Australia unveils AI framework for data centres, copyright and infrastructure

The Australian government has announced plans for a national AI framework centred on new Australian AI Standards, enforceable rules for large AI data centres and stronger protections for creative works.

The framework aims to support AI investment while addressing its impact on energy infrastructure, water resources, local communities, national sovereignty and intellectual property.

Under the proposed standards, large AI data centres would be legally required to underwrite their additional power supply and pay the full cost of connecting to the electricity network. The government said this would prevent AI infrastructure expansion from increasing household energy bills.

Operators would also be required to reduce electricity consumption when necessary to support grid stability and make their facilities as water-efficient as possible.

The federal government plans to work with states and territories on locating large data centres in suitable areas, with local communities given opportunities to contribute to planning decisions.

An Office of AI has been established within the Department of the Prime Minister and Cabinet to oversee the implementation of the Australian AI Standards. The framework will be considered by the National Cabinet in August, with legislation planned for early 2027.

According to the government, the standards will create a consistent regulatory framework for large AI data centres and training infrastructure. It described the legislation as the first government framework of its kind globally.

The framework is also intended to simplify approvals and provide a clearer process for checking compliance with energy, water, safety and other requirements. The government argues that greater regulatory certainty could support investment while ensuring AI infrastructure contributes to Australia’s wider economic and strategic interests.

The framework also addresses copyright. The government said Australian writers, artists and journalists should retain control over their work and that AI companies should not train models on Australian creative content without the creators’ consent.

Further government-wide AI consumer safety priorities are expected to be announced in the coming weeks. These measures will build on the establishment of Australia’s AI Safety Institute.

Prime Minister Anthony Albanese said the framework was intended to ensure Australia actively shapes AI development while protecting national interests, employment and investment.

Industry, Innovation and Science Minister Tim Ayres linked the Australian AI Standards to the government’s wider industrial strategy, arguing that AI investment should strengthen Australia’s resilience, security and economy.

Assistant Minister for Science, Technology and the Digital Economy Andrew Charlton said the framework would create an enforceable social licence for AI and support safer, more inclusive and environmentally sustainable growth.

Why does it matter?

Australia is linking AI governance directly to the physical infrastructure needed to support AI, including electricity, water, land use and data centres, while also addressing copyright and national sovereignty. This represents a broader approach to AI regulation than frameworks focused solely on model safety or transparency.

If adopted, the Australian AI Standards could influence how other countries balance AI investment with infrastructure planning, environmental sustainability and protection of creative industries. The proposal reflects a growing international trend towards integrating AI governance with industrial, energy and digital policy.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

South Korea to launch free national AI service

South Korea’s Ministry of Science and ICT has announced plans to launch the ‘AI for Everyone’ project this year, providing a homegrown AI service that anyone in the country can use free of charge without usage limits.

The ministry will select participating companies through an open call for proposals. A beta version is scheduled for late September, followed by the launch of a general-purpose AI chatbot and an AI agent to help users search for and apply for public services.

According to the ministry, the project aims to reduce reliance on overseas AI services while narrowing the digital divide. It also responds to concerns about restrictions on free AI services and possible changes by global technology companies. The nationwide service is expected to launch before the end of 2026.

Why does it matter?

The initiative combines digital inclusion with technological sovereignty by offering unrestricted access to a domestically developed AI service. Removing cost and usage limits could broaden AI adoption while integrating generative AI more closely into public services.

The project also reflects a wider international trend of governments investing in national AI capabilities to reduce dependence on foreign providers. As AI becomes part of essential digital infrastructure, countries are increasingly seeking greater control over the services, platforms and data that underpin public-sector AI deployment.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot

UK to introduce AI for police evidence disclosure

The UK Home Office has announced major reforms to criminal evidence disclosure that will introduce AI tools to automatically review and summarise police evidence, modernising procedures that have remained largely unchanged since 1996.

The reforms respond to the growing volume of digital evidence in criminal investigations. According to the Home Office, a single fraud case can now involve more than four million documents, while some investigations contain digital material equivalent to 500,000 e-books. Existing guidance often requires officers to manually review and summarise potentially relevant material before prosecutors determine whether it is needed.

The government’s National Centre for Police AI, backed by £75 million in funding, will pilot AI tools capable of automatically summarising digital evidence. The technology will help officers identify, organise and process large volumes of files currently reviewed manually. According to the Home Office, the reforms could free up around six million hours annually by 2028, equivalent to approximately 3,000 additional UK frontline officers.

