Welcome to the EU AI Act Newsletter, a brief biweekly newsletter by the Future of Life Institute providing you with up-to-date developments and analyses of the EU artificial intelligence law.
MEPs support postponement of certain rules: Members of the European Parliament (MEPs) adopted a joint position on simplifying the AI Act, with 101 votes in favour, 9 against and 8 abstentions. Notably, the proposal supports postponing activation of certain high-risk AI system rules, given that key standards may not be finalised by the 2 August 2026 deadline. To ensure predictability, MEPs propose fixed application dates: 2 December 2027 for high-risk systems and 2 August 2028 for systems covered by EU sectorial safety legislation. In addition, MEPs favour shorter watermarking compliance extensions until 2 November 2026. Separately, they introduce a ban on “nudifier” systems creating or manipulating sexually explicit images resembling identifiable persons without consent, excluding systems with effective safeguards. They also back extending SME support measures to small mid-cap enterprises. Following the Parliament’s plenary vote expected on 26 March, negotiations with the Council will commence.
Council agrees its position to streamline rules: The Council has agreed its position on streamlining AI rules, treating the proposal with utmost priority. Member states broadly maintain the thrust of the Commission’s proposal whilst adding some provisions. The Council mandate prohibits AI practices generating non-consensual sexual and intimate content or child sexual abuse material. Similarly to the Parliament's position, it introduces fixed application timelines with the same dates. Importantly, the mandate reinstates provider registration obligations in the EU database for systems considered exempt from high-risk classification. It postpones AI regulatory sandbox establishment until 2 December 2027. The text also clarifies the competences of the AI Office for the supervision of AI systems based on general-purpose AI models where the model and that system are developed by the same provider. Finally, the Council mandate requires the Commission to provide guidance to assist high-risk AI system operators covered by sectoral legislation in complying with AI Act requirements whilst minimising compliance burden.
Could agents be the next stumbling block for Europe’s AI rules? Claudie Moreau and Maximilian Henning from Euractiv have highlighted that autonomous AI agents are rapidly entering mainstream adoption, raising questions about whether EU rules adequately address their capabilities. Unlike AI chatbots requiring user interaction, agents operate more autonomously, using digital tools to execute tasks. Examples include coding assistants receiving high-level instructions and “OpenClaw” agents running on scheduled intervals without user prompts. Notably, one OpenClaw agent generated headlines after apparently going rogue, attempting unauthorised contributions to open-source software and publishing attacks on project volunteers. The problem is that the AI Act, drafted before the rise of agentic AI, may not adequately address these systems’ capabilities. Greens MEP Sergey Lagodinsky asked the Commission whether agents fall under existing rules; Commissioner Henna Virkkunen suggested they likely do. Nevertheless, some officials consider dedicated rules necessary. However, a November report stated that EU capitals argued against new rules, citing “regulatory fatigue” and suggesting “soft law” approaches based on UN frameworks instead.
Enforcement of the AI Act: Tristan Marcelin from the European Parliament Research Service has published an overview showing that the Act is enforced through a hybrid model shared between Member States and the European Commission. Specifically the risk-based approach enforces AI systems at the national level with centralised support, whereas general-purpose AI (GPAI) rules are exclusively supervised by the European Commission. However, the decentralised pattern remains dominant, potentially causing uneven enforcement across the EU. Under the AI Act, Member States must designate two authorities – a notifying authority and market surveillance authority – functioning as single national contact points. Although the deadline for designation was 2 August 2025, many Member States have faced delays. To support enforcement, the AI Act established EU-level entities: 1) the AI Office enforces GPAI provisions and develops soft instruments; 2) the European AI Board coordinates national authorities and disseminates expertise; 3) the Scientific Panel of independent experts centralises AI expertise advising the AI Office and national authorities; and 4) the AI Advisory Forum comprises industry, start-ups, SMEs, civil society and academic stakeholders, providing technical expertise and contributing to regulatory tasks.
Equinet-ENNHRI statement on the Digital Omnibus: Equinet and ENNHRI, representing independent European equality and human rights authorities, have issued a joint statement expressing concern that proposed amendments to the AI Act are proceeding without adequate impact assessments and public consultation, thereby risking fundamental rights protections. They emphasise the Commission’s obligations for transparent consultation and impact assessments under the EU Treaties and Better Regulation Guidelines. Critically, they note that the AI Act only entered into force on 1 August 2024, with most obligations applying from 2 August 2026, making meaningful impact assessment premature. Such changes could undermine ongoing implementation and legal certainty. They also caution that regulatory simplifications tied to company size rather than to the risk of AI systems could have systemic implications, given SMEs and Small Mid-Caps represent the overwhelming majority of European companies. Consequently, they recommend eight specific measures: 1) preserve AI registration requirements, 2) safeguard fundamental rights authorities’ powers, 3) maintain high-risk AI system timeline, 4) preserve strict necessity and fundamental rights standards, 5) prevent weakening of AI literacy responsibilities, 6) reject GDPR personal data definition weakening, 7) preserve key information obligations, and 8) reject automated decision-making amendment.
Open letter calling to reserve the horizontal approach: Multiple organisations, including TÜV-Verband, AlgorithmWatch and ForHumanity, are warning against Digital Omnibus proposals moving high-risk products to Annex I-B, which would abandon the AI Act’s horizontal regulatory approach. They contend that this would not simplify legislation but instead increase regulatory fragmentation, legal uncertainty and long-term compliance burdens. The reason: sector-specific legislation would require developing AI safety requirements across numerous directives without guaranteed timelines, creating diverging requirements and procedures. For companies, this means increased bureaucracy, higher compliance costs and reduced legal certainty. AI deployed in safety-critical areas, such as medical diagnostics, industrial machinery and automated decision-making, requires binding, clear and uniform standards. Currently, most EU product legislation lacks specific AI requirements and existing software provisions insufficiently address key AI risks. Moreover, uniform rules strengthen Europe’s global competitiveness and supply chain integration. By contrast, fragmented sector-specific rules would slow innovation, increase complexity and burden start-ups and SMEs.

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.