The EU is considering a new 'AI Act.' Search the official European Parliament and Commission website...

research prompt

The EU is considering a new 'AI Act.' Search the official European Parliament and Commission websites for the latest draft text, any proposed amendments from the last 30 days, and summaries from major European policy blogs.

date
May 4, 2026
blind battlewinner: parallelGeminiParallel
metricGeminiParallel
formatproseprose
word count3,3431,459
sources025
processing time1s270s
has imagesnono
has tablesnono
citation style

Gemini

prose3,343 words

The European Union Artificial Intelligence Act: Legislative Evolution, the 2026 'Digital Omnibus' Amendments, and Policy Perspectives

Key Points
  • Current Status: The European Union Artificial Intelligence Act (Regulation (EU) 2024/1689) is officially in force, having been published in the Official Journal on July 12, 2024.
  • Proposed Amendments: Research suggests a shifting regulatory timeline. The European Commission's "Digital Omnibus on AI" (proposed November 2025) seeks to alleviate administrative burdens and delay the enforcement of high-risk AI obligations originally slated for August 2026.
  • Recent Developments: It seems likely that the proposed extensions (pushing compliance to December 2027 and August 2028) have encountered political hurdles; trilogue negotiations reportedly stalled in late April 2026 due to disagreements over how AI embedded in regulated products should be governed.
  • Policy Discourse: Summaries from major policy blogs highlight a tension between fostering EU digital competitiveness (as championed by the Draghi report) and preserving the robust fundamental rights safeguards that the AI Act originally intended to establish.
Introduction to the Legislative Context

The European Union has positioned itself at the vanguard of global digital regulation with the adoption of the Artificial Intelligence Act. However, translating this landmark legislation from text to operational reality has proven highly complex. In response to industry concerns and the necessity of establishing harmonized standards, the European Commission introduced a targeted legislative package known as the Digital Omnibus. This package aims to streamline compliance, particularly for high-risk systems.

The Stalemate of Spring 2026

The most recent 30 days of legislative activity have been characterized by intense trilogue negotiations between the European Parliament, the Council of the European Union, and the European Commission. These discussions unexpectedly collapsed on April 28, 2026. The breakdown was not rooted in the decision to delay compliance deadlines, which enjoys broad consensus, but rather in the structural architecture of conformity assessments for AI systems integrated into products already governed by sectoral safety laws.

Scope of the Report

This report provides a comprehensive academic analysis of the latest draft texts and official amendments surrounding the EU AI Act. It details the foundational Regulation (EU) 2024/1689, dissects the provisions and current political deadlock of the Digital Omnibus on AI, and synthesizes critical viewpoints from major European policy blogs and research institutions, offering an exhaustive overview of the current European AI governance landscape.


1. Foundational Legal Framework: Regulation (EU) 2024/1689

To understand the currently proposed amendments, it is first necessary to examine the original text of the AI Act. The European Commission initially unveiled its proposal for a comprehensive artificial intelligence act in April 2021 [cite: 1]. Following years of protracted negotiations, culminating in a 36-hour marathon trilogue in December 2023, the European Parliament adopted the Act in March 2024, and the Council of the European Union endorsed it in May 2024 [cite: 1, 2].

The final text was promulgated as Regulation (EU) 2024/1689 in the Official Journal of the European Union on July 12, 2024 [cite: 3, 4, 5]. This established the first comprehensive legal framework for artificial intelligence by a major global regulator [cite: 6]. The Regulation entered into force twenty days after publication, on August 1, 2024 [cite: 4, 5, 7].

1.1 The Risk-Based Classification Architecture

The fundamental philosophy of the EU AI Act is a graduated, risk-based approach, ensuring that regulatory burdens are proportionate to the potential for harm to health, safety, and fundamental rights [cite: 8, 9]. The legislation categorizes AI systems into four distinct tiers:

Risk CategoryRegulatory ApproachExamples of AI SystemsImplementation Date (Original)
Unacceptable RiskStrict prohibition and ban from the EU market.Government social scoring, biometric categorization, predictive policing, subliminal manipulation.February 2, 2025 [cite: 8, 10, 11].
High Risk (Annex III & Annex I)Subject to stringent obligations: risk management, quality datasets, technical documentation, human oversight, and conformity assessments.CV-scanning tools, AI in critical infrastructure, medical devices, law enforcement, education.August 2, 2026 (Annex III) & August 2, 2027 (Annex I) [cite: 7, 8, 12].
Limited / Transparency RiskSubject to specific transparency obligations, ensuring users are informed they are interacting with AI.Chatbots, deepfakes, AI-generated synthetic content.August 2, 2026 [cite: 7, 8, 11].
Minimal or No RiskLargely left unregulated; no mandatory requirements, though voluntary codes of conduct are encouraged.AI-enabled video games, spam filters.N/A (Exempt) [cite: 6, 7, 11].
1.2 General-Purpose AI (GPAI) Models

In addition to the risk tiers, the final text introduced specific provisions for General-Purpose AI (GPAI) models, a late addition reflecting the rise of generative AI. Obligations for GPAI models took effect on August 2, 2025 [cite: 7, 12]. Providers of such models must adhere to transparency requirements, provide technical documentation, respect EU copyright laws, and, for models posing systemic risks, conduct adversarial testing and incident reporting [cite: 5, 13]. To bridge the gap until harmonized European standards are finalized, the AI Office developed a Code of Practice for GPAI, with final drafts published in mid-2025 [cite: 12, 14].


2. The Digital Omnibus on AI: Proposed Amendments (2025–2026)

Despite the formal adoption of Regulation (EU) 2024/1689, challenges rapidly emerged regarding its practical implementation. The lack of harmonized standards, delays in designating national competent authorities, and a shortage of notified bodies capable of conducting conformity assessments generated widespread industry concern [cite: 4, 15, 16, 17]. Furthermore, the September 2024 Draghi report on European competitiveness highlighted that fragmented and complex digital regulations were stifling innovation and overburdening small and medium-sized enterprises (SMEs) [cite: 18, 19].

