The European Union has changed the practical compliance calendar for the AI Act. The update does two things that should be read together: it creates a new prohibition on AI-generated or manipulated non-consensual intimate content, and it delays when most high-risk AI obligations will apply.
For companies building or deploying AI in Europe, this is not a retreat from regulation. It is a reprioritization. Rules on harmful intimate-image generation are moving quickly, while the most operationally complex high-risk obligations get more time.
A new prohibition targets AI-enabled intimate-image abuse
The updated law prohibits AI practices involving non-consensual sexual or intimate content, including systems that generate nude images of real people or alter existing images to reveal intimate parts. The Council of the European Union says the prohibition is set to apply in December 2026.
That gives providers, platforms, and deployers a clear near-term product question: can their systems create, edit, distribute, or facilitate this category of synthetic content? The answer cannot live only in a policy document. It needs to show up in model safeguards, reporting paths, moderation operations, vendor controls, and incident response.
Most high-risk AI obligations have moved later
The revised dates distinguish between two types of high-risk AI systems. Obligations for stand-alone high-risk systems, including many systems listed in Annex III, move to 2 December 2027. Obligations for high-risk AI embedded in regulated products move to 2 August 2028.
The change reflects implementation realities, including delayed standards, guidance, and national enforcement capacity. It also means that teams should not treat the delay as permission to pause. The extra time is best used to build an inventory of AI systems, document risk ownership, map data flows, and test governance processes before deadlines become urgent.
Transparency remains a nearer-term operational task
The new regulation shortens the adjustment period for certain transparency solutions for artificially generated content. The relevant deadline is 2 December 2026. Separately, the European Commission has recognized a voluntary Code of Practice on Transparency of AI-generated Content as a tool that can help providers and deployers demonstrate how they meet relevant obligations.
Voluntary does not mean irrelevant. The code can offer a useful operating reference for content marking, disclosure design, and documentation. But joining or following it is not conclusive proof of compliance, so organizations still need to understand the legal obligations that apply to their own products and use cases.
What leaders should do now
Start with a two-track plan. First, identify any product feature, model capability, or third-party service that could enable non-consensual intimate-image generation or manipulation. Put clear controls, escalation routes, and evidence retention around it before December.
Second, use the extended high-risk timeline to make compliance repeatable rather than rushed. Assign accountable owners, maintain a system register, define evaluation and monitoring routines, and include AI vendors in procurement and risk reviews. The organizations that use this time to operationalize governance will have more flexibility than those that simply move the deadline on a calendar.
The strategic takeaway
Europe’s AI rulebook is becoming more selective about urgency. It is accelerating action where the harm is direct and recognizable, while allowing more runway for complex high-risk system requirements. For AI teams, the lesson is straightforward: prioritize product safeguards around intimate-image abuse now, and use the additional high-risk runway to build governance that can survive scrutiny later.