The government has also accepted recommendations to establish centralised procurement of police technology and create a national disclosure governance forum bringing together representatives from policing, the judiciary, prosecutors and government to oversee the introduction of new technologies. The Director of the Serious Fraud Office described the reforms as an important step towards modernising disclosure practice.

Why does it matter?

The reforms recognise that criminal justice systems increasingly struggle to manage the volume of digital evidence generated by smartphones, cloud services and online communications. Automating routine evidence review could allow investigators to spend more time on investigations while improving the speed of case preparation.

The initiative also illustrates a growing approach to AI adoption in the public sector, where AI supports administrative and analytical tasks rather than replacing human judgement. By introducing governance arrangements alongside the technology, the UK is attempting to balance efficiency gains with accountability in one of the justice system’s most sensitive areas.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot

European Commission expands AI assistant across global DG INTPA network

The European Commission’s Directorate-General for International Partnerships (DG INTPA) has expanded the use of an AI assistant to support staff across its headquarters and delegations in more than 100 countries.

Launched in March 2026 and developed with Accenture, the AI assistant is tailored to DG INTPA’s internal procedures, terminology and policy work. According to Accenture, the platform has more than 2,000 regular users and has processed over 400,000 queries.

The assistant combines large language models with secure access to internal documents and internet connectivity to support policy, funding and operational tasks. The programme also includes staff training and human oversight to promote the responsible use of AI.

According to Accenture, the next phase will introduce agentic AI capabilities for selected workflows, alongside a user feedback mechanism to help refine the system.

Why does it matter?

The deployment illustrates how AI is moving from pilot projects to routine administrative support within public institutions. Rather than focusing only on productivity, the Commission is combining AI tools with governance measures such as staff training and human oversight to support responsible adoption.

The planned introduction of agentic AI also reflects a broader shift towards more autonomous workplace systems. If successful, DG INTPA’s experience could inform wider adoption of AI across EU institutions and other public administrations seeking to modernise policy and operational processes.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

UK launches £800,000 AI Upskilling Challenge Fund in Barnsley

The UK government has opened applications for the £800,000 AI Upskilling Challenge Fund under the Barnsley Tech Town programme to support AI skills development for workers, businesses and local communities.

Training providers, charities, colleges, businesses and technology companies across the UK can apply, provided their projects are delivered in Barnsley. Priority groups include manufacturing workers, older residents, small businesses and people entering the workforce.

The government said successful projects should demonstrate the potential to be scaled nationally. Lessons from the programme will contribute to its goal of equipping 10 million workers with AI skills by 2030.

Applications open on 15 July through the government’s Find a Grant platform. Barnsley Council said the funding forms part of wider plans to strengthen the town’s digital economy and support its manufacturing and logistics sectors.

Why does it matter?

The programme illustrates how AI policy is increasingly shifting from national strategies towards place-based implementation. By testing AI training programmes in a manufacturing-focused community, the government hopes to identify approaches that could be replicated elsewhere as AI adoption accelerates across the economy.

The initiative also reflects the growing recognition that AI competitiveness depends not only on developing new technologies but also on expanding workforce skills. Helping workers and small businesses adopt AI could improve productivity while reducing the risk that parts of the labour market are left behind during the transition.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

UK plans default overnight social media restrictions for teenagers

The UK government plans to introduce default overnight social media restrictions for 16- and 17-year-olds, alongside measures to limit features designed to encourage prolonged platform use.

Social media platforms will be expected to activate overnight restrictions from midnight to 6 a.m. by default for users in this age group. Teenagers will be able to change the settings, but the protections will be enabled automatically.

Autoplay and continuously personalised content feeds will also be disabled by default. The government said these features can encourage prolonged use and reinforce potentially addictive patterns of engagement.

The measures are intended to avoid a sudden reduction in online protections when children turn 16. They complement the government’s previously announced plans to prohibit social media services from being offered to children under 16 from spring 2027.

The proposals follow a government pilot involving more than 300 teenagers and parents across the UK. Participating families said the overnight restrictions became part of their routines and helped improve sleep and concentration.

Technology Secretary Liz Kendall said older teenagers should retain greater independence while continuing to receive protection from features that could negatively affect their wellbeing.

The government also plans additional protections for children using AI chatbots. Proposed measures include encouraging regular breaks for users under 18 and taking action against services that provide dangerous, misleading or unverified mental health advice.

