In Brussels in the early hours of May 7, negotiators from the European Parliament and the Council agreed on the first substantial patch to the AI Act. Brussels describes it as a simplification package under Omnibus VII. In practical terms, it is the first real easing of the law since the EU's AI rulebook went live.
The package moves in three directions at once: it delays key deadlines, relaxes some compliance paperwork, and adds a new set of prohibitions.
High-risk AI gets more than a year of extra runway
The main concession is the timetable. Standalone high-risk AI systems move from an August 2026 application date to December 2, 2027, a delay of about 16 months. High-risk AI embedded in products moves further out, from August 2026 to August 2, 2028, or roughly two additional years.
The dates matter because the EU had tied application of the rules to the availability of the required standards and tools. Parliament and Council have now left the underlying obligations intact while stopping the clock. National AI regulatory sandboxes also get more time: their deadline shifts from August 2026 to August 2, 2027.
From outside Europe, the change may look modest. Inside the EU, the negotiation was sharper. Parliament had pushed to expand sector exemptions from one industry to 12. The final deal gives a full exemption only to machinery. Swedish MEP Arba Kokalari said member states had not shared Parliament's ambitions, a signal that national governments were unwilling to loosen the law further.
A 500-employee SME threshold changes the compliance math
One of the most important simplification measures is easy to miss. The lighter technical documentation requirements for SMEs now extend to small mid-caps, meaning companies with fewer than 500 employees.
That is a significant shift. The AI Act's older SME line was 250 employees. Companies above that point faced the full documentation route. Under the new deal, many mid-sized European software firms can move from the full compliance lane into the simplified one. The political message is plain: Brussels is acknowledging that applying the same burden to European challengers and American hyperscalers can end up punishing its own market.
Sexual deepfakes are banned, with a December start date
Parliament also secured a new prohibition on AI-generated non-consensual sexual images and child sexual abuse material. These items were not part of the Commission's original proposal.
The new ban is scheduled to apply on December 2, 2026. On the same date, the grace period for AI-generated content transparency rules is cut from six months to three months, forcing platforms that provide generative AI tools to label AI-made content sooner.
Kokalari linked the move to recent controversy around xAI's Grok and X, saying lawmakers wanted to make clear that such conduct is banned in Europe. Irish co-rapporteur Michael McNamara added that the legal text does not define intimate body parts directly, while the preamble does. That leaves the kind of interpretive space European legislation often gives to courts. In practice, case law may matter more than the wording alone.
Liability reaches both deliberate tools and weak safeguards
The new prohibition is strict in two ways. Developers who intentionally build such apps can be fined. Platforms that fail to install adequate safeguards can also face penalties.
That second point is aimed squarely at open-weight models. A provider will have a harder time arguing that it merely released a model and cannot be responsible for downstream abuse. If the model is misused in the absence of reasonable protections, the platform can still carry liability. Companies such as Hugging Face and Stability AI may need to re-examine release procedures for the European market before the end of the year.
Simplification, or retreat?
Law firm Lewis Silkin characterized the deal as procedural refinement rather than a fundamental restructuring of the legislation. That is the core reading: the EU has not abandoned the AI Act's risk-based compliance model. It has admitted that the original schedule was too aggressive.
The market will read that in two ways. One view is that Europe has opened a small window for technology competitiveness. The other is that Europe remains the world's strictest AI regulatory zone and has merely adjusted the pace without lowering the final standard.
Formal adoption is still expected to take several weeks. After the legal-linguistic scrub and votes in both institutions, the target is to finish before August 2, 2026. Meanwhile, the United States is trying to use federal law to preempt state AI rules, while China continues to systematize its own regime. Europe is slowing down, America is speeding up, and China is organizing. The next question is how long that mismatch lasts.
Sources: Artificial Intelligence: Council and Parliament agree to simplify and streamline rules (Council of the EU official release); The Council and Parliament agree to slim down and delay parts of the EU AI Act (Lewis Silkin); Parliament and Council reach agreement on the amendment to the AI Act, CocoLoop, ban on sexual deepfakes finalised (EUNews); EU AI Act gets its first real haircut - high-risk deadlines pushed to 2027 (PPC.land)