In response, on November 19, 2025, the European Commission published the "Digital Omnibus" package (COM(2025) 836) [cite: 4, 16, 20]. This package consists of broader digital reforms (amending the GDPR, Data Act, and NIS2) and a specific Digital Omnibus on AI Regulation Proposal, which targets the AI Act directly under the political banner of "simplification and competitiveness" [cite: 20, 21, 22].

2.1 Postponement of High-Risk AI Obligations

The most prominent element of the proposed amendment from the Commission is the deferral of the AI Act's high-risk obligations (Chapter III, Sections 1 to 3). The Commission initially proposed a conditional mechanism linking the entry into application to the availability of support tools and harmonized standards [cite: 16, 21, 23]. However, during the legislative process in early 2026, both the Council of the European Union and the European Parliament converged on fixed postponement dates:

  • Annex III (Stand-alone High-Risk Systems): Pushed back from August 2, 2026, to December 2, 2027 [cite: 17, 24].
  • Annex I (AI Embedded in Regulated Products): Pushed back from August 2, 2027, to August 2, 2028 [cite: 17, 24].
2.2 Re-directing AI Literacy Obligations

Under Article 4 of the original Act, providers and deployers were required to "ensure" a sufficient level of AI literacy among their staff. The Omnibus proposes relaxing this obligation, shifting the primary responsibility to the European Commission and Member States, who would merely "encourage" AI literacy, thereby reducing corporate liability [cite: 18, 25, 26].

2.3 Exemptions and Registration Relief

The amendment removes the obligation for providers of AI systems exempted from high-risk classification (under Article 6(3)) to register their systems in the central EU database. Instead, providers would simply document a self-assessment before market placement [cite: 25, 26]. Additionally, simplifications granted to SMEs are extended to small mid-cap companies (SMCs) [cite: 7, 19].

2.4 Intersections with the GDPR and Data Processing

A critical component of the Digital Omnibus on AI is its interaction with data protection laws. The proposal introduces a new Article 4a to the AI Act and a corresponding Article 88c to the GDPR. These provisions clarify that processing personal data for the development and operation of AI models may rely on the "legitimate interest" legal basis [cite: 27, 28]. Furthermore, it relaxes the threshold for using special categories of personal data (e.g., race, health data) specifically for the purpose of bias detection and correction in both high-risk and non-high-risk systems [cite: 25, 26, 28].

2.5 Expansion of Regulatory Sandboxes

To foster innovation, the Omnibus broadens the scope of AI regulatory sandboxes. It permits the EU AI Office to establish Union-level sandboxes and expands the possibility for real-world testing outside formal sandbox environments, a provision previously restricted mostly to Annex III systems [cite: 18, 26, 27].


3. Trilogue Negotiations and the April 2026 Stalemate (Last 30 Days)

The legislative process requires the European Commission's proposal to be negotiated and agreed upon by the co-legislators: the European Parliament and the Council of the European Union. In March 2026, both bodies adopted their respective negotiating mandates [cite: 21]. The Council adopted its general approach on March 13, 2026, favoring the fixed delay deadlines, while the Parliament's Internal Market and Consumer Protection (IMCO) and Civil Liberties, Justice and Home Affairs (LIBE) committees adopted a joint report shortly thereafter [cite: 16, 21, 29].

With the mandates established, the institutions entered the trilogue phase, operating under immense time pressure to finalize the Omnibus before the original August 2, 2026, deadline triggered widespread enforcement [cite: 24].

3.1 The Breakdown of April 28, 2026

On April 28, 2026, the second political trilogue took place. Despite prior consensus on the primary objective—delaying high-risk implementation to December 2027 and August 2028—the negotiations collapsed after approximately twelve hours of debate, concluding in the early hours of April 29 [cite: 15, 21, 30].

The critical point of contention was the structural relationship between the AI Act and existing EU sectoral safety legislation (Annex I) [cite: 21]. The European Parliament pushed to shift a significant category of product-embedded high-risk AI systems (such as those in machinery, medical devices, and toys) out from under the direct scope of the AI Act and into their respective sectoral frameworks [cite: 30, 31].

The Council strongly opposed this move. Representatives argued that granting such carve-outs would dismantle the horizontal framework of the AI Act, effectively deregulating product-embedded AI rather than simplifying its compliance [cite: 31]. The deadlock highlights a profound philosophical disagreement: whether AI should be governed as a distinct technological category across all domains (the Council's view) or whether AI regulation should be subsumed into existing product safety laws to avoid overlapping jurisdictions (the Parliament's view).

3.2 Further Points of Friction

Beyond the Annex I dispute, other elements delayed the agreement:

  • Watermarking and Transparency: The Parliament proposed a three-month transitional period for generative AI systems to comply with the Article 50(2) watermarking obligations (compliance by November 2, 2026), whereas the Council and Commission favored a six-month period (compliance by February 2, 2027) [cite: 21, 26].
  • New Prohibitions: The Council mandate sought to introduce new bans on AI generating non-consensual sexual content or child sexual abuse material, as well as AI-enabled "nudification" tools [cite: 16, 21].
  • Cybersecurity Presumptions: The Parliament proposed that high-risk AI systems compliant with the Cyber Resilience Act should automatically be presumed compliant with the robustness requirements of the AI Act (Article 15). The Council rejected this automated presumption [cite: 24].

Following the collapse, negotiations were scheduled to resume in mid-May 2026. However, as noted by major legal commentators, if the Omnibus is not formally adopted and published before August 2, 2026, the original legal text of the AI Act will apply by default, forcing businesses into immediate compliance with the unmodified high-risk obligations [cite: 15, 24].


4. Summaries from Major European Policy Blogs and Institutes

The proposed amendments and the subsequent legislative stalemate have generated intense analysis across major European policy blogs, research institutes, and legal advisory networks. These analyses reveal deep schisms between industry representatives pushing for deregulation and civil society organizations advocating for the preservation of fundamental rights.

4.1 The European Parliamentary Research Service (EPRS)

The European Parliamentary Research Service (EPRS) provided thorough briefings on the digital package. Their reports acknowledge that while the Digital Omnibus is welcomed by industry stakeholders aiming to reduce administrative costs (saving an estimated €5 billion by 2029), it raises significant concerns regarding fundamental rights [cite: 23, 29]. The EPRS highlighted the risk that "simplification could upset the fragile equilibrium achieved during the initial trilogue negotiations" in 2023 [cite: 29]. Furthermore, the EPRS noted challenges within the governance framework, warning that the highly decentralized enforcement model—relying on national market surveillance authorities—could lead to uneven enforcement across Member States, exacerbating the very fragmentation the Omnibus seeks to cure [cite: 32].

