After roughly nine hours of negotiation and the wreckage of a failed first attempt on 28 April, the European Parliament and the Council reached a provisional agreement on the Digital Omnibus on AI in the early hours of 7 May 2026. The deal, which still has to be formally adopted and published in the Official Journal, reshapes some of the most contested obligations of the EU AI Act before they were ever supposed to bite. It is the most consequential recalibration of the bloc’s flagship technology regulation since the original text was adopted, and its terms reveal as much about Europe’s evolving theory of innovation as they do about the specific compliance issues that triggered the renegotiation.
The headline change is the postponement of the high-risk regime. Obligations for Annex III systems, originally due to apply from 2 August 2026, now slide to 2 December 2027. For high-risk systems covered by EU product safety legislation under Annex I, the deadline moves further to 2 August 2028. The shift was driven less by ideological retreat than by a practical recognition that the conformity assessment infrastructure — notified bodies, harmonised standards, and the technical guidance that providers need to interpret the law — would not be in place in time. Executive Vice-President Henna Virkkunen, who carried the file for the Commission, framed the package as a way to make rules simpler and more innovation-friendly without lowering the safety bar, a formulation that captures both the political ambition and the analytical tension at the core of the agreement.
That tension surfaces most clearly around the new prohibition added to Article 5. From 2 December 2026, AI systems used to generate or manipulate sexually explicit or intimate images, audio, or video without consent — the so-called nudifier tools — and any system producing child sexual abuse material will be prohibited outright. The provision responds to a wave of harms documented by national prosecutors and child protection NGOs that the original 2024 text did not adequately anticipate. By moving these systems into the prohibited category rather than treating them as high-risk, the legislators are signalling that risk-based proportionality has limits where the harm pattern is unambiguous and irreversible.
A second set of structural changes addresses the Annex I conformity assessment dispute that had broken the earlier trilogue. The Machinery Regulation has been relocated from Section A to Section B of Annex I, so AI systems falling within its scope will be governed primarily through that sectoral framework. This is a significant move because it carves out a large portion of industrial AI — embedded in assembly lines, robotics, and safety-critical machinery — from the direct heart of the AI Act and instead routes it through the established machinery regime. Industry has lobbied for precisely this outcome; civil society groups warn that it risks dilution of horizontal AI safeguards in industrial contexts.
The political subtext is straightforward. European policymakers have watched the United States deregulate aggressively under a second Trump administration and the United Kingdom pursue a deliberately lighter-touch innovation strategy. Brussels does not intend to abandon its risk-based architecture, but the Omnibus signals that it will trim, delay, and clarify wherever ambiguity has become a tax on the European AI ecosystem. The decision to move quickly enough so that the deadline postponement enters into force before the original 2 August 2026 cutoff was itself a piece of credible commitment, designed to reassure investors and providers that the regulatory floor will not shift unpredictably.
Whether the Omnibus stabilises the AI Act or invites further reopening will depend on how the new prohibitions are enforced and how rigorously the AI Office and national authorities push for the long-promised harmonised standards. For now, the agreement reads as a controlled retreat with sharper edges in the places that matter most.




