Policy
EU approves delay to AI Act high-risk rules, leaving August 2 transparency duties in place
The Council signed off on the AI omnibus, moving high-risk deadlines to December 2027 and August 2028. Most transparency duties still start on August 2, 2026.
HackHoster Team · · 10 min read

At a glance
- The Council of the EU gave final approval to the Digital Omnibus on AI on June 29, 2026, after the European Parliament approved it on June 16.
- Rules for stand-alone high-risk AI, such as hiring and credit scoring, now apply from December 2, 2027 instead of August 2, 2026.
- High-risk AI built into regulated products moves from August 2, 2027 to August 2, 2028.
- Article 50 transparency duties for chatbots and generated content still apply from August 2, 2026; older systems get until December 2 for marking.
- A new ban on AI systems that generate non-consensual intimate imagery or child sexual abuse material applies from December 2, 2026.
The Council of the European Union gave its final approval on Monday to the Digital Omnibus on AI, a package of amendments to the EU AI Act. The European Parliament approved the same text on June 16, so the legislative process is finished. What remains is signature and publication in the Official Journal of the EU. The amending regulation enters into force on the third day after publication, which has not happened yet.
The change most people will notice is the delay for high-risk AI. The change most product teams need to plan around is what did not move: the AI Act's transparency rules for chatbots and generated content still apply from August 2, 2026, about a month from now.
Not legal advice. This is a plain-language summary for builders. The final text still has to be published, and how it applies depends on your product, your role and your market. If you ship AI features to people in the EU, check how this applies to you with counsel.
What moved, and to when
The omnibus changes dates rather than the structure of the law. According to NicFab's and Sidley's summaries of the final text:
| Obligation | Original date | New date |
|---|---|---|
| Stand-alone high-risk systems (Annex III) | August 2, 2026 | December 2, 2027 |
| High-risk AI in regulated products (Annex I) | August 2, 2027 | August 2, 2028 |
| Machine-readable marking (Article 50(2)), systems already on the market before August 2, 2026 | August 2, 2026 | December 2, 2026 |
| Machine-readable marking, systems launched on or after August 2, 2026 | August 2, 2026 | Unchanged |
| Other Article 50 transparency duties | August 2, 2026 | Unchanged |
| National AI regulatory sandboxes running | August 2, 2026 | August 2, 2027 |
| New ban on AI-generated intimate imagery and abuse material | Did not exist | December 2, 2026 |
Annex III covers uses such as hiring and worker management, access to essential services like credit, education, and biometric identification. Annex I covers AI that is a safety component of products already governed by EU product law, such as medical devices.

How the AI Act got here
The AI Act is not new. According to Wikipedia's history of the law, the European Commission proposed it on April 21, 2021. Parliament approved it on March 13, 2024, by 523 votes to 46 with 49 abstentions, the Council approved it unanimously on May 21, 2024, and it entered into force on August 1, 2024. Its obligations were designed to switch on in stages.
| Date | Milestone |
|---|---|
| April 21, 2021 | Commission proposes the AI Act |
| August 1, 2024 | AI Act enters into force |
| February 2, 2025 | Bans on unacceptable-risk practices apply |
| August 2, 2025 | Rules for general-purpose AI models apply |
| November 19, 2025 | Commission proposes the Digital Omnibus on AI |
| May 7, 2026 | Parliament and Council reach a provisional agreement |
| June 16, 2026 | Parliament approves the final text |
| June 29, 2026 | Council gives final approval |
| August 2, 2026 | Article 50 transparency duties apply |
The law sorts AI by risk. Some practices are banned outright. High-risk systems must meet quality, transparency, human oversight and safety obligations and pass conformity assessments, and some need a fundamental rights impact assessment before deployment. Limited-risk systems carry transparency duties, and minimal-risk systems are left alone. General-purpose AI models have their own category.

