European Parliament Approves Digital Omnibus: Major Updates to EU AI Act Take Effect August 2026
Parliament votes 423–57 to advance digital omnibus reforms, bringing transparency rules, content bans, and compliance deadlines to the EU AI Act.
Parliament Approves Digital Omnibus
The European Parliament approved the digital omnibus on 16 June 2026 by 423 votes to 57, with 174 abstentions. The Council of the European Union must formally adopt the digital omnibus changes, which is expected before 2 August 2026.
Core Prohibitions and New Compliance Deadlines
The digital omnibus adds a prohibition to Article 5 of the AI Act on AI systems that generate child sexual abuse material or that create intimate or sexually explicit images, video, or audio of an identifiable person without consent.
The nudifier ban applies to both providers placing such systems on the EU market and deployers using them for that purpose, with compliance required by 2 December 2026.
Transparency Obligations Take Effect August 2026
Most of the AI Act’s transparency obligations under Article 50 still apply from 2 August 2026, including the duty to tell people when they are interacting with an AI system such as a chatbot, and the duty for those deploying AI to clearly label deepfakes and AI-generated text published on matters of public interest.
Watermarking Requirements Phased In
The provider obligation to embed machine-readable marking in AI-generated content—the watermarking requirement—is delayed to 2 December 2026, and that extension applies to generative systems already placed on the market before 2 August 2026. Systems launched after 2 August 2026 are expected to comply with watermarking requirements right away.
High-Risk AI Timelines Extended
Stand-alone high-risk AI systems listed in Annex III move from 2 August 2026 to 2 December 2027. High-risk AI embedded as safety components in products covered by EU sectoral legislation, listed in Annex I, move from 2 August 2027 to 2 August 2028.
Broader Regulatory Changes
The deadline for member states to establish AI regulatory sandboxes moves from 2 August 2026 to 2 August 2027.
Processing special-category personal data to detect and correct bias is permitted across AI systems where strictly necessary, with safeguards.
AI that only assists users or optimizes performance will not automatically be high-risk if its failure does not create health or safety risks.
Existing exemptions for small and medium enterprises under the EU AI Act are extended to small mid-cap enterprises.
The EU AI Office gains a clearer supervisory role over certain general-purpose AI systems.
Source: Elevate Consult
Developments since publication
-
The EU AI Act's transparency and information obligations under Article 50 became generally applicable and enforceable by national competent authorities across the EU on 2 August 2026. Source
-
Providers of any AI system designed to interact directly with natural persons (such as chatbots or virtual assistants) must ensure individuals are clearly informed they are dealing with an AI system, Source
-
Providers and deployers of AI systems generating synthetic audio, image, video, or text (including deepfakes) must mark outputs in a machine-readable, detectable format. Source
-
Providers of generative AI systems already on the market before 2 August 2026 have been given until 2 December 2026 to comply with the machine-readable marking obligation under the AI Omnibus. Source
-
Deployers of emotion recognition or biometric categorisation systems must inform exposed individuals of the system's operation and process any personal data in line with EU data protection law. Source
-
Non-compliance with Article 50 transparency obligations may give rise to administrative fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher, under Article 99(4) of the E Source
-
The AI Omnibus pushed the application of high-risk AI system obligations (for standalone Annex III systems including employment, education, law enforcement, and critical infrastructure) back to 2 Dece Source
-
AI systems embedded within products regulated under EU product safety legislation (Annex I), such as medical devices, toys, and lifts, must comply with AI Act requirements by 2 August 2028. Source
-
The AI Omnibus softens the mandatory AI literacy obligation: Article 4 now requires providers and deployers to take measures to support the development of AI literacy of their staff, rather than requi Source
-
The AI Omnibus extends simplified compliance measures previously limited to SMEs to a new 'small mid-cap' (SMC) category of businesses. Source
-
The AI Omnibus prohibits AI 'nudification' applications and AI systems capable of generating child sexual abuse material (CSAM) as new prohibited practices under Article 5, applying from 2 December 20 Source
-
The new prohibitions on nudification and CSAM-generation carry the AI Act's highest penalty tier: fines of up to €35 million or 7% of worldwide turnover, whichever is higher. Source
-
