← All briefings
International AI Law · European Union · December 2

The Omnibus didn’t only delay things. It banned two more.

Every summary of the Digital Omnibus led with the delay, high-risk obligations pushed to December 2027 and August 2028. That is real, and it is the half everyone reported. The same regulation added two new prohibited practices to Article 5, applicable 2 December 2026, in the tier that carries fines of €35 million or 7% of worldwide turnover. If you build a generative image, video or audio product, that is the sentence in this briefing that matters.

What was actually added

Regulation (EU) 2026/1744 inserts two new points into Article 5(1) of the AI Act. In the enacted text they are points (ba) and (bb), not the letters most commentary guessed at, which is a small sign of how much of the coverage was written from summaries rather than the instrument.

Point (ba), non-consensual intimate material. It prohibits placing on the market, putting into service or using an AI system that generates or manipulates realistic images, videos, audio or similar material of an identifiable person’s intimate parts, or of an identifiable person engaged in sexually explicit activities, without that person’s freely given, specific, informed, unambiguous and explicit consent. The “nudifier” app class is the obvious target. It is not the only thing caught.

Point (bb), child sexual abuse material. Defined by cross-reference to Article 2, points (c) and (e), of Directive 2011/93/EU, with an exception where a “without right” defence applies under national law.

The scoping question almost everyone gets backwards

New Article 5(1a) splits the test by role, and the two halves are not symmetrical, which changes who should be reading this.

If you deploy someone else’s tool, you are probably outside it. A deployer is caught only where it uses the system for the purpose of generating or manipulating such material. Simply having a third-party image or video generator in your stack does not bring you inside this prohibition. That is a narrow, intent-shaped test, and most companies will clear it in one sentence, but write the sentence down, because “we obviously don’t do that” is not a record.

If you build or ship the system, the test is much wider. A provider is caught where either that generation is the intended purpose, or, and this is the operative limb, the system’s design, training, architecture, capabilities or user-facing functionalities make such generation a reasonably foreseeable and reproducible outcome, without requiring significant technical modification, and the system lacks reasonable and adequate safeguards to reliably prevent it.

Read that carefully. You do not have to have marketed the product for this use. A general-purpose image, video or audio generator can fall inside a prohibited practice, the tier where no control remediates the finding, on the strength of what a determined user can reproducibly get out of it.

Audio is in scope

The text says “images, videos, audio or similar material.” Most of the commentary described this as a deepfake-imagery prohibition and stopped there. Voice cloning and synthetic-speech products sit inside point (ba) on the same terms as visual generators. If your screening question has been about pictures, it has a hole in it.

What “adequate safeguards” has to mean

The standard is not “we have a filter.” The statutory test is reproducibility without significant technical modification, so the question an assessor should be asking is not whether a guardrail exists but whether a competent user can rerun a bypass. In practice that means four things, evidenced rather than asserted: refusal training, prompt guardrails, output content filtering, and abuse detection. And it means red-team records, with dates, method, and a named person, run against foreseeable misuse. A guardrail that was configured and never adversarially tested does not meet the standard on its own terms.

There is a second duty inside the same limb that is easy to miss: safeguards must also correct observed or reported misuse. That is continuing, not design-time. A provider with strong preventive controls and no abuse-report intake, triage and patch loop has not satisfied Article 5(1a). This is a post-market monitoring obligation wearing a prohibited-practice hat, and it fails independently of the preventive controls.

What is not caught

The instrument is narrower than a first read suggests, and knowing the edges keeps you from escalating false positives:

  • Article 5(1b) carves out manipulation that neither increases the exposure of depicted intimate parts nor alters the nature of depicted sexually explicit activities. Ordinary editing does not become “manipulation” because the source image was of a person.
  • Material that does not depict identifiable people.
  • Realistic partially nude depictions where intimate parts are not revealed and no sexually explicit activity is depicted; and non-realistic artistic nudes.
  • Applications where intimate parts are not exposed, or exposure is consented, the recitals name try-on applications and medical applications such as anatomical simulations and mammograms explicitly, plus exceptional medical diagnosis and treatment use by medical professionals.

These sit in the recitals rather than the operative text, so they are scoping guidance for an analyst, not exemptions to quote at a regulator.

The date, and why it is a real deadline

Article 113 was amended so that points (ba) and (bb) and Article 5(1a) and (1b) apply from 2 December 2026, separately from the rest of Chapters I and II. Prohibited practices are the one part of the Act where a finding is not remediable by controls; it is a stop, not a corrective action. Before that date an unmet finding is a gap with a remediation window. After it, it is a prohibition.

One further wrinkle worth knowing: Article 5 is not uniform across the Union. Denmark’s legal opt-out disapplies three existing prohibited-practice limbs there. Anyone testing “the AI Act prohibits X” against a specific deployment needs to know which member state’s law is being applied.

What to do between now and December

  1. Settle your role in writing. Provider or deployer, per system, with the reasoning. Under Article 5(1a) that determination decides almost everything else.
  2. Ask the capability question honestly. Can the system generate or manipulate realistic images, video or audio of identifiable people? Record the answer either way, with a date. “We never checked” is the worst position to be in on 2 December.
  3. Red-team against the statutory standard, not your own. Foreseeable misuse, reproducible without significant technical modification. Keep the records.
  4. Build the correction loop. Who receives abuse reports, what the triage window is, how a fix ships, and evidence it has happened.

This briefing is general information from Sentinel Assurance Group, not legal advice. It is written from the enacted text of Regulation (EU) 2026/1744 as published in the Official Journal on 24 July 2026 (in force 27 July 2026), Article 1(7) and Article 1(40). The scope of point (bb) turns on Directive 2011/93/EU, which is not reproduced here, and the “without right” defence is a matter of national law that varies by member state. Regulatory dates and requirements change, verify against primary sources and counsel before acting. Last reviewed August 2, 2026.

See how a Gap Assessment maps your exposure →

Does Article 5 reach what you build?
Find out before December 2.

The free AI Risk Exposure call settles the provider-or-deployer question, tests your capability answer against the statutory standard, and tells you whether your safeguards evidence would survive being asked for.

Book the call →