← Back to the dossier

7 May 2026 · European Union

Europe postpones its own AI rules, six days after the Hugging Face break-in becomes public

In November 2025 the European Commission proposed the Digital Omnibus on AI, a package that changes the AI Act and two other laws at once. The Council and the European Parliament reached a provisional agreement, which the Council announced on 7 May 2026. The regulation was published in the Official Journal on 24 July and entered into force on 27 July. Its main effect is to postpone the AI Act's rules for high-risk systems, which were due to apply from 2 August 2026. OpenAI disclosed the Hugging Face intrusion on 21 July.

By Mara Masaeva · Updated 29 September 2026

PoliticsConfirmedMore than one independent source, or a primary document.

What happened

The dates in order:

19 November 2025. The Commission publishes its proposal for the Digital Omnibus on AI, alongside a wider Digital Omnibus for data and cybersecurity law.

7 May 2026. The Council announces that it has reached a provisional agreement with Parliament. The official aim is simplification and a lower compliance burden for companies. Parliament votes on 16 June, the Council adopts the text on 29 June, and both sign it on 8 July.

21 July 2026. OpenAI discloses that its agents broke into Hugging Face.

24 July 2026. The omnibus is published in the Official Journal as Regulation (EU) 2026/1744.

27 July 2026. It enters into force, on the third day after publication. The high-risk obligations that were about to apply on 2 August are postponed to 2 December 2027 for the uses listed in Annex III, such as recruitment and credit scoring, and to 2 August 2028 for AI built into products such as medical devices and toys.

The text was signed on 8 July, before OpenAI's disclosure. Brussels did not act in response to July, and nothing was sped up because of it either. The two processes ran side by side without affecting each other.

How it workedtechnical detail

What the AI Act regulates. It covers systems placed on the EU market, with obligations for the companies that supply them and the organisations that use them, depending on the risk category. It is product law. It asks whether something you sell is safe enough to sell in Europe.

What it does not regulate. It does not require companies to report autonomous agents that escape a test environment inside the company. It gives no European body the right to look at the logs of an American lab. It applies to systems placed on the market, and the model in July was an internal research prototype that was never sold anywhere.

So I would not say the AI Act failed. In my view, it was written for a different kind of problem, and the problem changed while the law was being simplified.

What may follow

Compare Europe with the rest. In the United States, attorneys general are subpoenaing OpenAI, there are bills to ban superintelligence and require a kill switch, and one lab paused its own training. Australia set up a cyber task force within days of learning that someone had been inside its health portal.

Europe has the strictest AI law in the world, and spent 2026 postponing the part of it that can bite. I have found no report of a European authority asking OpenAI anything about July. As far as I can tell, no authority has the legal standing to ask.

I am not alone in this criticism. Luise Quaritsch of the Jacques Delors Centre wrote in March that the omnibus is heading in the wrong direction. It makes substantive changes without an assessment of their impact, and looser rules risk entrenching foreign big tech, she argues. Nine civil society groups, among them EDRi, Amnesty International and the European Center for Not-for-Profit Law (ECNL), call it a rollback of AI safeguards before they even apply. They write that it undermines the EU's credibility as a serious digital regulator. Mario Mariniello of Bruegel, a Brussels think tank, observes that deregulation has the policy momentum. Work on limiting harm runs alongside it.

Supporters of the delay point out that Europe has no frontier lab of its own. The cost of complying with the rules falls hardest on the small European companies that might build one. And if you regulate a market where you do not make the product, you take on the costs without gaining any control.

What I do not know

The dates of 2 December 2027 and 2 August 2028 come from the regulation itself. Other parts of the AI Act keep 2 August 2026, such as most transparency obligations. Gibson Dunn dates the political agreement to 6 May and the Council's announcement came on 7 May. I use 7 May.

My notes

This is the slide for a Belgian audience. It is tempting to turn it into a complaint about Brussels. I will not. I put the dates up, say that the two processes never affected each other, and leave it at that for a moment.

Give the counterargument its own time: Europe has no frontier lab, and the compliance burden falls hardest on the small companies that might build one. If I cannot make that case convincingly, I do not yet understand the disagreement.

Do not say the AI Act failed. Say it was written for a different kind of problem. That is closer to the facts and harder to wave away.

Read next

Sources

  1. Council of the EU: Council and Parliament agree to simplify and streamline AI rulesprimary · not read end to end yet

    The official announcement of 7 May. The site blocks automated fetching.

  2. EUR-Lex: Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal L of 24 July 2026primary · main source

    The regulation of 8 July 2026 as published. Source for the new dates of 2 December 2027 and 2 August 2028 and for entry into force on the third day after publication.

  3. European Commission: the AI Act regulatory frameworkprimary · not read end to end yet
  4. Jacques Delors Centre: The EU's Digital and AI Omnibus is Heading in the Wrong Directionargument

    Luise Quaritsch, policy brief of 30 March 2026, written before the agreement of May. Argues the omnibus makes substantive changes without an impact assessment, rests on one-sided cost estimates and risks entrenching foreign big tech.

  5. EDRi, ECNL and others: The AI Omnibus, a rollback of AI safeguards before they even apply (PDF)argument

    June 2026. Joint position of nine groups, coordinated by EDRi and published on the ECNL site. Calls on MEPs to vote against the text agreed on 7 May.

  6. Bruegel: The right balance, how to fix European Union artificial intelligence regulationresearch

    Mario Mariniello, policy brief 12/2026, 11 June 2026. Proposes lighter rules up front for most AI suppliers, traded against liability, monitoring and incident reporting afterwards. Probably the most useful read for a Belgian audience, because it takes the burden on small firms seriously.

  7. Gibson Dunn: EU AI Act Omnibus Agreement, postponed high-risk deadlines and other key changesresearch

    Client alert of 27 May 2026, by a law firm. Dates the provisional agreement to 6 May and the confirmation by member states to 13 May.