Much of the coverage leading up to August 2, 2026 described it as the date the EU AI Act’s high-risk rules would take effect. A late-stage legislative package that entered into force just six days earlier means that description is no longer accurate for the obligations that matter most — and the political fight behind that package reveals more about where EU technology policy is heading than the compliance calendar does on its own.
By Vladimir Tsakanyan, PhD | Director, Center for Cyber Diplomacy and International Security (CCD-IS)
The EU Artificial Intelligence Act entered into force on August 1, 2024, and has since rolled out in staggered phases: prohibited practices and AI-literacy obligations became applicable in February 2025, and governance rules for general-purpose AI models followed in August 2025. The next major milestone under the Act’s original text was August 2, 2026, when obligations for high-risk AI systems — those used in areas such as employment, education, critical infrastructure, credit scoring, and law enforcement — were due to apply. By late 2025, the European Commission judged that timeline to be off track and proposed a package of amendments, the Digital Omnibus on AI, that entered into force on July 27, 2026, six days before the original deadline. The amendments substantially change what August 2 actually requires, and the process that produced them says as much about the current balance of power in Brussels as the substance does about AI regulation.
What the Omnibus Changed
The Omnibus followed a compressed but complete legislative path: proposed by the Commission on November 19, 2025, a provisional political agreement between Parliament and Council on May 7, 2026, formal Parliament approval by a 423–57 vote on June 16, Council’s final sign-off on June 29, publication in the Official Journal on July 24, and entry into force on July 27. Its most consequential change defers the high-risk obligations for standalone systems under Annex III of the Act from August 2, 2026 to December 2, 2027, a delay of sixteen months. High-risk obligations for AI embedded in products already covered by separate EU product-safety law, such as medical devices or machinery, move from August 2027 to August 2028. Systems already placed on the EU market before the new deadlines are grandfathered out of full high-risk compliance unless later substantially modified, a threshold regulators have not yet defined. The package also expands the AI Office’s supervisory powers, extends the GDPR’s legal basis for processing special-category data for bias detection and correction, and introduces a new prohibition, effective December 2, 2026, on AI systems generating non-consensual intimate imagery and child sexual abuse material.
The one element of the original deadline that survives largely intact is Article 50, the Act’s transparency provisions, covering obligations such as disclosing AI-generated content and labeling interactions with AI systems. Those apply from August 2, 2026 as originally scheduled, with a narrow exception for systems already on the market, which catches up on December 2, 2026 alongside the new prohibitions.
The Competitiveness Case and Its Critics
The Commission has not framed the Omnibus primarily as a response to implementation problems with the AI Act specifically; it has framed it as one instalment of a broader competitiveness agenda that Ursula von der Leyen made central to her second term as Commission president after her 2024 re-election. That agenda traces directly to the 2024 Draghi Report on European competitiveness, which argued that regulatory fragmentation and compliance burden were contributing to the EU’s widening productivity gap with the United States and China. The AI Omnibus is one of roughly ten such “simplification” packages the Commission has pursued across the EU’s legislative acquis, alongside parallel efforts touching sustainability reporting, the GDPR, the ePrivacy Directive, and the Data Act. Commission officials have consistently described the goal as removing overlap and disproportionate burden rather than lowering substantive protections, a distinction critics reject: a coalition of privacy and civil-rights organizations, including Liberties.eu, has characterized the package as a rollback of the AI Act’s fundamental-rights safeguards conducted with less public deliberation than the original law received, arguing that the current Parliament and Commission majorities differ meaningfully in composition from those that passed the AI Act and the GDPR.
The competitiveness case itself is not uncontested on its own economic terms. Analysts at the Jacques Delors Centre have argued that the administrative savings from delaying high-risk compliance are likely to be modest relative to the legal uncertainty the delay introduces, and that a genuinely pro-competitiveness policy would need to address the EU’s dependence on a small number of dominant, mostly American, cloud and model providers — dependence the Omnibus does not directly reduce. On this reading, the immediate beneficiaries of delayed high-risk obligations are less likely to be smaller European AI developers, who face proportionally higher compliance costs relative to revenue, than the large incumbents who can absorb regulatory costs either way and who lobbied hardest for the delay.
