Hey 👋
I’m Oliver Patel, author and creator of Enterprise AI Governance.
On 19 November 2025, the European Commission proposed targeted amendments to the EU AI Act as part of its Digital Omnibus package. On 13 March 2026, the Council of the EU (i.e., the EU member state governments) agreed its negotiating position, broadly maintaining the Commission’s proposals whilst introducing several notable changes. Finally, on 18 March, the European Parliament’s Internal Market and Civil Liberties committees adopted their joint position by 101 votes to 9, with a plenary vote expected on 26 March. Trilogue negotiations between the three institutions will follow this vote.
This article analyses the eight most consequential proposed amendments, comparing and contrasting the positions of the Commission and the Council. For each, I explain what is in the law today, what the Commission is proposing, and what the Council is proposing. I have excluded the European Parliament’s position from this analysis, as it has not yet been formally approved by MEPs via the plenary vote.
If you value my work and want to read a comprehensive guide to the EU AI Act and enterprise AI governance, sign up to secure a 25% discount for my forthcoming book, Fundamentals of AI Governance (2026).
The key AI Act changes this article analyses are:
Expanding the list of prohibited AI practices.
Timeline changes for high-risk AI system compliance.
Timeline changes for transparency-requiring AI system compliance.
Limiting registration in the EU public database for high-risk AI systems.
Softening of the AI literacy obligation.
Processing sensitive personal data for bias mitigation.
Expanding the scope of the European AI Office’s regulatory powers.
Proportionality for small mid-cap (SMC) enterprises.
Before diving in, three caveats are needed. First, this article presents the positions of two of the three co-legislating EU institutions—neither of which represents the final text. Second, the upcoming trilogue negotiations may result in significant changes. Third, and critically, the existing AI Act remains fully in force. Unless and until these amendments are formally adopted, the current obligations and timelines apply, including the 2 August 2026 applicable date for high-risk AI system compliance.
Here are the key documents this article is based on:
European Commission AI Act amendments and negotiating position (November 2025)
Council of the EU AI Act amendments and negotiating position (March 2026)
European Parliament Committee position and vote details (March 2026)
Scope: this article focuses on the eight EU AI Act changes that are most consequential for enterprises implementing AI governance. It does not cover all EU AI Act changes, nor the proposed amendments to the GDPR or other EU digital legislation.
Disclaimer: this article is not legal advice and should not be used, relied on, or interpreted as such. Always consult a qualified legal professional.
1. Expanding the list of prohibited AI practices
What is in law today?
Article 5 of the EU AI Act lists eight distinct prohibited AI practices. These provisions have been applicable since February 2025 and they carry the largest enforcement penalties under the AI Act, of up to 7% of global annual turnover for the most serious violations.
What is the European Commission’s position
The Commission did not propose amendments or additions to the prohibited AI practices outlined in Article 5.
What is the Council’s position?
The most significant amendment proposed by the Council is to add two new prohibited AI practices to Article 5 of the AI Act. Under this proposal, AI systems capable of “generating, manipulating or reproducing” non-consensual intimate imagery (and similar content) would be prohibited, as well as AI systems capable of “generating, manipulating or reproducing” CSAM. These prohibitions cover the following scenarios:
The intended purpose of the AI system is to generate, manipulate or reproduce non-consensual intimate imagery or CSAM.
It is a “reasonably foreseeable” reproducible outcome that the AI system could be used in this way, without requiring significant technical modification, due to the way the AI system has been developed and its functionality. Furthermore, the safety measures and guardrails are not effectively able to prevent this type of use.
The second point is significant, as it puts the onus on AI system providers to ensure that the safety features and guardrails they develop and configure are sufficiently robust to prevent this type of malicious and harmful use. The Council provides the following as examples of effective safety features and guardrails:
Refusal training
Data cleaning
Output controls
Content classification and filtering
Usage restrictions
Abuse detection
Notice action and corrective measures
2. Timeline changes for high-risk AI system compliance
What is in law today?
From 2 August 2026, unless there is a change in the law, providers and deployers must adhere to the obligations and requirements for high-risk AI systems. However, this applicable date only applies to high-risk AI systems listed in Annex III (e.g., education, employment, law enforcement etc.) that are placed on the market or put into service from 2 August 2026 onwards. Annex III high-risk AI systems that predate this are only subject to these EU AI Act obligations and requirements if there is a significant change in the AI system’s design or intended purpose. For high-risk AI systems that are products, or safety components of products, regulated by the EU product safety laws listed in Annex I, the applicable date is 2 August 2027.
