by DPEX Editorial Team
What began as a theoretical blueprint for technology oversight has been forced into a frantic, late-stage overhaul to regulate General-Purpose AI (GPAI), and as of August 2026, the grace periods are officially expiring. The core transparency rules under the EU AI Act Article 50 are now fully active, making it a legal requirement to explicitly disclose chatbots and deepfakes.
Yet, just as organisations scrambled to meet these deadlines, a major legislative intervention completely rewrote the compliance roadmap. The European Commission, the Council, and the European Parliament aligned on the view that Europe’s red tape and overlapping laws may stifle innovation, cause the region to lag behind other fast-moving global tech hubs, and thus accelerate economic decline.
The Genesis of the AI Omnibus
The official EU Artificial Intelligence Act Regulation came into force on 1 August 2024 as the world's first comprehensive, legally binding framework built on a strict, risk-based approach. Under this structure, AI applications are grouped into four explicit risk tiers—unacceptable risk, high risk, limited risk, and minimal risk—with each level subject to varying degrees of requirements designed to guarantee human safety and fundamental rights.
Much like the GDPR, the EU AI Act features intense extraterritorial reach: if an organisation develops an AI model, exports an AI-driven service, or deploys an AI system whose outputs are used within the EU, they are legally bound by these rules. Initially, lawmakers set very aggressive deadlines for compliance. However, as those deadlines grew closer, governments and industry experts realised that society was structurally unready for enforcement.
On 27 July 2026, the Digital Omnibus on AI entered into force after a rushed 7-month timeline. This move delayed key provisions, for example, extending deadlines for High-Risk AI systems - such as AI used in international recruitment, educational grading, and credit scoring - until 2 December 2027. Similarly, AI embedded as safety components in heavily regulated physical products—like medical devices, aviation software, and industrial machinery destined for European markets—has been pushed back to 2 August 2028.
By removing duplicative paperwork between the AI Act and existing sectoral safety laws, the Omnibus has given governance professionals breathing room to coordinate their cross-border risk frameworks. However, this fast-tracked deregulation has drawn fierce criticism. Tech watchdogs have condemned the Omnibus as a huge step backwards for a more accountable tech environment in Europe, while regional policy experts warn that its rushed, last-minute amendments create vast legal loopholes and heighten uncertainty rather than reducing complexity.
Amid the delays, two deadlines still apply on the calendar. The first is 2 August 2026, already in effect, when the majority of the Act's rules came into force, including enforcement of the Article 50 transparency obligations discussed above. The second is 2 December 2026, when the new prohibitions on non-consensual sexual deepfakes and CSAM-generating systems take hold, alongside a transitional deadline for providers of synthetic-content systems already on the market before August 2026 to fall in line with Article 50(2). Unlike the Annex III and Annex I high-risk deadlines pushed back to December 2027 and August 2028 respectively, these two milestones were left untouched by the Omnibus. Particularly, the ban on nudifiers later this year stands out and is worth examining more closely.
Accelerating the Ban on Nudifiers
While some high-risk deadlines were delayed, human rights protections were fast-tracked through an ironclad prohibition on “nudifier” applications and services. This targets generative AI systems designed to manipulate existing imagery to create malicious, non-consensual sexually explicit content, deepfake pornography, or child sexual abuse material.
While lawmakers celebrated this as a massive milestone for civil protections, an enforcement gap exists, as many national authorities currently lack the legal authority and technical infrastructure necessary to enforce this prohibition effectively across the open web. To bridge this gap, the law shifts the weight onto the technology itself, forcing AI system providers to implement proactive engineering safeguards, including data cleaning, model refusal training, protected prompt designs, content filtering, usage restrictions, abuse detection systems, and mechanisms for notice and action. The burden of proof should legally rest on the creator or sharer of the images to demonstrate explicit consent, rather than forcing traumatised victims to jump through corporate hurdles to prove they did not authorise the content after it has already gone viral.
What This Means for Governance Professionals in Asia
Governance professionals in Asia who think the EU AI Act is a "European issue" face a dangerous compliance blind spot. Organisations that develop AI models, sell AI-driven services into the EU, or use AI outputs that touch EU markets are still bound by the Act's extraterritorial reach.
For organisations already building on Singapore's Model AI Governance Framework, or preparing PDPA-aligned AI risk assessments, the underlying governance work does not need a restart. Documentation habits, risk-tiering, and human oversight requirements carry over reasonably well to the Act’s disclosure duties and upcoming high-risk obligations.
However, organisations that develop AI models for the EU, sell AI-driven services into the EU, or use AI outputs that touch EU markets are bound by the Act's extraterritorial reach, and two deadlines demand action now. First, confirm that any customer-facing AI system reachable by EU users such as chatbots, image generators, and content tools alike, already disclose their AI nature. Second, revisit vendor contracts for any image or video manipulation tools used in your organisation. The Omnibus’ new prohibitions shift the burden onto providers to show that safeguards are built in, thus responsibility is on its owner to ensure its compliance.
While the Omnibus offers a temporary reprieve for certain high-risk systems, the underlying shift toward accountability is already here. Organisations that take a measured approach now and adapt their existing frameworks to meet these European standards will find themselves well-prepared as these rules increasingly shape the global AI governance landscape.
If you are managing data privacy and compliance within the European regulatory landscape, explore our IAPP CIPP/EU course to gain specialised expertise needed to lead data privacy efforts in one of the world's constantly changing regulatory environments.
Sources: EU Artificial Intelligence Act, Digital Omnibus - European Commission, High Risk AI Systems - European Commission, Ban on Nudifiers - EU AI Act