The European Union is taking a step closer to improving the EU's landmark AI Act, with the European Council proposing new amendments aimed at simplifying regulations while addressing emerging risks from artificial intelligence.
See also: MEPs agree to ban non-consensual AI deepfakes

On Friday, the Council published its position on updates to the EU's AI Act, including a new ban on AI tools that generate nude images and stricter standards around the use of sensitive personal data. The proposal is part of the wider "OmnibusVII" legislative package designed to simplify the EU's digital regulatory framework and reduce compliance burdens for businesses.
While the changes aim to make the rules more practical for companies, the latest amendments also reflect growing concerns about the misuse of AI technologies and the need for stronger safeguards.
One of the most significant changes proposed in the updated EU AI Act is a new ban targeting AI tools capable of generating sexual or intimate images without consent.
According to the Council, the new provision explicitly prohibits “AI practices that involve the creation of non-consensual sexual and intimate content or child sexual abuse material.” The move comes as regulators across Europe increasingly confront the real-world harms caused by AI-generated deepfake content.
See also: Deepfakes and injection attacks breach identity verification

The proposal follows a similar step earlier this week, when members of the European Parliament approved their own version of the ban. The alignment between the two bodies suggests that restrictions on AI tools for nude images are likely to remain in the final version of the EU AI Act once negotiations are completed.
The push for stricter rules comes after a high-profile incident involving the Grok chatbot developed by xAI and integrated into the social platform X (formerly Twitter). Since late December, the chatbot is reported to have created millions of non-consensual intimate images that quickly spread online, causing widespread reaction.
In response, the European Commission launched an official investigation into the platform and its AI capabilities earlier this year.
For policy makers, the episode highlighted the speed at which generative AI tools can create and distribute harmful content — and why the EU AI Act needs mechanisms to address such risks.
According to the Council's proposal, the revised deadlines will be:
– 2 December 2027 for autonomous high‑risk AI systems
– 2 August 2028 for high‑risk AI systems embedded in products
See also: Deepfake attacks and biometric spoofing

These extensions aim to provide organizations with clearer guidance and sufficient preparation time, while ensuring the regulatory framework remains enforceable.
