The EU Just Updated the AI Act Again: Here’s What CIPP/E Privacy Candidates Should Know
- Olufunmilayo Owolabi
- Jun 22
- 4 min read

If you've been following European privacy and technology law recently, you've probably noticed that the conversation has expanded far beyond personal data.
Today, privacy professionals are increasingly finding themselves involved in discussions about artificial intelligence, algorithmic accountability, risk management, and governance. As organizations adopt artificial intelligence tools across recruitment, education, healthcare, financial services, and countless other sectors, regulators face a new challenge: how to create rules that protect individuals without adding unnecessary complexity for organizations trying to comply?
That question sits at the center of the latest update to the European Union Artificial Intelligence Act.
On May 7, 2026, the European Parliament and the Council of the European Union reached a provisional agreement to amend parts of the Artificial Intelligence Act through what is being called the Artificial Intelligence simplification package. While the headlines focused on delayed compliance deadlines and regulatory exemptions, the changes reveal something much bigger about how European regulation evolves once organizations begin implementing it in practice.
The Original Rules Were Starting to Collide With Other Laws
When the Artificial Intelligence Act was adopted, its goal was clear: create safeguards for high-risk artificial intelligence systems while protecting fundamental rights across the European Union.
The challenge emerged when organizations started mapping the law against their existing compliance obligations.
Consider a manufacturer developing an artificial intelligence-enabled medical device or industrial machine. That product might already be subject to medical device legislation, product safety requirements, cybersecurity obligations, and machinery regulations. The introduction of the Artificial Intelligence Act raised an important question: would organizations need to comply with multiple sets of rules covering similar risks?
That concern became a major focus during negotiations.
The revised agreement attempts to address this issue by clarifying how the Artificial Intelligence Act interacts with existing sector-specific legislation. Machinery products, for example, will generally be regulated through the Machinery Regulation where overlapping requirements already exist.
The objective is not to remove safeguards but to reduce duplication and provide greater clarity about which rules apply in specific situations.
More Time Before Key Compliance Requirements Arrive
The reform also gives organizations additional time to prepare for some of the law's most significant obligations.
Artificial intelligence systems used in areas such as biometrics, education, employment, border management, law enforcement, and critical infrastructure will now have until December 2027 before certain requirements take effect. Artificial intelligence systems embedded within products will have until August 2028.
These extended timelines reflect the reality that compliance involves more than simply reading legislation. Organizations need time to develop governance programs, conduct risk assessments, create documentation processes, implement oversight mechanisms, and establish internal accountability structures.
For many organizations, the challenge is no longer understanding that the rules exist. The challenge is operationalizing them.
The European Union Is Still Drawing Firm Boundaries
Although some requirements have been simplified, the reform package does not signal a softer approach toward high-risk uses of artificial intelligence.
One notable change is the prohibition of so-called "nudifier" applications. These systems use artificial intelligence to generate sexually explicit content involving children or identifiable individuals. Compliance with this prohibition is expected to begin in December 2026.
The reforms also restore requirements for registering high-risk artificial intelligence systems in the European Union database and accelerate timelines for certain transparency obligations related to artificial intelligence-generated content.
Taken together, these measures show that while implementation challenges are being addressed, the European Union remains focused on accountability, transparency, and the protection of fundamental rights.
Why Not Everyone Agrees
Whenever major technology regulation changes, different stakeholders tend to view the outcome through different lenses.
The European technology trade association DIGITALEUROPE welcomed aspects of the reform, particularly efforts to reduce overlapping compliance obligations affecting manufacturers and technology providers. The organization argued that clearer requirements can help companies allocate resources more effectively while maintaining compliance.
Consumer advocacy organizations took a different position. The European Consumer Organisation, known as BEUC, expressed concern that some changes could weaken safeguards originally built into the Artificial Intelligence Act. From their perspective, simplifying compliance should not come at the cost of protections designed to address risks associated with high-risk artificial intelligence systems.
These differing reactions highlight a challenge that appears throughout modern technology regulation. Policymakers must balance innovation, competitiveness, compliance, feasibility, and individual rights simultaneously.
Why This Matters for CIPP/E Exam Preparation
For someone preparing for the Certified Information Privacy Professional/Europe (CIPP/E) certification, this reform provides a useful example of how European regulation works beyond the text of the law itself.
Many concepts covered in the CIPP/E body of knowledge can feel abstract when encountered in study materials. Accountability, transparency, risk-based regulation, protection of fundamental rights, and regulatory cooperation are easier to understand when viewed through real-world developments.
The Artificial Intelligence Act reform brings several of these concepts into focus.
The debate around high-risk systems reflects the European Union's broader risk-based approach to regulation. The emphasis on transparency obligations mirrors principles found throughout the General Data Protection Regulation. The discussion around protecting individuals from harmful uses of artificial intelligence reflects the European Union's long-standing commitment to fundamental rights.
Following developments like this can help candidates move beyond memorization and begin understanding how European institutions apply regulatory principles in practice.
It also helps build familiarity with the broader policy environment that increasingly influences privacy, artificial intelligence governance, cybersecurity, and digital regulation across Europe.
The Bigger Picture
The Artificial Intelligence Act is now entering a phase where many major regulations will eventually be reached.
Once implementation begins, organizations identify practical challenges, regulators receive feedback, and lawmakers evaluate whether adjustments are necessary. The result is often a gradual refinement of the framework rather than a complete redesign.
The latest amendments reflect that process.
For privacy professionals, the reforms offer a reminder that compliance is not a static exercise. Regulatory frameworks continue to evolve as technologies mature, industries adapt, and new risks emerge.
For CIPP/E candidates, this serves as another example of how European institutions balance innovation, accountability, and the protection of fundamental rights when shaping the future of digital regulation.




Comments