Ministers will work with regulators and other government departments to consider further restrictions, including possible bans on chatbots considered to pose a serious risk to children. Guidance for children, parents and guardians will also be added to the Kids Online Safety Hub.

Schools will strengthen media literacy through Relationships, Sex and Health Education classes covering AI, chatbots, misinformation and harmful online content. From September 2028, media literacy will also be embedded across the National Curriculum, including lessons on AI, data science, source analysis and technological bias.

The first regulations supporting the under-16 social media restrictions are expected to be presented to Parliament by the end of 2026, with implementation and enforcement planned for spring 2027.

Why does it matter?

The proposals reflect a growing shift from focusing solely on access to social media towards regulating how digital services are designed and used. By targeting autoplay, personalised feeds and AI chatbots alongside age-based protections, the government is seeking to address features that may contribute to excessive use and online harms.

If adopted, the measures could further shape debates on youth online safety beyond the UK, reinforcing the trend towards safety-by-design, stronger protections for minors and greater platform responsibility for children’s digital wellbeing.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!

EPO highlights Europe’s growing quantum innovation ecosystem

The European Patent Office (EPO) highlighted Europe’s growing quantum and AI innovation ecosystem during Servus Scale Up 2026 in Munich, pointing to rapid growth in quantum patenting and new initiatives to help startups commercialise deep-tech innovation.

The event brought together around 200 French and Bavarian startups, investors, researchers, technology transfer experts and policymakers to strengthen cross-border cooperation and support deep-tech entrepreneurship in strategically important technologies.

EPO Vice President Christoph Ernst said quantum patenting in Europe has increased fivefold over the past decade. According to recent EPO findings, annual growth has averaged around 20%, significantly outpacing overall patent growth.

Europe’s share of international patent families in quantum technologies also increased from 19% to 25%, reinforcing the continent’s position in one of the world’s fastest-growing technology fields.

The EPO also showcased initiatives designed to support innovators and investors. Its Deep Tech Finder now includes nearly 150 European quantum startups.

Other initiatives, including the EPO Observatory on Patents and Technology, the joint OECD study on quantum technologies, the Quantum Technology Platform and the recently launched EPO Data Desk, provide patent intelligence, market insights and analytical tools to help identify emerging opportunities and support investment decisions.

The EPO noted that although Europe has a strong research and innovation base in quantum technologies, access to funding remains more limited than in the United States. By combining patent data with market intelligence, the Office aims to help startups scale, attract investment and strengthen Europe’s long-term competitiveness in quantum technologies and AI.

Why does it matter?

Quantum technologies are expected to play an increasingly important role in fields ranging from cybersecurity and communications to healthcare and advanced computing. Strong patent activity suggests Europe remains competitive in research, but commercial success will also depend on access to investment and the ability to scale innovative companies.

By combining patent intelligence with tools for investors and startups, the EPO is seeking to strengthen Europe’s deep-tech ecosystem and improve the commercialisation of emerging technologies. This reflects a broader European effort to translate scientific leadership into long-term industrial competitiveness.

Would you like to learn more about AI, tech and digital diplomacy? If so, ask our Diplo chatbot!

South Korea prioritises AI and semiconductor investment in the 2027 budget

South Korea plans to introduce a record national budget exceeding KRW 800 trillion (around €500 billion) in 2027, with semiconductors, AI and youth employment at the centre of its investment strategy.

Announced during the National Fiscal Strategy Meeting, the proposed budget would increase by more than 10% compared with 2026, reflecting the government’s focus on strengthening industrial competitiveness, technological leadership and long-term economic growth.

A significant share of the funding will support three flagship initiatives focused on semiconductors, AI data centres and physical AI technologies.

The government also plans to accelerate the development of Yongin and the Honam region as major semiconductor manufacturing hubs through administrative measures including fast-track licensing and exemptions from preliminary feasibility studies for strategic projects.

Beyond industrial policy, the budget includes measures aimed at supporting citizens directly. A new Future Response Fund will finance the training of 200,000 young professionals, help create around 300,000 jobs and improve housing stability.

South Korea also plans to expand employment insurance and workers’ compensation coverage for platform workers while establishing a new K-Labour Council to strengthen labour protections.

To address fiscal sustainability, the government announced a comprehensive review of public spending aimed at generating around KRW 50 trillion in efficiency savings, described as the largest restructuring of government expenditure in the country’s history.