The AI Omnibus broadens the legal basis for processing special category personal data for bias detection and correction to cover deployers of high-risk systems and providers and deployers of other AI Source
-
The EU AI Office, not national regulators, now holds direct supervisory authority over systems built on general-purpose AI models and over AI features embedded in designated very large online platform Source
-
The Commission's Guidelines on transparency obligations for providers and deployers of AI systems were adopted on 20 July 2026. Source
-
The Commission's enforcement press release was published on 31 July 2026. Source
-
From 2 August 2026, AI-generated or AI-altered content must carry machine-readable marks to enable easier detection. Source
-
The Code of Practice on transparency of AI-generated content operationalises the AI Act's transparency rules for AI-generated content. Source
-
Providers of AI systems already on the market before 2 August 2026 have until 2 December 2026 to implement machine-readable watermarking under Article 50(2). Source
-
Deepfakes — images, videos, or audio edited or generated using AI — must be labelled as such under the AI Act transparency rules effective 2 August 2026. Source
-
Article 5 of the AI Act now bans AI systems designed to generate non-consensual intimate imagery (nudifier applications) and child sexual abuse material. Source
-
Providers whose AI systems were already on the EU market before 2 August 2026 have until 2 December 2026 to comply with Article 50 machine-readable marking obligations. Source
-
Stand-alone high-risk AI systems listed in Annex III — including recruitment tools, credit scoring, education, law enforcement, border control, and critical infrastructure — now face full compliance o Source
-
AI embedded in products already covered by EU product safety law under Annex I — including medical devices, machinery, and toys — has a compliance deadline of 2 August 2028. Source
-
The Annex I deadline extension to August 2028 was driven by CEN-CENELEC indicating that harmonised standards required for high-risk AI conformity assessments would not be available until Q4 2026 at th Source
-
The Digital Omnibus deal was reached on 7 May 2026, after a first trilogue collapsed on 28 April 2026. Source
-
The AI Act's General Purpose AI (GPAI) model obligations and penalties became applicable on 2 August 2026. Source
-
The European Commission published a first list of more than 180 organisations that have signed the Code of Practice on transparency of AI-generated content. Source
-
The Regulation of Artificial Intelligence Act 2026 was signed into law by President Connolly on 21 July 2026. Source
-
The Regulation of Artificial Intelligence Act 2026 establishes Oifig IS na hÉireann (AI Office of Ireland) as an independent statutory body. Source
-
Paul Byrne was appointed as the first Chief Executive Officer of the AI Office of Ireland. Source
-
Paul Byrne joins the AI Office of Ireland from the Medical Council of Ireland, where he served as Executive Director of Education, Innovation and Artificial Intelligence. Source
-
Paul Byrne is the President of the Council on Licensure, Enforcement and Regulation (CLEAR), the international alliance of professional and occupational regulators. Source
-
Paul Byrne is a member of the World Health Organization's Expert Working Group on Regulatory Considerations of AI for Health. Source
-
The AI Office of Ireland will act as the Single Point of Contact for the EU AI Act for the European Commission, national sectoral regulators, and the public. Source
-
The Irish Regulation of Artificial Intelligence Act 2026 is structured in 10 Parts with 139 Sections and 4 Schedules. Source
-
The Irish Regulation of Artificial Intelligence Act 2026 amends the Central Bank Act 1942 and Competition and Consumer Protection Act 2014 to enable these bodies to impose administrative sanctions for Source
-
The Irish Regulation of Artificial Intelligence Act 2026 is a technical implementing measure and does not add to the obligations placed on regulated entities by the EU AI Regulation. Source
-
Due to complexity of the EU AI Act, further legislation arising from amendments from the Digital Omnibus on AI will be brought forward by Ireland in the Autumn. Source
-
From 2 August 2026, the European Commission's AI Office, together with national authorities, began enforcing the Artificial Intelligence Act. Source
-
From 2 August 2026, new AI Act transparency rules require certain AI systems to tell users when they are interacting with AI and when content has been generated or altered by it. Source
-
From 2 August 2026, chatbots and other interactive AI systems must tell users they are dealing with AI, not a human. Source
-
From 2 August 2026, deepfakes — images, videos, or audio edited or generated using AI — must be labelled as such. Source
-
From 2 August 2026, AI-generated or altered content must carry machine-readable marks so it can be detected more easily. Source
-
The EC page carrying this enforcement announcement was last updated on 31 July 2026 and is classified as a press release. Source
-
