Article · 7 MIN

The EU Is Already Rewriting Its AI Act Just Months After Adoption

The EU Is Already Rewriting Its AI Act Just Months After Adoption

What the Omnibus VII Reform Reveals About the Real Challenges of AI Regulation in Europe

The European Union spent years building the world’s most ambitious artificial intelligence regulation.

Now, before most of its core obligations even apply, Brussels is already rewriting significant parts of it.

On May 7, 2026, the European Parliament and the Council of the European Union reached a political agreement under the “Omnibus VII” simplification package to amend several provisions of the EU AI Act. The reform introduces delayed compliance deadlines, lighter obligations for certain industrial actors, expanded regulatory support for smaller companies, and new prohibitions targeting AI-generated intimate deepfakes.

This is not a minor technical correction.

It is one of the clearest signs yet that regulating artificial intelligence at industrial scale is proving far more complex than policymakers initially anticipated.

For legal departments, compliance teams, AI governance officers, and technology companies, this development fundamentally changes how the AI Act should be interpreted moving forward.

The European AI regulatory framework is no longer static.

It is becoming adaptive, negotiable, and economically sensitive.

 

Why the EU Is Modifying the AI Act So Quickly

When the AI Act entered into force in August 2024, it was presented as the global benchmark for trustworthy AI regulation. The legislation introduced a risk-based framework governing prohibited AI practices, high-risk systems, foundation models, transparency obligations, and governance mechanisms across the European market.

However, implementation pressure rapidly exposed several structural tensions:

  • overlapping compliance obligations;
  • uncertainty regarding technical standards;
  • certification duplication for industrial products;
  • operational complexity for SMEs;
  • and concerns that excessive regulatory burden could weaken European competitiveness against U.S. and Chinese AI ecosystems.

The Omnibus VII reform package is the European Union’s first major acknowledgment that implementation realities matter as much as regulatory ambition.

This matters far beyond Europe.

Because every multinational company building, deploying, integrating, or procuring AI systems in the EU now faces a moving compliance target rather than a fixed regulatory endpoint.

 

The Most Important Changes Introduced by the Omnibus VII AI Reform

1. High-Risk AI Obligations Have Been Delayed

One of the most consequential reforms concerns the timeline for high-risk AI systems.

Under the political agreement reached on May 7, 2026:

  • obligations for standalone high-risk AI systems under Annex III are postponed to December 2, 2027;
  • obligations for AI systems embedded in regulated products are delayed until August 2, 2028.

These categories include systems used in:

  • biometrics;
  • employment;
  • education;
  • migration;
  • border control;
  • critical infrastructure;
  • and certain law enforcement contexts.

The official justification is straightforward: technical standards and implementation guidance are not ready yet.

Legally, this creates a critical implication for organizations.

Compliance strategies based on the original AI Act timeline may already require revision.

 

2. The EU Is Reducing Regulatory Overlap

Another major objective of the Omnibus VII package is simplification.

Industrial stakeholders had argued that the AI Act duplicated existing sectoral certification frameworks, particularly for machinery and regulated products already governed by European safety laws.

The reform therefore seeks to streamline interactions between the AI Act and existing sector-specific regulations. Certain machinery-related systems may now fall outside portions of the AI Act framework where equivalent regulatory obligations already exist.

This reflects a broader policy shift.

The European Commission is increasingly prioritizing “regulatory coherence” over cumulative compliance layering.

For legal teams, this means AI governance can no longer be analyzed in isolation.

AI compliance is becoming deeply interconnected with:

  • product safety law;
  • cybersecurity law;
  • consumer protection;
  • medical device regulation;
  • and digital platform obligations.

3. The EU Is Simultaneously Tightening Certain AI Prohibitions

While some obligations are being softened or delayed, the EU is also expanding restrictions in areas considered socially or politically sensitive.

The Omnibus VII agreement introduces explicit prohibitions targeting AI systems generating non-consensual sexually explicit content, often referred to as “nudifier” applications.

This reform emerged amid growing concern regarding:

  • AI-generated intimate deepfakes;
  • synthetic abuse imagery;
  • and unauthorized sexualized manipulation of identifiable individuals.

This dual movement is legally significant.

The EU is not abandoning AI regulation.

It is recalibrating its priorities.

