In late April 2026, the European Parliament and the Council reached an agreement on a series of amendments to the EU AI Regulation (AI Act). The provisional agreement, part of the so-called „Digital Omnibus,” provides for extended deadlines for high-risk AI systems, clearer definitions of the term “high risk,” and expanded relief measures for smaller companies. This results in an adjusted regulatory roadmap for providers and operators of AI systems.
Extended Implementation Deadlines for High-Risk AI Systems
A key element of the agreement is the adjusted implementation deadlines. The goal is to make it easier for providers to comply with the AI Regulation without compromising essential provisions or the risk-based approach.
Requirements for high-risk AI systems take effect as of December 2, 2027 for applications in the fields of biometrics, critical infrastructure, education, employment, law enforcement, and border management.
For systems that are classified as safety components under EU sector-specific legislation, a deadline has been set for August 2, 2028 specified.
With these adjustments, EU lawmakers are responding to criticism that the originally proposed deadlines were too tight, given the lack of technical standards and support measures. The extensions are intended to give companies time to bring their systems into compliance with the regulations without facing legal uncertainty.
The watermarking requirement—that is, the technical labeling of AI-generated content for traceability—will, however, take effect as early as December 2, 2026 into effect, and thus earlier than the Commission had originally proposed. For affected For providers, this means a tighter timeline.
A Clearer Definition: What Constitutes a High-Risk System?
In addition to the deadline extensions, the agreement includes clarifications on specific points that are of considerable practical relevance to companies.
As a result, products with AI functions that are intended solely to assist users or optimize performance—and whose failure does not pose any health or safety risks—will no longer be automatically classified as high-risk systems. This will provide greater clarity regarding which requirements actually apply. The aim is to ease the burden on providers whose systems are not functionally safety-critical.
With regard to machinery products, it is also clarified that these need only comply with sector-specific safety regulations and not with the requirements of the AI Regulation, provided that an equivalent level of protection is ensured. This eliminates overlapping requirements that would have led to duplicative efforts in practice.
Expanded Scope of the SME Exemptions
Until now, small and medium-sized enterprises (SMEs) have benefited from certain exemptions under the AI Regulation. The agreement now extends these exemptions to so-called small mid-cap enterprises (SMEs). These are companies that have exceeded the SME threshold but do not yet have the resources of large corporations. The Commission’s proposal sets a threshold for SMCs of fewer than 750 employees, as well as an annual turnover of no more than 150 million euros or a balance sheet total of no more than 129 million euros. The final definition will be set out in the final text of the regulation.
Privacy: Processing of Personal Data for Bias Detection
Another aspect concerns the handling of personal data: Under certain conditions, it will be permissible in the future to process such data if this is absolutely necessary to identify and correct bias in AI systems, provided that appropriate safeguards are in place. This provision applies to both high-risk and other AI systems. This takes into account the fact that fair and non-discriminatory AI requires targeted quality checks of the underlying data.
Ban on "nudification" apps
The agreement also includes two new prohibitions: According to the agreement, AI systems may not create sexually explicit depictions of identifiable individuals without their Consent as well as systems used to generate material involving the sexual exploitation of children, will no longer be made available on the EU market. The ban covers image, video, and audio content. Providers have until December 2, 2026, to adapt their systems.
Centralized Enforcement for General-Purpose AI
In the future, the enforcement of certain obligations for general-purpose AI systems will be centralized at the EU AI Office. This is intended to ensure coherent and efficient oversight at the European level and reduce fragmentation caused by different national authorities.
Formal adoption has yet to take place
The agreement reached is provisional for now. Before it becomes legally binding, Parliament and the Council must formally approve it. Adoption is scheduled to take place before August 2, 2026, the date on which the previous rules for high-risk systems would have otherwise taken effect.
However, companies should note the following: The revised deadlines in the AI Regulation do not change the fact that the GDPR already applies in full to AI-supported data processing. The time saved should therefore be used to establish structures for governance, Compliance- and to establish risk management for the use of AI at an early stage.
Would you like to implement the AI Act in your company in a legally compliant manner?
While the new deadlines do provide some leeway, the regulatory requirements are complex.
2B Advice helps you classify AI systems, Compliance-Identify gaps and establish a future-proof AI governance structure tailored to your company's size and industry.
Contact us! We'll guide you every step of the way, from the initial assessment to successful implementation.
Frequently Asked Questions About the AI Act
What are the new deadlines for high-risk AI systems under the EU AI Regulation?
Under the agreement described in the article, obligations for certain high-risk AI systems are set to take effect on December 2, 2027. This applies, among other things, to applications in areas such as biometrics, critical infrastructure, education, employment, law enforcement, and border management. For AI systems that fall under EU sector-specific legislation as safety components, a later deadline of August 2, 2028, is provided.
Does the extension of the deadline mean that companies can wait to comply with the AI Act?
No. The extended deadlines provide more time, but they do not change the fact that companies must identify, classify, and manage their AI systems early on. In addition, the GDPR already today for AI-supported processing of personal data. Companies should use the time they have gained to systematically establish AI governance, risk management, data protection reviews, and accountability.
What changes are being made to the classification of high-risk AI systems?
The agreement is intended to provide a clearer definition of when an AI system is actually considered a high-risk system. AI functions that merely support users or optimize performance—and whose failure does not pose any health or safety risks—should not automatically be classified as high-risk systems. For companies, this makes the accurate classification of their AI use cases even more important.
What relief measures are planned for SMEs and smaller mid-cap companies?
The relief measures previously intended for small and medium-sized enterprises are to be extended to so-called small mid-cap enterprises. This is intended to provide relief to companies that are larger than traditional SMEs but do not have the resources of large corporations. Nevertheless, Documentation, risk assessment, and governance structures are key requirements for the use of AI.
Why Does Data Protection Remain Relevant Despite the New AI Act Deadlines?
Even though certain obligations under the EU AI Regulation will take effect at a later date, the GDPR already today. As soon as AI systems personal data process, must have a legal basis, Earmarking, Transparency, Rights of data subjects, Data minimization, storage limits, and potential DSFA obligations should be reviewed. AI Act Compliance and Data protection should therefore not be considered separately, but rather together.
Which solution helps companies comply with the EU AI Regulation, AI classification, and AI governance?
Companies should use a solution that systematically tracks AI systems and AI use cases, assesses risks, documents responsibilities, maps approvals, and facilitates reviews. Ailance AI Governance helps companies meet the requirements of the EU AI Regulation regarding data protection, Compliance and to integrate risk management and establish a robust AI governance structure.





