The EU just simplified its AI rulebook — and made exactly one thing stricter.
The Digital Omnibus delays most high-risk AI obligations to December 2027. But from 2 December 2026, AI systems that generate child sexual abuse material and exploitation or non-consensual intimate imagery are banned outright — with fines up to €35M or 7% of global turnover.
And the ban doesn't require intent. If your model can produce this material and you can't evidence your safeguards, you're in scope.
Our new Supply Unchained investigation, The Golden Thread - Fundamental Rights Impact Assessments and the New Rules of AI, explains what this means — and what to do next.
The core idea is simple. Every major digital law — the EU AI Act, the DSA, the UK Online Safety Act, the US child-safety statutes — now measures harm the same way: through human rights. And protecting children from sexual abuse and exploitation is where those rules bite hardest.
Four things every AI company needs to know:
⚖️ Regulation — the deadlines moved. Transparency duties: August 2026. The CSAM/NCII ban: December 2026. High-risk duties and Fundamental Rights Impact Assessments: December 2027.
🚩 Enforcement— it's centralising. The EU AI Office now supervises AI inside the major platforms directly, with inspection powers. Ofcom, the FTC and the state AGs are already enforcing.
🟢 Fundamental Rights Impact Assessment (FRIA) — from December 2027, a Fundamental Rights Impact Assessment is required before first use of high-risk AI. Who it applies to: public bodies, private organisations delivering public services (healthcare, education, utilities, social services), and any deployer using AI for credit scoring or life and health insurance pricing. And if you provide the models they build on, they will need your documentation to complete it — expect that demand long before 2027.
✈️ Next Steps— build one human-rights-based risk assessment and evidence everything. When we re-scored four leading AI providers against the new prohibition, every score dipped — not for lack of genuine safety work, but because so much of that work isn't yet documented in the form regulators will look for. That gap is closable, and the providers and platforms who close it first will earn the trust dividend: the confidence of regulators, enterprise customers and the public. If you're working on this, we'd love to compare notes.
The message from every regulator — Brussels, London, Dublin, Washington — is the same: prove it.
