AI Omnibus: What Parliament Gets in Exchange for Delaying the Bill

Partager

On June 16, 2026, Parliament approved the Digital Omnibus Act on AI by a vote of 423 in favor, 57 against, and 174 abstentions. The compromise defers the “high-risk” classification but adds prohibitions and retains the risk-based approach.

The Essentials in 30 Seconds

  • Annex III: December 2, 2027.
  • Annex I: August 2, 2028.
  • Non-consensual intimate content and child sexual abuse material: ban.
  • Targeted labeling: December 2, 2026.

What Happened

Chapter III is postponed to December 2, 2027 for autonomous systems under Article 6(2) and Annex III, and to August 2, 2028 for Article 6(1) and Annex I. The text links this deadline to the availability of standards and supporting measures. Synthetic content systems placed on the market before August 2 must be labeled, in the prescribed form, by December 2, 2026.

The vote alone does not conclude the legislative process. However, it does give the Parliament a position on a compromise that balances the timeline, product safety, and expressly prohibited uses. The majority was broad, but the number of abstentions serves as a reminder that the postponement of obligations also raised concerns.

The text distinguishes between two categories of high-risk systems. Annex III covers use cases specified by the regulation. Annex I concerns safety products or components subject to harmonization legislation. This distinction explains why the proposed deadlines are not identical.

The reference to standards and supporting measures is important. It links effective implementation to tools that enable operators to understand the expectations and incorporate them into their processes. The postponement, therefore, does not amount to the elimination of the framework; it alters the sequence of the expected work.

The Analysis

The trade-off is real: a ban on systems that generate child sexual abuse material and non-consensual intimate or sexually explicit content involving an identifiable person. Machines fall under a sector-specific framework without redundant rules, with equivalent protection. Simplified registration for non-high-risk systems never exempts the provider from documenting its qualification; profiling remains high-risk.

The ban on non-consensual intimate content addresses a specific harm. It targets tools that facilitate the production of content that infringes upon an identifiable person. Its inclusion in the compromise shows that administrative simplification has been accompanied by a targeted strengthening of protection against certain uses.

The clarification provided for the machinery sector follows a different rationale. When sector-specific requirements provide equivalent protection, the goal is to avoid a proliferation of rules for the same product. This does not exempt the company from identifying the applicable regulatory framework or from justifying the approach chosen.

The starting point remains the classification of the system. A feature presented as incidental may influence a decision regarding a person or access to a service. The analysis must therefore focus on the actual use, and not solely on the commercial description of the tool.

Operational Impact

For each system, the decision must be linked to a specific purpose, an identifiable version, a legal role, the individuals likely to be affected, and the deployment context. An up-to-date inventory, controlled user instructions, and a clear assignment of responsibilities are the prerequisites for demonstrable compliance. Management must be able to distinguish between directly applicable obligations, deferred deadlines, and tasks that remain useful in all cases. This discipline facilitates responses to regulatory authorities, contract management, and coordination among business teams.

At this stage, teams can distinguish between reversible decisions and investments that depend on a deadline. Mapping, describing data flows, and assigning a person in charge remain useful regardless of the final timeline. On the other hand, a project designed solely for a specific date must be reevaluated in light of the compromise.

The qualification dossier should include a brief, dated note. It can describe the intended purpose, the users, the individuals involved, the outputs produced, and the known limitations. Such a note helps clarify why the organization chose one category over another.

Contracts require the same caution. The supplier’s commitments, the information provided to the deployer, and the conditions for modifying the system must remain consistent with the selected classification. Establishing an update mechanism prevents the documentation from becoming tied to an outdated version.

What to Do Now

  • Map — identify the system, version, purpose, and legal role.
  • Document — preserve the reasoning and evidence.
  • Plan — assign a responsible party, deadline, and review.
  • Monitor — reconcile contracts, instructions, and technical measures.

Create a decision list rather than a purely technical inventory. Each line should specify who uses the system, for what activity, and with what potential impact. Experimental tools should be included when they produce results that inform a decision.

Retain the evidence that led to the exclusion of high risk. This record must be reviewed when the purpose, target audience, or level of autonomy changes. The classification is not a label fixed at the time of purchase.

Inform management of the text’s exact status: a compromise approved by Parliament, not a rule that is already in effect. This wording reduces the risk of premature statements to clients, partners, or internal teams.

Sources

  • European Parliament, press release dated June 16, 2026: plenary vote of 423 in favor, 57 against, and 174 abstentions; ban on stripping tools; no redundant rules for machine safety: europarl.europa.eu
  • Council of the European Union, compromise text forwarded for adoption (PE-30-2026): data.consilium.europa.eu
  • AI Act Service Desk, Article 6 of Regulation (EU) 2024/1689 on the classification of high-risk systems: ai-act-service-desk.ec.europa.eu

Lire la suite