EU waters down its own AI Act with delayed deadlines and new deepfake bans
The EU Council and European Parliament reached a provisional deal this morning to water down the AI Act, delaying high-risk AI system rules by over a year and adding new bans on AI-generated non-consensual sexual content and CSAM.
The agreement is part of the so-called Omnibus VII package, the EU’s simplification agenda pushed hard by industry lobbying over the past six months. The original AI Act entered into force in August 2024 with high-risk provisions set to kick in on 2 August 2026. Under today’s deal, standalone high-risk AI systems now have until 2 December 2027 to comply. AI systems embedded in products get until 2 August 2028.
That is a 16-month delay for standalone systems and a full two years for embedded ones.
The official justification is that needed standards and compliance tools are not ready. The Commission had proposed adjusting the timeline to match the availability of these technical resources. Co-legislators broadly accepted this reasoning and treated the file with what they called “utmost priority,” given the looming August 2026 deadline.
In exchange for the delays, negotiators added new restrictions. AI applications generating non-consensual sexual or intimate content, including so-called nudifier apps, are now explicitly banned. The same provision covers AI-generated child sexual abuse material. Transparency requirements for AI-generated content got shortened from a six-month grace period to three months, with a new deadline of 2 December 2026.
The deal also clarifies the AI Office’s supervisory role over general-purpose AI models, with exceptions carved out for law enforcement, border management, judicial authorities, and financial institutions, which remain under national authority oversight.
SME exemptions get extended to small mid-caps. The obligation for providers to register AI systems in the EU database even when claiming high-risk exemption was reinstated. The “strict necessity” standard for processing sensitive personal data in bias detection was also restored.
Regulatory sandbox deadlines moved to 2 August 2027.
A compromise on industrial AI addressed overlaps between the AI Act and sectoral legislation covering medical devices, toys, machinery, lifts, and watercraft. The machinery regulation was exempted from direct AI Act applicability, with the Commission empowered to add health and safety requirements through delegated acts instead.
Not everyone is happy. POLITICO reports that both lawmakers and industry groups are already pushing for more deregulation, calling today’s deal insufficient. CCIA, the tech industry lobby, said negotiators “missed opportunities.” Amnesty International warned back in April that the simplification agenda would “roll back our rights.”
Critics frame this as Europe caving to big tech pressure, particularly U.S. companies. Reuters called it a “watered-down” deal. The previous round of negotiations collapsed after 12 hours on April 29, with talks only resuming this week.
The deal marks the first deliverable under the “One Europe, One Market” roadmap agreed by EU institutions last week. It still needs formal adoption by both the Council and Parliament.
Sources: EU Council, POLITICO, Reuters, The Next Web, DW, European Parliament