The Commission published an AI Act complaints tool, a Whistleblower Tool, and a complaints channel for downstream providers using general-purpose AI models as part of the enforcement infrastructure la Source
-
AI embedded in regulated products under Annex I — such as medical devices, machinery, and toys — has its high-risk compliance deadline extended to 2 August 2028. Source
-
A new prohibition on AI-generated non-consensual intimate imagery was added to Article 5 of the EU AI Act via the Digital Omnibus. Source
-
The AI Omnibus regulation came into force on 27 July 2026. Source
-
Transparency rules under Article 50 of the EU AI Act begin to apply from 2 August 2026. Source
-
Article 50(1) requires AI systems that interact directly with people to disclose that the user is dealing with a machine, unless that is obvious from context. Source
-
Article 50(2) requires AI systems that generate synthetic content to carry machine-readable markings. Source
-
Article 50(3) requires emotion recognition and biometric categorisation systems to inform the people exposed to them. Source
-
Article 50(4) requires deepfakes or AI-generated text on matters of public interest to be disclosed as artificially generated. Source
-
AI-generated or manipulated outputs under Article 50(2) and deepfakes under Article 50(4) that were generated before 2 August 2026 do not need to be marked or labelled retroactively. Source
-
The new prohibitions on non-consensual deepfakes and CSAM-generating AI have been postponed to 2 December 2026. Source
-
The transition deadline for machine-readable marking under Article 50(2) for AI systems already on the market before 2 August 2026 is 2 December 2026. Source
-
High-risk AI rules under Annex III — covering biometrics, critical infrastructure, education, employment, and migration/asylum/border control — were originally due to apply from 2 August 2026. Source
-
Following the AI Omnibus, Annex III high-risk AI obligations now apply from 2 December 2027 instead of 2 August 2026. Source
-
The substance of Annex III is unchanged by the Omnibus; no new high-risk use-case was added. Source
-
Under Annex I, only AI embedded in machinery-regulation products is excluded from the high-risk regime by the Omnibus; other Annex I products such as toys, lifts, and medical devices are not excluded. Source
-
Toys, lifts, and medical devices under Annex I must comply with high-risk AI obligations by 2 August 2028. Source
-
The AI Omnibus introduces a 'small mid-cap' company category defined as having under 750 employees and under €150 million in turnover, which qualifies for SME-level regulatory relief. Source
-
The obligation for Member States to have at least one operational AI regulatory sandbox has moved from 2 August 2026 to 2 August 2027. Source
-
From 2 August 2026, enforcement formally begins for prohibited practices, GPAI obligations, transparency rules, and AI literacy obligations. Source
-
The article was authored by Dr. Andreas Splittgerber, a Partner at Reed Smith based in Munich. Source
-
Cyberpsychology: Journal of Psychosocial Research on Cyberspace published Issue 3 of Volume 20 on 26 June 2026. Source
-
Issue 3, Volume 20 of Cyberpsychology journal contains twelve articles. Source
-
Issue 3, Volume 20 of Cyberpsychology journal covers topics including online incivility and victimisation, digital piracy, and presentation on social media. Source
-
All articles in the Cyberpsychology journal are published as open access. Source
-
The Cyberpsychology journal closed new submissions from 16 June to 31 August 2026, citing a sharp increase in submissions in 2025 and the need to protect editor workload. Source
-
The Cyberpsychology journal will reopen for new manuscript submissions on 1 September 2026. Source
-
The Cyberpsychology journal describes itself as a diamond open access (non-profit) journal, meaning its growth is not tied to financial expansion. Source
-
Issue 2, Volume 20 of Cyberpsychology journal was published on 14 April 2026 and contains eight open-access articles. Source
-
Issue 2, Volume 20 of Cyberpsychology journal covers topics including AI aversion, online sexual health knowledge, online dating, and videoconference fatigue. Source
-
Issue 1, Volume 20 of Cyberpsychology journal was published on 28 January 2026. Source
-
Issue 1, Volume 20 of Cyberpsychology journal covers topics including adolescents' and young people's mobile and social network habits, prosocial and antisocial online behaviours, social media influen Source
-
The EU Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force on 27 July 2026, three days after its publication in the Official Journal. Source
-
AI Act transparency obligations under Article 50 — covering chatbot disclosure, synthetic content marking, and deepfake labelling — became enforceable on 2 August 2026. Source
-
Article 5 of the EU AI Act now prohibits AI systems designed to generate non-consensual intimate imagery, with the ban applying from 2 December 2026. Source
-
High-risk AI systems under Annex III of the EU AI Act now have a compliance deadline of 2 December 2027, extended from the original August 2026 deadline. Source
