EU AI Act: Where Things Stand in May 2026
If you have been trying to keep pace with EU AI Act developments, you would be forgiven for finding it difficult. Just as many businesses were working through what the August 2026 deadline would require of them, a significant political agreement reached on 7th May 2026 has changed the picture. This post explains what has happened, what it means for the timelines you may have been planning around, and what obligations remain firmly in place right now.
What Is Already in Force?
The first obligations under the EU AI Act took effect in February 2025. These included the prohibition on certain AI practices considered fundamentally incompatible with EU values: social scoring systems operated by public authorities, AI systems that exploit vulnerabilities to manipulate individuals in ways that cause harm, and certain uses of biometric categorisation and real-time remote biometric identification in public spaces. These prohibitions are absolute and apply without any transitional period.
Also from February 2025, the AI literacy obligation under Article 4 became active. This requires providers and deployers to ensure that staff working with AI have a sufficient level of understanding of the systems they use, calibrated to their role and the risks involved.
August 2025 brought the next significant set of changes. The rules on general-purpose AI (GPAI) models came into force, applying to providers of powerful AI models, including large language models. These providers must meet obligations around technical documentation, copyright transparency, and, for models that carry systemic risk, more stringent requirements including model evaluations and incident reporting to the EU AI Office.
The EU's governance structures also became operational from August 2025. The AI Board, the Scientific Panel of independent experts, and the AI Office within the European Commission are now active. Member States were required by that date to designate their national market surveillance authorities and to set out their domestic penalty frameworks.
The Latest Updates of the EU AI Act
The European Parliament and the Council of the EU reached a political agreement on 7th May 2026 on a package of changes to the AI Act, proposed by the European Commission under what it is calling the Digital Omnibus on AI. The stated purpose is to make the Act simpler to implement for businesses, particularly smaller ones, without reducing the protections it is designed to provide for people across the EU.
It is important to note that this agreement has not yet been formally adopted. The European Parliament and the Council must still complete that process, after which the changes will be published in the Official Journal and take effect later. That said, the political agreement reflects where things are heading, and businesses should factor it into their planning now. The Council of the EU press release sets out the detail of what was agreed.
What Has Changed About the EU AI Act Timelines?
One of the most significant outcomes of this agreement is a shift in the dates by which the rules for high-risk AI systems will apply. Under the Digital Omnibus, the obligations for AI systems used in areas including biometrics, critical infrastructure, education, employment, migration, asylum and border control will now apply from 2nd December 2027. For AI systems that are built into products such as lifts or toys, the deadline has been moved to 2nd August 2028.
The reasoning behind this sequencing is that it is intended to allow time for technical standards and other supporting tools to be in place before the rules begin to apply. This is an acknowledgement that readiness requires preparation on all sides, including from the regulators and standards bodies that businesses will need to rely on. If you were working toward the August 2026 date, this is a material change worth revisiting with your legal adviser.
What New Protections Are Being Added?
The agreement says that AI systems that generate non-consensual sexually explicit or intimate content, including AI-powered nudification applications, will be prohibited under the revised rules. The generation of child sexual abuse material by AI is also explicitly banned, such as AI ‘nudification' apps. These additions strengthen the Act's protections for individuals in ways that reflect how AI is actually being misused.
What Is Changing for Businesses?
The Digital Omnibus introduces a number of changes designed to make compliance more accessible. Certain privileges that were previously available only to small and medium-sized enterprises are being extended to small mid-cap companies, which broadens the range of businesses that can benefit from simplified rules and reduced obligations.
What Is the EU Digital Omnibus and Why Does It Matter?
The EU has spent the past decade building one of the most comprehensive digital regulatory frameworks in the world. That ambition has not gone away, but there is a growing recognition, reflected in both the Draghi and Letta reports on European competitiveness, that layering regulation on top of regulation has in some cases made it harder, not easier, for businesses to operate and grow within the EU.
The Digital Omnibus is the Commission's answer to that, a package of targeted amendments designed to reduce compliance costs, cut administrative duplication, and make the rules clearer without weakening the protections they were built to deliver.
Proposed in November 2025 and agreed politically by the European Parliament and Council on 7th May 2026, the Digital Omnibus on AI touches several areas at once. On data, it consolidates a number of separate regulations, including the Data Governance Act, the Open Data Directive, and the Free Flow of Non-Personal Data Regulation, into a single, cleaner framework within the Data Act. It also makes targeted adjustments to GDPR obligations, with smaller businesses and those carrying out lower-risk processing in mind.
One long-overdue change addresses cookie consent fatigue: the proposal moves toward browser-based, machine-readable consent signals, which would reduce the need for the pop-up banners that have frustrated both users and businesses for years. On cybersecurity, it introduces a single entry point for incident reporting, so that businesses facing an obligation to notify multiple regulators can do so in one step rather than several. It also repeals the Platform-to-Business Regulation, which has largely been superseded by the Digital Markets Act and Digital Services Act. You can read the full details here.
For businesses using or building AI, the most significant changes concern timing and burden. Small mid-cap companies, not just SMEs, now benefit from reduced obligations. As mentioned previously in this article, implementation deadlines for high-risk AI systems have been extended to 2nd December 2027 for systems in areas like employment, education and border control, and to 2nd August 2028 for AI embedded in physical products.
These extensions are said not to be a retreat from the Act's ambitions. They are intended to allow the technical standards and guidance that businesses will actually need to comply properly to be developed and published first.
How Can Gerrish Legal Help?
Gerrish Legal is a dynamic digital law firm. We pride ourselves on giving high-quality and expert legal advice to our valued clients. We specialise in many aspects of digital law such as GDPR, data privacy, digital and technology law, commercial law, and intellectual property.
We give companies the support they need to successfully and confidently run their businesses whilst complying with legal regulations without the burdens of keeping up with ever-changing digital requirements.
We are here to help you, get in contact with us today for more information.