All posts

Policy

EU approves delay to AI Act high-risk rules, leaving August 2 transparency duties in place

The Council signed off on the AI omnibus, moving high-risk deadlines to December 2027 and August 2028. Most transparency duties still start on August 2, 2026.

HackHoster Team · · 10 min read

The Europa building in Brussels, seat of the Council of the European Union, with EU flags on poles in the foreground at sunset
Photo: Cbliu / Wikimedia Commons, CC BY-SA 4.0

At a glance

  • The Council of the EU gave final approval to the Digital Omnibus on AI on June 29, 2026, after the European Parliament approved it on June 16.
  • Rules for stand-alone high-risk AI, such as hiring and credit scoring, now apply from December 2, 2027 instead of August 2, 2026.
  • High-risk AI built into regulated products moves from August 2, 2027 to August 2, 2028.
  • Article 50 transparency duties for chatbots and generated content still apply from August 2, 2026; older systems get until December 2 for marking.
  • A new ban on AI systems that generate non-consensual intimate imagery or child sexual abuse material applies from December 2, 2026.

The Council of the European Union gave its final approval on Monday to the Digital Omnibus on AI, a package of amendments to the EU AI Act. The European Parliament approved the same text on June 16, so the legislative process is finished. What remains is signature and publication in the Official Journal of the EU. The amending regulation enters into force on the third day after publication, which has not happened yet.

The change most people will notice is the delay for high-risk AI. The change most product teams need to plan around is what did not move: the AI Act's transparency rules for chatbots and generated content still apply from August 2, 2026, about a month from now.

Not legal advice. This is a plain-language summary for builders. The final text still has to be published, and how it applies depends on your product, your role and your market. If you ship AI features to people in the EU, check how this applies to you with counsel.

What moved, and to when

The omnibus changes dates rather than the structure of the law. According to NicFab's and Sidley's summaries of the final text:

ObligationOriginal dateNew date
Stand-alone high-risk systems (Annex III)August 2, 2026December 2, 2027
High-risk AI in regulated products (Annex I)August 2, 2027August 2, 2028
Machine-readable marking (Article 50(2)), systems already on the market before August 2, 2026August 2, 2026December 2, 2026
Machine-readable marking, systems launched on or after August 2, 2026August 2, 2026Unchanged
Other Article 50 transparency dutiesAugust 2, 2026Unchanged
National AI regulatory sandboxes runningAugust 2, 2026August 2, 2027
New ban on AI-generated intimate imagery and abuse materialDid not existDecember 2, 2026

Annex III covers uses such as hiring and worker management, access to essential services like credit, education, and biometric identification. Annex I covers AI that is a safety component of products already governed by EU product law, such as medical devices.

A microphone in the foreground of the European Parliament's chamber in Strasbourg, with rows of seats blurred behind it
The European Parliament's chamber in Strasbourg during a 2024 plenary session. Parliament approved the AI omnibus on June 16, 2026. Photo: European Parliament / Wikimedia Commons, CC BY 2.0

How the AI Act got here

The AI Act is not new. According to Wikipedia's history of the law, the European Commission proposed it on April 21, 2021. Parliament approved it on March 13, 2024, by 523 votes to 46 with 49 abstentions, the Council approved it unanimously on May 21, 2024, and it entered into force on August 1, 2024. Its obligations were designed to switch on in stages.

DateMilestone
April 21, 2021Commission proposes the AI Act
August 1, 2024AI Act enters into force
February 2, 2025Bans on unacceptable-risk practices apply
August 2, 2025Rules for general-purpose AI models apply
November 19, 2025Commission proposes the Digital Omnibus on AI
May 7, 2026Parliament and Council reach a provisional agreement
June 16, 2026Parliament approves the final text
June 29, 2026Council gives final approval
August 2, 2026Article 50 transparency duties apply

The law sorts AI by risk. Some practices are banned outright. High-risk systems must meet quality, transparency, human oversight and safety obligations and pass conformity assessments, and some need a fundamental rights impact assessment before deployment. Limited-risk systems carry transparency duties, and minimal-risk systems are left alone. General-purpose AI models have their own category.

The Berlaymont building in Brussels, headquarters of the European Commission: a large cross-shaped glass building seen at an angle on a clear morning
The Berlaymont building in Brussels, headquarters of the European Commission, which proposed the AI omnibus in November 2025. Photo: Trougnouf (Benoit Brummer) / Wikimedia Commons, CC BY 4.0

The Commission presented the delay as part of a wider simplification drive. Euronews reported at the time that the Commission pointed to slow implementation by member states, companies needing more time to adapt, and the fact that the harmonised technical standards companies would use to show compliance were not ready. Many member states had also missed the August 2025 deadline to designate the authorities that would enforce the law, according to the testing and certification industry group TIC Council, as quoted by Euronews.

