The European Parliament and the Council of the EU reached a provisional agreement in the early hours of May 7 on what officials are calling the Digital Omnibus on AI, a package of targeted amendments to the AI Act that softens parts of the regime while tightening others. The deal lands less than three months before the Act's high-risk obligations were due to take effect on August 2, 2026.
Under the agreement, the application date for stand-alone high-risk systems listed in Annex III shifts to December 2, 2027. Obligations covering high-risk AI embedded in regulated products under Annex I move to August 2, 2028. Companies preparing to comply by this summer now have more breathing room, although the headline rules on prohibited uses and general-purpose models remain in place.
What gets tighter, what gets looser
The Omnibus tightens enforcement in one notable area. A full EU-wide ban applies to AI systems whose primary purpose is to generate non-consensual intimate imagery, with operators given until December 2, 2026 to withdraw such products from the market. Watermarking and labelling requirements for AI-generated content have a new deadline of the same date, reducing the original grace period from six months to three.
Smaller players come out better. Regulatory privileges previously reserved for SMEs now extend to small mid-cap companies, those large enough to fall outside the SME definition but lacking the legal resources of a major corporation. The Council press release describes the change as an attempt to keep European AI startups competitive with US peers.
The deal also closes a long-running source of confusion for industrial AI developers by clarifying how the AI Act interacts with existing EU product safety legislation. Companies building AI into machinery, medical devices, and other regulated products will face one set of certification procedures rather than two overlapping regimes, a change White & Case flagged as one of the most consequential operational shifts in the package.
Mixed reception
Civil society groups had a mixed reaction. The Computer & Communications Industry Association called the package a missed opportunity to address deeper structural problems with the Act. TechPolicy.Press reported that consumer advocates welcomed the deepfake ban but criticised the high-risk deadline extension as a concession to industry lobbying.
Formal adoption is expected before August 2. Until then, the original rules remain in force.
Sources
- i. www.consilium.europa.eu
- ii. www.whitecase.com
- iii. www.techpolicy.press
- iv. www.lewissilkin.com
- v. www.dastra.eu
- vi. ccianet.org
Commentarii · 0