EU Amends the AI Act: High-Risk Deadlines Pushed to 2027–2028, New CSAM Prohibition Added
EU Council and Parliament negotiators reached a deal on May 7 to slim down the AI Act — extending compliance deadlines for high-risk AI systems, expanding SME exemptions to mid-caps, and adding an outright ban on AI-generated CSAM.
The EU AI Act just got its first significant rollback. On May 7, 2026, EU Council and European Parliament negotiators reached a provisional agreement under the “Omnibus VII” simplification package that extends major compliance deadlines, broadens exemptions, and adds a new prohibition that wasn’t in the original text.
The deadline shifts. The most consequential change: high-risk AI systems that operate as stand-alone software now face a new application date of December 2, 2027 — up from August 2026. That’s a 16-month extension for the segment of AI products that generates the most compliance overhead. High-risk AI embedded in physical products (medical devices, machinery, vehicles) gets even more time: August 2, 2028. Companies that spent the past year building compliance frameworks for the original dates now have breathing room, though that also means the regulation’s protections are further delayed.
The exemptions get broader. The original AI Act limited several regulatory exemptions to small and medium enterprises (SMEs). The new agreement extends those exemptions to small mid-caps (SMCs) — companies above the SME threshold but below a new upper bound. The practical effect is that a wider tier of companies can defer full compliance frameworks and access national regulatory sandboxes under lighter terms.
Sandboxes pushed back. National-level AI regulatory sandboxes, which were meant to let companies test AI products under regulatory supervision before full market deployment, now don’t have to be operational until August 2027 instead of the original date. This is a delay that primarily affects innovative startups — the companies that arguably benefit most from sandbox protections.
The transparency deadline tightens. One change moves in the opposite direction: the grace period for AI-generated content transparency labeling was cut from 6 months to 3 months, moving the deadline to December 2, 2026. If your product generates synthetic audio, video, or images, the requirement to disclose that to end users arrives sooner than the original schedule.
New prohibition: AI-generated CSAM. The co-legislators added an entirely new prohibition not present in the original AI Act text: an outright ban on AI systems used to generate non-consensual sexual content and child sexual abuse material (CSAM). This fills a gap that critics had pointed to since the regulation’s initial publication.
The deal still requires formal endorsement by both the Council and Parliament before it becomes binding law. Given the provisional nature of the agreement, there’s limited risk of further changes at that stage, but a vote has not yet been scheduled.
For product teams: the extended deadlines provide real relief, but compliance work that was already underway shouldn’t be abandoned. The direction of travel — stringent requirements for high-risk AI — hasn’t changed. The clocks have just been reset.
Related reading
- Policy & Regulation EU Parliament Backs Delaying AI Act High-Risk Rules to 2028 — and Proposes GDPR Rollbacks That Alarm Privacy Groups
- Policy & Regulation Federal AI Law Is Stalled. States and Plaintiffs Are Filling the Vacuum — and the Compliance Map Is Getting Complicated
- AI Policy EU Council Agrees to Delay AI Act High-Risk Rules by Up to 16 Months