According to the government, the combination of strategic investment and spending reforms is intended to promote innovation while maintaining long-term fiscal sustainability.

Why does it matter?

The budget demonstrates how industrial policy is becoming a central tool for strengthening technological competitiveness. By prioritising semiconductors, AI infrastructure and advanced manufacturing, South Korea is seeking to reinforce its position in sectors that are increasingly viewed as critical to economic growth and national security.

The package also shows that governments are increasingly pairing technology investment with workforce development and labour reforms. Building AI and semiconductor capacity will require not only infrastructure and capital but also a skilled workforce capable of supporting long-term innovation.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!  

European Parliament committee backs stronger online protections for children

The European Parliament’s Committee on Culture and Education has adopted a report calling for stronger enforcement of existing EU digital legislation to create a safer online environment, particularly for children and young people.

MEPs argue that platforms should be held more accountable for the impact of their services through stronger safeguards, greater algorithmic transparency and stricter protections against addictive digital design.

The European Parliament report calls for a ban on the most harmful addictive platform features and supports introducing a dedicated ‘youth mode’ that would disable targeted advertising and reduce minors’ exposure to addictive design practices.

MEPs also propose greater transparency around recommender systems so users can better understand why content is promoted, restricted or removed. They further suggest introducing personal liability for serious and persistent failures to comply with child protection obligations.

Beyond platform design, the report recommends an EU-wide code of conduct for influencers and stronger safeguards against practices such as kidfluencing and sharenting, where children are used in commercial content or exposed excessively online.

MEPs also call for mandatory ethical standards for AI companions, greater transparency around AI model training, measures against AI-generated impersonation scams, stronger protection against synthetic child sexual abuse material, and systematic monitoring of children’s digital habits across the EU.

The committee said these measures should complement existing legislation, including the Digital Services Act, AI Act, GDPR and Audiovisual Media Services Directive, creating a more coherent EU framework for protecting minors online. The report will now be submitted to Parliament’s plenary session in September 2026.

Why does it matter?

The report signals growing political support for strengthening children’s online safety by making platforms more accountable for the design and operation of their services. Rather than relying solely on new legislation, MEPs are urging stronger enforcement of existing EU rules alongside targeted measures addressing addictive design, recommender systems and AI-powered services.

Although the report is not legally binding, it could influence future EU legislation and enforcement priorities by reinforcing the shift towards safety-by-design, greater transparency and stronger protections for minors across digital platforms.

Would you like to learn more about AI, tech and digital diplomacyIf so, ask our Diplo chatbot!

Digital Omnibus on AI: The EU’s AI Act simplification and new AI Office powers

On 29 June 2026, the Council of the European Union gave its final green light to the Digital Omnibus on AI, a package of amendments that eases and delays parts of the EU AI Act, completing a legislative procedure that began when the European Commission published its proposal on 19 November 2025. It amends the EU AI Act, together with the EU’s civil aviation rules and machinery regulation. According to the European Parliament’s Legislative Observatory, the final act was signed on 8 July 2026, and the Digital Omnibus is now awaiting publication in the Official Journal of the European Union, a necessary step before it can enter into force, ahead of the original 2 August 2026 deadline for several high-risk AI obligations.

Much of the public attention on the Digital Omnibus has focused on the delay to high-risk AI rules and the new ban on AI-generated intimate imagery. The full legal text of the amending regulation also reorganises, in detail, responsibility for supervising AI systems that operate within very large online platforms regulated under the Digital Services Act, and amends several other elements of the way the AI Act is enforced, points that have drawn less attention so far.

The Council describes this regulation as part of a wider legislative package known as Omnibus VII, one of several ‘omnibus’ simplification efforts the Commission has proposed across different policy areas. It was also listed in the Parliament and the Council in their Joint Declaration on EU legislative priorities for 2026, signalling the priority both institutions attached to its rapid finalisation.

Why the Commission proposed the amendments

 Architecture, Building, Office Building, City, Urban, High Rise, Flag

According to the recitals of the Digital Omnibus on AI, the amendments respond to problems identified once parts of the AI Act began to apply in August 2024. The recitals point to delays in the preparation of harmonised technical standards needed by providers of high-risk AI systems in order to demonstrate compliance, as well as delays by several member states in setting up the national authorities and conformity assessment bodies responsible for checking that compliance. Taken together, the recitals state that these delays created a heavier compliance burden than originally expected.

