Brussels wants to run over the simplification as well through the legislation that turned the European Union into a pioneering power in the regulation of Artificial Intelligence. The objective is to harmonize the application of the rules and correct what the institutions call “practical challenges” detected during the implementation of the regulatory framework. The European Parliament plans the definitive approval of this omnibus package this Tuesday, after negotiators reached a political agreement with the Twenty-Seven.
What the co-legislators are pursuing with this reform is, mainly, to reduce administrative burdens for companies, facilitate priority access to controlled testing environments, and adapt certain obligations to the operational reality of European companies. In parallel, the text reinforces some specific prohibitions, especially those related to the generation of non-consensual sexual content through Artificial Intelligence systems.
“We have over-regulated Europe. We have prevented European companies from being able to pick up the gauntlet thrown by the United States and China regarding the latest AI models. For this reason, we depend on their infrastructure,” defended the rapporteur of the text, the Swedish popular MEP Arba Kokalari, during the debate held this Monday in the Plenary of the European Parliament. According to the parliamentarian, the reform will allow correcting some of the requirements she considers “exaggerated” of the first European regulation on Artificial Intelligence and offer a more favorable environment for entrepreneurship and technological innovation.
For his part, the Irish liberal MEP who spoke on behalf of his group appealed to address the issue from a transversal perspective and recalled that European legislators have both the obligation to regulate and the responsibility to “allow technology to flourish in Europe.” “Leaving AI to free will is not the solution,” he stated during the parliamentary debate.
More time for high-risk systems
One of the main points of friction during the negotiations was the implementation schedule for certain technical provisions. The European Parliament even proposed the elimination of what it considered excessive discretion by the European Commission, setting specific dates for the entry into force of several annexes to the regulation.
Finally, the Council accepted a good part of this position, establishing that certain obligations linked to high-risk systems will not begin to apply until December 2027 and August 2028, depending on the corresponding regulatory block. According to negotiators, this temporal margin will allow for the development of harmonized standards and offer greater legal certainty to both companies and supervisory authorities.
The decision also responds to the repeated demands of the technology sector, which had been requesting more time to adapt products, processes, and internal systems to requirements that, in many cases, still lack fully defined technical standards.
Reinforced prohibition of sexual deepfakes
The agreement, which will predictably be ratified this Tuesday, significantly expands the prohibitions related to systems designed to generate artificial explicit sexual images, commonly known as deepfakes.
The new wording prohibits not only systems specifically designed to produce this type of content, but also those capable of generating or manipulating realistic intimate material of identifiable individuals without their consent. Furthermore, the prohibition of tools intended to produce child sexual abuse material through Artificial Intelligence is explicitly incorporated.
However, the text includes a limited exemption for providers who can demonstrate that they have implemented effective security measures, such as specific filters, blocking mechanisms, or training systems aimed at rejecting requests that could reproducibly lead to this type of illicit content.
Negotiators believe that this approach will allow for the maintenance of technological innovation without sacrificing the protection of fundamental rights, especially in areas related to human dignity, privacy, and the protection of minors.
Advantages for mid-cap companies
One of the most relevant novelties affects so-called mid-cap companies, that is, those companies that have already surpassed the legal definition of SMEs but cannot yet be equated with large multinational corporations.
Once the new text enters into force, these companies will have priority access to the so-called regulatory sandboxes, in addition to being able to benefit from simplified technical documentation models.
Lawmakers argue that this measure will facilitate the growth of innovative companies, preventing the leap between the obligations applicable to SMEs and the requirements imposed on large companies from causing a "regulatory shock" that is difficult to bear in terms of administrative and bureaucratic costs.
The intention is to prevent business growth from becoming a regulatory penalty that ends up discouraging the expansion of European technological projects in advanced stages of development.
More flexible training for workers and users
The agreement also modifies the obligations relating to Artificial Intelligence literacy.
Providers and professional users will no longer have to limit themselves to "guaranteeing" a certain level of knowledge about these technologies. Instead, they will be obliged to take reasonable measures to promote the training and qualification of their staff.
These actions must be adapted to the technical and educational context of the affected workers and will be supported by practical examples that the European Commission will publish with the aim of facilitating compliance, especially among small and medium-sized enterprises.
In this way, the colegislators implicitly recognize that a uniform and rigid obligation could be ineffective or disproportionate for certain organizations. The new approach opts for a more flexible model, although it maintains the requirement for responsible and adequate training of personnel involved in the development or use of Artificial Intelligence systems.
Sensitive data to combat algorithmic bias
The interinstitutional negotiations also incorporated a provision that is particularly relevant from a technical and legal point of view.
The new article will allow, exceptionally, the processing of certain special categories of personal data—such as information relating to ethnic origin or religious beliefs—for the sole purpose of detecting, assessing, and correcting possible discriminatory biases present in Artificial Intelligence systems.
The novelty is that this legal basis will be extended to all AI models and systems, and not only to those classified as high-risk.
The processing of these data will be subject to strict guarantees. The information may only be used for this specific purpose and must be deleted once the identified bias mitigation process is concluded. Likewise, the regulations will expressly restrict the use of minors' data for these activities.
With this, Brussels seeks to strengthen the fight against algorithmic discrimination by providing developers with technical tools that allow them to verify that their models are sufficiently representative and do not generate unfair or biased results.
More power for the European AI Office
Another of the most significant structural changes affects the distribution of supervisory powers.
The European Commission's Artificial Intelligence Office will assume exclusive competence to supervise systems based on general-purpose models when the model provider and the system provider are the same entity or belong to the same business group.
This body will have expanded powers to conduct on-site inspections, request information under threat of financial penalty, and impose binding commitments on companies subject to supervision.
Brussels intends to concentrate the oversight of the most advanced and powerful models on a community-wide scale to ensure uniform application of the legislation and avoid divergent interpretations among the different national competent authorities.
According to community sources, this centralization will improve regulatory coherence and offer greater predictability to economic operators developing pan-European technologies.
"Ah, here we go again"
Tuesday's vote also takes place in a particularly sensitive context for European technological autonomy.
The recent suspension of the Fable 5 and Mythos 5 models by the company Anthropic, following a national security directive adopted by the United States, has revived the debate about the structural dependence that Europe maintains on the North American technological ecosystem.
The decision, which temporarily restricted international access to certain advanced Artificial Intelligence capabilities, caused numerous European companies, developers, and research centers to suddenly have their access to tools they had already integrated into their work processes interrupted.
For numerous observers, the episode demonstrates the extent to which European access to the most advanced technologies continues to be conditioned by decisions made outside the continent and subject to geopolitical considerations unrelated to the interests of the European Union.
Likewise, this move has opened a new front for reflection on the nature of technological power in the digital economy. While Brussels has concentrated much of its efforts on building a regulatory framework based on security, transparency, and fundamental rights, Washington has shown that effective control capacity also involves dominance over the infrastructure, foundational models, and commercial services that underpin the global Artificial Intelligence ecosystem.
Fearing that the United States will normalize similar restrictions on strategic technologies under increasingly broad national security criteria, the European Union faces growing pressure to accelerate its technological sovereignty strategy. The development of its own models, European advanced computing infrastructures, and open-source alternatives increasingly appears as a matter not only of economics but also of geopolitics.
In this context, the simplification of the Artificial Intelligence Act is presented as an attempt to balance two objectives that Brussels considers inseparable: maintaining European regulatory leadership in rights and security, while creating more favorable conditions for the development of a competitive technological ecosystem capable of reducing the community bloc's external dependence.