The EU Artificial Intelligence Act[1] or AI Act was designed to be the world’s first comprehensive legal framework for artificial intelligence. This piece of legislation was adopted in 2024 and is intended to regulate AI through a risk-based approach: the more serious the potential impact on people, safety or fundamental rights, the stricter the rules.
Table of Contents
However, even before the AI Act becomes fully applicable, the EU has already decided to amend it via an agreement reached on 7 May 2026 between the Council of the EU and the European Parliament. With the final approval of this update of the AI Act by the European Parliament on 16 June 2026, the proposed amendments will now only require formal adoption by the Council of the EU before entering into force. The update of the AI Act will be included in the so-called “Digital Omnibus” regulation which aims to introduce technical amendments to a large corpus of digital legislation, selected to bring immediate relief to businesses, public administrations, and citizens alike, and to stimulate competitiveness.
Despite the planned amendment to the AI Act, its core structure remains in place. Prohibited AI practices, obligations for general-purpose AI models, transparency requirements and high-risk AI rules are still central to the framework. The update of the AI Act mainly aims to delay the deadlines for some of the provisions in the AI ACT, to introduce stricter rules in order to protect children against sexual abuses (ban on nudifier apps) and to reduce overlaps between existing regulations and the AI Act.
Why is the AI Act being amended?
The AI Act is an ambitious regulation. It affects AI developers, businesses using AI, importers, distributors, public authorities and providers of general-purpose AI models. It also interacts with existing EU laws on product safety, machinery, medical devices, toys, data protection and sector-specific regulation.
Whilst the AI Act provides a welcome legal framework for the use of AI within the Union, it also represents a real implementation challenge. Professionals providing or deploying AI systems have had to deal with several compliance hurdles created by the entry into force of the AI Act. These hurdles include assessing whether the AI systems provided or deployed by professionals could be considered high risk, assessing the need to register their AI systems on the dedicated EU database, as well as possible uncertainties on the competent supervisory authority and the possible overlap between EU sectoral safety rules and the AI Act.
At the same time, the EU is under pressure to remain competitive in artificial intelligence. European policymakers want to avoid a situation where the AI Act becomes so complex that it discourages innovation, especially for smaller companies and European scale-ups.
The update of the AI Act aims to provide an answer to most of the issues detailed hereabove.
What are the main changes?
1. Delayed deadlines for the application of specific provisions in the AI Act

The new deadlines agreed upon between the Council of the EU and the European Parliament are:
- 2 December 2026: For AI systems placed on the market before 2 August 2026, the application of certain transparency obligations relating to AI-generated content, including machine-readable marking / watermarking, is expected to be postponed until 2 December 2026. This reflects a shorter extension than originally proposed by the Commission, which had suggested 2 February 2027;
- 2 August 2027: deadline for Member States to set up AI regulatory sandboxes;
- 2 August 2028: application of the obligations for high-risk AI systems used as a safety component of products such as lifts or toys.
This is a significant reprieve. It gives companies more time to classify their AI systems, prepare technical documentation, build governance processes, implement human oversight, and wait for standards and guidance that are still needed for practical compliance.
These new deadlines do not, however, change the fact that the AI Act is already in force, and that several provisions have already started to apply. The new deadlines introduced by the update of the AI Act are simply an acknowledgment that professionals should be given more time to comply with specific provisions.
2. Amendments to reduce regulatory overlap
Another important change is the reduction of regulatory overlap. Where AI is already part of a product covered by EU sectoral safety rules, the update to the AI Act seeks to avoid duplication between those rules and the AI Act. This is particularly relevant for industrial AI and machinery. The aim is not to lower safety standards, but to avoid forcing businesses to comply with two overlapping regimes for the same risk.
3. Clarification of the concept of safety component
The reform also clarifies the concept of a “safety component”. AI functions that merely assist users or optimise performance should not automatically be treated as high-risk if their failure does not create a genuine health or safety risk. This is a useful clarification for businesses using AI in operational, industrial or performance-enhancing tools.
4. SME-style simplifications will be extended to small mid-cap companies
The simplified rules currently available to SMEs will also apply to certain small mid-cap companies, i.e. companies with up to 750 employees and either an annual turnover not exceeding EUR 150 million or an annual balance sheet total not exceeding EUR 129 million. These simplifications include lighter technical documentation requirements and more proportionate treatment when penalties are assessed.
This matters because many innovative AI businesses are no longer small start-ups, but are not yet large corporations either. Under the current AI Act, these companies may face a compliance burden that is disproportionate to their size and resources. Extending simplified documentation requirements and more proportionate enforcement to small mid-caps should reduce unnecessary regulatory friction without exempting them from the AI Act altogether
This matters because many innovative AI businesses are no longer small start-ups, but are not yet large corporations either. Under the current AI Act, these companies may face a compliance burden that is disproportionate to their size and resources. Extending simplified documentation requirements and more proportionate enforcement to small mid-caps should reduce unnecessary regulatory friction without exempting them from the AI Act altogether”.[2]
5. New measure to detect and correct bias in AI systems
One of the more sensitive changes concerns the use of special categories of personal data, such as data revealing racial or ethnic origin, political opinions or similar protected characteristics.
The AI Act update would allow such data to be processed where strictly necessary to detect and correct bias in AI systems, subject to appropriate safeguards. This is a delicate but important point. In some cases, it may be difficult to assess whether an AI system produces discriminatory outcomes without using protected-category data. The reform therefore seeks to strike a balance between data protection and the prevention of discrimination.”
6. A new ban on AI “nudification” tools
The reform is not only about simplification. It also strengthens protection against a very specific and harmful use of AI.
The update introduces a ban on AI systems that generate non-consensual sexually explicit or intimate content, including so-called “nudification” tools, as well as AI systems used to generate child sexual abuse material.
This part of the reform shows that the EU is willing to move quickly where new AI risks become visible. The ban is expected to apply on 2 December 2026.
What should businesses do now?
Businesses should use additional time to map where AI is used, classify AI systems, identify whether any systems may be high-risk, review contracts with AI providers, prepare internal governance, and ensure that staff understand the basic risks and obligations linked to AI.
Whereas the update makes the AI Act more workable and gives the market more breathing space, it does not modify the core principles underpinning the AI Act and professionals should make full use of the delayed guidelines to ensure compliance with the amended AI Act once all provisions enter into force. Professionals should also ensure that they monitor the entry into force of the technical standards and guidelines which are to supplement the AI Act.
[1] Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence
[2] Mid-caps enterprises are defined in the Commission Recommendation (EU) 2025/1099
