Back to Blog
Policy & Regulation May 21, 2026 5 min read

EU AI Act Omnibus Deal Pushes High-Risk AI Compliance to 2027–2028 — What Changed and What Didn't

EU negotiators struck a provisional agreement on May 7 to simplify the AI Act and delay high-risk compliance deadlines by up to two years. The deal also adds a new prohibition on AI-generated non-consensual intimate content, effective December 2026.

EU AI Act Omnibus Deal Pushes High-Risk AI Compliance to 2027–2028 — What Changed and What Didn't

On May 7, 2026, EU Council and Parliament negotiators reached a provisional political agreement on the AI Act Omnibus — a package of amendments designed to reduce compliance burden and extend deadlines before the original rules took full effect. The deal is part of the broader “Omnibus VII” simplification initiative and must still be formally endorsed before becoming law.

The deadline shifts are the headline change. Under the original AI Act timeline, standalone high-risk AI systems faced compliance obligations in August 2026. That deadline has been pushed to December 2, 2027. High-risk AI systems embedded in regulated products — medical devices, machinery, vehicles — get an even longer runway, moving to August 2, 2028. For companies that have spent the last year doing compliance preparation, this is a meaningful reprieve. For those who have been watching and waiting, it extends the window to act without penalty.

The extension is not a signal that the rules have softened substantively. The high-risk categories remain defined as before: biometric identification, critical infrastructure management, education access, employment decision-making, essential services, law enforcement, migration, and justice. Providers and deployers in those areas still need to prepare — the timeline has shifted, not the obligations.

New prohibition added. The Omnibus deal introduces one new prohibition that takes effect on December 2, 2026: AI systems that generate non-consensual intimate imagery (NCII) or child sexual abuse material (CSAM) are explicitly banned. This was not in the original AI Act text and reflects pressure following a wave of deepfake abuse cases in 2025-2026. The prohibition applies to generation capability itself, not only to distribution.

Transparency obligations tighten on one axis. The grace period for AI-generated content transparency solutions — watermarking, disclosure systems for synthetic media — was cut from six months to three months. The new deadline is December 2, 2026. Platforms deploying generative AI for content creation need disclosure systems in place before that date.

One new administrative requirement survived the simplification push: providers must register high-risk AI systems in the EU AI database even when they claim an exemption. The exemption does not remove the registration requirement.

What the delay means for companies actually building products: The extended timelines reduce short-term compliance urgency, but the fundamental architecture of the AI Act — risk classification, conformity assessment, notified body involvement for the highest-risk categories — has not changed. Companies that use the extension to defer all compliance work will face the same compressed timeline they had in early 2026, with less runway and higher cost.

The provisional agreement still needs formal adoption by the European Parliament and Council. The political dynamics suggest this will clear, but the formal endorsement timing adds uncertainty to the effective dates.

The AI Act Omnibus is a significant simplification. It is not a rollback.

EU AI Act AI regulation compliance Europe