What else changed in the text

Beyond dates, the omnibus makes a set of smaller changes that matter for specific teams.

  • AI literacy is softened. Since February 2025, the AI Act has required providers and deployers to ensure a sufficient level of AI literacy among their staff. According to Gibson Dunn, the amended text asks them to support the development of AI literacy rather than guarantee it, and Sidley notes that the Commission and member states take on a duty to support and facilitate it.
  • Small mid-caps get SME treatment. Some exemptions that were limited to small and medium-sized enterprises now extend to small mid-cap companies, according to Sidley.
  • The safety-component test is narrower. Products whose AI only assists users, optimizes performance or adds convenience will not automatically count as high-risk unless a failure would create health or safety risks.
  • Registration stays. Providers that rely on the Article 6(3) exemption to argue an Annex III system is not high-risk still have to register it, through a simplified procedure.
  • Bias testing gets a clearer legal basis. According to Gibson Dunn, the legal basis for processing sensitive personal data to detect and correct bias extends from high-risk systems to all AI systems and general-purpose models, subject to a strict-necessity test.
  • The AI Office gains power. The Commission's AI Office gets exclusive competence over AI systems built on a general-purpose model by the same provider, and over AI built into very large online platforms and search engines, with powers to investigate, inspect and fine. National authorities keep law enforcement, border management, the judiciary and financial institutions.
  • Machinery is handled by machinery law. NicFab reports that the AI Act no longer applies directly to products under the Machinery Regulation, whose health and safety requirements cover AI instead, and EUbusiness reports a new mechanism to resolve overlaps with rules for products such as medical devices, toys, lifts and watercraft.

The rules for general-purpose AI models, in force since August 2025, remain fully applicable, according to NicFab.

Where lawmakers pushed back on the Commission

The final text is not simply the Commission's November proposal. The December 2027 date for Annex III systems survived, but negotiators changed several details along the way:

  • A shorter marking grace period. EUbusiness's report of the Council decision says the transition for marking AI-generated content was cut from the six months originally on the table to a deadline of December 2, 2026.
  • Registration restored. Sidley describes the registration duty for systems claimed to be exempt under Article 6(3) as reinstated, in simplified form, after the proposal had dropped it.
  • A tighter test for sensitive data. Sidley also reports that the agreement reinstated the strict-necessity threshold for processing special categories of personal data for bias detection, rather than the looser wording first proposed.
  • An earlier ban. In April, Tech Policy Press reported that a ban on nudification tools was then slated to apply only from February 2027. The final text brings the prohibition on AI-generated intimate imagery and abuse material forward to December 2, 2026.

For builders, the pattern matters more than the details: the delay bought time on the heaviest obligations, but the transparency and content-safety rules that touch most consumer AI products got stricter, not looser.

What still applies on August 2, 2026

Article 50 is the transparency article, and apart from the marking grace period for existing systems, it was not postponed. Gibson Dunn's analysis stresses the point: the broader Article 50 duties proceed from August 2. The text of the article sets out who must do what.

Provider versus deployer. The AI Act assigns duties to the providers of AI systems and to deployers, the organisations that use AI in a professional context. If you build an AI feature and ship it under your own name, expect to be treated as its provider; if you run someone else's AI system in your business, you are more likely a deployer. Confirm the role for each feature with counsel, because the duties differ.

  • Chatbots and other interactive AI, Article 50(1): providers must make sure people know they are dealing with an AI system, unless that is obvious to a reasonably well-informed person from the context.
  • Generated content, Article 50(2): providers of systems that generate synthetic audio, images, video or text must mark the output in a machine-readable way as artificially generated or manipulated. The solutions have to be effective, interoperable, robust and reliable as far as technically feasible. There are exceptions for assistive editing and for tools that do not substantially alter the input.
  • Emotion recognition and biometric categorization, Article 50(3): deployers must inform the people exposed to them.
  • Deepfakes and AI-written public-interest text, Article 50(4): deployers must disclose that the content is AI-generated or manipulated. Clearly artistic, satirical or fictional work gets a lighter duty, and text that has gone through human review with clear editorial responsibility is exempt.

The information has to be given clearly, at the latest at the first interaction or exposure. Breaches of these duties can draw fines of up to 15 million euros or 3% of worldwide annual turnover. Violations of the banned-practices list carry higher fines of up to 35 million euros or 7%.

An AI-generated landscape of a forest with red Shinto shrine buildings, a torii gate and mist-covered mountains
An image generated with Stable Diffusion in 2022. Under Article 50(2), output like this from a system offered in the EU will need machine-readable marking that it is AI-generated. Image: Benlisquare / Wikimedia Commons, public domain

The new ban, and who it reaches

The most significant addition is a new prohibited practice. From December 2, 2026, the AI Act bans AI systems that generate or manipulate non-consensual intimate imagery or child sexual abuse material. EUbusiness's report of the Council decision describes it as covering systems that generate nude images of real people or edit clothes out of existing photos.

The scope is wider than dedicated nudification apps. According to Gibson Dunn, the ban covers systems for which such output is a reasonably foreseeable and reproducible outcome without significant technical modification, unless they have adequate technical safeguards that reliably prevent it. In practice, a general-purpose image or video generator is not banned because it could be misused, but it is in scope if its safeguards are missing or inadequate.

Open questions and criticism

The delay was contested from the start. When the Commission proposed it, Euronews reported that the big-tech lobby group CCIA welcomed it but wanted bolder changes, while Finance Watch's Peter Norwood called it a deregulate-to-accelerate strategy that consumers would pay for, and the consumer group BEUC accused the Commission of putting Big Tech's interests first.

CCTV cameras mounted on a tall street-light pole at a roundabout, against a blue sky with power lines behind
Surveillance cameras on a street pole in Poland. Biometric identification is one of the Annex III high-risk uses whose rules now start in December 2027. Photo: WrS.tm.pl / Wikimedia Commons, public domain

The sharpest criticism concerns systems already on the market. Tech Policy Press reported in April that the AI Act's high-risk rules apply to systems placed on the market after the application date, so a longer delay widens the window for legacy systems. Laura Caroli, a former AI Act negotiator, told the publication that high-risk hiring systems already in use could stay outside the law indefinitely unless substantially changed. Sergey Lagodinsky, an MEP from Germany's Greens, called it a loophole, and Bram Vranken of the lobbying watchdog Corporate Europe Observatory warned that much of the high-risk AI placed on the market before December 2027 would never have to comply.

There are practical uncertainties too. Until publication in the Official Journal, NicFab notes, the original calendar is technically still the law, and the Council aimed to finish before August 2 precisely so that the old high-risk deadline never takes effect. The delay was justified partly by missing harmonised standards, and the new dates assume those standards will be ready in time. And the new ban depends on what counts as adequate safeguards, which regulators and courts will have to define.

A white industrial robot arm made by KUKA, raking patterns into a floor of sand in a gallery installation
An industrial robot arm at an art installation. Under the omnibus, AI in products covered by the Machinery Regulation is handled through machinery law rather than directly by the AI Act. Photo: Oleg Yunakov / Wikimedia Commons, CC BY-SA 4.0

A checklist for teams shipping AI to EU users

  1. Inventory every AI feature that EU users touch. For each one, note whether you are the provider or the deployer, and the date it was first placed on the EU market. That date now decides whether your marking deadline is August 2 or December 2.
  2. Add AI disclosure to chat interfaces before August 2. A short notice at the start of the conversation is the usual approach. Only skip it if a reasonable user could not miss that they are talking to software.
  3. Plan machine-readable marking for generated media and text. Check what your model provider already embeds, such as metadata or watermarks, and whether it survives your own pipeline, like resizing, re-encoding or copy-paste.
  4. Label deepfakes and AI-written public-facing text if your product publishes them on users' behalf, and document any editorial review you rely on for the text exception.
  5. Test image and video generation against the December 2 ban. If your product can produce realistic images of real people, document the safeguards that stop intimate imagery and abuse material, and test them adversarially now.
  6. Classify anything that might be high-risk. If a feature touches hiring, credit, education or biometrics, use the extra 16 months to build risk management, data governance, logging and human oversight, rather than treating the delay as a pause.
  7. Write down your reasoning. If you conclude a system is not high-risk under Article 6(3), keep the analysis and plan for the registration step.
  8. Watch for Official Journal publication, and have counsel confirm the final dates against the published text.

Practical tip for hackathon teams. Most of this lands on items 2 and 3. A one-line AI disclosure and a check that your image or text outputs carry provenance metadata are cheap to add during a build and hard to retrofit later.

Rows of bound volumes of the Official Journal of the European Union on a library shelf, purple covers with gold lettering
Bound volumes of the Official Journal of the European Union. The omnibus takes effect three days after it is published there. Photo: Pigranelle / Wikimedia Commons, CC0

What to watch

As of June 30, the next step is signature and publication in the Official Journal, which the Council aims to complete before August 2 so the old high-risk deadline never applies. After that come the dates in the table: Article 50 transparency on August 2, the marking deadline for existing systems and the new ban on December 2, sandboxes by August 2, 2027, and the high-risk rules in December 2027 and August 2028. The open work in between is guidance and standards, including the codes of practice for marking AI-generated content that Article 50 invites the Commission and the AI Office to encourage.

Sources