Tallinn: When the Artificial Intelligence Act was finalised two years ago, it was sold as the world’s first comprehensive attempt to put guardrails around a fast-moving technology. The problem, companies complained almost immediately, was that the rulebook arrived before anyone had built the practical machinery to comply with it. On 7 May negotiators from the Council, the Parliament and the Commission settled that argument with a compromise that gives the technology industry what it wanted most: time.
The agreement, part of a wider Digital Omnibus package the Commission tabled last November, pushes back several of the law’s most demanding deadlines. Obligations for so-called high-risk systems listed in Annex III, the category that covers tools used in hiring, education, credit scoring and other sensitive decisions, will no longer bite from August this year. They are deferred to December 2027, a delay of sixteen months that hands developers and the firms deploying their products more than a year of additional breathing room. The parallel requirement for member states to stand up at least one national regulatory sandbox, an experimental space where new systems can be tested under supervision, slips by a year to August 2027.
Officials in the digital-policy community frame the postponement as pragmatism rather than retreat. The standards, codes of practice and conformity-assessment bodies that the law assumes already exist are, in many cases, still being written or accredited. Forcing companies to certify against benchmarks that have not been published, the argument runs, would have produced paperwork rather than safety. Critics counter that every delay is a gift to the largest operators, who have the least incentive to move quickly and the most to gain from a permissive interim period.
The deal is not purely about loosening. Negotiators added two fresh prohibitions to the law’s list of banned practices, including a ban on systems designed to generate or manipulate non-consensual intimate imagery, a category of harm that has spread faster than any regulator anticipated. That prohibition takes effect in December this year, ahead of most of the postponed obligations, a sequencing that lets Europe claim it is tightening protection where the danger is most acute even as it relaxes timelines elsewhere.
More contentious are the changes bundled alongside the AI provisions that reach into the bloc’s data rulebook. The package reopens parts of the General Data Protection Regulation, the ePrivacy rules and the Data Act, and proposes to redraw the definition of what counts as personal data. Civil-society groups have reacted with alarm, warning that a narrower definition could let large technology firms scrape and reuse far more information to train and run their models. Supporters insist the clarification merely codifies how courts already interpret the law and removes a layer of legal uncertainty that has chilled smaller European developers.
The provisional agreement still needs formal sign-off from both the Parliament and member-state governments before it becomes law, and the data-protection elements in particular may yet be reopened. What is already clear is the direction of travel. After a half-decade in which Europe prided itself on writing rules first and worrying about implementation later, the political mood has shifted toward simplification and competitiveness. For a continent anxious about falling behind American and Chinese developers, the calculation is that a rulebook delayed is more useful than a rulebook ignored. Whether that gamble protects citizens as well as it reassures industry is the question the next eighteen months will answer.