4.2 The International Association of Privacy Professionals (IAPP)

The IAPP closely tracked the trilogue breakdown of April 28, 2026. Their policy coverage underscored the "increasing intersectionality of existing digital rules" [cite: 31]. The IAPP summarized the Parliament's attempt to move sectoral legislation from Annex I Section A to B, noting the warnings from civil society and MEP Michael McNamara that routing AI governance through sectoral legislation might be a deregulatory maneuver [cite: 31]. The IAPP also captured industry reactions, noting that the stalemate could result in "regulatory chaos" for European companies that had paused compliance preparations in anticipation of the delay [cite: 30]. Digital Europe Director General Cecilia Bonefeld-Dahl was quoted viewing the delay more pragmatically, stating it demonstrates the democratic process working and granting policymakers necessary time for deliberation [cite: 30].

4.3 Tech Policy Press and Corporate Europe Observatory

Blogs oriented toward tech policy and civil society, such as Tech Policy Press, raised severe alarms regarding the non-retroactivity of the AI Act combined with the Omnibus delays. They pointed out a "structural gap" or "loophole" in Article 111 [cite: 33]. Because the AI Act rules are not retroactive, systems placed on the market before the newly proposed deadlines (e.g., December 2027) would not need to comply unless substantially modified. Bram Vranken of the Corporate Europe Observatory (CEO) and MEP Sergey Lagodinsky argued that delaying the deadline to 2027 means "a large part of high-risk AI systems that have been placed on the market before December 2027 will never have to comply with the rules," allowing highly sensitive applications like algorithmic hiring systems to indefinitely dodge oversight [cite: 33].

4.4 Corporate Legal Advisories (DLA Piper, Ropes & Gray, TwoBirds, etc.)

Major corporate law blogs have focused heavily on the operational risks stemming from the trilogue stalemate.

  • Bird & Bird (TwoBirds) explicitly warned clients that "starting from zero is no longer realistic before August," advising that any compliance program recalibrated to the proposed 2027 timeline is now critically exposed due to the April 28 collapse [cite: 21].
  • DLA Piper focused on the employment sector, emphasizing that HR AI systems (recruitment, performance evaluation) remain classified as high-risk under Annex III. They advised that employers must continue preparing for the original August 2, 2026 deadline, as the Omnibus delay is not yet law [cite: 15].
  • Ropes & Gray observed that the accelerated timetable for the Omnibus was highly unusual by EU standards, reflecting a panicked acknowledgment of industry gaps in conformity assessment infrastructure. They highlighted the danger that the compliance framework businesses are building toward might shift exactly when the underlying legislation becomes operational [cite: 24].
  • A-LIGN and PwC framed the delay not as a concession, but as a symptom of unready regulatory infrastructure (e.g., a lack of notified bodies) [cite: 17, 18]. They advised clients that technical files required under Article 11 take immense time to compile, making a pause in compliance efforts a dangerous strategic error [cite: 17].

5. Comparative Global Context: The Rise of State-Level Regulation

While the European Union struggles to finalize its Omnibus amendments, policy blogs note that other jurisdictions are advancing their own AI regulatory frameworks, creating a complex, overlapping global compliance matrix for multinational entities [cite: 34, 35].

In the United States, in the absence of comprehensive federal legislation, state-level laws are anchoring enforcement. For instance, the Colorado Artificial Intelligence Act, focused on algorithmic discrimination in consequential automated decision-making tools (ADMT), was originally scheduled to take effect in June 2026. Interestingly, mirroring the EU's delays, Colorado lawmakers introduced a proposal in March 2026 to streamline their framework and delay the effective date to January 1, 2027 [cite: 35, 36]. Similarly, Texas enacted the Responsible Artificial Intelligence Governance Act effective January 2026, while California is rolling out the AI Transparency Act and the Generative AI Training Data Transparency Act, focusing on public summaries of training datasets and provenance data [cite: 34, 35].

These parallel global developments highlight that regardless of whether the EU AI Act's high-risk provisions apply in August 2026 or December 2027, the global regulatory trajectory is moving decisively toward mandated transparency, risk assessments, and bias mitigation.


6. Strategic Implications for Stakeholders

The uncertainty surrounding the Digital Omnibus on AI places organizations in a precarious strategic position. Based on the synthesized analysis of the draft texts and policy commentary, several conclusions emerge for AI providers and deployers:

  1. Assume the August 2026 Baseline: Because the trilogue negotiations stalled on April 28, 2026, the legally binding deadline for Annex III high-risk systems remains August 2, 2026. Legal commentators uniformly advise that companies treating the 2027 delay as settled law are operating on "legislative optimism rather than legal fact" [cite: 17]. Preparations for conformity assessments, CE marking, and EU database registration must proceed without delay [cite: 9, 15].
  2. Transparency Obligations Remain Imminent: Even if the Omnibus passes, many transparency obligations (Article 50) for limited-risk systems and generative AI will take effect in late 2026 or early 2027 [cite: 11, 21]. Organizations deploying chatbots or generating synthetic content must secure the technical capability to watermark and label outputs immediately.
  3. Prohibited Practices are Already Active: The delay negotiations only affect Chapter III (High-Risk) rules. The ban on unacceptable risk systems (e.g., specific biometric categorizations, subliminal manipulation) has been actively enforced since February 2, 2025 [cite: 5, 7, 8].
  4. Data Governance Adaptations: The proposed alignments between the AI Act and the GDPR (such as the clarification of legitimate interest and processing sensitive data for bias correction) suggest that organizations should tightly integrate their privacy and AI compliance programs. The Digital Omnibus explicitly attempts to force organizations away from siloed compliance toward unified Governance, Risk, and Compliance (GRC) models [cite: 20, 28].

