EU Parliament Backs Delaying AI Act High-Risk Rules to 2028 — and Proposes GDPR Rollbacks That Alarm Privacy Groups
The European Parliament voted overwhelmingly to advance the Digital Omnibus package, which would push enforcement of high-risk AI obligations two years past the original deadline while loosening GDPR protections in ways critics say benefit Big Tech.
The European Parliament voted 569-45 on March 26 to adopt a negotiating position on the Digital Omnibus — a sweeping legislative package that would delay enforcement of the EU AI Act’s high-risk provisions from August 2026 to as late as August 2028. Trilogue negotiations with the Council and Commission are scheduled for April 28. The delay is almost certain to go through.
The vote reflects two years of lobbying by European industry groups arguing that the AI Act’s high-risk compliance requirements — mandatory conformity assessments, risk management systems, human oversight obligations, and technical documentation — cannot be met on the current timeline because the harmonised standards the Act depends on have not been finalized. That argument is correct in the technical sense. The European standards bodies (CEN and CENELEC) are running behind, and companies cannot demonstrate conformity to standards that don’t yet exist.
What the vote also does, however, is relax GDPR rules alongside the AI Act delay. The Digital Omnibus proposal includes amendments that would reduce certain data minimisation obligations and broaden the legal basis for processing personal data for AI training purposes. The practical effect is that European companies — and foreign ones operating in Europe — would face fewer barriers to training models on personal data they have already collected. Amnesty International, the Electronic Frontier Foundation’s European counterpart EDRi, and a coalition of civil society groups have called this a “quiet GDPR rollback” that was buried inside a competitiveness package.
For developers and AI companies operating in Europe, the delay provides practical breathing room. Systems that would have needed to be in compliance by August 2026 now have until 2027 or 2028 depending on which obligations apply. The categories affected include AI used in employment decisions, credit scoring, biometric identification, critical infrastructure management, and law enforcement — not general-purpose LLMs, which fall under lighter transparency obligations that are already in force.
The delay does not affect provisions of the AI Act that are already active. The ban on social scoring systems and real-time remote biometric surveillance in public spaces took effect in February 2025 and is not touched by the Digital Omnibus. Obligations for general-purpose AI models — disclosures, safety evaluations, copyright transparency — also remain on the original schedule.
The April 28 trilogue will determine the final timeline. Given the Parliament’s lopsided vote and the Commission’s own support for the delay, the outcome is not in doubt. What remains uncertain is how much of the GDPR modification survives the process — that fight will define the regulatory ceiling for AI data practices in Europe for the rest of the decade.
The AI Act was supposed to be the world’s first comprehensive AI law. It still is. But “comprehensive” and “enforced on schedule” are turning out to be different things.
Related reading
- Policy & Regulation EU Amends the AI Act: High-Risk Deadlines Pushed to 2027–2028, New CSAM Prohibition Added
- Policy & Regulation Google's Ad-Tech Breakup Ruling Is Imminent — DOJ Wants AdX and DFP Sold Off
- Policy & Regulation Court Bars Google from Search Exclusivity Deals and Orders Data Sharing With Rivals