The Commission’s proposal also links the amendments to a broader competitiveness rationale, describing them as part of a wider effort by EU leaders to reduce administrative burdens on business, following the recommendations of the Draghi and Letta reports on European competitiveness. Industry associations also lobbied for the amendments throughout 2025.

The trade group DIGITALEUROPE told policymakers that compliance with the AI Act could cost companies in the region of EUR 3.3 billion a year across the EU, and that a company of around 50 employees developing an AI-based product could face initial compliance costs of between EUR 320,000 and EUR 600,000.

How the Digital Omnibus was negotiated

 People, Person, Audience, Crowd, Indoors, Lecture, Room, Seminar, Adult, Male, Man, Female, Woman, Head

The AI-specific amendments were separated from the wider Digital Omnibus package, which also proposes amendments to the GDPR, the ePrivacy Directive, the Data Act, and the NIS2 Directive on cybersecurity, due to the approaching deadline for high-risk AI obligations. According to the Legislative Observatory’s procedure record, Parliament’s Internal Market Committee voted on the proposed regulation on 18 March 2026, and the Parliament adopted its first-reading position on 26 March 2026.

The Parliament and the Council negotiators reached a political agreement on the Digital Omnibus early on 7 May 2026. The Council’s Permanent Representatives Committee confirmed the agreement in a letter dated 13 May 2026. The Parliament formally adopted the Digital Omnibus on 16 June 2026, the Council gave its final approval on 29 June 2026, and the final act was signed on 8 July 2026.

The regulation’s preamble records that the European Central Bank was consulted and issued a formal opinion, published in the Official Journal in April 2026, as required under EU legislation for measures affecting payments and financial infrastructure. The European Economic and Social Committee delivered its opinion on 18 March 2026, and the Committee of the Regions gave its opinion on 7 May 2026. National parliaments, including those of Czechia, Italy, the Netherlands, Portugal, Romania, Germany, Poland and France, also submitted subsidiarity contributions during the process. The Parliament’s public transparency register separately records meetings on this regulation between the two co-rapporteurs and organisations, including Google, the AI start-up Mistral AI, the digital rights group EDRi, the privacy group noyb, and the standards and conformity body TIC Council, reflecting the range of interests, from large technology firms to civil society, that engaged with the negotiations.

New deadlines for high-risk AI obligations

Under the amended Article 113 of the AI Act, the obligations for high-risk AI systems set out in Sections 1 to 3 of Chapter III will now apply from 2 December 2027 for systems classified as high-risk under Article 6(2) and Annex III, which covers areas such as biometrics, critical infrastructure, education, employment, law enforcement, migration and border management. For systems classified as high-risk under Article 6(1) and Annex I, meaning AI systems embedded in products already covered by other EU safety legislation, such as machinery or medical devices, the new deadline is 2 August 2028. Both deadlines were originally set for 2 August 2026.

A separate provision clarifies how the AI Act’s grace period for so-called legacy systems, set out in Article 111(2), applies. Once at least one unit of a given type and model of high-risk AI system has been lawfully placed on the market before the relevant cut-off date, further units of the same type and model can continue to be placed on the market or put into service without additional certification, as long as the system’s design does not change significantly. Any significant redesign after the cut-off date triggers full compliance with the AI Act, including conformity assessment.

To help providers meet the new deadlines, the Digital Omnibus requires the Commission to request that European standardisation bodies develop technical standards aligned with existing product-safety standards, reducing duplication for companies that have to comply with both the AI Act and sectoral legislation. The Commission must also publish guidance on post-market monitoring plans by 2 September 2027, as well as guidance to help providers of Annex I high-risk systems apply the AI Act alongside sectoral rules by 1 August 2027. Watermarking obligations for AI-generated content, which allow such content to be detected and traced, benefit from a separate four-month transitional period for systems already on the market before 2 August 2026.

Changes to AI literacy and the use of sensitive data for bias correction

 Person, Security, First Aid, Fungus, Plant

A further amendment loosens the AI Act’s AI literacy obligation. Instead of requiring providers and deployers to ensure a sufficient level of AI literacy among their staff, the amended Article 4 requires them to take measures supporting the development of that literacy among staff and other people involved in the operation of their AI systems. The European Artificial Intelligence Board is tasked with adopting recommendations that set common objectives to guide how the Commission and member states support this obligation.