-
High-risk AI systems under Annex I of the EU AI Act (AI embedded in regulated products) have a compliance deadline extended to 2 August 2028. Source
-
Violations of EU AI Act transparency obligations may result in fines of up to €15 million or 3% of total annual worldwide turnover, whichever is higher. Source
-
The AI Act Omnibus entered into force across the EU on 27 July 2026. Source
-
The AI Act Omnibus forms part of the EU's broader Omnibus legislative package aimed at simplifying digital regulation. Source
-
The compliance deadline for stand-alone high-risk AI systems (HRAIS) has been extended to 2 December 2027. Source
-
The compliance deadline for AI systems that are products or safety components of products (e.g. medical devices, toys, vehicles) has been extended to 2 August 2028. Source
-
AI systems placed on the EU market before the new HRAIS deadline dates will not be subject to high-risk AI requirements unless they undergo a substantial modification after those dates. Source
-
Transparency obligations under Art. 50 AI Act — including disclosure requirements for chatbots and deepfakes — apply from 2 August 2026. Source
-
The AI Act Omnibus extends the simplified compliance framework previously available only to SMEs to companies with up to 750 employees and €150 million in annual revenue (small mid-caps). Source
-
The AI Act Omnibus reinforces the AI Office's powers and centralises oversight of AI systems built on general-purpose AI models, with the stated aim of reducing governance fragmentation. Source
-
The AI Act rules on General-Purpose AI (GPAI) models became effective in August 2025. Source
-
On 19 June 2026, the Commission selected the EUROPA consortium as the winner of the Frontier AI Grand Challenge, a project to build a European open-source frontier AI model in all 24 EU languages. Source
-
The Council presidency and European Parliament negotiators reached a provisional agreement on streamlining AI rules on 7 May 2026. Source
-
The agreement postpones the application deadline for stand-alone high-risk AI systems to 2 December 2027. Source
-
The agreement postpones the application deadline for high-risk AI systems embedded in regulated products to 2 August 2028. Source
-
The agreement introduces a new prohibition on AI-generated non-consensual sexual and intimate content or child sexual abuse material. Source
-
The agreement reduces the grace period for providers to implement transparency solutions for artificially generated content from 6 months to 3 months, with the new deadline 2 December 2026. Source
-
The agreement postpones the deadline for establishment of AI regulatory sandboxes by competent authorities at national level until 2 August 2027. Source
-
The agreement clarifies that the AI Office has supervisory competence for AI systems based on general-purpose AI models where the model and system are developed by the same provider, with exceptions f Source
-
The agreement extends regulatory exemptions granted to SMEs to small mid-caps (SMCs). Source
-
The agreement exempts machinery regulation from direct applicability of the AI Act. Source
-
The agreement introduces an obligation for the Commission to provide guidance to assist economic operators of high-risk AI systems covered by sectoral harmonisation legislation in complying with AI Ac Source
-
The agreement must be endorsed by the Council and European Parliament before formal adoption of the legislative act in the coming weeks. Source
-
Microsoft recommends deploying Windows 11 updates within less than three days as the deferral period for quality updates. Source
-
Attackers are using AI to quickly exploit vulnerabilities in Windows 11 on unpatched systems. Source
-
Microsoft patched 206 security bugs in June 2026. Source
-
Microsoft's AI system MDASH achieved an 88.45% success rate in identifying vulnerabilities in Windows. Source
-
Once a vulnerability is publicly documented, AI can help attackers analyze the issue and develop an exploit within hours. Source
-
81.2% of companies running AI packages have at least one known vulnerability. Source
-
99.9% of AI vulnerability alerts with an available fix remain unpatched. Source
-
56% of AI adopters have deployed agent frameworks into production. Source
-
74.1% of companies running AI packages have at least one critical CVE. Source
-
64% of AI adopters have deployed vector databases that connect LLMs to internal documents, customer records, and proprietary knowledge. Source
-
Businesses using retrieval-augmented generation (RAG) operate an average of 3.78 vector databases. Source
-
Nearly 30% of AI adopters store at least one AI key in an insecure location. Source
-
The EU AI Act introduces additional requirements for high-risk AI systems beginning on August 2, 2026. Source
-
Independent MEP Michael McNamara first proposed the ban on AI nudifier tools in the European Parliament in March 2026. Source
-
The European Parliament voted by a significant majority to adopt new legislation banning AI nudifier tools as part of wider reforms to the EU's AI regulatory framework. Source