7. Conclusion

The European Union Artificial Intelligence Act represents an ambitious, unprecedented attempt to codify the ethical and safe deployment of AI technology on a continental scale. The final text, Regulation (EU) 2024/1689, established a rigorous risk-based architecture. However, the practical realities of enforcing this Act—characterized by a lack of technical standards and the looming threat to digital competitiveness—prompted the European Commission to propose the Digital Omnibus on AI in late 2025.

As of the last 30 days preceding May 2026, the legislative effort to delay high-risk compliance deadlines and simplify corporate burdens has fractured. A fundamental disagreement between the European Parliament and the Council regarding the intersection of the AI Act with sectoral product safety laws led to a trilogue collapse in April 2026.

Policy blogs and legal scholars paint a picture of a regulatory environment caught between two conflicting imperatives: the economic necessity of deregulating to foster innovation (as urged by the Draghi report) and the ethical mandate to prevent irreversible societal harms from unregulated legacy AI systems. As the August 2026 deadline fast approaches, the European Union faces a critical test of its legislative agility, and global technology firms must navigate an environment of profound regulatory uncertainty. Businesses must therefore pursue an agile, regulation-agnostic governance approach focused on core ethical principles, remaining prepared for immediate compliance while monitoring the volatile outcomes of the forthcoming trilogue sessions.

Sources:

  1. europa.eu
  2. caidp.org
  3. artificialintelligenceact.eu
  4. vde.com
  5. hunton.com
  6. artificialintelligenceact.eu
  7. europa.eu
  8. enterprise.gov.ie
  9. legalnodes.com
  10. optro.ai
  11. gdprlocal.com
  12. freshfields.com
  13. gunder.com
  14. artificialintelligenceact.eu
  15. dlapiper.com
  16. europa.eu
  17. a-lign.com
  18. pwc.com
  19. eui.eu
  20. pivotpointsecurity.com
  21. twobirds.com
  22. europa.eu
  23. europa.eu
  24. ropesgray.com
  25. activemind.legal
  26. mofo.com
  27. arnoldporter.com
  28. hannessnellman.com
  29. europa.eu
  30. iapp.org
  31. iapp.org
  32. epthinktank.eu
  33. techpolicy.press
  34. onetrust.com
  35. kiteworks.com
  36. lawandtheworkplace.com
references (36)

Gemini

prose3,343 words

The European Union Artificial Intelligence Act: Legislative Evolution, the 2026 'Digital Omnibus' Amendments, and Policy Perspectives

Key Points
  • Current Status: The European Union Artificial Intelligence Act (Regulation (EU) 2024/1689) is officially in force, having been published in the Official Journal on July 12, 2024.
  • Proposed Amendments: Research suggests a shifting regulatory timeline. The European Commission's "Digital Omnibus on AI" (proposed November 2025) seeks to alleviate administrative burdens and delay the enforcement of high-risk AI obligations originally slated for August 2026.
  • Recent Developments: It seems likely that the proposed extensions (pushing compliance to December 2027 and August 2028) have encountered political hurdles; trilogue negotiations reportedly stalled in late April 2026 due to disagreements over how AI embedded in regulated products should be governed.
  • Policy Discourse: Summaries from major policy blogs highlight a tension between fostering EU digital competitiveness (as championed by the Draghi report) and preserving the robust fundamental rights safeguards that the AI Act originally intended to establish.
Introduction to the Legislative Context

The European Union has positioned itself at the vanguard of global digital regulation with the adoption of the Artificial Intelligence Act. However, translating this landmark legislation from text to operational reality has proven highly complex. In response to industry concerns and the necessity of establishing harmonized standards, the European Commission introduced a targeted legislative package known as the Digital Omnibus. This package aims to streamline compliance, particularly for high-risk systems.

The Stalemate of Spring 2026

The most recent 30 days of legislative activity have been characterized by intense trilogue negotiations between the European Parliament, the Council of the European Union, and the European Commission. These discussions unexpectedly collapsed on April 28, 2026. The breakdown was not rooted in the decision to delay compliance deadlines, which enjoys broad consensus, but rather in the structural architecture of conformity assessments for AI systems integrated into products already governed by sectoral safety laws.

Scope of the Report

This report provides a comprehensive academic analysis of the latest draft texts and official amendments surrounding the EU AI Act. It details the foundational Regulation (EU) 2024/1689, dissects the provisions and current political deadlock of the Digital Omnibus on AI, and synthesizes critical viewpoints from major European policy blogs and research institutions, offering an exhaustive overview of the current European AI governance landscape.


1. Foundational Legal Framework: Regulation (EU) 2024/1689

To understand the currently proposed amendments, it is first necessary to examine the original text of the AI Act. The European Commission initially unveiled its proposal for a comprehensive artificial intelligence act in April 2021 [cite: 1]. Following years of protracted negotiations, culminating in a 36-hour marathon trilogue in December 2023, the European Parliament adopted the Act in March 2024, and the Council of the European Union endorsed it in May 2024 [cite: 1, 2].

The final text was promulgated as Regulation (EU) 2024/1689 in the Official Journal of the European Union on July 12, 2024 [cite: 3, 4, 5]. This established the first comprehensive legal framework for artificial intelligence by a major global regulator [cite: 6]. The Regulation entered into force twenty days after publication, on August 1, 2024 [cite: 4, 5, 7].

1.1 The Risk-Based Classification Architecture

The fundamental philosophy of the EU AI Act is a graduated, risk-based approach, ensuring that regulatory burdens are proportionate to the potential for harm to health, safety, and fundamental rights [cite: 8, 9]. The legislation categorizes AI systems into four distinct tiers:

Risk CategoryRegulatory ApproachExamples of AI SystemsImplementation Date (Original)
Unacceptable RiskStrict prohibition and ban from the EU market.Government social scoring, biometric categorization, predictive policing, subliminal manipulation.February 2, 2025 [cite: 8, 10, 11].
High Risk (Annex III & Annex I)Subject to stringent obligations: risk management, quality datasets, technical documentation, human oversight, and conformity assessments.CV-scanning tools, AI in critical infrastructure, medical devices, law enforcement, education.August 2, 2026 (Annex III) & August 2, 2027 (Annex I) [cite: 7, 8, 12].
Limited / Transparency RiskSubject to specific transparency obligations, ensuring users are informed they are interacting with AI.Chatbots, deepfakes, AI-generated synthetic content.August 2, 2026 [cite: 7, 8, 11].
Minimal or No RiskLargely left unregulated; no mandatory requirements, though voluntary codes of conduct are encouraged.AI-enabled video games, spam filters.N/A (Exempt) [cite: 6, 7, 11].
1.2 General-Purpose AI (GPAI) Models

In addition to the risk tiers, the final text introduced specific provisions for General-Purpose AI (GPAI) models, a late addition reflecting the rise of generative AI. Obligations for GPAI models took effect on August 2, 2025 [cite: 7, 12]. Providers of such models must adhere to transparency requirements, provide technical documentation, respect EU copyright laws, and, for models posing systemic risks, conduct adversarial testing and incident reporting [cite: 5, 13]. To bridge the gap until harmonized European standards are finalized, the AI Office developed a Code of Practice for GPAI, with final drafts published in mid-2025 [cite: 12, 14].