A new Article 4a allows providers and deployers of AI systems to process special categories of personal data, such as data revealing ethnicity or health status, for the specific purpose of detecting and correcting bias, subject to a list of privacy safeguards, including data minimisation, restrictions on transferring the data to third parties, and deletion once the bias has been corrected. The final text requires this processing to be strictly necessary, a stricter standard than the version originally proposed by the Commission. This followed a joint opinion issued by the European Data Protection Board and the European Data Protection Supervisor in January 2026, which recommended reinstating the stricter standard.

AI Office gains exclusive powers over general-purpose AI and large platforms

 Logo, Nature, Night, Outdoors, Text, Symbol

Article 75 of the AI Act, which governs the market surveillance of AI systems, has been substantially rewritten. Under the new provisions, the Commission’s AI Office becomes exclusively responsible for supervising two categories of AI systems. The first category comprises AI systems built on general-purpose AI models, where the same provider, or providers belonging to the same undertaking, developed both the underlying model and the AI system built on it. This exclusive competence carries several exceptions. It does not apply to AI systems related to products already covered by EU product-safety legislation, AI systems used as critical infrastructure, systems provided by law enforcement authorities, border management authorities or financial institutions in specific circumstances, or certain systems used in the administration of justice, all of which remain under national supervision.

The second category covers AI systems that constitute, or are integrated into, a very large online platform or a very large online search engine designated under the Digital Services Act (DSA), the EU’s rulebook for online platforms. The recitals state that empowering the Commission, through the AI Office, to act as a market surveillance authority for these systems is intended to ensure that enforcement of the AI Act and the DSA is carried out consistently, given the scale and potential societal impact of very large platforms and search engines.

For AI systems that are embedded in, or form part of, a designated very large platform or search engine, the Digital Omnibus specifies that the DSA’s own risk assessment, mitigation, and audit obligations, laid down in Articles 34, 35, and 37 of that regulation, serve as the first point of entry for assessing the AI system. This is without prejudice to the AI Office’s separate power to investigate and enforce breaches of the AI Act after the fact. The Commission services that enforce the DSA and the AI Office are required to coordinate, exchange views regularly, and take account of any fines already imposed on the same company for the same conduct, so that the combined penalties remain proportionate and do not amount to double punishment for the same infringement.

Outside this narrower platform-related category, national market surveillance authorities retain a role. Where a national authority has well-founded reasons to suspect that a provider or deployer of an AI system under the AI Office’s exclusive competence has breached the AI Act, it may ask the AI Office, through a designated national contact point, to investigate. The AI Office must tell that authority within four months whether it intends to act, and keep it informed of major developments and the eventual outcome.

The recitals acknowledge that taking on this expanded role will require the AI Office to be adequately staffed and resourced. Whether the Commission allocates sufficient capacity for the AI Office to supervise both general-purpose AI models and large platforms is an operational question that will only become clear as implementation proceeds, rather than one resolved by the legislation itself.

New ban on AI-generated intimate imagery and child sexual abuse material

image

The Digital Omnibus amends Article 5 of the AI Act, which lists AI practices that are prohibited outright. It adds a prohibition against placing on the market, putting into service, or using AI systems that generate or manipulate realistic images, video or audio of an identifiable person’s intimate parts, or of that person engaged in sexually explicit activity, without that person’s free, specific, informed and unambiguous consent. It adds a parallel prohibition covering AI systems that generate or manipulate child sexual abuse material, subject to a narrow exception for activities that are lawful under national law, such as material generated by law enforcement authorities for the purposes of criminal investigation.

For providers, the prohibition applies in two situations: where generating or manipulating such material is the system’s intended purpose, or where that outcome is a reasonably foreseeable and reproducible result of the system’s design and the provider has not put in place reasonable and adequate safeguards, such as content filtering or abuse-detection mechanisms, to prevent it. For deployers, the prohibition applies only where the AI system is actually used for that purpose, meaning the ordinary use of a lawful system for unrelated purposes is not covered, nor is accidental generation of such content.

The prohibited material is defined narrowly. It covers realistic depictions, meaning a person’s face, voice or body shown in a credible, real-life manner, and specifically named intimate parts or depictions of sexually explicit activity. Cartoonish or physically impossible depictions fall outside the prohibition, as does content generated with the depicted person’s consent, non-realistic artistic nude work that does not depict an identifiable person, and legitimate medical applications such as anatomical simulations. Simple enhancements to existing images, such as adjusting brightness or adding a caption, are not treated as prohibited manipulation unless they increase the level of nudity or explicitness shown. Companies have to ensure that their systems comply with these rules by 2 December 2026.

