Tallinn: Estonia’s digital ministry has begun mapping how providers under the AI Act’s expanded prohibition list will fit into national supervision once the Digital Omnibus deal lands on the statute book. Negotiators from Council, Parliament and Commission closed political agreement on the Omnibus on 7 May, and the text leaves the AI Act’s headline regime intact while sharpening enforcement against a narrow strip of misuse. The deal also pushes back the use-based high-risk obligations under Annex III from 2 August 2026 to 2 December 2027, a sixteen-month deferral that providers had pressed for since last autumn.
The headline change for Estonia and for every other supervising authority sits in the prohibitions chapter. From 2 December 2026, providers and deployers may not place on the market AI systems designed to produce non-consensual intimate deepfakes or child sexual abuse material, and they may not deploy systems that lack reasonable safeguards against being used that way. The wording covers nudifier applications, voice-cloning systems pointed at intimate audio, and generators tuned to evade content filters. Fines top out at €35 million or seven percent of worldwide turnover, whichever bites harder.
That penalty ceiling matches the AI Act’s existing top tier, signalling that the prohibition is being treated on equal footing with social scoring and untargeted facial scraping. The Council’s negotiators argued that the wave of synthetic intimate material produced by general-purpose models over the winter forced the change. Parliament’s lead negotiator pointed to the difficulty of pursuing model providers under the Digital Services Act alone, which catches the platform that hosts the output but rarely the developer that built the generator.
For Estonian deployers, the practical question is whether a provider’s safeguards count as reasonable. Draft guidance circulating among national authorities suggests three pillars: input filtering at prompt level, output classifiers tuned for sexual content involving minors, and refusal logging that survives jailbreak attempts. Providers that publish their safeguard documentation under the Code of Practice will get a presumption of conformity, though the AI Office retains the right to test that presumption ex post.
The Omnibus also addresses how prohibited practices interact with very large online platforms under the DSA. Where an AI system sits inside a designated VLOP or VLOSE, the DSA’s risk assessment and audit obligations now act as the first port of call, with the AI Office stepping in if national supervisors find the platform tier has missed the underlying model issue. That layered approach gives the Commission’s DG CNECT a clear path into enforcement without rerunning the entire AI Office’s intake pipeline.
Industry response has divided along familiar lines. The European DIGITAL SME Alliance welcomed the timeline relief on Annex III, calling the deferral overdue. Civil liberties groups including European Digital Rights warned that the prohibition’s reliance on intent language could leave loopholes for systems marketed as adult content tools. The Commission’s reply, hidden in the recitals, is that intent is read from system design and marketing combined, not from a developer’s stated purpose.
The Council’s final adoption is expected before the summer recess, with national supervisors then carrying the December trigger into their own enforcement plans.




