From the journal

EU Council and Parliament Agree to Simplify AI Act and Delay High-Risk Deadlines, May 2026

On 7 May 2026, the Council of the EU and European Parliament negotiators reached a provisional political agreement on the Digital Omnibus on AI Regulation. The agreement delays mandatory high-risk AI compliance dates to 2 December 2027 and 2 August 2028, extends simplified obligations to small mid-cap companies, and introduces a new ban on AI-generated non-consensual intimate imagery.

2 min read

EU Council and European Parliament negotiators reached a provisional political agreement on 7 May 2026. The instrument is the Digital Omnibus on AI Regulation, part of the EU Omnibus VII simplification package. It amends the EU AI Act (Regulation (EU) 2024/1689), which entered into force on 1 August 2024. The agreement remains provisional; formal adoption by both institutions and Official Journal publication are still pending.

The EU AI Act is the controlling regulation. Article 6 sets classification rules for high-risk AI systems. Annex III lists the covered use cases. The Omnibus agreement introduces two new fixed application dates for high-risk obligations: 2 December 2027 for stand-alone high-risk AI systems covered by Article 6(2) read with Annex III; and 2 August 2028 for high-risk AI systems that are safety components of products listed in Annex I subject to EU harmonisation legislation. The agreement also extends to small mid-cap companies the simplified technical documentation requirements previously available only to SMEs under existing AI Act provisions.

AI system providers and deployers classified as high-risk gain additional time before mandatory compliance begins. Developers at small mid-cap companies can now use the simplified technical documentation formats previously available only to SMEs. Developers seeking real-world testing conditions gain access to an EU-level regulatory sandbox alongside existing national sandboxes. A new prohibited practice is added to Article 5 of the AI Act. It bans AI systems from generating non-consensual sexual and intimate content or child sexual abuse material.

The Commission is separately consulting on draft guidelines for high-risk AI classification under Article 6(5). That consultation closes 23 June 2026. The Omnibus also resolves a duplication between the AI Act and the Machinery Regulation (EU) 2023/1230, aligning conformity assessment obligations for AI embedded in machinery. Formal adoption and Official Journal publication remain pending, so the application dates agreed here are not yet in force.

Licentium advises on EU AI Act compliance and maintains a partner network covering affected EU jurisdictions. Work we undertake includes AI Act obligation scoping for high-risk system providers and deployers, regulatory sandbox access applications, technical documentation preparation, and AI governance review for enterprise teams.

Source: Council of the EU, Artificial Intelligence: Council and Parliament agree to simplify and streamline rules, 7 May 2026

AI Regulatory

More from the journal

See all
Illia Prokopiev

Crypto Vaults and Lending Strategies Under U.S. Federal Securities Law

Commissioner Hester M. Peirce’s July 22, 2026 statement does not establish binding law, but it identifies the principal federal securities-law questions raised by crypto vaults and onchain lending strategies. This analysis examines when vault interests, lending claims, receipt tokens, and related service-provider activities may trigger the Securities Act, Exchange Act, Investment Company Act, and Investment Advisers Act.

MiCAR Transitional Regime for CASPs Expires Across the EU, July 2026

On 1 July 2026, the MiCAR transitional period under Article 143(3) of Regulation (EU) 2023/1114 expired across the EU. Former virtual asset service providers operating under national registrations must now hold a MiCAR crypto-asset service provider authorisation or cease providing crypto-asset services. In Luxembourg, the CSSF confirmed that VASP registration under the 2004 AML Law no longer provides a sufficient legal basis for market activity.

EDPB Adopts Final GDPR Guidelines on Blockchain Data Processing, EU, 8 July 2026

On 8 July 2026, the European Data Protection Board adopted the final version of Guidelines 02/2025 on the processing of personal data through blockchain technologies. The guidelines confirm that encrypted and hashed on-chain data remains personal data under the GDPR and that blockchain immutability does not override data subjects' right to erasure under Article 17. Controllers must address architecture choices and data minimisation before any on-chain recording of personal data.