The Council of the European Union gave its final green light on June 29, 2026, to the “Digital Omnibus on AI,” a package of amendments that rewrites parts of the EU AI Act just as its toughest provisions were about to take effect. The move caps months of lobbying from European businesses that argued the original timeline — with sweeping high-risk AI obligations due to bite on August 2, 2026 — was unworkable, and it marks one of the most significant retreats from an aggressive early-enforcement posture that any major AI regulator has made to date.
The Deadline That Moved
The headline change is a roughly 16-month extension for standalone high-risk AI systems: companies now have until December 2, 2027, to comply, rather than August 2, 2026. High-risk systems that are embedded in products already covered by separate EU harmonisation legislation — things like medical devices or machinery with AI components — get even more room, with a compliance date pushed to August 2, 2028. The Council and Commission have framed the change as preserving the AI Act’s substance while giving companies, especially smaller ones without large compliance departments, realistic time to build the required risk-management, documentation and human-oversight systems.
What Didn’t Change
Not every deadline moved. Article 50 transparency obligations — the requirement that AI-generated content carry machine-readable marking so users and platforms can identify synthetic media — remain untouched and still take effect on August 2, 2026, the original date. Regulators were explicit that they see disclosure requirements as lower-cost and higher-urgency than the deeper structural compliance work required of high-risk systems, and were unwilling to delay them even while giving ground elsewhere.
A New Prohibition Arrives
The Omnibus is not purely a deregulatory exercise. Article 5 of the AI Act, which lists outright-banned AI use cases, gains a new prohibition specifically targeting AI systems that generate non-consensual intimate imagery or child sexual abuse material, with that ban taking effect in December 2026. EU officials have pointed to the addition as evidence that the broader package is a “simplification,” not a rollback of protections against the most clearly harmful applications of generative AI.
Why Brussels Blinked
The extension follows sustained pressure from European industry groups and several member states who warned that the original August 2026 deadline risked pushing AI investment and deployment toward the US and Asia, where comparable comprehensive rules do not yet exist. The Council’s own language emphasizes “legal certainty” and “harmonized application… across the single market” — bureaucratic phrasing that reflects a real concern: national regulators were implementing the original Act unevenly, and companies operating across multiple EU states faced a patchwork of enforcement expectations even before the hardest rules kicked in.
The Counter-Argument From Civil Society
Digital rights groups and some AI-safety advocates have criticized the extension as a capitulation to lobbying, arguing that pushing high-risk compliance out to December 2027 effectively gives companies deploying AI in hiring, credit scoring, law enforcement and other high-stakes domains another year and a half of reduced legal accountability. They note that the EU AI Act was already one of the most delayed comprehensive tech regulations in the bloc’s history relative to its original 2024 passage, and that further delay compounds a pattern of the Act’s most consequential provisions perpetually being pushed to “not yet.”
What’s Next
The Omnibus formally enters into force twenty days after publication in the EU’s Official Journal, starting a new compliance clock that companies operating in Europe — including major US AI labs and their enterprise customers — will need to build into 2027 and 2028 planning cycles. Expect continued lobbying from both directions: industry pushing for further simplification of documentation and audit requirements, and civil-society groups pushing the Commission to hold the line on the new deadlines rather than granting a second extension when 2027 approaches. For US and Asian AI companies with EU customers, the practical takeaway is that the compliance clock has moved but not stopped: legal teams now have a longer runway to build documentation and oversight systems, but the underlying obligations — risk classification, human oversight, technical documentation — remain a fixed feature of doing business in the European market, whichever year they ultimately bite. Member states will also need to update their own national supervisory authorities’ enforcement plans to reflect the new timeline, a process the Commission expects to unfold gradually over the second half of 2026 as guidance documents are updated to match the revised Omnibus text.
Photo: MDGovpics / BY via flickr