The emerging model appears increasingly clear:

  • fewer administrative barriers where industrial competitiveness is threatened;
  • stronger prohibitions where human dignity and fundamental rights are directly impacted.

4. The Reform Expands Regulatory Support for Smaller Companies

The Omnibus VII package also extends certain simplification measures beyond SMEs to smaller mid-cap companies.

This includes broader access to AI regulatory sandboxes and support mechanisms intended to facilitate compliance experimentation.

From a governance perspective, this is particularly important.

One of the major criticisms of the original AI Act was that only very large technology companies possessed the legal and financial capacity to operationalize compliance at scale.

The revised approach implicitly recognizes that overregulation may consolidate market power instead of democratizing trustworthy AI innovation.

 

What This Reform Really Reveals About the AI Act

The deeper issue is not the delayed deadlines.

It is the speed of the correction itself.

The AI Act was originally presented as a stable long-term framework capable of structuring global AI governance.

Instead, Europe is already adjusting core implementation mechanisms before full enforcement begins.

This reveals several realities that many organizations underestimated.

AI regulation is evolving faster than traditional legislation

The AI ecosystem now changes faster than standard legislative cycles can realistically absorb.

By the time obligations are operationalized, the underlying technologies, deployment models, and industrial practices may already have shifted.

Industrial feasibility is becoming central to digital regulation

The Omnibus VII reform demonstrates that AI governance is no longer solely a fundamental rights discussion.

It is also an industrial competitiveness issue.

This explains why several major European industrial actors publicly pushed for simplification measures before the agreement.

Compliance strategies must become dynamic

Legal departments can no longer treat AI governance as a “one-time compliance project.”

The regulatory environment itself is now iterative.

Organizations will increasingly need:

  • continuous AI governance reviews;
  • adaptive risk classification processes;
  • regulatory monitoring mechanisms;
  • and evolving internal AI policies.

Key Legal Questions Companies Should Now Ask

The Omnibus VII reform raises immediate operational questions for legal and compliance teams:

Does your AI governance roadmap still reflect the updated implementation timeline?

Many organizations prepared based on the original deadlines.

That may now require recalibration.

Are your AI systems subject to overlapping sectoral regulation?

The revised framework increases the importance of mapping AI systems against existing regulatory regimes rather than analyzing the AI Act independently.

Are your transparency mechanisms future-proof?

The EU continues tightening obligations regarding synthetic content labeling and prohibited manipulative uses.

Are your internal AI governance structures flexible enough to absorb future reforms?

The AI Act is increasingly behaving like a living regulatory framework rather than a static legal instrument.

 

The Bigger Strategic Shift Behind the Omnibus VII Reform

The most important lesson may ultimately be political rather than technical.

Europe is discovering that regulating AI requires balancing three forces simultaneously:

  • protection of fundamental rights;
  • industrial competitiveness;
  • and operational enforceability.

The Omnibus VII reform shows that legal ambition alone is insufficient if implementation becomes economically or technically impracticable.

This does not mean the EU AI Act has failed.

But it does suggest that AI regulation is entering a new phase: a phase of continuous adjustment rather than rigid stabilization. And for companies operating in AI, that may become the new normal.

 

FAQ: EU AI Act Omnibus VII Reform

Why is the EU already changing the AI Act?

The EU introduced the Omnibus VII package to simplify implementation, reduce regulatory overlap, delay certain compliance obligations, and address concerns raised by industry regarding feasibility and competitiveness.

When will high-risk AI obligations now apply?

Following the May 7, 2026 political agreement:

  • standalone high-risk systems will generally apply from December 2, 2027;
  • AI systems embedded in regulated products will apply from August 2, 2028.

What are “nudifier” AI applications?

These are AI systems capable of generating sexually explicit or intimate images of individuals without consent. The Omnibus VII reform explicitly prohibits these practices within the EU.

Does the reform weaken the AI Act?

The reform softens certain implementation burdens while simultaneously strengthening restrictions on specific harmful AI practices. The core risk-based structure of the AI Act remains intact.

Why does this reform matter for legal departments?

Because AI compliance strategies now require continuous monitoring. The regulatory framework itself is evolving, meaning organizations must treat AI governance as an ongoing operational process rather than a one-time legal exercise.