Analysis of the key changes to the AI Act following the European Parliament vote on 26 March 2026
29 March 2026 · Reading time: approx. 15 minutes
July 2024. The European Union publishes the AI Act. Over 400 pages of legal text, a flagship regulation of artificial intelligence, months of negotiations, compromises, lobbying. It was meant to last for years. It was meant to set a global standard.
Less than two years later, on 26 March 2026, the European Parliament voted through 83 amendments to that very same act. 569 votes in favour, 45 against, 23 abstentions.
No, this is not a joke. It actually happened.
And these are not minor editorial corrections. Parliament restructured the architecture of Annex I, introduced 12 new articles amending sectoral legislation, redefined the concept of safety component, overhauled the supervisory model over the AI Office, and added an entirely new prohibition that the Commission had not even proposed. All as part of a package called the "Digital Omnibus on AI", which was officially meant to be a "simplification".
Sounds like material for a thorough analysis? Because it is. Let us break it down.
Why is the EU amending legislation that has not even taken effect yet?
To understand the rationale behind these amendments, we need to go back to the AI Act implementation timeline. It is not that the provisions were poorly drafted. The problem is different: the entire apparatus that was supposed to enable their application simply does not exist.
Let us start with the facts.
Harmonised standards are not ready. CEN-CENELEC Joint Technical Committee 21 - the body responsible for developing technical standards - was supposed to deliver them by 30 April 2025. The chair admitted back in 2024 that they would not make the deadline, but promised that companies would have standards by the end of 2025 or early 2026. In October 2025, the deadline was pushed again, to the end of 2026. According to Progress Chamber, this was already the third postponement.
The European Commission itself missed its own deadline. By 2 February 2026, it was supposed to publish guidelines on Article 6, the classification of high-risk systems. It did not. As IAPP reports, the Commission acknowledged that it was "integrating months of feedback" and planned to publish the final draft "by the end of the month". The final version? Perhaps March, perhaps April.
Member States have not designated supervisory authorities. Many countries still do not have designated AI regulators. Conformity assessment bodies (those responsible for certifying AI systems) have not been established. AI system providers do not know against which standards they are supposed to demonstrate compliance, because no one has told them yet.
Imagine someone telling you: "you must pass an exam in 6 months". But they do not give you the textbook. They do not tell you what the questions will be. The examiner has not been hired yet. And the institution that was supposed to organise everything admits it has not managed to prepare the materials itself.
That is exactly the situation faced by companies that were supposed to comply with AI Act requirements for high-risk systems by 2 August 2026.
Hence the Digital Omnibus on AI package, published by the Commission on 19 November 2025 as part of the broader "Simpler and Faster Europe" programme. The intention was simplification. In practice, Parliament added changes to the Commission's proposal that go far beyond cosmetics.
The vote and what comes next: trilogue under time pressure
On 26 March 2026, the European Parliament adopted its position at first reading. 569 votes in favour, 45 against, 23 abstentions. Earlier, on 13 March, the Council of the EU adopted its negotiating mandate. Now both institutions enter trilogue with the Commission.
And this is where the race against time begins.
The Cypriot Presidency, which is leading the Council's work, has set a target: agreement by 28 April 2026. According to Pinsent Masons, the first technical meetings began on the day of the vote and are set to continue through the Easter period. Why the rush? Because if the Omnibus is not adopted before 2 August 2026, the original timeline takes effect automatically. And then companies must comply with requirements for which there are still no standards.
The good news: the Council and Parliament are largely aligned. Both institutions rejected many of the "simplifications" proposed by the Commission. As Global Policy Watch notes, this convergence suggests the ambitious timeline is achievable.
New deadlines: more time, but zero discretion
This is the key change and it is worth understanding precisely.
The Commission proposed a flexible mechanism: Chapter III provisions (high-risk systems) would not take effect automatically, but only after the Commission issued a decision confirming that the regulatory ecosystem was ready. Following such a decision, a further 6 or 12 months would apply. If no decision was made, the provisions would come into force from specific fallback dates anyway.
Parliament rejected this mechanism. It said: no, thank you. The dates are fixed and automatic.
High-risk AI systems from Annex III (biometric identification, critical infrastructure, employment, migration, administration of justice) must comply by 2 December 2027.
