisation, write down who reads it, what they check, and the date on which the board next tests whether they can still do it. That tolerance is yours to set, and no omnibus can defer it.

Which leaves the question this week put on the table, and it belongs in the minutes: if the deadline moved, what were we doing it for?


Reading List


What We Are Watching Next

  • Whether any organisation that built an AI competence programme against the 2 August 2026 high-risk deadline states publicly what it will do with that programme now the date has moved
  • Whether the Alphabet audit-committee proposal filed on 5 May reaches a vote, and whether asking for a charter amendment draws more support than asking for a report has done
  • Whether employers acting on the ISE findings formally redesign entry-level roles, given that 43% report roles already evolving without anyone redesigning them
  • Whether any supervisor sets out what it expects of firms during the deferral period, or leaves the interval to be filled by whoever is deploying

The next issue goes deeper into one of these. If you want a specific function or sector covered, reply to this email.

— Liga


TwinLadder Weekly is a weekly intelligence report on judgment, governance, and the boards accountable for both. Subscribe at twinladder.ai/newsletter. Forward this issue freely.