Timeline

European Parliament approves Digital Omnibus on AI, delaying high-risk deadlines

Standalone high-risk systems now have until December 2027 to comply and embedded ones until August 2028; the deal also newly bans AI-generated non-consensual intimate imagery and CSAM under the Act.

  • Government & policy
  • Major

The European Parliament voted 423 in favour, 57 against and 174 abstaining to approve the Digital Omnibus on AI, an agreement reached with the Council in trilogue negotiations in May that rewrites the compliance timetable for the EU AI Act’s high-risk provisions. Obligations under Annex III for standalone high-risk AI systems, originally due to bind from August 2026, were pushed to 2 December 2027; high-risk systems embedded in other products were given until 2 August 2028. A separate deadline for marking AI-generated content produced by systems already on the market before August 2026 was set for December 2026.

The delay affected one of the Act’s central enforcement milestones — the point at which providers of systems used in areas such as employment, credit scoring, law enforcement and critical infrastructure would have had to meet documentation, risk-management and human-oversight requirements or face penalties. Supporters of the delay argued that neither the harmonised standards nor the conformity-assessment infrastructure the Act depends on were ready in time; critics said it weakened Europe’s claim to have the world’s most comprehensive binding AI law just as the compliance date approached.

The package was not purely deregulatory. It added a new prohibited practice to the Act’s list: AI systems generating non-consensual intimate or sexual imagery, alongside child sexual abuse material, were explicitly banned. It also reinstated simplified registration for non-high-risk systems, extended simplified documentation to medium-sized companies, reinforced the powers of the EU’s AI Office, and removed AI-enabled machinery from the Act’s direct scope, redirecting it to the separate Machinery Regulation.

The vote left the AI Act’s core structure intact but confirmed that its highest-profile compliance date — the one most often cited as proof the EU would regulate frontier and high-risk AI ahead of other jurisdictions — would not arrive as originally legislated, shifting the practical test of the law’s enforcement to late 2027 and 2028.

Referenced by