-
The new rules banning AI nudifier tools are expected to come into effect on December 2, 2026. Source
-
Providers of AI systems capable of generating or manipulating sexually explicit images resembling identifiable individuals without their consent will be prohibited from placing such systems on the EU Source
-
The prohibition on AI nudifier tools will also extend to deployers who use AI systems specifically for the purpose of creating non-consensual intimate images. Source
-
In January 2026, the European Commission launched an investigation into Grok, the AI tool integrated into the social media platform X, over concerns surrounding the generation and circulation of sexua Source
-
In March 2026, the number of Garda investigations involving images generated using the Grok AI tool had increased from 200 to 244 in a relatively short period. Source
-
Under the revised timetable in the AI Act, obligations governing stand-alone high-risk AI systems will apply from December 2027. Source
-
Under the revised timetable in the AI Act, AI systems embedded as safety components within products covered by existing EU sectoral legislation will become subject to the rules from August 2028. Source
-
Minister of State for Trade Promotion, Artificial Intelligence and Digital Transformation Niamh Smyth launched a new industry consultation inviting businesses from manufacturing, tourism, construction Source
-
The consultation forms part of a study being undertaken by Accenture on behalf of the Department of Enterprise, Tourism and Employment to understand how Irish businesses are currently using AI, the op Source
-
The submissions from the consultation will inform the first phase of the department's Sectoral Strategy for Enterprise Adoption of AI. Source
-
Businesses are invited to participate in the DETE AI in Enterprise Consultation by 24 July 2026. Source
-
A steering group chaired by Assistant Secretary Jean Carberry is guiding the study, comprising representatives from industry, enterprises operating in the priority sectors and relevant policy stakehol Source
-
The AI Act entered into force on 1 August 2024 and will be fully applicable on 2 August 2026, with some exceptions. Source
-
Prohibited AI practices including social scoring, subliminal manipulation, and real-time biometric remote identification in public spaces became effective on 2 February 2025. Source
-
Rules for high-risk AI systems embedded into regulated products have an extended transition period until 2 August 2028 as a result of the political agreement on the proposal to simplify the AI Act. Source
-
The Code of Practice on marking and labelling of AI-generated content will be a voluntary tool to guide providers and deployers of generative AI systems to comply with transparency obligations. Source
-
On 7 May 2026, EU legislative bodies reached a political agreement on proposed amendments to the AI Act as part of the AI Act Omnibus. Source
-
The AI Act omnibus extends the compliance deadline for stand-alone high-risk AI systems to 2 December 2027. Source
-
The AI Act omnibus extends the compliance deadline for AI systems that are products or safety components regulated by certain EU product safety laws to 2 August 2028. Source
-
The AI Act omnibus introduces a prohibition on AI systems that generate or manipulate sexually explicit or intimate images, video, or audio without explicit consent, or that create child sexual abuse Source
-
The AI Act omnibus makes it easier to use GDPR special category personal data where necessary to detect and mitigate bias in AI models. Source
-
Formal adoption of the AI Act omnibus by the European Parliament and Council is expected by July 2026. Source
-
The primary driver of the proposed delays is the slower than expected development of harmonised technical standards and guidance, which are critical to operationalising the AI Act. Source
-
Nudifier applications (those that create non-consensual sexually explicit or intimate content, or child sexual abuse material) are to be categorised as prohibited AI systems from 2 December 2026. Source
-
The process to turn the amendments into law is expected to be complete by 2 August 2026, with the amendments to be formally adopted by the European Council and thereafter formally published in the Off Source
-
The European Parliament on 16 June 2026 granted its final approval to certain material amendments to the EU Artificial Intelligence Act. Source
-
Standalone high-risk AI systems within Annex III categories will take effect from 2 December 2027 rather than 2 August 2026, a 16-month delay. Source
-
High-risk AI systems that are products or safety components regulated by EU product safety laws listed in Annex I will take effect from 2 August 2028 rather than 2 August 2027, a 12-month delay. Source
-
Watermarking obligations for certain AI systems placed on the market before 2 August 2026 will take effect from 2 December 2026 rather than 2 August 2026. Source
-
