AIO APEX

EU Formally Adopts AI Act Amendments, Pushing High-Risk AI Compliance Deadline to 2027

European Council
Share:
EU Formally Adopts AI Act Amendments, Pushing High-Risk AI Compliance Deadline to 2027

The European Union has formally closed the loop on its AI Act overhaul. The EU Council adopted the Digital Omnibus on AI on June 29, 2026 — the final procedural step after the European Parliament approved the same text on June 16. With Council adoption complete, the amendments will be published in the Official Journal of the EU and enter into force shortly after, reshaping compliance timelines for AI companies operating in Europe.

The Digital Omnibus is the most consequential set of changes to the EU AI Act since the regulation passed in 2024. Its core effect: companies deploying high-risk AI systems across healthcare, education, employment, law enforcement, and critical infrastructure have been given significantly more time to comply — in some cases 16 months beyond the original deadlines. The move reflects sustained lobbying from industry groups who argued that the original timelines were unworkable, and a European Commission that has been increasingly focused on boosting competitiveness rather than tightening regulatory burdens in the AI race with the US and China.

What Changed — and What Didn't

The amendments restructure compliance timelines along two tracks depending on how a high-risk AI system is deployed:

Standalone high-risk AI systems (Annex III): These include AI used in hiring decisions, credit scoring, biometric identification, educational assessment, and access to essential services. The original compliance deadline was August 2, 2026 — just weeks away. Under the Digital Omnibus, that deadline moves to December 2, 2027. Companies in this category have gained 16 additional months.

AI embedded in regulated products (Annex I): AI components integrated into products already governed by existing EU safety legislation — such as medical devices, industrial machinery, and vehicles — will now face compliance requirements by August 2, 2028, one year later than the previous August 2027 deadline.

General-purpose AI (GPAI) model rules, which govern frontier models from companies like Anthropic, Google, Meta, and OpenAI, are unchanged. The obligations for GPAI providers — including transparency documentation, adversarial testing, and systemic risk assessments for models above the compute threshold — remain on their original timeline.

A New Prohibition Added

While the amendments relax deadlines, they also tighten the prohibition list in one area: AI systems designed to generate non-consensual intimate imagery (NCII), commonly referred to as deepfake pornography tools, and AI systems that generate child sexual abuse material (CSAM) are now explicitly banned under the AI Act. Compliance with this prohibition is required by December 2, 2026 — a near-term deadline that stands in contrast to the longer extensions granted elsewhere in the package.

The addition signals the EU's intent to use the AI Act as a vehicle for content safety regulation, not only systemic and technical risk. It also brings the AI Act into alignment with other EU legislative efforts targeting online harm.

Why the Extension Was Granted

The original AI Act timelines were criticized from multiple directions. Industry groups argued that the compliance infrastructure required — internal documentation, conformity assessments, registration in the EU database, notified body audits — was not ready at the scale needed, particularly for mid-size companies. Legal practitioners flagged ambiguity in how several categories in Annex III should be interpreted, creating compliance uncertainty even for companies that wanted to move quickly.

The European Commission, which proposed the Digital Omnibus in early 2026, framed the amendments as a "simplification" and competitiveness measure rather than a retreat from regulation. Commissioner for Digital, Henna Virkkunen, cited the need to avoid regulatory fragmentation and ensure European companies were not disadvantaged during a period of rapid AI investment globally.

Critics, including civil society groups and some Members of the European Parliament, argued the extensions weaken protections in sensitive domains at exactly the moment AI deployment in hiring, healthcare, and law enforcement is accelerating. The final text preserved the extensions while adding the NCII prohibition as a concession.

Practical Implications for Companies

For companies building or deploying AI systems in the EU, the Digital Omnibus changes the near-term compliance calendar significantly. The August 2026 deadline had been driving urgency among legal and compliance teams; that pressure is now removed for Annex III standalone systems until late 2027.

What companies should not do is treat the extension as a signal to pause compliance work entirely. The EU AI Act's documentation requirements, risk classification obligations, and technical standards are becoming clearer as regulatory bodies publish guidance. Companies that use the extension to build compliant processes — rather than simply delaying — will be better positioned when December 2027 arrives. Those that wait until mid-2027 to begin will face the same infrastructure crunch the original timeline created.

For non-EU companies selling AI-powered products or services in the EU market, the jurisdictional reach of the AI Act remains unchanged. The Digital Omnibus adjusted timelines, not scope.

Source Attribution

This article is based on official EU Council and European Parliament announcements, legal analysis from Gibson Dunn, Morgan Lewis, and White & Case, and the official Digital Omnibus text published by the European Commission.

Originally reported by European Council. Read the original article for additional details.

View original source
Share: