Editor’s Note: Europe just reset the clock on one of the world’s most influential AI laws, nine days before the first tranche of its high-risk rules was due to apply. The Digital Omnibus on AI, published July 24 in the Official Journal as Regulation (EU) 2026/1744 and in force July 27, moves the AI Act’s core compliance dates to December 2027 and August 2028, adds a conditional ban on AI systems that generate non-consensual intimate imagery, effective Dec. 2, 2026, and redraws the line between the AI Act and sectoral product law.

For cybersecurity, data privacy, regulatory compliance and eDiscovery professionals, the package is a double signal: enforcement timelines relaxed, but a new prohibited practice arrives with top-tier penalties attached. Consent mechanisms, content-marking evidence and safeguard documentation may become important evidence in investigations and litigation, which puts governance and discovery teams near the middle of AI compliance whether they asked to be or not.

Watch three things next: the Commission’s Annex I acts and guidance, the pace at which member states stand up market surveillance authorities, and the still-pending data strand of the Digital Omnibus. December 2026, not December 2027, is the date that should be circled on planning calendars.


Content Assessment: EU rewrites the AI Act's clock and bans nudification tools in one stroke

Information - 93%
Insight - 92%
Relevance - 93%
Objectivity - 92%
Authority - 91%

92%

Excellent

A short percentage-based assessment of the qualitative benefit expressed as a percentage of positive reception of the recent article from ComplexDiscovery OÜ titled, "EU rewrites the AI Act's clock and bans nudification tools in one stroke."


Industry News – Artificial Intelligence Beat

EU rewrites the AI Act’s clock and bans nudification tools in one stroke

ComplexDiscovery Staff

Nine days before the first major tranche of the AI Act’s high-risk obligations was set to bite, the European Union tore up the compliance calendar. The replacement schedule, published July 24 in the Official Journal, buys industry as much as 16 extra months and hands victims of AI-generated abuse a ban with teeth.

Regulation (EU) 2026/1744, better known as the Digital Omnibus on AI, amends the AI Act, the aviation safety regulation and the machinery regulation in a single instrument. Signed July 8 and published July 24, it enters into force July 27, the third day after publication. It lands after a sprint of a legislative process: the European Commission proposed the package Nov. 19, 2025, negotiators struck a provisional deal May 7, 2026, the European Parliament approved the final text June 16, 2026, by 423 votes to 57, with 174 abstentions, and the Council gave its final approval June 29. The timing was no accident. Lawmakers raced to finish before Aug. 2, 2026, the date the first tranche of Annex III high-risk rules would have begun to apply.

For compliance teams across cybersecurity, information governance and eDiscovery, the regulation answers one question and raises a dozen. The deadlines moved. Most core obligations remain, although the omnibus narrows some duties and shifts others into sectoral law.

A compliance calendar redrawn at the deadline

The headline change is time. High-risk AI systems listed in Annex III, the standalone category covering employment screening, credit scoring, biometric identification and similar uses, now face a Dec. 2, 2027, application date instead of Aug. 2, 2026. High-risk systems embedded in products already regulated under sectoral law, the Annex I category that sweeps in medical devices, toys, lifts and watercraft, move from Aug. 2, 2027, to Aug. 2, 2028.

Member states also get relief. The deadline for national authorities to establish at least one AI regulatory sandbox slips to Aug. 2, 2027. And providers of synthetic-content-generating systems already on the market before Aug. 2, 2026, receive a grace period, ending Dec. 2, 2026, to implement the machine-readable marking of synthetic images, audio, video and text required under Article 50(2). Systems placed on the market on or after Aug. 2, 2026, must comply from day one. The extension belongs to providers alone: deployers’ separate disclosure duties under Article 50(4) receive no such grace period.

Marilena Raouna, Cyprus’ deputy minister for European affairs, said when the deal was struck in May that the agreement supports European companies by reducing recurring administrative costs. Industry had lobbied hard for the delay, according to reporting throughout the fall of 2025, and the Commission folded the argument into its broader simplification agenda for the digital rulebook. One caution for readers tracking Brussels: this regulation is the AI strand of that agenda. The separate Digital Omnibus covering data protection and ePrivacy rules remains in the legislative pipeline and is not part of the text published July 24.

The delay is real, but so is the fine print. General-purpose AI model obligations, in force since August 2025, keep their core duties and application dates. Most governance and penalty provisions remain on their existing application schedules, although the omnibus revises AI Office competence, code-of-practice mechanics and some penalty rules. The AI literacy duty under Article 4 survives, though the omnibus recasts it in more flexible form. An organization that reads the omnibus as a two-year holiday is misreading it.

Nudification tools face a December ban

The omnibus does not only loosen. It adds a new prohibited practice to Article 5’s list of banned AI uses: the generation of non-consensual sexual and intimate content, along with child sexual abuse material. AI systems built to generate nude images of real, identifiable people, or to edit clothing out of existing photographs to reveal intimate parts, are banned beginning Dec. 2, 2026.

“We’re talking about systems designed to strip clothes from photographs of real people,” Michael McNamara, the Irish MEP who served as co-rapporteur on the file, said during the parliamentary debate before the June vote, according to Tech Policy Press, describing services that industrialize that capability at scale and for profit.

The rule is narrower than a blanket prohibition on any general-purpose model that might be misused. For providers, placing a system on the market or putting it into service is prohibited when generating or manipulating the specified material is its intended purpose, or when that result is reasonably foreseeable and reproducible and the system lacks reasonable and adequate safeguards. For deployers, the prohibition applies when the system is used for that purpose. The regulation’s recitals point to measures such as refusal training, safe prompt design, output controls and content filtering as possible safeguards, examples rather than a universal checklist. Violations sit in the AI Act’s top penalty tier: fines of up to 35 million euros or 7 percent of worldwide annual turnover for the preceding financial year, whichever is higher, subject to Article 99’s lower-cap rule for small and medium-sized enterprises, or SMEs.

Advocates for victims say the ban’s architecture leaves gaps. Belén Luna Sanz, a women’s and digital rights advocate, told Tech Policy Press the requirement that a depicted person be identifiable creates a higher threshold for protection. Enforcement capacity is a separate worry: as of the June vote, only eight member states had designated the market surveillance authorities who would police the ban, the outlet reported.

Brussels takes the wheel on general-purpose AI oversight

The regulation also settles a supervision question that had hung over the AI Act since adoption. The AI Office, the Commission’s enforcement arm for general-purpose AI, now holds exclusive competence to supervise AI systems built on general-purpose AI models when the model and the system are developed by the same provider or by providers within the same undertaking, subject to the regulation’s listed exceptions. In practice, that centralizes oversight of the major model developers’ downstream products in Brussels rather than in 27 national capitals.

The centralization has limits. The AI Office’s exclusive competence does not cover Annex I product systems or Annex III critical-infrastructure systems, and it does not cover certain systems provided by law-enforcement, border-management and financial institutions, to the extent covered by Article 74(6), or Annex III systems used in the administration of justice. In those categories, national authorities remain competent, a reflection of how firmly member states guard supervisory prerogatives in those sectors.

Sectoral law gets the right of way

For the Annex I world, the omnibus redraws the boundary between the AI Act and the product-safety statutes that already govern medical devices, aviation, toys and dozens of other categories. The relief is not automatic. The AI Act steps back only where the Commission adopts delegated acts specifying the systems, the duties, the conditions and the scope for which sectoral law provides equivalent or greater protection, an anti-duplication mechanism aimed at manufacturers that faced two overlapping conformity regimes for the same product. Those acts are due by Aug. 2, 2027.

Machinery gets the sharpest cut, though not a clean exit. Products covered by the machinery regulation move from Annex I’s Section A to its Section B, taking them out of the AI Act’s direct high-risk regime while leaving selected AI Act provisions applicable. Most substantive requirements are instead to be folded into the machinery rulebook itself: the Commission must adopt delegated acts under the machinery regulation adding health and safety requirements for AI in machinery, with those requirements to apply by Aug. 2, 2028. The risk did not vanish; the rulebook housing it changed.

The Commission also picks up a duty to publish guidance helping Annex I operators comply with the AI Act’s high-risk requirements in a way that minimizes compliance burden. For manufacturers, that guidance, when it arrives, will be the practical map through the sectoral interplay provisions.