European standardisation bodies have faced delays in delivering key standards, with many now expected towards the end of 2026. Source
-
Nudifier applications are to be categorised as prohibited AI systems from 2 December 2026. Source
-
The simplified compliance framework applicable to SMEs will be extended to SMCs with up to 750 employees and €150 million in annual revenue. Source
-
AI systems within scope of the Machinery Regulation (EU) 2023/1230 will primarily be governed by sectoral rules as opposed to the AI Act, with this regulation being moved from Section A to Section B o Source
-
The European Council is expected to formally adopt the amendments, with this process expected to be complete by 2 August 2026. Source
-
In exceptional circumstances, where strictly necessary and subject to safeguards, special category data may be processed for bias detection and correction. Source
-
The Commission will launch a call to increase EU evaluation capacity of AI models before they are placed in the EU market, expected to be operational by 2027. Source
-
A Code of Practice on marking and labelling of AI-generated content selected by the AI Office will be a voluntary tool to guide providers and deployers of generative AI systems to comply with transpar Source
-
Guidelines on transparent AI systems and the Code of Practice on marking and labelling of AI-generated content will be published in the second quarter of 2026. Source
-
The AI Act's prohibited practices became effective in February 2025. Source
-
Rules for systems used in certain high-risk areas—including biometrics, critical infrastructure, education, employment, migration, asylum and border control—will apply from 2 December 2027. Source
-
For systems integrated into products such as lifts or toys, high-risk AI rules will apply from 2 August 2028. Source
-
The Agreement extends compliance deadlines for stand-alone high-risk AI systems to 2 December 2027. Source
-
For AI systems that qualify as regulated products or safety components, the compliance deadline is extended to 2 August 2028. Source
-
Violations of the prohibition on AI-generated intimate content may trigger fines of up to €35 million or 7% of annual worldwide turnover, whichever is higher. Source
-
The July 2026 action plan on Cybersecurity and AI sets out a coordinated approach to help Member States, businesses and public authorities address cybersecurity and resilience challenges posed by the Source
-
The Commission will launch a call to increase EU evaluation capacity of AI models, before they are placed in the EU market. Expected to be operational by 2027, this will strengthen third-party assessm Source
-
The Commission and the European Union Agency for Cybersecurity (ENISA) will create a blueprint to secure access to advanced AI systems for cybersecurity purposes and establish a secure testing platfor Source
-
On 7 May 2026, EU legislative bodies reached a political agreement on proposed amendments to the AI Act. This 'AI Act Omnibus' forms part of the EU's broader Omnibus legislative package aimed at simpl Source
-
Effective December 2, 2026, the Agreement extends prohibitions to 'nudifier' applications — AI systems that generate or manipulate sexually explicit or intimate images, video, or audio without explici Source
-
Violations of the nudifier and CSAM prohibitions may trigger fines of up to €35 million or 7% of annual worldwide turnover, whichever is higher. Source
-
The Agreement extends the compliance deadlines for stand-alone HRAIS to December 2, 2027. This stand-alone extension does not apply to AI systems that qualify as regulated products or safety component Source
-
The AI Act's simplified compliance framework for small- and medium-sized enterprises will be extended to companies with up to 750 employees and €150 million in annual revenue. Source
-
Under a grandfathering rule introduced by the Agreement, generative AI systems placed on the market or put into service before August 2, 2026 must comply with the watermarking requirements only as of Source
-
Violations of watermarking requirements may result in fines of up to €15 million or 3% of total annual worldwide turnover, whichever is higher. Source
-
AI used in industrial applications and products already regulated under the Machinery Regulation is exempt from the AI Act. Source
-
The text will proceed to formal adoption by the European Parliament and the Council, which is expected by July 2026 — ahead of August 2, 2026, when HRAIS requirements would otherwise take effect. Source
-
On 7 May 2026, the Council and the European Parliament reached a provisional political agreement on a set of targeted amendments to the AI Act. Source
-
The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024. Source
-
The compliance deadline for standalone high-risk AI systems (Annex III) has been postponed to 2 December 2027. Source
-
The compliance deadline for AI systems embedded as safety components in products governed by sectoral EU safety legislation (Annex I) has been postponed to 2 August 2028. Source
-
