SYSTEM NOTICE

Auto translation by AI. Be sure, accuracy, nuances and authorial intent may not be fully reflected.
見出し画像

EU AI Act Digital Omnibus Final Compromise Proposal / Determination of Application Dates and Practical Adjustments: Observations



I. Course Correction for the Implementation of the European AI Act

Regarding the AI Act enacted in the European Union, a legislative amendment process is already underway to resolve practical issues at the time of enforcement. On March 16, 2026, the joint committee of the European Parliament's Committee on the Internal Market and Consumer Protection (IMCO) and the Committee on Civil Liberties, Justice and Home Affairs (LIBE) published the final compromise amendment proposal regarding the 'Digital Omnibus' regulation, which aims to simplify the application of the AI Act (Regulation (EU) 2024/1689) [Note 1]. The co-rapporteurs are MEP Arba Kokalari (EPP) and MEP Michael McNamara (Renew), and the proposal is expected to move to trilogue negotiations with the Council following its adoption at the plenary session on March 26.
In the process of translating the philosophy of the law into the actual industrial structure, compliance burdens on businesses and overlaps with existing laws inevitably arise. The background to this compromise proposal includes the fact that delays in the formulation of harmonized standards regarding the obligations of Chapter III concerning high-risk AI systems, delays in the establishment of national competent authorities, and delays in the development of conformity assessment frameworks have overlapped, resulting in practical burdens exceeding initial expectations [Note 2]. The presented compromise amendments are organized below as specific adjustments to prevent delays in law enforcement while trimming excessive practical burdens.

II. Key Issues Regarding High-Risk AI Regulations

1. Determination of Application Deadlines

A clear deadline has been set for the application date of requirements for high-risk AI systems, which was the greatest concern for businesses. Through the amendment of Article 113 by CA 2, the fluid mechanism for determining the application date, which depended on the status of the European Commission's development of compliance support measures, has been abolished, and a definitive deadline has been introduced [Note 3].
The framework of the design is as follows: If the European Commission adopts a decision confirming the availability of measures to support compliance with Chapter III, the respective obligations will apply 6 months after that decision for systems based on Annex III (biometric identification, etc.), and 12 months after for systems based on Annex I (machinery, medical devices, etc.). However, even if the Commission's decision is delayed or not issued, an upper limit is clearly stated, with application starting on December 2, 2027, for the former, and August 2, 2028, for the latter.
The design of 'conditional application start,' which incorporates technical conditions such as standard development as requirements for the emergence of legal obligations, can simultaneously serve a disciplinary function that encourages the Commission to develop standards and guidance. While it is true that the general application date of August 2, 2026, originally set by the AI Act, has receded for high-risk AI regulations, it differs in nature from simple deregulation in that it specifies an upper limit rather than an indefinite postponement.

2. Elimination of Overlap with Product Safety Regulations

For product AI subject to existing sectoral product safety regulations, such as machinery and medical devices, measures have been taken to eliminate double regulation. CA 2 deletes Section A of Annex I and transfers its scope to Section B, while also establishing a set of articles (Articles 110a to 110l) that incorporate the high-risk AI requirements of the AI Act into sectoral product safety regulations, including the Medical Device Regulation (Regulation (EU) 2017/745) and the In Vitro Diagnostic Medical Devices Regulation (Regulation (EU) 2017/746) [Note 4].
The purpose of this reorganization is an approach that allows sectoral safety regulations to function as a 'primary framework' while incorporating the high-risk AI requirements of the AI Act into the essential safety requirements of those sectoral laws. It can be said to be a design that attempts to maintain the horizontal consistency of the AI Act while suppressing situations where businesses in existing strict regulatory environments are forced to undergo double conformity assessments. While the substance of the adjustments in the process of formulating delegated legislation will be questioned, the direction is commendable.

3. Grace Period for Watermarking Obligations

Regarding the watermarking obligation under Article 50(2) of the AI Act, a 3-month transition period is provided for generative AI systems already placed on the market before August 2, 2026, and businesses are required to take compliance measures by November 2, 2026 [Note 5]. The fact that this is halved from the 6-month grace period originally proposed by the European Commission reflects the European Parliament's concern regarding the spread of synthetic content.

