top of page
Search

EU Gives Final Green Light to AI Act Simplification — the Harder Data-Protection Fight Comes Next

  • Jul 7
  • 3 min read

The Council of the EU has given its final approval to a regulation that simplifies and streamlines parts of the AI Act, clearing the last hurdle for the first piece of the bloc's "Digital Omnibus" to become law. The vote follows the European Parliament's endorsement on 16 June and the provisional deal struck between the co-legislators on 7 May. The act will be published in the Official Journal in the coming days and enters into force on the third day after publication.

The regulation is part of the EU's wider simplification agenda, which aims to cut administrative burdens by at least 25% for all companies — and 35% for SMEs — by 2029. For the AI Act specifically, it functions as a set of targeted "quick fixes" rather than a rewrite: the goal is to reduce compliance friction and buy industry more time, while keeping the risk-based architecture intact.

The most concrete change is on timing. The most demanding obligations for high-risk AI systems are being pushed back to fixed dates: 2 December 2027 for stand-alone high-risk systems listed in Annex III (biometrics, critical infrastructure, education, employment, law enforcement, migration and border control), and 2 August 2028 for high-risk AI embedded in regulated products. In practice, this gives providers and deployers a longer, clearer runway before the full weight of the rules applies — a response to industry complaints that standards, guidance and support tools were not ready in time.

Notably, the package is not only about loosening rules. It also tightens them where it counts: the regulation adds explicit prohibitions on AI-generated or manipulated sexual deepfakes and on AI-generated child sexual abuse material. The message from co-legislators is that streamlining compliance should not come at the expense of fundamental rights and protections against the most harmful uses of the technology.


Simpler, yes — but "challenges and uncertainties" remain

The green light closes one chapter and opens a more contested one. The AI-focused text adopted this week is only half of the Digital Omnibus that the Commission tabled on 19 November 2025. The other half reaches deep into the EU's data rulebook — the GDPR, the ePrivacy Directive and the Data Act — and that part has not yet reached political agreement. This is where the reform gets genuinely difficult.

Two proposed changes have drawn the sharpest criticism. The first is a narrowing of the definition of "personal data," which would tie identifiability more closely to what an individual controller claims it can do with the information. Critics warn this could pull large swathes of data outside the GDPR's protection depending on who is holding it. The second is a broadened use of "legitimate interest" as a legal basis for training AI on personal data — a route that current law keeps tightly constrained for large-scale processing.

The pushback has been unusually direct. In a joint opinion, the European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) backed the simplification and competitiveness goals but urged co-legislators not to adopt the narrower personal-data definition, calling it premature and potentially harmful, and flagged that the new legitimate-interest provision for AI training lacks adequate safeguards. National data protection authorities have rejected many of the proposed GDPR changes outright, and civil-society groups argue the package would weaken hard-won protections and make it easier for large platforms to harvest data for AI.


Why it matters for responsible AI

For anyone tracking sustainable and rights-respecting AI governance, this week's vote is a useful signal of where Europe is heading: pragmatic on process, and increasingly willing to trade regulatory speed for competitiveness — but not (yet) willing to dismantle the AI Act's core safeguards, as the new deepfake and CSAM bans show. The real test is the data reform still on the table. If the final GDPR text follows the Commission's original direction, the balance between innovation and fundamental rights could shift more decisively than the AI Act changes alone suggest.

For now, organisations should treat the new high-risk deadlines as firm planning dates — not as a reason to slow down governance work — and watch the data-side negotiations closely, because that is where the next, and larger, fight over Europe's digital rulebook will be decided.

 
 
 

Comments


bottom of page