Eu parliament bans ai deepfake nudes but gives big tech 3 extra years to obey

Three and a half years. That is how long a European company now has to keep generating non-consensual sexual deepfakes before the law finally knocks. MEPs voted Thursday to outlaw ai systems that fabricate naked bodies from a stranger’s selfie, then immediately postponed every painful compliance deadline until 2027—an eternity in model-release cycles.

The ban that waits until the harm is routine

From December 2027 onward, any platform that lets users undress an unsuspecting face with a prompt will face fines up to 7 % of global turnover. Until then, the practice sits in a regulatory freezer: legal, trackable, monetisable. Start-ups can still harvest engagement from revenge-porn algorithms, provided they promise to add a ‘safety layer’ nobody audits today.

Parliament’s own text calls this lag ‘predictability and legal certainty’. Translation: lobbyists wanted breathing room, and they got 16 months of it. The same cushion applies to ‘high-risk’ ai—biometric border gates, hiring bots, exam-scoring scripts—now granted a Christmas 2027 grace period. A second tranche, covering drones and medical devices already governed by CE-mark rules, slips to August 2028.

Watermark fiction and the sme loophole

Watermark fiction and the sme loophole

Watermark obligations for synthetic audio, video or text do not kick in until November 2026. By that date the diffusion models circulating on Discord will be three generations ahead of whatever watermark survives compression. Mid-caps—firms with up to €500 m annual sales—are folded into the same soft lane, a concession Brussels sells as ‘innovation-friendly’ while Paris and Berlin court ai unicorns.

Consent is redefined as a post-crisis cost. If your likeness ends up on a porn site, you can sue—after the clip has ricocheted across Telegram. The burden of proof stays with the victim, not the middleware that served the pixels. The Parliament even rewards vendors that hoover up personal data to ‘fix bias’, as long as the intrusion is ‘strictly necessary’, a phrase the text never quantifies.

Industry lawyers are already billing hours to map the overlap. A cardiac implant that runs an ai arrhythmia detector must now satisfy both the Medical Device Regulation and the ai Act, but MEPs quietly trimmed the latter’s safety requirements if the former already applies. The result: a thicket of contradictory standards no start-up can navigate without a compliance department the size of Nokia’s.

Meanwhile, the raw computational power to generate a nude doppelgänger doubles every six months. By the time the prohibition is enforceable, a single consumer GPU will produce 4K fakes in real time. The law will arrive pre-outpaced, a museum piece before it is binding.

Brussels has legislated the appearance of control while leaving the machinery untouched. Call it the Brussels two-step: grandstand today, stall tomorrow, regulate never.