Systems covered by sectoral EU law (machinery, toys, medical devices, civil aviation) must comply by 2 August 2028.
Industry gets more time. But the Commission does not get a "switch". It will not decide when provisions "turn on". Parliament obliges it to provide support tools "in a timely manner", which is an elegant way of saying "do your part before the deadlines arrive".
And interestingly, in one case Parliament accelerated the deadline. Providers of generative systems already on the market must implement watermarking (Art. 50(2)), the marking of synthetic content) by 2 November 2026. Three months earlier than the Commission wanted (which proposed February 2027).
Why the acceleration here specifically? Because transparency of AI content is a topic that cannot wait. But more on that later.
The nudifier ban: when Grok overturned the table
This is perhaps the most high-profile change in the entire Omnibus. And at the same time a story that shows why AI regulation is not an abstract legal topic, but a response to real, concrete harm.
The Commission did not propose any new prohibited AI practices. Parliament did so on its own.
New Art. 5(1)(ha) prohibits the placing on the market, putting into service, or use of AI systems that generate intimate images or videos depicting recognisable persons without their consent. So-called "nudifier apps".
Where does the ban come from? From real life. From a very specific scandal.
In December 2025, Elon Musk's xAI made image generation and editing available on platform X through Grok with the Aurora model. Safeguards were minimal.
What happened next exceeded the worst-case scenarios.
Users on X immediately began mass-submitting photos of women and children with the instruction "undress her". Grok carried out these instructions.
The numbers are shocking. According to the New York Times, within 9 days Grok generated 4.4 million images, of which 1.8 million were sexualised depictions of women. The Center for Countering Digital Hate estimated that in 11 days, 23,000 sexualised images of children were created.
23 thousand. Images. Of children. In 11 days.
What was happening inside xAI
To understand how this happened, one needs to look at what was going on inside the company.
According to The Verge, an anonymous employee who left xAI stated plainly: "Safety is a dead organization at xAI". The source indicated that the shift of Grok towards NSFW content was partly due to the safety team being let go. Only basic CSAM filters remained.
The same employee added: "He [Musk] is actively trying to make the model more unhinged, because for him safety equals censorship".
Musk himself joined the "undress" trend, posting on X his own image generated by Grok. This was not an accident. It was a signal.
And the exodus from the company? As of 29 March 2026, all 11 original co-founders of xAI (apart from Musk) have left the company. In February 2026 alone, within a few days, co-founders Yuhuai "Tony" Wu and Jimmy Ba departed, followed by more than 11 engineers and key staff. According to Bloomberg, Musk carried out a restructuring and is "rebuilding the company from the ground up". But on the organisational chart he published himself, there was no trace of a safety team.
The world's reaction
The situation escalated rapidly:
- January 2026: Indonesia and Malaysia blocked Grok following repeated safeguard failures
- January 2026: The European Commission launched an investigation into xAI under the Digital Services Act (DSA)
- January 2026: The California Attorney General opened an investigation
- January 2026: xAI introduced restrictions on generating sexualised images, but Dutch organisation Offlimits demonstrated they could be easily circumvented
- United Kingdom: Ofcom and the Information Commissioner's Office (ICO) launched independent investigations
- 26 March 2026: A court in Amsterdam ordered xAI to cease generating nude images. Penalty: EUR 100,000 per day for each day of non-compliance, up to a maximum of EUR 10 million. xAI must also pay EUR 2.2 million in legal costs to the organisation Offlimits. According to CNBC and Reuters, this is a precedent-setting ruling in Europe.
- Baltimore became the first city in the US to sue xAI for violating local consumer protection regulations
- Three teenagers from Tennessee sued xAI for generating their likenesses in sexualised poses
All of this happened within three months.
What the ban looks like
The ban under Art. 5(1)(ha) is not absolute. There are exceptions:
- Providers with safeguards - if a company has implemented effective technical measures preventing the generation of such content, it is excluded from the ban
- Research and development - research into the technology itself is permitted
The ban targets the intentional or negligent provision of the tool, not the technological capability itself. In other words: you can have a model that is theoretically capable of doing this, but you must secure it so that it does not.
Both the Council and Parliament introduced this ban, which suggests it will survive the trilogue. The Council additionally extended it to material depicting the sexual exploitation of children.