2. The Digital Omnibus on AI: Proposed Amendments (2025–2026)

Despite the formal adoption of Regulation (EU) 2024/1689, challenges rapidly emerged regarding its practical implementation. The lack of harmonized standards, delays in designating national competent authorities, and a shortage of notified bodies capable of conducting conformity assessments generated widespread industry concern [cite: 4, 15, 16, 17]. Furthermore, the September 2024 Draghi report on European competitiveness highlighted that fragmented and complex digital regulations were stifling innovation and overburdening small and medium-sized enterprises (SMEs) [cite: 18, 19].

In response, on November 19, 2025, the European Commission published the "Digital Omnibus" package (COM(2025) 836) [cite: 4, 16, 20]. This package consists of broader digital reforms (amending the GDPR, Data Act, and NIS2) and a specific Digital Omnibus on AI Regulation Proposal, which targets the AI Act directly under the political banner of "simplification and competitiveness" [cite: 20, 21, 22].

2.1 Postponement of High-Risk AI Obligations

The most prominent element of the proposed amendment from the Commission is the deferral of the AI Act's high-risk obligations (Chapter III, Sections 1 to 3). The Commission initially proposed a conditional mechanism linking the entry into application to the availability of support tools and harmonized standards [cite: 16, 21, 23]. However, during the legislative process in early 2026, both the Council of the European Union and the European Parliament converged on fixed postponement dates:

  • Annex III (Stand-alone High-Risk Systems): Pushed back from August 2, 2026, to December 2, 2027 [cite: 17, 24].
  • Annex I (AI Embedded in Regulated Products): Pushed back from August 2, 2027, to August 2, 2028 [cite: 17, 24].
2.2 Re-directing AI Literacy Obligations

Under Article 4 of the original Act, providers and deployers were required to "ensure" a sufficient level of AI literacy among their staff. The Omnibus proposes relaxing this obligation, shifting the primary responsibility to the European Commission and Member States, who would merely "encourage" AI literacy, thereby reducing corporate liability [cite: 18, 25, 26].

2.3 Exemptions and Registration Relief

The amendment removes the obligation for providers of AI systems exempted from high-risk classification (under Article 6(3)) to register their systems in the central EU database. Instead, providers would simply document a self-assessment before market placement [cite: 25, 26]. Additionally, simplifications granted to SMEs are extended to small mid-cap companies (SMCs) [cite: 7, 19].

2.4 Intersections with the GDPR and Data Processing

A critical component of the Digital Omnibus on AI is its interaction with data protection laws. The proposal introduces a new Article 4a to the AI Act and a corresponding Article 88c to the GDPR. These provisions clarify that processing personal data for the development and operation of AI models may rely on the "legitimate interest" legal basis [cite: 27, 28]. Furthermore, it relaxes the threshold for using special categories of personal data (e.g., race, health data) specifically for the purpose of bias detection and correction in both high-risk and non-high-risk systems [cite: 25, 26, 28].

2.5 Expansion of Regulatory Sandboxes

To foster innovation, the Omnibus broadens the scope of AI regulatory sandboxes. It permits the EU AI Office to establish Union-level sandboxes and expands the possibility for real-world testing outside formal sandbox environments, a provision previously restricted mostly to Annex III systems [cite: 18, 26, 27].


3. Trilogue Negotiations and the April 2026 Stalemate (Last 30 Days)

The legislative process requires the European Commission's proposal to be negotiated and agreed upon by the co-legislators: the European Parliament and the Council of the European Union. In March 2026, both bodies adopted their respective negotiating mandates [cite: 21]. The Council adopted its general approach on March 13, 2026, favoring the fixed delay deadlines, while the Parliament's Internal Market and Consumer Protection (IMCO) and Civil Liberties, Justice and Home Affairs (LIBE) committees adopted a joint report shortly thereafter [cite: 16, 21, 29].

With the mandates established, the institutions entered the trilogue phase, operating under immense time pressure to finalize the Omnibus before the original August 2, 2026, deadline triggered widespread enforcement [cite: 24].

3.1 The Breakdown of April 28, 2026

On April 28, 2026, the second political trilogue took place. Despite prior consensus on the primary objective—delaying high-risk implementation to December 2027 and August 2028—the negotiations collapsed after approximately twelve hours of debate, concluding in the early hours of April 29 [cite: 15, 21, 30].

The critical point of contention was the structural relationship between the AI Act and existing EU sectoral safety legislation (Annex I) [cite: 21]. The European Parliament pushed to shift a significant category of product-embedded high-risk AI systems (such as those in machinery, medical devices, and toys) out from under the direct scope of the AI Act and into their respective sectoral frameworks [cite: 30, 31].

The Council strongly opposed this move. Representatives argued that granting such carve-outs would dismantle the horizontal framework of the AI Act, effectively deregulating product-embedded AI rather than simplifying its compliance [cite: 31]. The deadlock highlights a profound philosophical disagreement: whether AI should be governed as a distinct technological category across all domains (the Council's view) or whether AI regulation should be subsumed into existing product safety laws to avoid overlapping jurisdictions (the Parliament's view).

