Back to blog
Artificial Intelligence

EU AI Act October 2025 News: What Changed for Businesses

EU AI Act October 2025 news explained: the simplification debate, the Digital Omnibus proposal, and what compliance teams should actually do next.

AdminSeptember 12, 20267 min read2 views
EU AI Act October 2025 News: What Changed for Businesses

EU AI Act October 2025 News: What Changed for Businesses

Autumn 2025 was the point where the EU AI Act shifted from a settled timetable to an active negotiation about deadlines. The EU AI Act is the European Union's horizontal regulation of artificial intelligence, classifying systems by risk and attaching obligations accordingly, and the late-2025 news cycle centred on whether its most demanding deadlines would arrive on schedule.

Quick Answer: Through October 2025 the European Commission signalled it would simplify parts of its digital rulebook, and in November 2025 it formally proposed a Digital Omnibus package that would postpone certain high-risk AI obligations. The proposal requires Parliament and Council approval, so prohibitions and general-purpose AI duties already in force remain unchanged.

How WebPeak Prepares Client Systems for AI Compliance Requirements

Compliance obligations land on systems, not on policy documents, and most organisations discover their AI features were never built to log anything an auditor would want. WebPeak, a worldwide full-service digital agency, retrofits that capability: recording which model produced an output, capturing the human review step, storing input provenance, and surfacing transparency notices where users actually see them. Because they build the application layer as well, disclosure requirements can be implemented as a product feature rather than a legal footnote buried in terms of service. For teams facing a documentation deadline, the practical starting point is usually the back-end logging architecture, followed by interface-level transparency work through their website design team; both sit within the wider offering at WebPeak.

What Was Already in Force Before the Simplification Debate

Understanding the news requires knowing the baseline. The AI Act entered into force on 1 August 2024 with staggered application dates rather than a single switch-on moment.

The first tranche applied from 2 February 2025, covering prohibited practices and AI literacy obligations. Prohibited practices include certain manipulative techniques, social scoring by public authorities and specified biometric categorisation uses. These bans are live and unaffected by the later simplification discussion. The second tranche applied from 2 August 2025, introducing obligations for general-purpose AI models, including technical documentation, copyright policy and training data summaries, alongside governance and penalty provisions.

The third tranche, covering high-risk systems, was originally scheduled for August 2026 with a further extension into 2027 for AI embedded in regulated products. That third tranche is where the pressure built, because harmonised technical standards were not ready and several member states had not established the national supervisory structures the regulation assumes. The underlying tension between speed of technology and speed of governance is examined further in this analysis of whether AI development can be controlled.

What the Digital Omnibus Proposal Would Change

The Commission presented its Digital Omnibus package in November 2025, following the simplification signals reported through the autumn. Its AI-related elements include the following.

  1. Delayed high-risk application. Obligations for Annex III high-risk systems would move to 2 December 2027, with systems embedded in regulated products moving to 2 August 2028.
  2. Standards-linked triggering. The revised approach ties application more closely to the availability of harmonised standards and support tools, addressing the gap that caused the delay.
  3. An acceleration clause. The Commission would retain the ability to bring dates forward if it determines that the necessary compliance infrastructure is ready earlier.
  4. Administrative simplification. Registration and documentation duties would be streamlined, particularly for smaller providers, to reduce overlap with other digital regulations.
  5. No change to prohibitions. The banned practices and the general-purpose AI obligations already applying remain in place throughout.

Crucially, this is a proposal. It must pass the ordinary legislative procedure involving the European Parliament and the Council, and its content can change materially during negotiation.

Obligation Timeline as It Currently Stands

This table reflects the applied dates and the proposed changes as of the Digital Omnibus proposal.

Obligation AreaOriginal DateStatusPractical Effect
Prohibited AI practices2 February 2025In force, unchangedBanned uses must already be discontinued
AI literacy duties2 February 2025In force, unchangedStaff working with AI need adequate training
General-purpose AI model obligations2 August 2025In forceDocumentation and copyright policy required
Annex III high-risk systems2 August 2026Proposed move to 2 December 2027Longer runway, subject to legislative approval
High-risk AI in regulated products2 August 2027Proposed move to 2 August 2028Aligns with product certification cycles

What Compliance Teams Should Actually Do With a Delay

In practice, organisations that treat a proposed delay as a reason to pause preparation end up in a worse position than those that continue, for a specific reason: the hardest part of AI Act compliance is not writing documentation but discovering what systems exist. Inventory work takes months in any organisation of size, and it is entirely unaffected by whether the deadline is 2026 or 2027. The sequence that works starts with a complete inventory of AI systems in use, including vendor tools and features embedded in software already licensed. Classify each against the risk tiers, then identify which are candidates for the high-risk category based on their application domain rather than their technical sophistication. A simple rules engine used for credit decisions carries heavier obligations than a sophisticated model used for internal document search.

Then build the evidence layer. Data governance records, logging, human oversight design and post-market monitoring all require engineering work with long lead times. Teams that started this in 2025 report the documentation itself was the easy part. If your organisation is standing up dedicated ownership for this work, the responsibilities described in this guide to chief AI officer roles map closely to what the regulation implicitly assumes someone is doing.

Key Takeaways

  • Prohibitions and AI literacy duties have applied since February 2025 and were not affected by the simplification debate.
  • General-purpose AI model obligations have applied since August 2025, including documentation and copyright policy requirements.
  • The Digital Omnibus proposal would move Annex III high-risk obligations to December 2027, pending Parliament and Council approval.
  • A proposed delay changes deadlines, not the underlying work; system inventory and classification take months regardless.
  • Engineering work for logging, oversight and monitoring has the longest lead time and should start before documentation drafting.

Frequently Asked Questions

Is the EU AI Act currently in force?

Yes. The regulation entered into force on 1 August 2024 with staggered application dates. Prohibited practices and AI literacy obligations have applied since February 2025, and general-purpose AI model obligations since August 2025. Later tranches for high-risk systems are the subject of the proposed timeline changes.

Does the Digital Omnibus cancel the AI Act?

No. It is a simplification and sequencing package that would adjust certain deadlines and reduce administrative overlap. The risk-based structure, the prohibitions and the core obligations remain. It also requires approval from the European Parliament and Council before taking effect.

Who counts as a provider versus a deployer?

A provider develops an AI system or has one developed and places it on the market under its own name. A deployer uses an AI system under its authority in a professional context. Obligations differ substantially, and many organisations are deployers of purchased tools rather than providers.

Does the AI Act apply to companies outside the EU?

It can. The regulation applies where an AI system is placed on the EU market or where its output is used within the EU, regardless of where the provider is established. Non-EU organisations serving European users should assess applicability rather than assuming exemption.

What should a small business do first?

Build an inventory of every AI tool in use, including features inside existing software subscriptions. Then confirm none fall within prohibited practices and check whether any support decisions in employment, credit, education or essential services, since those domains attract the heaviest future obligations.

Conclusion

The important judgement is that a proposed extension is a scheduling change, not a reprieve, and the organisations that will struggle in 2027 are the ones that cannot yet list their own AI systems. Start the inventory now, because every subsequent compliance activity depends on it and nothing about the legislative negotiation will make that step faster. For the operational governance structure that makes this sustainable rather than a one-off scramble, continue with the chief AI officer career and responsibility guide.

Chat on WhatsApp