What else did Parliament change? A lot.
A narrower definition of high-risk systems
This change may not sound newsworthy, but for companies building products with AI, it is significant.
Previously, any AI system that was a "safety component" of a product covered by sectoral legislation automatically fell into the high-risk category. Now it must be indispensable for ensuring the product's compliance with safety requirements.
The difference is fundamental. A voice assistant in a coffee machine? Not indispensable for safety. Performance optimisation in a smartwatch? Neither. AI controlling packaging aesthetics? Even less so.
These systems fall outside the high-risk regime. This is a meaningful slimming-down that excludes a considerable amount of AI embedded in IoT devices and consumer products from the most demanding requirements.
12 new articles organising sectoral law
Parliament went further than the Commission in organising the relationship between the AI Act and sectoral product legislation.
It removed the entire Section A of Annex I and introduced 12 new articles (110a to 110l). Each amends a different piece of legislation: the Machinery Regulation, the Toy Safety Directive, the Medical Devices Regulation, and others.
The mechanism is twofold:
- AI Act requirements are treated as "essential health and safety requirements" within the meaning of sectoral law
- The Commission cannot, when adopting sectoral specifications, go beyond what the AI Act provides
One set of requirements, one compliance pathway. No more double reporting. For companies building products with an AI component, this is genuine relief.
GPAI model providers under scrutiny
The Commission did not touch Art. 25 of the AI Act. Parliament expanded it to cover providers of general-purpose AI (GPAI) models whose models are integrated into high-risk systems.
What does this mean in practice? If you are building a high-risk system on GPT, Claude, Gemini, or any other foundation model, the provider of that model must now:
- Provide you with technical documentation
- Disclose known limitations and failure modes of the model
- Provide technical access for testing purposes
Violation of these obligations is subject to penalties under the general rules. Parliament closed the loophole where a foundation model provider could wash its hands of what was built on top of its model. A sound change, given how rapidly GPAI models are entering critical applications in medicine, recruitment, and the justice system.
The AI Office loses exclusivity
The Commission wanted to give the AI Office exclusive supervisory competence over systems based on GPAI (where the model and system come from the same provider) and over systems in very large online platforms and search engines (DSA).
Parliament removed the word "exclusive". National authorities may act if the Commission has not initiated proceedings. AI systems in critical infrastructure were excluded from the AI Office's competence and remain under the supervision of sectoral regulators.
The model shifted from centralisation to shared competence, with a national backstop.
On a related note, two important points:
- Parliament mandated that the AI Office coordinate with data protection authorities and the EDPB
- Parliament added a requirement for "adequate human, financial, and technical resources" for the AI Office. Not without reason: according to MLex, the AI Office was planning to hire just 53 additional staff. For an office that is supposed to oversee the entire AI ecosystem in the EU, that is not an impressive number.
Sensitive data: stricter than the Commission wanted
The Commission proposed a broad, horizontal legal basis for processing sensitive data (race, health, sexual orientation) for the purpose of detecting AI bias. For all AI systems and models. The standard: "necessary".
Parliament and the Council jointly narrowed this:
- The standard "necessary" was replaced with "strictly necessary"
- The scope was limited to high-risk systems
- Extension to other systems is possible only where bias threatens health, safety, or leads to prohibited discrimination
- The provision does not create an obligation to conduct debiasing
This change is consistent with Joint Opinion 1/2026 issued by the EDPB and EDPS, which expressed concerns about overly broad access to sensitive data under the pretext of fixing bias.
AI literacy: Parliament held firm
The Commission and the Council attempted to soften the AI literacy obligation (Art. 4) from a binding requirement on providers and deployers to "encouragement" from Member States and the Commission.
Parliament reinstated the obligation as binding, but lowered the standard from "ensuring a sufficient level" to "supporting the improvement of AI literacy". It also added a requirement for the Commission to issue practical implementation guidelines and encouraged public-private partnerships.
A compromise? Yes. But the direction is clear: companies building and deploying AI must invest in educating their teams.
