EU AI Act: High-risk requirements delayed, cybersecurity tightened
The EU adjusts its AI regulatory framework, delaying certain requirements for high-risk systems while strengthening cybersecurity oversight and support for SMEs. The aim is to balance innovation with safety and regulatory compliance.

What happened?
On 26 July 2026, the EU introduced new adjustments to its AI regulatory framework through the latest Digital Omnibus package. These changes include delays to certain obligations for AI systems classified as high-risk, expanded support for SMEs, and strengthened powers for the European AI Office. Additionally, new restrictions are being implemented against harmful AI-generated content.
Key facts
”Artificial intelligence is moving faster than governments can regulate it, creating a difficult balance between innovation, security, and public protection. The European Union is now adjusting its ambitious AI governance framework with new changes designed to give companies more”
Why it matters
The adjustments aim to provide companies with more time to prepare for the new requirements while reinforcing protection against dangerous AI applications. This balances the pace of innovation with necessary safety measures. Cybersecurity research has shown that advanced AI models may attempt to perform risky actions, underscoring the need for robust safeguards.
Who is affected?
Companies developing or using AI, particularly those with systems classified as high-risk, are directly affected by the delayed implementation timelines. SMEs receive increased support, and users are impacted by stricter rules regarding AI-generated content. Cybersecurity experts are affected by the tightened security requirements for AI systems.
Impact on the EU
The changes apply to all EU member states, affecting organisations and individuals operating within EU jurisdiction. The powers of the European AI Office to monitor and enforce the regulation are being strengthened.
What else you should know
New guidelines also address transparency, cybersecurity resilience, and compliance expectations for generative AI systems. This provides greater clarity for developers on how to manage their AI models.
Quick answers about this story
Vad har hänt?
När hände det?
Varför spelar det roll?
Påverkar det EU?
The link opens in a new window and leads to the publisher's own site.
Källan har spårats automatiskt från utgivaren via Aheadlines signalkedja.
AI-verktyg i artikeln
Topics
Get similar news straight to your inbox
The reader's room
Send in a question or an addition. The newsroom reads everything before it's published and replies when relevant. No AI-generated text – just people.
Sign in to submit a comment or question.
Read the article through your role
- Decide whether this affects strategy over 6–12 months or is just noise.
- Discuss with leadership: do we own the right question or does ownership need to move?
- Ask: what risk are we taking by NOT acting on this this quarter?
Generated angle — not editorial analysis of "EU AI Act: High-risk requirements delayed, cybersecurity tig"