The Commission presented the delay as part of a wider simplification drive. Euronews reported at the time that the Commission pointed to slow implementation by member states, companies needing more time to adapt, and the fact that the harmonised technical standards companies would use to show compliance were not ready. Many member states had also missed the August 2025 deadline to designate the authorities that would enforce the law, according to the testing and certification industry group TIC Council, as quoted by Euronews.
What else changed in the text
Beyond dates, the omnibus makes a set of smaller changes that matter for specific teams.
- AI literacy is softened. Since February 2025, the AI Act has required providers and deployers to ensure a sufficient level of AI literacy among their staff. According to Gibson Dunn, the amended text asks them to support the development of AI literacy rather than guarantee it, and Sidley notes that the Commission and member states take on a duty to support and facilitate it.
- Small mid-caps get SME treatment. Some exemptions that were limited to small and medium-sized enterprises now extend to small mid-cap companies, according to Sidley.
- The safety-component test is narrower. Products whose AI only assists users, optimizes performance or adds convenience will not automatically count as high-risk unless a failure would create health or safety risks.
- Registration stays. Providers that rely on the Article 6(3) exemption to argue an Annex III system is not high-risk still have to register it, through a simplified procedure.
- Bias testing gets a clearer legal basis. According to Gibson Dunn, the legal basis for processing sensitive personal data to detect and correct bias extends from high-risk systems to all AI systems and general-purpose models, subject to a strict-necessity test.
- The AI Office gains power. The Commission's AI Office gets exclusive competence over AI systems built on a general-purpose model by the same provider, and over AI built into very large online platforms and search engines, with powers to investigate, inspect and fine. National authorities keep law enforcement, border management, the judiciary and financial institutions.
- Machinery is handled by machinery law. NicFab reports that the AI Act no longer applies directly to products under the Machinery Regulation, whose health and safety requirements cover AI instead, and EUbusiness reports a new mechanism to resolve overlaps with rules for products such as medical devices, toys, lifts and watercraft.
The rules for general-purpose AI models, in force since August 2025, remain fully applicable, according to NicFab.
Where lawmakers pushed back on the Commission
The final text is not simply the Commission's November proposal. The December 2027 date for Annex III systems survived, but negotiators changed several details along the way:
- A shorter marking grace period. EUbusiness's report of the Council decision says the transition for marking AI-generated content was cut from the six months originally on the table to a deadline of December 2, 2026.
- Registration restored. Sidley describes the registration duty for systems claimed to be exempt under Article 6(3) as reinstated, in simplified form, after the proposal had dropped it.
- A tighter test for sensitive data. Sidley also reports that the agreement reinstated the strict-necessity threshold for processing special categories of personal data for bias detection, rather than the looser wording first proposed.
- An earlier ban. In April, Tech Policy Press reported that a ban on nudification tools was then slated to apply only from February 2027. The final text brings the prohibition on AI-generated intimate imagery and abuse material forward to December 2, 2026.
For builders, the pattern matters more than the details: the delay bought time on the heaviest obligations, but the transparency and content-safety rules that touch most consumer AI products got stricter, not looser.
What still applies on August 2, 2026
Article 50 is the transparency article, and apart from the marking grace period for existing systems, it was not postponed. Gibson Dunn's analysis stresses the point: the broader Article 50 duties proceed from August 2. The text of the article sets out who must do what.
Provider versus deployer. The AI Act assigns duties to the providers of AI systems and to deployers, the organisations that use AI in a professional context. If you build an AI feature and ship it under your own name, expect to be treated as its provider; if you run someone else's AI system in your business, you are more likely a deployer. Confirm the role for each feature with counsel, because the duties differ.
- Chatbots and other interactive AI, Article 50(1): providers must make sure people know they are dealing with an AI system, unless that is obvious to a reasonably well-informed person from the context.
- Generated content, Article 50(2): providers of systems that generate synthetic audio, images, video or text must mark the output in a machine-readable way as artificially generated or manipulated. The solutions have to be effective, interoperable, robust and reliable as far as technically feasible. There are exceptions for assistive editing and for tools that do not substantially alter the input.
- Emotion recognition and biometric categorization, Article 50(3): deployers must inform the people exposed to them.
- Deepfakes and AI-written public-interest text, Article 50(4): deployers must disclose that the content is AI-generated or manipulated. Clearly artistic, satirical or fictional work gets a lighter duty, and text that has gone through human review with clear editorial responsibility is exempt.
The information has to be given clearly, at the latest at the first interaction or exposure. Breaches of these duties can draw fines of up to 15 million euros or 3% of worldwide annual turnover. Violations of the banned-practices list carry higher fines of up to 35 million euros or 7%.

The new ban, and who it reaches
The most significant addition is a new prohibited practice. From December 2, 2026, the AI Act bans AI systems that generate or manipulate non-consensual intimate imagery or child sexual abuse material. EUbusiness's report of the Council decision describes it as covering systems that generate nude images of real people or edit clothes out of existing photos.
The scope is wider than dedicated nudification apps. According to Gibson Dunn, the ban covers systems for which such output is a reasonably foreseeable and reproducible outcome without significant technical modification, unless they have adequate technical safeguards that reliably prevent it. In practice, a general-purpose image or video generator is not banned because it could be misused, but it is in scope if its safeguards are missing or inadequate.
Open questions and criticism
The delay was contested from the start. When the Commission proposed it, Euronews reported that the big-tech lobby group CCIA welcomed it but wanted bolder changes, while Finance Watch's Peter Norwood called it a deregulate-to-accelerate strategy that consumers would pay for, and the consumer group BEUC accused the Commission of putting Big Tech's interests first.