3.2 Further Points of Friction

Beyond the Annex I dispute, other elements delayed the agreement:

  • Watermarking and Transparency: The Parliament proposed a three-month transitional period for generative AI systems to comply with the Article 50(2) watermarking obligations (compliance by November 2, 2026), whereas the Council and Commission favored a six-month period (compliance by February 2, 2027) [cite: 21, 26].
  • New Prohibitions: The Council mandate sought to introduce new bans on AI generating non-consensual sexual content or child sexual abuse material, as well as AI-enabled "nudification" tools [cite: 16, 21].
  • Cybersecurity Presumptions: The Parliament proposed that high-risk AI systems compliant with the Cyber Resilience Act should automatically be presumed compliant with the robustness requirements of the AI Act (Article 15). The Council rejected this automated presumption [cite: 24].

Following the collapse, negotiations were scheduled to resume in mid-May 2026. However, as noted by major legal commentators, if the Omnibus is not formally adopted and published before August 2, 2026, the original legal text of the AI Act will apply by default, forcing businesses into immediate compliance with the unmodified high-risk obligations [cite: 15, 24].


4. Summaries from Major European Policy Blogs and Institutes

The proposed amendments and the subsequent legislative stalemate have generated intense analysis across major European policy blogs, research institutes, and legal advisory networks. These analyses reveal deep schisms between industry representatives pushing for deregulation and civil society organizations advocating for the preservation of fundamental rights.

4.1 The European Parliamentary Research Service (EPRS)

The European Parliamentary Research Service (EPRS) provided thorough briefings on the digital package. Their reports acknowledge that while the Digital Omnibus is welcomed by industry stakeholders aiming to reduce administrative costs (saving an estimated €5 billion by 2029), it raises significant concerns regarding fundamental rights [cite: 23, 29]. The EPRS highlighted the risk that "simplification could upset the fragile equilibrium achieved during the initial trilogue negotiations" in 2023 [cite: 29]. Furthermore, the EPRS noted challenges within the governance framework, warning that the highly decentralized enforcement model—relying on national market surveillance authorities—could lead to uneven enforcement across Member States, exacerbating the very fragmentation the Omnibus seeks to cure [cite: 32].

4.2 The International Association of Privacy Professionals (IAPP)

The IAPP closely tracked the trilogue breakdown of April 28, 2026. Their policy coverage underscored the "increasing intersectionality of existing digital rules" [cite: 31]. The IAPP summarized the Parliament's attempt to move sectoral legislation from Annex I Section A to B, noting the warnings from civil society and MEP Michael McNamara that routing AI governance through sectoral legislation might be a deregulatory maneuver [cite: 31]. The IAPP also captured industry reactions, noting that the stalemate could result in "regulatory chaos" for European companies that had paused compliance preparations in anticipation of the delay [cite: 30]. Digital Europe Director General Cecilia Bonefeld-Dahl was quoted viewing the delay more pragmatically, stating it demonstrates the democratic process working and granting policymakers necessary time for deliberation [cite: 30].

4.3 Tech Policy Press and Corporate Europe Observatory

Blogs oriented toward tech policy and civil society, such as Tech Policy Press, raised severe alarms regarding the non-retroactivity of the AI Act combined with the Omnibus delays. They pointed out a "structural gap" or "loophole" in Article 111 [cite: 33]. Because the AI Act rules are not retroactive, systems placed on the market before the newly proposed deadlines (e.g., December 2027) would not need to comply unless substantially modified. Bram Vranken of the Corporate Europe Observatory (CEO) and MEP Sergey Lagodinsky argued that delaying the deadline to 2027 means "a large part of high-risk AI systems that have been placed on the market before December 2027 will never have to comply with the rules," allowing highly sensitive applications like algorithmic hiring systems to indefinitely dodge oversight [cite: 33].

4.4 Corporate Legal Advisories (DLA Piper, Ropes & Gray, TwoBirds, etc.)

Major corporate law blogs have focused heavily on the operational risks stemming from the trilogue stalemate.

  • Bird & Bird (TwoBirds) explicitly warned clients that "starting from zero is no longer realistic before August," advising that any compliance program recalibrated to the proposed 2027 timeline is now critically exposed due to the April 28 collapse [cite: 21].
  • DLA Piper focused on the employment sector, emphasizing that HR AI systems (recruitment, performance evaluation) remain classified as high-risk under Annex III. They advised that employers must continue preparing for the original August 2, 2026 deadline, as the Omnibus delay is not yet law [cite: 15].
  • Ropes & Gray observed that the accelerated timetable for the Omnibus was highly unusual by EU standards, reflecting a panicked acknowledgment of industry gaps in conformity assessment infrastructure. They highlighted the danger that the compliance framework businesses are building toward might shift exactly when the underlying legislation becomes operational [cite: 24].
  • A-LIGN and PwC framed the delay not as a concession, but as a symptom of unready regulatory infrastructure (e.g., a lack of notified bodies) [cite: 17, 18]. They advised clients that technical files required under Article 11 take immense time to compile, making a pause in compliance efforts a dangerous strategic error [cite: 17].

5. Comparative Global Context: The Rise of State-Level Regulation

While the European Union struggles to finalize its Omnibus amendments, policy blogs note that other jurisdictions are advancing their own AI regulatory frameworks, creating a complex, overlapping global compliance matrix for multinational entities [cite: 34, 35].

In the United States, in the absence of comprehensive federal legislation, state-level laws are anchoring enforcement. For instance, the Colorado Artificial Intelligence Act, focused on algorithmic discrimination in consequential automated decision-making tools (ADMT), was originally scheduled to take effect in June 2026. Interestingly, mirroring the EU's delays, Colorado lawmakers introduced a proposal in March 2026 to streamline their framework and delay the effective date to January 1, 2027 [cite: 35, 36]. Similarly, Texas enacted the Responsible Artificial Intelligence Governance Act effective January 2026, while California is rolling out the AI Transparency Act and the Generative AI Training Data Transparency Act, focusing on public summaries of training datasets and provenance data [cite: 34, 35].

These parallel global developments highlight that regardless of whether the EU AI Act's high-risk provisions apply in August 2026 or December 2027, the global regulatory trajectory is moving decisively toward mandated transparency, risk assessments, and bias mitigation.