What is the European Commission’s position
The Commission’s position is to link the availability of standards with the applicable date for high-risk AI system compliance. To do this, two options are proposed.
Scenario 1. If harmonised standards and associated support tools for high-risk AI system compliance are finalised and approved by the Commission, then the applicable compliance date should be six months after this approval (for high-risk AI systems listed in Annex III) and 12 months after this approval (for product safety-related high-risk AI systems covered by Annex I).
Scenario 2. If harmonised standards and associated support tools for high-risk AI system compliance are not finalised or approved by the Commission in a given timeframe (i.e., before the dates below), then the applicable compliance dates should be 2 December 2027 (for high-risk AI systems listed in Annex III) and 2 August 2028 (for product safety-related high-risk AI systems covered by Annex I). These effectively serve as backstop dates.
What is the Council’s position?
The Council’s position is more straightforward. Its proposal is that the applicable date for high-risk AI system compliance should be 2 December 2027 (for high-risk AI systems listed in Annex III) and 2 August 2028 (for product safety-related high-risk AI systems covered by Annex I). These dates would apply irrespective of the availability of harmonised standards and associated support tools.
3. Timeline changes for transparency-requiring AI system compliance
What is in law today?
Article 50(2) requires providers of AI systems that generate “synthetic audio, image, video, or text content” to ensure that their AI system outputs are “marked in a machine-readable format and detectable as artificially generated or manipulated”. Currently, this specific obligation applies from 2 August 2026. This compliance date applies to all AI systems, irrespective of whether they are placed on the market or put into service before or after 2 August 2026.
What is the European Commission’s position?
The Commission proposes to postpone the applicable date for this specific transparency obligation to 2 February 2027 for providers of AI systems that have been placed on the market before 2 August 2026. This proposed six-month postponement only applies to obligation stipulated in Article 50(2) and not the other transparency obligations outlined in Article 50.
What is the Council’s position?
The Council’s position is the same as the Commission’s. No changes were proposed to the Commission’s original proposal.
4. Limiting registration in the EU public database for high-risk AI systems
What is in law today?
Annex III of the EU AI Act lists eight categories of high-risk AI system, including law enforcement (#6), education and vocational training (#3), and employment, workers’ management and access to self-employment (#5).
However, AI systems listed in Annex III are not considered high-risk if it is demonstrated that they do not pose significant risk of harm to health, safety, or fundamental rights. For example, if the AI system does not materially influence decisions or is only used for a narrow procedural task, the provider is entitled to demonstrate, based on a documented assessment, that it is not a high-risk AI system. The parameters of this derogation are outlined in Article 6(3). This derogation procedure only applies to AI systems listed in Annex III.
Providers must register high-risk AI systems listed in Annex III in the EU public database for high-risk AI systems. This registration obligation also includes “exempted” AI systems that the provider has concluded are not high-risk via the derogation procedure outlined in Article 6(3).
What is European Commission’s position?
The Commission proposes to limit the scope of this registration obligation so that it no longer applies to AI systems that providers have concluded are not high-risk via the Article 6(3) derogation procedure. Simply put, where a provider has assessed and documented that an AI system used in an Annex III domain is not high-risk, the provider would not have to register that AI system in the EU public database.
What is the Council’s position?
The Council is proposing a more moderate amendment. Rather than completely removing the registration obligation for these exempted AI systems, registration would still be mandatory. However, less information would be required to be submitted as part of the registration. Annex VIII of the EU AI Act lists 9 information attributes that must be registered in relation to these exempted AI systems. The Council’s position is to remove 2 out of 9 attributes:
The summary of why the AI system is not high-risk.
The EU member states in which the AI system is placed on the market, put into service, or made available.
The purpose of this is to make the registration process more simplified and streamlined in these scenarios, whilst retaining the transparency and accountability registration provides.
5. Softening of the AI literacy obligation
What is in law today?
