EU AI Act Delayed: High-Risk Rules Pushed to Dec 2027
- What happened
- EU Parliament voted 423–57–174 to approve the AI Act Digital Omnibus, delaying high-risk AI rules to December 2, 2027 and adding a ban on AI-generated non-consensual intimate images.
- Why it matters
- Frontier model providers get an 18-month compliance runway instead of a five-week fire drill — but the GPAI-model timeline is separate and unaffected.
- What to do
- Complete your AI system inventory, classify by risk tier, and prioritize the December 2026 nudifier ban and transparency deadlines — the most expensive obligations wait, but the near-term ones do not.
This is a regulatory reprieve, not a repeal. On June 16, 2026, the European Parliament voted 423–57–174 to approve the AI Act Digital Omnibus, pushing the heaviest compliance obligations to December 2, 2027. The core architecture — risk-based classification, prohibited practices, and general-purpose AI rules — remains intact. The clock reset is real, but the framework is not going away.
What happened
The European Parliament approved a package of targeted amendments to the EU AI Act on June 16. The Council is expected to formally adopt the text on June 29, with publication in the Official Journal before August 2, 2026.
The vote was notably cooler than the March 2026 negotiating mandate (569 yes, 45 no, 23 abstentions). Support dropped by 146 yes votes as abstentions nearly quadrupled — a signal that simplification is more politically divisive than it appears (Matheson LLP, 2026).
The new compliance timeline:
| Obligation | Old Deadline | New Deadline | Delta |
|---|---|---|---|
| High-risk Annex III (standalone) | Aug 2, 2026 | Dec 2, 2027 | +17 months |
| High-risk Annex I (safety components) | Aug 2, 2027 | Aug 2, 2028 | +12 months |
| Watermarking / transparency (Art. 50) | Aug 2, 2026 | Dec 2, 2026 | +4 months |
| Nudifier / CSAM prohibition | Not applicable | Dec 2, 2026 | New |
| AI regulatory sandboxes | Aug 2, 2026 | Aug 2, 2027 | +12 months |
The headline change: standalone high-risk AI systems under Annex III — covering biometrics, critical infrastructure, education, employment, law enforcement, and border management — now face compliance by December 2, 2027 instead of August 2, 2026. Seventeen extra months.
A substantive new prohibition was added: AI systems designed to generate non-consensual intimate images and child sexual abuse material are now explicitly banned. During the plenary debate, co-rapporteur Michael McNamara described the ban as a priority: "They impact real people, overwhelmingly women, with the purpose of humiliating, degrading and objectifying them" (Dastra, 2026). Compliance deadline: December 2, 2026.
Several definitions were refined. Machinery products under Regulation (EU) 2023/1230 are carved out from direct AI Act applicability. The "safety component" definition now excludes AI systems that merely assist users or optimize performance — only those whose malfunction would endanger health or safety fall into the high-risk category. And the AI literacy obligation shifted from "ensure a sufficient level" to "support the development" — a meaningful reduction in legal exposure (Pasquale Pillitteri, 2026).
The EU AI Office gained teeth. It now holds exclusive competence to supervise AI systems integrating general-purpose AI models when the same provider develops both the model and system, plus those embedded in very large online platforms.
Why it matters
The most resource-intensive obligations just became an 18-month planning horizon instead of a five-week fire drill. For frontier model providers operating in the EU market — including every general-purpose AI model provider — the immediate pressure is off, but the reprieve is not unconditional.
Claude 4 Opus (Anthropic) and GPT-4o (OpenAI) remain squarely in scope for general-purpose AI rules, which run on a separate timeline. The transparency obligations for AI-generated content still hit August 2, 2026 for new systems. And the AI Office now has explicit enforcement powers over GPAI-model providers — regulatory muscle that will be flexed.
The nudifier ban is the one change with immediate teeth. It takes effect this year and covers both providers and deployers. For any tool or platform that could be repurposed to generate non-consensual intimate imagery, the compliance clock is already ticking.
What did not change: prohibited practices remain prohibited, employment-related AI stays high-risk, and fiscal penalties were not reduced. The delay is a scheduling change, not a deregulation.
What changes for you
The practical advice from legal analysts is consistent (Matheson LLP, 2026): complete your AI system inventory now, classify by risk tier, map compliance deadlines by category, and sequence remediation. The clock did not stop — it just got reset for the most expensive obligations.
- High-risk AI deployers: you have until December 2027. Use the time to build your governance framework, not to delay starting.
- Content platforms and tools: the nudifier ban hits December 2026. Audit your systems for potential misuse now.
- GPAI model providers: your obligations run on a separate, earlier timeline. This delay does not apply to you.
- AI literacy: the softened language reduces your legal exposure, but regulators will still expect demonstrated effort.
FAQ
Does this repeal the EU AI Act?
No. The core architecture — risk-based classification, prohibited practices, general-purpose AI rules, and the penalty framework — is untouched. The Digital Omnibus is a timeline adjustment and definitional refinement, not a rollback.
When do general-purpose AI model providers need to comply?
GPAI-model rules run on their own timeline and are not affected by this delay. Providers of models like Claude 4 Opus and GPT-4o still face the deadlines set out in the original AI Act for general-purpose AI systems. The high-risk extension covers deployers of stand-alone high-risk systems, not model developers under the GPAI chapter.
What takes effect first?
December 2, 2026 is the nearest new deadline: watermarking and transparency obligations for AI-generated content, plus the new prohibition on nudifier apps and CSAM-generating AI systems. If your system produces or could be used to produce AI-generated imagery, this is your priority deadline.
Affected tools & models
Never need to catch up again
The weekly delta — only verdict changes and act-now items. No digest filler.