6. Strategic Implications for Stakeholders

The uncertainty surrounding the Digital Omnibus on AI places organizations in a precarious strategic position. Based on the synthesized analysis of the draft texts and policy commentary, several conclusions emerge for AI providers and deployers:

  1. Assume the August 2026 Baseline: Because the trilogue negotiations stalled on April 28, 2026, the legally binding deadline for Annex III high-risk systems remains August 2, 2026. Legal commentators uniformly advise that companies treating the 2027 delay as settled law are operating on "legislative optimism rather than legal fact" [cite: 17]. Preparations for conformity assessments, CE marking, and EU database registration must proceed without delay [cite: 9, 15].
  2. Transparency Obligations Remain Imminent: Even if the Omnibus passes, many transparency obligations (Article 50) for limited-risk systems and generative AI will take effect in late 2026 or early 2027 [cite: 11, 21]. Organizations deploying chatbots or generating synthetic content must secure the technical capability to watermark and label outputs immediately.
  3. Prohibited Practices are Already Active: The delay negotiations only affect Chapter III (High-Risk) rules. The ban on unacceptable risk systems (e.g., specific biometric categorizations, subliminal manipulation) has been actively enforced since February 2, 2025 [cite: 5, 7, 8].
  4. Data Governance Adaptations: The proposed alignments between the AI Act and the GDPR (such as the clarification of legitimate interest and processing sensitive data for bias correction) suggest that organizations should tightly integrate their privacy and AI compliance programs. The Digital Omnibus explicitly attempts to force organizations away from siloed compliance toward unified Governance, Risk, and Compliance (GRC) models [cite: 20, 28].

7. Conclusion

The European Union Artificial Intelligence Act represents an ambitious, unprecedented attempt to codify the ethical and safe deployment of AI technology on a continental scale. The final text, Regulation (EU) 2024/1689, established a rigorous risk-based architecture. However, the practical realities of enforcing this Act—characterized by a lack of technical standards and the looming threat to digital competitiveness—prompted the European Commission to propose the Digital Omnibus on AI in late 2025.

As of the last 30 days preceding May 2026, the legislative effort to delay high-risk compliance deadlines and simplify corporate burdens has fractured. A fundamental disagreement between the European Parliament and the Council regarding the intersection of the AI Act with sectoral product safety laws led to a trilogue collapse in April 2026.

Policy blogs and legal scholars paint a picture of a regulatory environment caught between two conflicting imperatives: the economic necessity of deregulating to foster innovation (as urged by the Draghi report) and the ethical mandate to prevent irreversible societal harms from unregulated legacy AI systems. As the August 2026 deadline fast approaches, the European Union faces a critical test of its legislative agility, and global technology firms must navigate an environment of profound regulatory uncertainty. Businesses must therefore pursue an agile, regulation-agnostic governance approach focused on core ethical principles, remaining prepared for immediate compliance while monitoring the volatile outcomes of the forthcoming trilogue sessions.

Sources:

  1. europa.eu
  2. caidp.org
  3. artificialintelligenceact.eu
  4. vde.com
  5. hunton.com
  6. artificialintelligenceact.eu
  7. europa.eu
  8. enterprise.gov.ie
  9. legalnodes.com
  10. optro.ai
  11. gdprlocal.com
  12. freshfields.com
  13. gunder.com
  14. artificialintelligenceact.eu
  15. dlapiper.com
  16. europa.eu
  17. a-lign.com
  18. pwc.com
  19. eui.eu
  20. pivotpointsecurity.com
  21. twobirds.com
  22. europa.eu
  23. europa.eu
  24. ropesgray.com
  25. activemind.legal
  26. mofo.com
  27. arnoldporter.com
  28. hannessnellman.com
  29. europa.eu
  30. iapp.org
  31. iapp.org
  32. epthinktank.eu
  33. techpolicy.press
  34. onetrust.com
  35. kiteworks.com
  36. lawandtheworkplace.com
references (36)

Parallel

prose1,459 words

EU AI Act Omnibus 2026 – Draft, Deadlines & Decision-Points for Industry

Executive Summary

The European Commission's "Digital Omnibus on AI" (COM 2025 PC 0836), published in November 2025, aims to introduce targeted simplification measures to the EU AI Act [1] [2]. However, efforts to finalize these amendments before the looming August 2026 compliance deadline have stalled. On April 28, 2026, a critical 12-hour trilogue negotiation between the European Parliament and the Council collapsed without an agreement [3] [4] [5].

While all institutions broadly agree on delaying the enforcement of high-risk AI rules to December 2027 (for stand-alone systems) and August 2028 (for embedded systems) [6] [7], deep divisions remain regarding sectoral carve-outs and fundamental rights protections [8] [7]. With the next trilogue scheduled for mid-May 2026 [3], companies face a potential "regulatory cliff" [9]. If no agreement is reached, the original August 2, 2026 deadline for high-risk AI systems will remain in force [3] [7]. Organizations must immediately prepare parallel compliance pathways, treating the original 2026 deadline as a reality while monitoring the May negotiations.

1 Context & Legislative Timeline

The European Commission introduced the Digital Omnibus on AI on November 19, 2025, as part of a broader package to streamline EU digital regulations, including the AI Act and civil aviation rules [8] [10]. The primary driver for this proposal was the delayed establishment of harmonized standards and national competent authorities, which threatened the feasibility of the AI Act's original August 2, 2026 application date for high-risk systems [1] [6].

The legislative process moved rapidly through early 2026. The Council agreed on its general approach on March 13, 2026 [6] [11]. Shortly after, the European Parliament adopted its negotiating position during the second March 2026 plenary session, with 569 votes in favor, 45 against, and 23 abstentions [6] [12]. Trilogue negotiations commenced on March 26, 2026, aiming for a swift resolution [12]. However, the failure of the April 28 session has left the timeline highly uncertain, with May representing the final window to amend the Act before the August 2026 deadline becomes unavoidable [4].

2 Core Text of the Digital Omnibus

The draft text of the Digital Omnibus (Regulation COM(2025) 836) focuses on technical amendments designed to ensure efficient implementation without altering the core political agreement of the AI Act [1]. The Commission explicitly noted that because the amendments are technical, no formal impact assessment was conducted [1].