Article 4 of the EU AI Act obliges providers and deployers of AI systems to implement “AI literacy”. Specifically, Article 4 requires organisations to ensure that “staff and other persons dealing with the operation and use of AI systems” have a “sufficient level of AI literacy”. The AI literacy obligation has been applicable since February 2025. However, there are no enforcement penalties for non-compliance with it.
What is the European Commission’s position?
The Commission proposes to remove the obligation for providers and deployers to implement AI literacy. Rather than providers and deployers being legally obliged to ensure their staff operating and using AI systems have sufficient levels of AI literacy, the Commission and member states will be required to foster and encourage AI literacy.
What is the Council’s position?
The Council’s position is largely aligned with the Commission’s. There would no longer be a broad and widely applicable AI literacy obligation for providers and deployers of AI systems. Rather, the Commission and member states will be obliged to encourage AI literacy across the EU.
However, the Council’s proposal is to clarify, in Article 4, that providers and deployers of high-risk AI systems have specific AI literacy and training-related obligations, stipulated or implied in different parts of the EU AI Act. For example, deployers must assign human oversight (of high-risk AI systems) to individuals with the “necessary competence, training and authority”. Also, as part of the provider’s quality management framework, roles and responsibilities must be assigned to management and other staff, and these individuals must be adequately trained and competent to fulfil these responsibilities.
Nonetheless, this clarification does not introduce substantive new AI literacy or training-related obligations for organisations. It merely reinforces what is already required for high-risk AI system compliance.
6. Processing sensitive personal data for bias mitigation
What is in law today?
The GDPR stipulates that the processing of “special categories” of personal data (i.e., sensitive personal data) is prohibited, apart from in limited circumstances. Sensitive personal data includes:
Racial or ethnic origin
Political opinions
Religious or philosophical beliefs
Trade union membership
Genetic data
Biometric data for the purpose of uniquely identifying a natural person
Health data
Sex life or sexual orientation
Sensitive data can only be processed in limited circumstances, where a specific GDPR Article 9(2) exception applies. This includes, but is not limited to, where explicit consent has been obtained or where processing the data is necessary to “protect the vital interests of the data subject” where they are “physically or legally incapable of giving consent”.
Article 10(5) of the AI Act provides another way in which sensitive personal data can be processed. It stipulates that providers of high-risk AI systems can process sensitive personal data for the purpose of “ensuring bias detection and correction” in relation to their high-risk AI systems. However, it must be “strictly necessary” to use the sensitive personal data in this way, and the bias detection and correction cannot be effectively achieved by other means. These conditions create a high practical bar for providers. Furthermore, this exception is subject to additional strict conditions, such as implementing robust safeguards relating to data transfer, reuse, and deletion.
What is the European Commission’s position?
The Commission’s proposal is to broaden the scope of when organisations can process sensitive personal data for bias detection and correction. Rather than limiting this exclusively to providers of high-risk AI systems, it is expanded to providers and deployers of other AI systems and AI models, including deployers of high-risk AI systems. The rationale for this is because harmful biases could also arise from the use of AI in other contexts.
This means that sensitive personal data could be lawfully processed for bias detection and correction in a much broader range of circumstances and by a wider range of organisations. For this reason, the proposal is to move this provision from Article 10 to Article 4a of the AI Act, as it applies more broadly than to just high-risk AI systems.
Additionally, rather than this type of data processing only being permitted when it is “strictly necessary”, sensitive data could be processed when it is merely “necessary” (to ensure bias detection and correction). This subtle change lowers the bar for when organisations can use sensitive personal data in this way.
What is the Council’s position?
The Council largely agrees with broadening the scope—beyond providers of high-risk AI systems—for when sensitive personal data could be processed for bias detection and correction. This means that providers and deployers of other AI systems, including deployers of high-risk AI systems, would be permitted to process sensitive personal data for this bias detection and correction. However, the Council’s proposed changes are more limited than the Commission’s, in two important ways:
Processing sensitive personal data would still have to be “strictly necessary” for ensuring bias detection and correction.
Providers and deployers of other AI systems and deployers of high-risk AI systems would only be permitted to do so to address specific types of biases impacting health, safety, fundamental rights, or discrimination.
Therefore, although a wider range of organisations could process sensitive personal data for bias detection and correction in a broader range of circumstances than what the AI Act currently allows for, it would nonetheless be more limited than what the Commission is proposing.
