AI Act: EU protects what really concerns you (and delays the rest)
On March 26, 2026, the European Parliament voted to delay the enforcement of the AI Act’s toughest rules. Headlines screamed “retreat.” The reality is more nuanced, and a bit more interesting.
What’s Happening
On March 26, 2026, the European Parliament adopted the “Digital Omnibus on AI” in first reading, amending the AI Act passed in 2024, with 569 votes in favor, 45 against, and 23 abstentions. The text is now in trilogue with the Council, with no set date for final adoption.
Two major delays were agreed upon. Rules governing high-risk AI systems listed in Annex III (biometrics, public space surveillance, recruitment, student assessment, access to essential services, judicial decisions, border management) have been pushed back to December 2, 2027 (from the initially planned August 2, 2026). Systems integrated into regulated sectoral products in Annex II (medical devices, radio equipment, toys) have until August 2, 2028.
In exchange, two obligations have been maintained or accelerated. Watermarking of AI-generated content (images, audio, video, deepfakes) comes into effect on November 2, 2026. The ban on “nudifiers” (AI systems producing realistic sexual images of people without their consent) is effective immediately, unless the system integrates proven effective protections.
Sources: European Parliament press release, March 26, 2026 · Adopted text TA-10-2026-0098
Why This Matters for You
The delay of high-risk rules made waves. Here’s some context.
These rules weren’t targeting end-users. They were targeting businesses deploying AI systems in high-stakes contexts: employers using AI to sort CVs, courts relying on recidivism prediction tools, administrations filtering student aid applications.
These organizations had to (and will still have to) document their systems, manage risks, ensure human oversight. The delay pushes the deadline back by 16 months to allow time for harmonized standards to be published. Those technical standards aren’t ready yet, and enforcing an obligation without available compliance tools is regulatory honesty.
What really changes for you is AI watermarking. From November 2026, all AI-generated or significantly manipulated content must bear a detectable trace: an invisible digital watermark and, in some cases, explicit labeling. You’ll start seeing “generated by AI” labels on images, standardized metadata on videos. It’s not foolproof (a watermark can be removed), but it sets a norm and legal responsibility for platforms distributing unmarked content.
The ban on nudifiers is immediate and clear-cut. It’s one of the few rules directly protecting an individual against malicious AI use. Banning it doesn’t solve the technical issue (tools exist and some are open-source), but it creates a legal basis for pursuing platforms hosting or offering these services.
The nuance to note: the AI Act isn’t dead, it’s refocused. The EU has made a clear choice: speeding up what protects individuals (watermarking, nudifiers), delaying what constrains businesses (high-risk B2B). Your iPhone and Mac aren’t directly affected by Annex III rules.
What This Means in Practice
From November 2026: platforms distributing AI-generated content (synthetic images, cloned voices, deepfake videos) must mark them. You’ll start seeing badges or metadata on images you encounter on social media. The display isn’t standardized yet, but the C2PA (Coalition for Content Provenance and Authenticity) norm, already adopted by Apple, Adobe, Microsoft, and others, will likely be the vector. On a Mac, you can verify this in image files’ EXIF metadata.
Effective immediately: services offering “nudifiers” (generators of realistic sexual images of real people without consent) fall under the ban. If you come across such tools online, hosted in the EU, they’re operating illegally. The AI Act’s extraterritorial reach applies when services are offered to European users.
What hasn’t changed yet: AI systems used in HR, justice, or education remain under the AI Act’s existing rules until their delayed dates. No direct impact on your Mac workflow yet.
To understand how the EU thinks about digital governance and why regulatory ambitions keep running into technical realities, consider this parallel to Chat Control: The EU wants to scan all your private messages. Again, regulatory ambition bumps up against realities that transcend technical standards. This time, it’s fundamental rights.
Sources
- European Parliament · Press release, March 26, 2026: “Artificial Intelligence Act: delayed application, ban on nudifier apps”
- EP adopted text · TA-10-2026-0098 (March 26, 2026)