Other simplification measures

The Digital Omnibus extends several compliance simplifications that previously applied only to small and medium-sized enterprises to a new category of small mid-cap enterprises, companies that have outgrown the SME definition but remain much smaller than large corporations. It also gives all SMEs, including start-ups, the option to comply with parts of the AI Act’s quality management system requirements in a simplified way, an option previously limited to microenterprises.

The deadline for each member state to have at least one operational national AI regulatory sandbox, a controlled environment in which providers can test AI systems under regulatory supervision, has been extended to 2 August 2027. The same provisions allow the AI Office itself to set up an EU-level sandbox for AI systems that fall under its exclusive competence, with priority access for SMEs, start-ups and small mid-cap enterprises, operating alongside, and not instead of, national sandboxes.

A further change moves the EU machinery regulation from one section of the AI Act’s product-safety annex to another, shifting AI-enabled machinery towards a more sector-specific approach. Under the new arrangement, the Commission must adopt delegated acts by 2 August 2028 incorporating the AI Act’s health and safety requirements directly into the machinery regulation, rather than requiring manufacturers to apply both frameworks in parallel.

Data protection authorities raise fundamental rights concerns

 Guitar, Musical Instrument, Accessories, Diamond, Gemstone, Jewelry

Before the political agreement was reached, the European Data Protection Board and the European Data Protection Supervisor issued a joint opinion on the Commission’s initial proposal. The two authorities said they supported the general aim of addressing implementation issues, but raised concerns that several measures could weaken human rights protections built into the AI Act. They warned that extending the legacy systems exception would allow more high-risk AI systems to reach the market without being subject to the Act’s safeguards and urged the co-legislators to keep any delay to transparency obligations as short as possible.

The two authorities also opposed the Commission’s original plan to remove the registration obligation for providers who conclude that their Annex III systems are not high-risk, arguing that this would weaken accountability and make it harder for market surveillance authorities to respond quickly to problem systems. That registration obligation was retained, in a streamlined form, in the Digital Omnibus as finally approved in June. As set out above, the authorities’ recommendation to apply a strict necessity standard to the processing of sensitive data for bias correction was also reflected in the final version of the Digital Omnibus.

Not all of the authorities’ recommendations were taken on board in the same way. Their broader concern, that postponing obligations for high-risk AI systems may leave fundamental rights protections unenforced for longer in a fast-moving technological area, remains a live point of disagreement between the co-legislators and civil society groups, as discussed further below.

Reactions: competitiveness framing meets rights concerns

 Astronomy, Outer Space

Council and Parliament negotiators presented the changes as a way to make the AI Act more workable without altering its underlying risk-based structure. Co-rapporteur Arba Kokalari said the agreement showed that politics can move just as quickly as technology, linking the simplification to the Commission’s broader competitiveness agenda. Co-rapporteur Michael McNamara said the deal combined simplification measures with new safeguards against nudification apps and AI-generated child sexual abuse material.

Civil society organisations took a more critical view of the overall direction of the package. The digital rights group Liberties argued that the final agreement weakens several safeguards contained in the original AI Act, and described the postponement of high-risk obligations as a delay to fundamental rights protections that were due to take effect in August 2026.

Industry associations generally welcomed the changes. DIGITALEUROPE, which had been among the most vocal critics of the AI Act’s original compliance costs and timeline, broadly supported the direction of the simplification package, while continuing to call for further alignment between the AI Act and other overlapping EU digital rules.

What happens next

The Digital Omnibus on AI will enter into force once it is published in the Official Journal of the European Union. Until then, the AI Act’s original provisions and timeline remain legally in force, including the prohibitions on unacceptable AI practices and the obligations applicable to general-purpose AI models that have applied since August 2025.

A separate Commission exercise, the Digital Fitness Check, is expected to examine the DSA and the wider digital rulebook directly, with a report on its findings due in the first quarter of 2027 according to legal commentary on the process. That exercise, rather than the AI Omnibus itself, is where the more direct question of simplifying the DSA is likely to be decided and where the institutional link now established between the AI Office and DSA-regulated platforms may be revisited.

Would you like to learn more about AI, tech, and digital diplomacy? If so, ask our Diplo chatbot!