Penalties: not the same for everyone
Article 99 of the AI Act provides for three tiers of penalties:
| Violation | Penalty |
|---|---|
| Prohibited AI practices (Art. 5) | Up to EUR 35 million or 7% of global turnover |
| Violation of other provisions | Up to EUR 15 million or 3% of global turnover |
| Providing false information | Up to EUR 7.5 million or 1% of global turnover |
The Omnibus extended preferential penalty rules to small mid-cap companies (fewer than 750 employees and under EUR 150 million in turnover). But with an important caveat: providers of GPAI models with systemic risk do not benefit from reduced penalty caps, even if they are formally a small company. A startup developing a frontier-class model will not get preferential treatment.
Logical. A large model means large risk, regardless of office size.
Watermarking and Art. 50: this is not just "adding a label"
This topic deserves separate treatment, because many companies still think of watermarking as "adding the words AI generated". Nothing could be further from the truth.
Article 50 of the AI Act establishes a two-layer transparency model:
Layer 1: Provider (of the generative system)
If your system generates audio, images, video, or text, you must:
- Machine-readable labelling - metadata embedded in the file at the moment of generation, digitally signed. Reference standard: C2PA (Coalition for Content Provenance and Authenticity). Required fields: provider name, the fact that AI was used, timestamp, unique content identifier.
- Invisible watermark - "woven" into the content, resistant to manipulation (cropping, compression, re-uploading to platforms)
- Fingerprinting/logging - as a fallback. Hashing for images, logging for text.
- Provenance certificate - for content where embedding is difficult, proof of origin
- Detector / verification API - you must provide an interface through which third parties can verify whether a given piece of content was generated by your system. This is not optional.
- Protection against removal - technology and terms of service must prohibit the removal of watermarks. Loss of metadata during file conversion may also constitute a violation.
As the European Commission states in the description of the Code of Practice, "no single marking technique is sufficient" to meet the requirements of Art. 50. Multiple techniques must be applied simultaneously.
Layer 2: Deployer (the entity using the AI system)
If you use a generative system (e.g. you integrate GPT into your product), you must:
- Label AI-generated content with a visible tag for users
- Disclose deepfakes (images, audio, video resembling existing persons)
- Disclose AI-generated texts on matters of public interest (unless they have undergone editorial review)
- Apply a common taxonomy (currently being standardised at EU level): "Fully AI-generated" vs "AI-assisted"
Deadline
For systems already on the market: 2 November 2026 (accelerated by Parliament from February 2027).
Penalties for violating Art. 50: up to EUR 15 million or 3% of global turnover.
The Code of Practice is being developed by independent experts appointed by the AI Office. The first draft was published on 17 December 2025, the second in March 2026, with finalisation expected in June 2026.
Regulatory sandboxes: with data protection authority involvement
A regulatory sandbox at EU level, run by the AI Office, is a Commission proposal that Parliament accepted. But it added a condition: when the sandbox involves the processing of personal data, the participation of national data protection authorities and the EDPB is mandatory.
It also provided for priority access to sandboxes for SMEs and startups. A good direction, if it is actually implemented.
What the Omnibus does NOT change
It is worth stating this plainly, because it is easy to get lost in the noise:
- The catalogue of prohibited AI practices (Art. 5) - unchanged, apart from the addition of nudifiers
- Substantive requirements for high-risk systems (Art. 8-15) - untouched. Technical documentation, risk management, data governance, accuracy, robustness, cybersecurity - everything stands
- Substantive obligations of GPAI model providers (Art. 53 - general, Art. 55 - systemic risk) - unchanged
- Supervisory mechanisms over codes of practice (Art. 56) and synthetic content labelling requirements (Art. 50) were amended, but these are procedural matters
The Omnibus changes deadlines, procedures, the supervisory architecture, and the relationship with sectoral law. It does not change the substance of what is required of companies. This is not a relaxation of requirements. It is a postponement of their enforcement.
What happens next: trilogue and the race against time
The calendar looks as follows:
- 13 March 2026 - Council adopted its negotiating mandate
- 26 March 2026 - Parliament adopted its position (569 in favour, 45 against)
- April 2026 - Trilogue (three-way negotiations: Parliament, Council, Commission)
- Target: 28 April or May 2026 - Agreement (ambitious, but the Cypriot Presidency is pushing)
- Before 2 August 2026 - Formal adoption (otherwise the original deadlines take effect)
If the Omnibus is not adopted in time, companies will face the original timeline: requirements for high-risk systems from August 2026. Without ready standards, without guidelines, without certifiers.