The Coalition Behind the Vote
The Omnibus divided Parliament along lines that shifted over the course of negotiation. When the Commission presented the proposal to committee in December 2025, members of the EPP, Renew, and ECR groups broadly welcomed it, while members of the S&D, the Greens, and the Left questioned whether the changes were necessary at all, with some explicitly asking whether the proposal reflected geopolitical pressure from the United States rather than an independent EU assessment. Negotiations proved difficult enough that a scheduled trilogue in April 2026 collapsed after twelve hours without agreement, and the eventual political deal was reached only after a further round of talks concluded at 4:30 a.m. on May 7. Pressure from German Chancellor Friedrich Merz’s CDU, pushing for a broader exemption of regulated sectors from the Act, reportedly came close to unraveling the compromise in its final stages.
The final Parliament vote, 423 in favor to 57 against on June 16, was considerably wider than the committee-level split suggested, indicating that a substantial share of the center-left ultimately voted for the package rather than against it. Reporting on the negotiations suggests this reflected a deliberate trade by the parliamentary left: rather than spend its now-diminished political capital attempting to block the broader deregulatory thrust, which analysts judged unlikely to succeed given the composition of the current Parliament, left-aligned negotiators concentrated their leverage on securing the new prohibition on AI-generated non-consensual intimate imagery, winning that provision while ceding ground on the sixteen-month delay to high-risk obligations. Further to the right of von der Leyen’s own EPP, groups including the European Conservatives and Reformists, Patriots for Europe, and Europe of Sovereign Nations pushed for the Commission’s proposal to go further still; lobbying records cited by the Jacques Delors Centre show Meta representatives met with members of those groups 38 times as of January 2026, a level of engagement that outpaced contact with more centrist blocs and that critics have pointed to as evidence of whose interests were most directly represented in the final text.
A Brief International Contrast
The EU’s decision to slow its highest-stakes AI obligations coincided, within the same several weeks, with a much faster and narrower move in China. On July 15, 2026, the Cyberspace Administration of China and four other ministries brought into effect the Interim Measures for the Administration of AI Anthropomorphic Interactive Services, governing AI products that simulate human personality and sustained emotional interaction. The measures require algorithm filing and security assessment, mandate disclosure that such services are AI-generated, and prohibit providing minors with simulated intimate-relationship features. On the day the measures took effect, ByteDance’s Doubao and Alibaba’s Qwen withdrew personalized AI-companion features used by hundreds of millions of people. The contrast is not a claim that either jurisdiction’s approach is more effective; it illustrates that the EU and China both reached significant AI-governance milestones within weeks of each other in mid-2026 on entirely different timelines, in different registers, and over different categories of risk.
Outlook
The Digital Omnibus’s new backstop dates give the Commission and Member States a defined runway rather than a resolved compliance regime, and the coalition that produced them is not obviously stable. Whether the December 2027 and August 2028 dates hold will depend on whether the harmonized technical standards the high-risk rules require are actually completed on schedule, a process that was itself a contributing cause of the original 2026 deadline’s unraveling — a further slippage would test whether the same right-leaning majority that delivered this delay is prepared to grant another one, or whether the left’s willingness to trade away substantive protections for narrower symbolic wins has a limit. The undefined threshold for a “substantial modification” that would strip a grandfathered system of its exemption is likely to become an early flashpoint once enforcement begins, with industry incentivized toward the narrowest possible reading. And the question several MEPs raised during committee review, whether the Omnibus reflects an independent EU competitiveness judgment or a response to sustained American pressure on European technology regulation, is unlikely to be settled by the text itself; it will be settled by whether Washington continues treating EU digital rules as a subject of bilateral friction after this concession, or moves on to the next one.
Sources
- European Commission, Digital Strategy, “AI Act” implementation timeline and Digital Omnibus materials
- Gibson Dunn, “EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes”
- Freshfields, “EU AI Act unpacked #34: The final Digital Omnibus on AI”
- Orrick, “EU AI Act Update: Digital Omnibus Finalizes 8 Compliance Changes”
- Jacques Delors Centre, “The EU’s Digital and AI Omnibus is Heading in the Wrong Direction”
- Liberties.eu, “AI Omnibus: Fast-Tracking Deregulation, Weakening Digital Rights”
- Tech Policy Press, “What the EU AI Omnibus Deal Changes for the AI Act and What Lies Ahead”
- European Parliament, Legislative Train Schedule, “Digital Omnibus on AI”
- BSA TechPost, “Europe’s AI Omnibus: Missing the Simplification Bus?”
- Bird & Bird, “China’s New Regulations on AI Anthropomorphic Interactive Services”


Leave a comment