Executive summary:
For a long time, organisations have planned regulatory change backwards from a date.
A requirement was announced. A commencement date was published. Programmes were approved, budgets allocated and workstreams sequenced around it.
It was a sensible way to create certainty around something that was otherwise difficult to plan.
That certainty is becoming harder to find.
Across sustainability, AI and wider governance requirements, timetables are changing, obligations are being separated, and different jurisdictions are moving at different speeds. The EU's sustainability simplification has changed both the scope and timing of some requirements, while the AI Act is now applying in stages, with some obligations already in force and others extending into 2027 and 2028.
For organisations trying to plan several years ahead, that creates an obvious problem.
But there is a more important question underneath it.
What happens when we stop treating the deadline as the thing we are preparing for?
Because the deadline may move.
The exposure does not.
There is nothing unusual about planning around a regulatory timetable.
It gives an organisation something concrete to work towards. A date allows a programme to be scoped, a budget to be justified and progress to be measured.
The difficulty comes when the date starts to become less reliable than the capability it was supposed to produce.
That is increasingly the environment organisations are operating in.
The EU's sustainability rules are a good example. Changes agreed in 2026 have narrowed the scope of some reporting and due-diligence obligations and altered implementation timelines. The objective is to simplify requirements and reduce administrative burden, but for businesses operating across markets, the practical result is another layer of movement in a landscape that was already difficult to navigate.
AI regulation has developed differently, but with a similar consequence for planning.
The AI Act's transparency obligations began applying on 2 August 2026. Other requirements have later application dates, including rules for certain high-risk systems from December 2027 and others from August 2028.
So, there is no longer one neat regulatory clock to plan against.
There are several.
And they will not necessarily move together.
For a multinational organisation, which is more than a compliance inconvenience. It changes the assumptions behind long-term planning.
This is where I think the conversation needs to change.
A regulatory requirement may ask an organisation to demonstrate something at a particular point in time.
The business does not stop needing to understand it simply because the date changes.
The board still wants to know where the organisation is exposed.
An executive still needs to understand which dependencies could affect continuity.
A risk committee still needs confidence that important assumptions are supported by evidence.
A customer may still ask how critical dependency is being managed.
None of those questions has a commencement date.
And procurement sits unusually close to many of them.
The organisation's exposure to a supplier is not created when a regulation recognises it.
Its dependence on a market does not begin when a reporting obligation becomes effective.
A weakness in a contract does not become a weakness because somebody has put it into a regulatory framework.
The regulation may change the requirement to demonstrate the issue.
It does not create the underlying issue.
That distinction matters.
I think this is where some organisations may be drawing the wrong conclusion from regulatory uncertainty.
When a deadline moves, the natural response is to reconsider the programme built around it.
That is reasonable.
What is less reasonable is assuming that everything the programme was intended to achieve has therefore become less important.
The two things are not the same.
A deadline tells you when something must be demonstrated.
A capability determines whether you can answer the question at all.
That difference becomes significant when the questions are not exclusively regulatory.
Consider the information a leadership team may need to understand:
Where are our most important supplier dependencies?
Which exposures have increased?
Where are we relying on a small number of suppliers, markets, or locations?
Which commercial commitments matter most to operational continuity?
Where have changes in the business created dependencies that were not visible previously?
These are not questions that appeared because a regulator wrote them down.
They are questions any well-governed organisation should be capable of answering.
The regulatory timetable simply gives some of them a formal deadline.
I would not start by asking whether an organisation is ready for the next regulatory milestone.
I would ask something more immediately.
If the question arrived this afternoon, how much would we know?
Not how quickly a programme could produce the answer.
Not whether someone could assemble it with enough notice.
Not whether the organisation has a project underway.
What can be answered now?
That is a different test.
And it is becoming a more important one.
Because procurement is increasingly being asked to contribute to decisions that sit well beyond the traditional boundaries of purchasing.
Supplier risk is part of resilience.
Commercial dependencies are part of enterprise risk.
Technology procurement is becoming part of AI governance.
And AI itself is increasingly being acquired across software, services, infrastructure, and autonomous capabilities rather than through one clearly defined procurement category. Gartner's August 2026 research makes the point directly: CPOs are increasingly being asked to manage AI capabilities as an enterprise concern, not simply individual suppliers.
That changes the question procurement is expected to answer.
It is less often:
“Did we complete the process?”
And increasingly:
“What does the organisation need to know before it makes the decision?”
This Is Also Why AI Needs a Different Conversation
There is an understandable tendency to treat AI as the answer to the problem.
I am less convinced that it is that simple.
AI can accelerate analysis, surface patterns, and support decisions. But it does not remove the organisation's responsibility for understanding what sits underneath those decisions.
In fact, as AI becomes more embedded in procurement, that responsibility becomes more important.
If AI is being used to evaluate suppliers, support sourcing decisions, monitor risk or influence commercial choices, leadership needs confidence not only in the output but in the information and decision logic behind it.
The EU's current AI framework reflects part of that direction of travel. The rules increasingly emphasise transparency, documentation, traceability, human oversight, and the quality of information used by higher-risk systems.
The broader lesson for procurement is straightforward.
Automation does not remove accountability. It changes where accountability sits.
That is a leadership issue, not a technology issue.
This is why I would be cautious about allowing a moving regulatory timetable to determine the pace of organisational improvement.
Some things genuinely should wait for clarity.
But other things have value regardless of what the final timetable looks like.
Understanding the organisation's supplier dependencies has value.
Understanding where commercial exposure sits has value.
Having confidence in the information behind important decisions has value.
Being able to explain the basis for an answer has value.
Those capabilities do not become obsolete because a regulation is postponed.
If anything, they make the organisation better prepared for whichever version of the requirement eventually applies.
That is broadly the thinking behind our approach at RobobAI.
Our focus is not to turn every regulatory change into another technology programme. It is to help organisations make better use of the procurement information they already hold, so that questions about spending, suppliers, contracts, and exposure can be considered from a stronger information base.
Technology is useful.
But the capability is the point.
There will be programmes in many organisations today whose urgency has changed because the deadline behind them has moved.
That is understandable.
But before deciding what to stop, slow down or defer, there is one question worth asking.
If the deadline had never existed, would we still want the capability this programme was intended to create?
If the answer is yes, then perhaps the deadline was never the most important part of the programme.
It was simply the date that made the need impossible to ignore.
The more important question is whether the organisation can understand its exposure, explain its decisions and respond when the question arrives.
Because deadlines can move.
Accountability does not.
And neither does the exposure sitting underneath it.