As Global Policy Watch writes, the broad convergence of Council and Parliament positions (both institutions rejected many of the Commission's simplifications) suggests that an agreement is realistic. But nothing is settled until the signature is in place.
What I think about this
As someone who works with AI models every day and builds a product on top of them, I see several things here.
The deferral was inevitable. Enacting ambitious regulation without verifying whether anyone is capable of implementing it is a classic European problem. The European Commission missed its own deadline for guidelines. CEN-CENELEC pushed back its deadline three times. Member States did not designate authorities. And then everyone is surprised that companies are not ready? Good intentions, poor execution.
It is good that Parliament is giving industry time. But at the same time, it is holding the Commission to its word, because the dates are fixed. No one can say "not yet".
The nudifier ban is a response to a real threat. 23,000 sexualised images of children in 11 days. This is not a hypothetical problem. It happened. The xAI safety team was dismantled, all co-founders left, and the company's CEO personally participated in the "undress" trend. It is good that the EU responded. And it is good that both the Council and Parliament are aligned on this.
For us, the builders, the direction is what matters. The AI Act is not letting up. The substantive requirements stand. Art. 8-15 were not touched. Those who begin adapting now will be in a better position. Those who count on "it will sort itself out" may be in for a surprise when the December 2027 deadlines take automatic effect.
Watermarking is a genuine technical challenge. It is not "adding a caption". It involves metadata, watermarks, fingerprinting, verification APIs, protection against removal. C2PA as the reference standard. Deadline: November 2026. If you are building a generative system, you need to start now.
And most importantly: Europe is regulating faster than it can implement. And then it has to walk it back under the pressure of its own deadlines. The Digital Omnibus, despite its name suggesting simplification, is in essence an admission that the original act was not sufficiently thought through.
This time it is not the tech industry that cannot keep up with regulation. It is the regulation that cannot keep up with itself.
Key dates to remember
| Deadline | What happens |
|---|---|
| 2 August 2025 | Obligations for GPAI model providers (already in force) |
| 2 November 2026 | Watermarking - labelling of AI-generated content (Art. 50(2)) |
| 2 December 2027 | High-risk systems from Annex III (biometrics, critical infrastructure, migration) |
| 2 August 2028 | AI systems covered by sectoral EU law (machinery, toys, medical devices) |
| 2 August 2030 | AI systems in large-scale public sector IT systems |
Sources (18 items)
- Zbigniew Okon, "Digital Omnibus on AI: nowelizacja AI Act w PE", cyberprawo.org, 27.03.2026
- "Artificial Intelligence Act: delayed application, ban on nudifier apps", European Parliament, 26.03.2026
- "Elon Musk's Grok ordered to stop creating AI nudes by a Dutch court", CNBC, 27.03.2026
- "MEPs Adopt Joint Position on Proposed Digital Omnibus on AI", Global Policy Watch, 26.03.2026
- "What's behind the mass exodus at xAI?", The Verge, 13.02.2026
- "European Commission misses deadline for AI Act guidance on high-risk systems", IAPP, 03.02.2026
- "EU AI simplification package reaches critical milestone", Pinsent Masons, 26.03.2026
- "EU Parliament and Council in favour of new deadlines and bans on AI regulation", RSM Ebner Stolz, 24.03.2026
- "Dutch court rules against Grok over AI-generated images", Reuters, 26.03.2026
- Article 50 - Transparency obligations, EU AI Act
- Article 99 - Penalties, EU AI Act
- Code of Practice on marking and labelling of AI-generated content, European Commission
- "EU Digital Omnibus on AI update", Addleshaw Goddard, 27.03.2026
- "On the AI Act, the EU Need Not Move Fast and Break Things", Progress Chamber
- "The EU Parliament Plenary adopts text to amend the Digital Omnibus on AI", MediaLaws, 26.03.2026
- "Dutch court bans xAI's Grok from generating nonconsensual nude images", Al Jazeera, 26.03.2026
- "xAI MAJOR SHAKEUP: Entire Founding Team Now Gone", post on X, 29.03.2026
- "Elon Musk Restructures xAI's Teams After Co-Founders Exit", Bloomberg, 11.02.2026