III. Coexistence of Regulatory Strengthening and Obligation Retreat

1. Explicit Prohibition of Non-Consensual Sexual Deepfakes

CA 2 adds a new category to the list of prohibited practices in Article 5 of the AI Act. This is the prohibition of placing on the market or using AI systems that generate or modify realistic images or videos depicting sexual activities or intimate body parts of an identifiable natural person without their consent [Note 6]. This is a direct regulation with so-called deepfake pornography in mind, demonstrating a stance of extending the regulatory net without hesitation against direct harm.
However, an exemption applies if the provider or deployer has implemented effective safety measures to continuously prevent the generation and misuse of such depictions. It is also stipulated that AI businesses are not prevented from developing such technical capabilities themselves. While the lack of clarity regarding the content and level of 'effective safety measures' may cause interpretative issues in the future, the design of the framework itself, which distinguishes between technical development capability and the prohibition of misuse, is rational.

2. Retreat of AI Literacy Obligations

CA 1 brings about a substantial transformation to Article 4 of the AI Act. The pre-amendment Article 4 had a structure that obligated providers and deployers to 'ensure a sufficient level of AI literacy' for staff, etc., but the amendment shifts the subject and nature to a form where the European Commission and Member States 'encourage' providers and deployers, and it is explicitly stated that this is not an obligation to guarantee a certain level of literacy for specific individuals [Note 7]. While the motivation to avoid compliance fatigue caused by uniform education obligations is understandable, from the perspective of staff protection, it can be described as a retreat in normative power. Whether the structure of 'encouragement' will have effectiveness will be left to the content of the guidance to be formulated in the future.

3. Processing of Sensitive Personal Data for Bias Detection

CA 2 inserts a new Article 4a, establishing a special legal basis for the processing of sensitive personal data for the purpose of bias detection and correction. While similar provisions already exist for providers of high-risk AI systems in Article 10(5) of the AI Act, this amendment extends them to providers and deployers of other AI systems and models [Note 8]. As conditions for permitting processing, multiple cumulative conditions are imposed, such as the inability to effectively perform bias detection through other data processing, the application of state-of-the-art safety measures including pseudonymization, strict access control, prohibition of provision to third parties, and deletion after correction is completed. As an approach to finding a balance between the technical reality that actual data processing is unavoidable to verify bias and the requirements of data protection, the direction is understandable.

4. Expansion of Consideration for SMEs

Burden reduction measures such as simplification of technical documentation, simplification of quality management system requirements, and special exceptions for maximum fines have been expanded to apply not only to SMEs but also to larger small and medium-sized companies (SMCs) [Note 9]. It can be said to be a consideration to prevent companies in the growth stage from losing competitiveness due to excessive regulatory costs.

IV. In Conclusion

Looking at this compromise amendment as a whole, it can be categorized as a product of policy judgment that seeks to lower the friction associated with practical implementation to a realistic level while maintaining the protected legal interests of the AI Act. While the confirmation of application deadlines and coordination with product safety legislation increase predictability for the industry, the structure is one of coexistence between strengthening and retreating—as seen in the prohibition of non-consensual sexual deepfakes, where the regulatory net is widened to address direct harm that cannot be overlooked.
I continue to monitor whether the design of 'conditional commencement of application' can be applied to other regulatory areas in the future, and how the final text will be transformed through the trilogue process.

[Note 1] European Parliament, Committee on the Internal Market and Consumer Protection / Committee on Civil Liberties, Justice and Home Affairs, Final Compromise Amendments on the Draft Report on the Proposal for a Regulation of the European Parliament and of the Council amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI), 2025/0359(COD) - CJ40/10/04577, SM/AS/ZR/TQ/ab, 16 March 2026 [hereinafter 'this compromise amendment'].
[Note 2] This compromise amendment, Recital (2).
[Note 3] This compromise amendment, Compromise Amendment 2 (CA 2), Article 113.
[Note 4] This compromise amendment, CA 2, Articles 110a–110l, Annex I.
[Note 5] This compromise amendment, CA 2, Article 111(4); Recital (20).
[Note 6] This compromise amendment, CA 2, Article 5(1)(ha).
[Note 7] This compromise amendment, Compromise Amendment 1 (CA 1), Article 4.
[Note 8] This compromise amendment, CA 2, Article 4a.
[Note 9] This compromise amendment, Compromise Amendment 5, Article 11; Compromise Amendment 6, Articles 63, 99.

(Magazine) 'Random Thoughts on AI and Law'

*Please refer to the following for the table of contents

note General Terms of Service, Article 3, Paragraph 2, First Sentence
3.2 The copyright of digital content created by the creator belongs to the creator.
P.S. This is shared for academic discussion only.

いいなと思ったら応援しよう!