Compliance dates · 2 December 2026 · EU
Two new prohibited AI practices apply from 2 December 2026
Two new prohibited AI practices added by the AI Omnibus apply from 2 December 2026. They are AI systems intended to generate non-consensual intimate imagery of identifiable people, and systems intended to generate child sexual abuse material.
Breach of a prohibition carries fines up to EUR 35 million or 7 per cent of worldwide turnover. A prohibition is not a duty to document, it is a line that cannot be crossed. A prohibited practice has no compliance route: the system either falls inside the description or it does not.
Providers and deployers alike
Providers and deployers of AI systems on the EU market. Both roles are named, so a business that deploys someone else's system is inside the prohibition as well as the firm that built it.
Checking your systems against the two prohibitions
- List the AI systems you provide and the AI systems you deploy.
- Test each against the two new prohibitions rather than against the wider risk tiers.
- Withdraw anything that falls inside either prohibition before 2 December 2026.
- Record the check and its date against the EUR 35 million or 7 per cent exposure.
- Keep the list of systems checked, so a later system can be tested against the same two descriptions.
The EU AI Act system
The two prohibitions were added to the EU AI Act by the Omnibus, so the AI Act system is where they are covered.
EU AI Act £3,000
Risk-based obligations for providers and deployers of AI systems in the EU.
Regulation (EU) 2024/1689 · European Union
Verified 19 August 2026.