Key provisions in the draft text include:

  • Article 29 & 30 Amendments: Modifies the application process for conformity assessment bodies, requiring them to apply for designation using specific codes and categories set out in a new Annex XIV for the NANDO information system [1].
  • Article 43 Clarifications: Adjusts conformity assessment procedures for high-risk AI systems covered by Union harmonization legislation listed in Section A of Annex I [1].
  • Article 111 Adjustments: Introduces a 6-month transitional period for providers to retroactively integrate technical solutions making generative AI outputs machine-readable and detectable [1].
  • Article 113 (Entry into Application): Proposes linking the application of Chapter III high-risk obligations to the Commission's confirmation that necessary compliance tools (standards, guidelines) are available [1].

3 Key Institutional Positions

While the Commission proposed a flexible deadline linked to the availability of standards [1] [6], the co-legislators have pushed for fixed dates and additional behavioral guardrails.

InstitutionPosition on DeadlinesPosition on Bans & RegistrationKey Stance / Quote
European ParliamentFixed deadlines: Dec 2, 2027 (stand-alone) & Aug 2, 2028 (embedded) [6]Proposes targeted ban on AI generating sexual/intimate content without consent [6]Seeks to reformulate conditions for processing special data for bias detection [6]
European CouncilAligns with Parliament on fixed Dec 2027 / Aug 2028 dates [6]Adds bans on child sexual abuse material; reinstates simplified registration for non-high-risk AI [6]Supports standard of "strict necessity" for processing special categories of data [6]
European CommissionFlexible deadline triggered by availability of standards [6]Relies on original AI Act prohibitions [1]Amendments are "technical in nature" [1]

The most significant friction point involves Annex I and sectoral alignment. The Parliament supports carving out certain high-risk AI systems from the AI Act's direct scope, moving them under sectoral laws (like the Medical Device Regulation), a move the Council and Commission currently resist [7].

4 Trilogue Outcomes & Forward-Look

The highly anticipated trilogue on April 28, 2026, collapsed after 12 hours of negotiation [3] [5]. The European Parliament and Council walked out without a deal, leaving the original August 2, 2026 deadline intact for now [3] [5].

A follow-up political trilogue is tentatively scheduled for mid-May (approximately May 13, 2026) [3]. This represents the final realistic window for EU institutions to pass the Omnibus before the August enforcement begins [4]. If negotiations drag on, the legislative environment will become further complicated when Ireland takes over the EU presidency on June 30, 2026 [7].

5 Policy-Level Implications

The current deadlock creates severe strategic risks for the technology sector. Industry representatives warn of "pure regulatory chaos" and a "regulatory cliff" if the Omnibus is not adopted [9]. If the simplification proposal fails to pass by August 2, 2026, companies will be forced to comply with the original rules, potentially for only a few months before a delayed Omnibus takes effect, destroying legal certainty [9].

Furthermore, the debate over structural changes to the AI Act threatens ongoing standardization work. The chair of CEN-CENELEC AI standards development warned that structural changes to high-risk applications could invalidate years of foundational standards work [7]. The Commission's aggressive push for these reforms has been characterized by some analysts as "AI FOMO" (fear of missing out), driving a multitude of initiatives that risk upsetting the fragile equilibrium achieved in the original AI Act [8] [13].

6 Sector-Specific Impact Matrix

The proposed Omnibus significantly alters the compliance timeline depending on how an AI system is categorized and deployed.

AI System CategoryCurrent AI Act DeadlineProposed Omnibus DeadlineSectoral Overlap / Notes
Stand-alone High-Risk AI (Annex III)August 2, 2026 [1] [7]December 2, 2027 [6] [7]Direct enforcement under AI Act.
Embedded High-Risk AI (Regulated Products)August 2, 2026 [1]August 2, 2028 [6] [7]Subject to debate over Annex I carve-outs into sectoral laws (e.g., Machinery, Medical Devices) [7].
Civil Aviation AIAugust 2, 2026Aligned with Omnibus datesIntegrated into Regulation (EU) 2018/1139 to ensure consistent application [1] [8].
Generative AI SystemsAugust 2, 2026+6 month transitional periodExtra time granted to retroactively include machine-readable detection solutions [1].

7 Stakeholder & Market Reaction

Reaction to the Digital Omnibus is highly polarized. Most industry stakeholders initially welcomed the digital package, hoping it would reduce administrative costs and help businesses scale [8]. However, the current legislative mess has left executives unsure how to allocate compliance resources, with some advisors suggesting a "pens down" approach until clarity emerges [9].

Conversely, civil society and consumer protection groups have expressed alarm. An open joint letter warned that the Commission's promise of "targeted simplification" must not become deregulation, stressing that the balance of the original AI Act is essential to protect consumers and ensure trustworthy AI [14].

8 Action Roadmap for Companies

Given the failure of the April trilogue, organizations cannot rely on the proposed deadline extensions.

  1. Assume the August 2026 Deadline: Treat the original August 2, 2026 enforcement date for high-risk systems as reality [7]. Resume or accelerate compliance planning immediately.
  2. Audit Generative AI Content: Review all generative AI models against the Parliament and Council's proposed bans on generating non-consensual sexual content and child sexual abuse material [6]. Implement technical filters now to mitigate future liability.
  3. Map Sectoral Overlaps: For AI embedded in products (medical devices, machinery), prepare dual-track compliance strategies that account for both the AI Act and specific sectoral regulations, as the Annex I carve-out remains unresolved [7].
  4. Engage in the May Window: Utilize the narrow window before the mid-May trilogue to submit stakeholder feedback regarding the necessity of fixed deadlines and the preservation of existing CEN-CENELEC standards work [3] [7].

9 Appendices

  • Appendix A: Key Document Links
  • Draft Proposal COM(2025) 836: EUR-Lex PDF [1]
  • Legislative Observatory Procedure File: 2025/0359(COD) [6] [15]
  • Appendix B: Glossary
  • Digital Omnibus: A 3-part proposal to amend EU laws governing data, cybersecurity, privacy, and AI [16].
  • NANDO: New Approach Notified and Designated Organisations information system, which will utilize a new Annex XIV for AI conformity assessment body codes [1].

ai-generated content. verify independently. preserved in the museum of queries.

more research comparisons

Want this comparison for your own question? Run a blind battle between deep research AIs or see the deep research API leaderboard from all community votes.