Simplification’s critics see a retreat

Civil society groups read the same text and see erosion. “Today’s adoption of the AI Omnibus in the European Parliament weakens fundamental rights protections in the AI Act, delays enforcement of key provisions, and empowers Big Tech companies,” Diego Naranjo, senior advocacy adviser at the Civil Liberties Union for Europe, said after the June vote.

Eva Simon, the organization’s head of tech and rights, said the package “delays safeguards before they can take effect, weakens transparency obligations, and creates loopholes that primarily benefit tech companies.” Rights groups also faulted the process itself: a seven-month dash from proposal to adoption, without the impact assessment that normally accompanies amendments of this weight.

The Parliament’s own numbers hint at a fraying consensus. The March negotiating mandate drew 569 votes in favor; the final June text drew 423, with abstentions rising from 23 to 174. The two votes concerned different texts at different procedural stages, so the comparison is not like for like, but the drift in support is hard to miss.

What practitioners should do before December

The practical agenda starts with the nearest date, not the farthest. Providers whose generative systems were on the market before Aug. 2, 2026, should verify before Dec. 2, 2026, that machine-readable marking of AI-generated content is in place, because the provider grace period ends then and the new prohibition arrives the same day. Deployers should not borrow that comfort; their separate disclosure duties run on their own schedule. Trust and safety, information governance and legal teams should document the safeguards their generative systems carry, since refusal training, output controls and content filtering may become the compliance evidence regulators ask to see. American providers should resist the instinct to file this under foreign news. The AI Act reaches any provider placing a system on the EU market, wherever the company is established, and the penalty math is calculated on worldwide turnover.

The new prohibition also creates a records question worth answering early. Providers relying on consent to generate synthetic intimate content lawfully must be able to collect and demonstrate that consent, and consent mechanisms, content-marking evidence and safeguard testing may become important in investigations or litigation. The regulation does not establish a general retention schedule or expressly mandate particular logs for every system, so retention, integrity and production duties will depend on the actor, the system and other applicable law, including GDPR accountability and litigation-preservation requirements. When the first enforcement actions arrive, teams that treated these artifacts as engineering exhaust rather than potential evidence will feel the difference.

High-risk providers gained time and should spend it deliberately: mapping systems against Annex III, tracking the Commission’s promised Annex I guidance, and watching which national authorities are actually stood up, since sandbox and surveillance capacity now varies widely across member states.

The EU has bet that a slower, simpler AI Act will be a better-enforced one. By December 2027, the first evidence will be in. Will the extra time produce readier regulators and cleaner compliance, or did Brussels just teach the world that AI deadlines are negotiable?



News sources



Assisted by GAI and LLM Technologies

Additional reading

Source: ComplexDiscovery OÜ

ComplexDiscovery’s mission is to enable clarity for complex decisions by providing independent, data‑driven reporting, research, and commentary that make digital risk, legal technology, and regulatory change more legible for practitioners, policymakers, and business leaders.

 

Have a Request?

If you have information or offering requests that you would like to ask us about, please let us know, and we will make our response to you a priority.

ComplexDiscovery OÜ is an independent digital publication and research organization based in Tallinn, Estonia. ComplexDiscovery covers cybersecurity, data privacy, regulatory compliance, and eDiscovery, with reporting that connects legal and business technology developments—including high-growth startup trends—to international business, policy, and global security dynamics. Focusing on technology and risk issues shaped by cross-border regulation and geopolitical complexity, ComplexDiscovery delivers editorial coverage, original analysis, and curated briefings for a global audience of legal, compliance, security, and technology professionals. Learn more at ComplexDiscovery.com.

 

Generative Artificial Intelligence and Large Language Model Use

ComplexDiscovery OÜ recognizes the value of GAI and LLM tools in streamlining content creation processes and enhancing the overall quality of its research, writing, and editing efforts. To this end, ComplexDiscovery OÜ regularly employs GAI tools, including ChatGPT, Claude, Gemini, Grammarly, Midjourney, and Perplexity, to assist, augment, and accelerate the development and publication of both new and revised content in posts and pages published (initiated in late 2022).