7. Expanding the scope of the European AI Office’s regulatory powers
What is in law today?
The AI Act enforcement architecture for AI systems is decentralised.
The AI Office, which is part of the European Commission, is responsible for overseeing and enforcing the provisions on general-purpose AI (GPAI) models. At the member state level, the national market surveillance authorities (there are typically several per member state) are responsible for overseeing and enforcing the provisions on AI systems (e.g., high-risk and transparency-requiring AI systems), as well as most other AI Act provisions.
Article 75(1) provides the AI Office with powers to monitor and supervise AI systems based on GPAI models. This applies when the AI model and AI system are developed by the same provider. However, this is not an exclusive power. National market surveillance authorities can also oversee and enforce applicable provisions relating to these AI systems. This creates potential situations of overlapping competence and providers being regulated by multiple regulators simultaneously.
What is the European Commission’s position?
The Commission proposes to “centralise oversight over a large number of AI systems built on general-purpose AI models” when the same provider develops both the GPAI model and the AI system.
The proposed amendments to Article 75 would render the AI Office as the sole body responsible for monitoring and supervising compliance of AI systems that leverage GPAI models. However, this would only apply when the GPAI model and the AI system are developed and placed on the market or put into service by the same provider. In such scenarios, the AI Office would be “exclusively competent”, which means that the market surveillance authorities in the respective EU member states would no longer have a supervisory role. The AI Office would also have “all the powers of a market surveillance authority”. In a nutshell, the key change to Article 75 is the shift from shared to exclusive competence.
This change primarily affects high-risk AI systems listed in Annex III and transparency-requiring AI systems regulated by Article 50 (where such AI systems leverage general-purpose AI models). It does not apply to high-risk AI systems covered by an EU product safety law listed in Annex I.
What is the Council’s position?
Whilst the Council broadly aligns with the Commission’s proposals, it has introduced specific exceptions to this expansion in scope of the AI Office’s regulatory powers.
Under the Council’s proposal, the AI Office would be “exclusively competent” for the supervision and enforcement of AI Act provisions for AI systems based on GPAI models where the AI model and AI system are developed by the same provider— which includes different entities in the same corporate group (a subtle change to the Commission’s position). However, the exceptions to this AI Office exclusive competence are:
Product safety-related high-risk AI systems covered by Annex I.
AI systems used for critical infrastructure management and operation (Annex III, point 2).
AI systems provided by law enforcement authorities and border management authorities.
AI systems provided by certain financial institutions.
AI systems used for the administration of justice and democratic processes (Annex III, point 8).
This proposal means that, for the above exceptions, the AI Office would not have exclusive competence. The Council is signalling that these areas (i.e., critical infrastructure, law enforcement, border management, financial services etc.) should be the domain of member state regulators, not the European Commission.
8. Proportionality for small mid-cap (SMC) enterprises
The AI Act provides an element of flexibility and proportionality for micro, small, and medium-size enterprises (SMEs), including start-ups. For example, the compliance penalties which SMEs can face are capped as follows:
35 million EUR or 7% of total worldwide annual turnover (whichever is lower).
15 million EUR or 3% of total worldwide annual turnover (whichever is lower).
7.5 million EUR or 1% of total worldwide annual turnover (whichever is lower).
This contrasts with the “whichever is higher” penalty logic that applies for all other businesses (i.e., those which are not SMEs).
What is the European Commission’s position?
The first proposed change is to include legal definitions of SME and small mid-cap enterprise (SMC) to the AI Act. These are:
SME: an enterprise which employs fewer than 250 people and which has an annual turnover not exceeding 50 million EUR, and/or an annual balance sheet total not exceeding 43 million EUR.
SMC: an enterprise which employs fewer than 750 people and which has an annual turnover not exceeding 150m EUR or an annual balance sheet total not exceeding 129m EUR.
The second and more significant proposed change is to extend the proportionate, inverse penalty regime for SMEs to SMCs also. This would significantly reduce the total potential penalty exposure of SMCs (i.e., many more companies) in certain circumstances. SMCs that are providers of high-risk AI systems would also be able to provide the required technical documentation in a simplified manner.
What is the Council’s position?
The Council has adopted the same position as the European Commission. This means that penalties for SMCs would also be capped at the lower amount, just as they are for SMEs today.



