The European Union spent years building the world's most ambitious rulebook for artificial intelligence. On 29 June 2026, it decided to loosen part of that rulebook and tighten another part in the same stroke — pushing back the deadlines for its most consequential "high-risk" obligations while writing a hard prohibition on non-consensual sexual deepfakes directly into the law.

The Council of the EU gave its final green light that day to the so-called "digital omnibus" package, a simplification measure that the European Parliament had formally endorsed on 16 June. The act will be published in the Official Journal and enter into force three days later. Brussels is calling it housekeeping. Critics are calling it the first crack in a landmark law that has not fully taken effect.

What actually changed

The headline change is a delay. Under the omnibus, the application date for stand-alone high-risk AI systems — the category covering AI used in hiring, credit scoring, education, biometric identification and critical infrastructure — moves to 2 December 2027. High-risk AI embedded in regulated products, such as medical devices and machinery, gets even longer, until 2 August 2028. Both are significant slips from the original 2 August 2026 trigger date that had loomed over developers all year.

The Council's stated rationale is pragmatic rather than ideological. The presidency framed the deferral as a way to deliver greater legal certainty, make obligations more proportionate and ensure more harmonised implementation across member states — arguing that the technical standards and support tools meant to guide compliance are running behind schedule and cannot be enforced against until they exist. The package sits inside the EU's broader "Omnibus VII" simplification agenda, a competitiveness-driven push to lighten regulatory load on European firms trying to keep pace with rivals in the United States and Asia.

That framing has not gone unchallenged. Michael McNamara, the Parliament's lead negotiator on the AI omnibus, warned in an interview with Tech Policy Press that folding AI governance into existing sectoral laws could ultimately prove "deregulatory rather than simplifying." He was not alone. In the run-up to the vote, more than 40 organisations signed a letter to Parliament arguing the changes weaken the AI Act's fundamental-rights protections, singling out biometric identification, AI used in schools and medical AI. A separate coalition of 127 civil society groups, trade unions and public-interest defenders urged the Commission to halt the omnibus entirely and defend what they called Europe's hard-won digital rights protections.

The deepfake ban that goes the other way

If the high-risk delay is the omnibus giving industry breathing room, the deepfake provision is the same law moving in the opposite direction — and fast.

The omnibus adds new entries to the AI Act's list of outright prohibited practices. It bans AI systems whose purpose is to generate or manipulate realistic depictions of an identifiable person's intimate parts, or of an identifiable person in sexually explicit activity, without that person's freely given, specific, informed and explicit consent. It separately bans the generation or manipulation of child sexual abuse material. Crucially, providers are caught not only when producing such content is the system's intended purpose, but also when it is a reasonably foreseeable and reproducible output and the provider has failed to build in adequate technical safeguards.

Unlike the high-risk rules, this prohibition is not being delayed. AI systems that generate nude images of real people — the "nudifier" apps that strip clothing from ordinary photographs — are set to be banned as of 2 December 2026, this year. Breaching an AI Act prohibition carries fines of up to 35 million euros or 7 percent of a company's worldwide annual turnover, whichever is higher.

The timing is not accidental. The ban follows a wave of AI-enabled abuse, most visibly the December 2025 Grok episode, when the picture-editing feature on X produced a surge of non-consensual sexualised images and exposed how thinly existing law covered the harm. The EU is racing to close that gap even as it pumps the brakes elsewhere.

Two speeds, one law

The split screen is the story. On one side, Brussels is telling the AI industry it has until late 2027 and 2028 to comply with the bulk of its risk-management regime — an implicit acknowledgment that the compliance scaffolding was never ready and that competitiveness anxiety has real political weight. On the other, it is drawing an absolute red line around a category of harm where the victims are overwhelmingly women and children and where public outrage left no room for delay.

Whether the two impulses can coexist is the open question. Civil society groups worry that a law repeatedly reopened before it takes full effect signals to industry that deadlines are negotiable and protections are provisional. Supporters counter that a regime willing to prohibit the most egregious abuses outright, while giving genuine flexibility on complex technical compliance, is exactly what proportionate regulation looks like.

For now, the EU has chosen both restraint and severity at once. The nudifier apps have a date with prohibition in December. The rest of the high-risk apparatus has been handed a two-year reprieve. The coming months will show which signal the market hears loudest.

"deregulatory rather than simplifying"
-- Michael McNamara, Parliament lead negotiator on the AI omnibus
Dec 2027
Stand-alone high-risk AI date
Aug 2028
Embedded high-risk AI date
EUR 35M
Max fine (or 7% turnover)