AI systems already on the market before the compliance deadline only remain subject to high-risk obligations if they undergo significant design changes from the deadline date onwards. Source
-
On 19 May 2026, the European Commission published draft guidelines on the classification of high-risk artificial intelligence systems under the EU AI Act. Source
-
The watermarking obligation under Article 50 of the AI Act applies from 2 August 2026, with a four-month grace period allowing generative AI systems already on the market to comply by 2 December 2026. Source
-
On 8 May 2026, the European Commission published draft guidelines clarifying how the transparency obligations under Article 50 should be applied in practice. Source
-
The definition of 'safety component' has been refined so that an AI system only qualifies as a safety component if its intended purpose is to prevent or mitigate risks to the health and safety of pers Source
-
A new prohibition on AI systems that generate child sexual abuse material (CSAM) or non-consensual intimate content ('nudifiers') has been added to Article 5 of the AI Act. Source
-
Providers have until 2 December 2026 to bring AI systems generating CSAM or non-consensual intimate content into compliance with the new prohibition. Source
-
Article 4 of the AI Act has been amended so that providers and deployers are required to take appropriate measures to support the development of AI literacy among their staff, rather than to ensure a Source
-
The AI Act now formally recognises 'small mid-cap enterprises' (SMCs), which are companies that have outgrown the SME category but still face challenges comparable to smaller businesses regarding regu Source
-
By 2 August 2027, each Member State must establish at least one AI testing environment ('sandbox'). Source
-
The EU AI Office gains exclusive supervisory and enforcement competence over AI systems built on general-purpose AI (GPAI) models where the model and system share the same provider. Source
-
The EU AI Office gains exclusive supervisory and enforcement competence over AI systems integrated into very large online platforms (VLOPs) or very large online search engines (VLOSEs). Source
-
The European Commission and Member States are tasked with supporting AI literacy compliance efforts. Source
-
The AI Board will issue recommendations, including common objectives, to further promote AI literacy across the EU. Source
-
The AI Act amendments have not yet been formally adopted and remain subject to approval by both the European Parliament and the Council, with adoption envisaged before 2 August 2026. Source
-
The European Commission must clarify the scope and application of adjustments regarding AI in machinery by 2 August 2027. Source
-
The Commission must adopt guidance, including a template, for post-market monitoring plans by 2 September 2027. Source
-
The AI Act entered into force on 1 August 2024, and will be fully applicable 2 years later on 2 August 2026, with some exceptions: prohibited AI practices and AI literacy obligations entered into appl Source
-
The AI Act prohibits eight practices: harmful AI-based manipulation and deception, harmful AI-based exploitation of vulnerabilities, social scoring, individual criminal offence risk assessment or pred Source
-
On 7 May 2026, EU legislative bodies reached a political agreement on proposed amendments to the AI Act called the 'AI Act Omnibus,' which extends compliance deadlines for high-risk AI systems and int Source
-
Under the AI Act Omnibus agreement, the compliance deadline for stand-alone high-risk AI systems is extended to 2 December 2027 (deferred by 16 months from the original 2 August 2026 deadline). Source
-
Under the AI Act Omnibus agreement, the compliance deadline for high-risk AI systems that are products or safety components of products regulated under EU product safety laws is extended to 2 August 2 Source
-
Effective 2 December 2026, the AI Act Omnibus extends prohibitions to AI systems that generate or manipulate sexually explicit or intimate images, video, or audio without explicit consent, or that cre Source
-
Under the AI Act Omnibus grandfathering rule, generative AI systems placed on the market or put into service before 2 August 2026 must comply with watermarking requirements for AI-generated or manipul Source
-
The AI Act Omnibus extends simplified compliance requirements granted to small and medium-sized enterprises to small mid-cap companies with up to 750 employees and €150 million in annual revenue. Source
-
The AI Act Omnibus amendment narrows the definition of 'safety component' for high-risk AI system classification purposes so that regulated products with AI functions that merely assist users or optim Source
-
The AI Act Omnibus amendments make it easier to use GDPR special category personal data (health information, biometric data, race, or sexual orientation) where necessary to detect and mitigate bias in Source
-
Formal adoption of the AI Act Omnibus amendments is expected by July 2026, ahead of the originally scheduled 2 August 2026 deadline for high-risk AI system requirements to take effect. Source