The sharpest criticism concerns systems already on the market. Tech Policy Press reported in April that the AI Act's high-risk rules apply to systems placed on the market after the application date, so a longer delay widens the window for legacy systems. Laura Caroli, a former AI Act negotiator, told the publication that high-risk hiring systems already in use could stay outside the law indefinitely unless substantially changed. Sergey Lagodinsky, an MEP from Germany's Greens, called it a loophole, and Bram Vranken of the lobbying watchdog Corporate Europe Observatory warned that much of the high-risk AI placed on the market before December 2027 would never have to comply.
There are practical uncertainties too. Until publication in the Official Journal, NicFab notes, the original calendar is technically still the law, and the Council aimed to finish before August 2 precisely so that the old high-risk deadline never takes effect. The delay was justified partly by missing harmonised standards, and the new dates assume those standards will be ready in time. And the new ban depends on what counts as adequate safeguards, which regulators and courts will have to define.

A checklist for teams shipping AI to EU users
- Inventory every AI feature that EU users touch. For each one, note whether you are the provider or the deployer, and the date it was first placed on the EU market. That date now decides whether your marking deadline is August 2 or December 2.
- Add AI disclosure to chat interfaces before August 2. A short notice at the start of the conversation is the usual approach. Only skip it if a reasonable user could not miss that they are talking to software.
- Plan machine-readable marking for generated media and text. Check what your model provider already embeds, such as metadata or watermarks, and whether it survives your own pipeline, like resizing, re-encoding or copy-paste.
- Label deepfakes and AI-written public-facing text if your product publishes them on users' behalf, and document any editorial review you rely on for the text exception.
- Test image and video generation against the December 2 ban. If your product can produce realistic images of real people, document the safeguards that stop intimate imagery and abuse material, and test them adversarially now.
- Classify anything that might be high-risk. If a feature touches hiring, credit, education or biometrics, use the extra 16 months to build risk management, data governance, logging and human oversight, rather than treating the delay as a pause.
- Write down your reasoning. If you conclude a system is not high-risk under Article 6(3), keep the analysis and plan for the registration step.
- Watch for Official Journal publication, and have counsel confirm the final dates against the published text.
Practical tip for hackathon teams. Most of this lands on items 2 and 3. A one-line AI disclosure and a check that your image or text outputs carry provenance metadata are cheap to add during a build and hard to retrofit later.

What to watch
As of June 30, the next step is signature and publication in the Official Journal, which the Council aims to complete before August 2 so the old high-risk deadline never applies. After that come the dates in the table: Article 50 transparency on August 2, the marking deadline for existing systems and the new ban on December 2, sandboxes by August 2, 2027, and the high-risk rules in December 2027 and August 2028. The open work in between is guidance and standards, including the codes of practice for marking AI-generated content that Article 50 invites the Commission and the AI Office to encourage.
Sources
- Final green light for simpler, streamlined EU rules on artificial intelligence (EUbusiness, reporting the Council decision)
- Digital Omnibus on AI, the Council's final green light (NicFab)
- EU lawmakers reach provisional agreement to delay key EU AI Act obligations (Sidley Data Matters)
- EU AI Act omnibus agreement, postponed high-risk deadlines and other key changes (Gibson Dunn, May 2026)
- Article 50, transparency obligations for providers and deployers of certain AI systems (EU AI Act text, AI Act Explorer)
- European Commission proposes delaying full implementation of AI Act to 2027 (Euronews, November 2025)
- EU's AI Act delays let high-risk systems dodge oversight (Tech Policy Press, April 2026)
- Artificial Intelligence Act (Wikipedia)
More from the blog

Policy ·
Third Circuit upholds ruling that ROSS's AI training on Westlaw headnotes was not fair use
A federal appeals court affirmed that ROSS Intelligence infringed Thomson Reuters' copyrights by training a legal search tool on Westlaw headnotes. The opinion itself is still sealed.
10 min read

Policy ·
FCC adds foreign-made humanoids, quadrupeds and other mobile robots to its Covered List
New models of foreign-produced mobile robots can no longer get FCC authorization. Robots you already own, and models already approved, are not affected.
11 min read

Security ·
An OpenAI research agent got past access blocks on an Australian Medicare statistics portal
Australia's prime minister says an OpenAI model researching medicine spending got past access controls on a government portal in June. OpenAI told the government in September.
10 min read