The European Union spent two years building the world's first comprehensive rulebook for artificial intelligence. On 29 June its member states agreed to soften it. The Council gave final approval to the Digital Omnibus on AI, the first set of amendments to the AI Act since the law passed in 2024, and the headline change is a generous one for industry: the most demanding obligations, those covering so-called high-risk systems, will arrive far later than planned.
Under the original schedule, rules for high-risk AI were due to bite on 2 August 2026. That deadline is gone. Standalone high-risk systems, the kind used in hiring, credit scoring, education and law enforcement, now face a compliance date of 2 December 2027. AI built into regulated physical products such as machinery and medical devices gets even longer, until 2 August 2028. Brussels has handed developers more than a year of breathing room, and in some cases close to two.
Why the climbdown
The official framing is that the timeline was never realistic. Much of the technical scaffolding the AI Act depends on, including harmonised standards and guidance from the new AI Office, simply was not ready, and companies argued they could not comply with rules whose details did not yet exist. Dr Nils Rauer, a lawyer who has followed the file closely, called the revised schedule "a more realistic implementation timeline" while cautioning that "much will depend on how the framework is implemented in practice."
There is a competitive subtext too. European officials have watched American and Chinese labs ship frontier models at speed, and the bloc has faced steady lobbying that its own rules risk leaving European firms behind. The Omnibus also trims duplicate paperwork for AI embedded in products already governed by EU safety law, and it carves out lighter obligations for small mid-cap companies that complained the original act treated them like tech giants.
The part that got tougher
Easing the rulebook was only half the story. The same package adds a new prohibition aimed squarely at one of generative AI's ugliest uses. Tools whose purpose is to produce non-consensual intimate imagery, the "nudify" apps that strip clothing from photographs of real people, are being banned outright, alongside AI-generated child sexual abuse material. The ban is set to take effect in December 2026, well before most of the delayed high-risk provisions.
It is a telling pair of decisions. Brussels is willing to give companies more time on the broad, complex obligations that touch thousands of ordinary business systems, but it is moving quickly on the narrow harms that are already causing real damage to real victims. The Omnibus also shortens the grace period for labelling AI-generated content. Providers who release generative models before August now have until 2 December 2026 to apply watermarks or similar transparency measures, rather than the longer window the Commission had floated.
What happens next
The Council's vote is the final legislative step, and formal publication follows. For AI developers selling into Europe, the message is mixed. The hardest deadlines have moved, but the obligations have not vanished, and providers of high-risk systems will still need to register in an EU database even when they believe an exemption applies. Anyone shipping a nudify generator, on the other hand, has roughly six months before the door closes.
For readers following how governments are drawing lines around AI, the Omnibus fits a wider pattern of regulators picking their battles. We have seen it in Rhode Island's ban on chatbots posing as therapists and in Norway's near-total restriction on AI in primary schools. Europe has just shown it can pull in two directions at once: lighter where the cost of compliance felt heavy, firmer where the cost of inaction falls on people who never agreed to be in the picture.
Commentarii · 0