Tech AI News - 테카이

The EU AI Act in August 2026, what really changes — the real-time/retrospective facial recognition boundary and the shock of the 'Digital Omnibus'

· 15 min read

This post was translated from the Korean original by AI.한국어 원문 읽기 →

The EU AI Act in August 2026, what really changes — the real-time/retrospective facial recognition boundary and the shock of the 'Digital Omnibus'

August 2, 2026 has been billed for more than a year as the EU AI Act's most important date. But in November 2025 the European Commission unveiled its 'Digital Omnibus' package proposing to delay high-risk AI obligations by up to 16 months, and on May 7, 2026 the European Parliament and Council reached a provisional agreement. The result is more than a schedule change. The ban on real-time facial recognition survived, but retrospective facial recognition and workplace and education AI obligations are pushed beyond December 2027. Here is how the 'world's first AI regulation' wobbled, and what remained intact.


Background — why this topic now

The EU AI Act is the world's first comprehensive AI regulation, in force since August 1, 2024.

Under its phased schedule, the 'prohibited practices' provisions took effect in February 2025, and August 2, 2026 was slated for the full application of obligations for high-risk AI systems. That domain covers hiring algorithms, credit scoring engines, biometric identification systems, educational AI, public service AI, and more (Netguardia, 2026).

The fines exceed the GDPR's. Under Article 99 of the official text of the EU AI Act (Regulation (EU) 2024/1689), they are imposed in a three-tier structure. Violations of prohibited practices (Article 5) carry up to 35 million euros or 7% of global turnover, violations of high-risk system obligations 15 million euros or 3% of turnover, and supplying incorrect information to authorities 7.5 million euros or 1% of turnover (AI Act Service Desk, 2026). All follow the 'whichever is higher' principle, and the penalty provisions themselves have already been in force since August 2, 2025.

But on November 19, 2025, the situation changed abruptly when the European Commission unveiled its 'Digital Omnibus on AI' package. The measure reflected industry concern that standards and compliance tools would not be ready in time (IIEA, December 2025). On March 18, 2026 the European Parliament's joint IMCO–LIBE committee adopted the deferral by 101 for / 9 against / 8 abstentions, and the March 26 plenary vote granted a negotiating mandate by 569 for / 45 against / 23 abstentions (European Parliament, March 2026). The second trilogue on April 28 broke down and then resumed, and on May 7, 2026 the European Parliament and the Council reached a provisional agreement(Hogan Lovells, May 2026).

However, as of late May 2026, when this article was written, the provisional agreement has not yet been formally adopted. Formal votes in both the Parliament and Council plenaries must be completed in June–July, and if it is not formally adopted before August 2, the original schedule takes effect as is (NicFab, May 2026 / White & Case, May 2026). There is another variable to watch. During negotiations, the European Parliament proposed adding a new prohibition to Article 5 that was not in the Commission's original draft — a ban on 'nudifier apps' — a provision explicitly prohibiting AI systems that generate or manipulate sexual or intimate images of identifiable real people without consent (MediaLaws, March 2026).

This article answers three questions. First, what actually changes and what is deferred in August 2026? Second, where is the boundary drawn between real-time and retrospective facial recognition? Third, what does this change mean for AI regulation in countries outside the EU, such as Korea?


Key data and current state

  • AI Act entry into force: August 1, 2024 (Regulation (EU) 2024/1689)
  • Prohibited practices in force: February 2, 2025 (Clearview-style facial scraping, emotion recognition in workplaces and education, etc.)
  • Original date for high-risk obligations: August 2, 2026 (Annex III systems)
  • Digital Omnibus proposal date: November 19, 2025, announced by the Commission
  • European Parliament committee adoption: March 18, 2026 (101 / 9 / 8)
  • Provisional agreement date: May 7, 2026, Parliament–Council agreement
  • New high-risk obligation dates (provisional): December 2, 2027 (standalone high-risk), August 2, 2028 (product-embedded) (Addleshaw Goddard, May 2026)
  • Watermarking obligation deferral: August 2, 2026 → December 2, 2026 (Morrison Foerster, December 2025)
  • Fines (Regulation (EU) 2024/1689 Article 99): Three-tier structure — Tier 1 (Article 5 prohibition violations) €35M or 7% of turnover, Tier 2 (provider and deployer obligation violations) €15M or 3% of turnover, Tier 3 (supplying incorrect information to authorities) €7.5M or 1% of turnover, all on the 'whichever is higher' principle (official EU AI Act text Article 99 / AI Act Service Desk, 2026)
  • Penalty provisions effective date: Already applied since August 2, 2025 (AI Act Article 113(b))
  • Compliance cost estimates (consulting-firm modeling, wide variance by source): Large enterprises USD 8–15 million, mid-sized USD 2–5 million, SMEs USD 0.5–2 million (Axis Intelligence / ai2.work estimates, 2026) — though SoftwareSeni, Witness, and others give more conservative figures

? Interpretation: On the surface it looks like 'the EU delayed regulation', but the prohibited practices survived intact and what was deferred is the high-risk system obligations. In other words, the key point is that the 'this is absolutely not allowed' domain was left untouched, and only the timing of the 'this requires impact assessment, documentation, and human oversight' domain was pushed back.


In-depth analysis

1. The 'Digital Omnibus' — what was deferred and what survived

The 'Digital Omnibus on AI' the Commission unveiled in November 2025 is a package that leaves the AI Act's core structure untouched and adjusts only timing and administrative burden. It explicitly set out the following three purposes (Hogan Lovells, May 2026).

First, align the timing of application with the availability of standards and tools.

Second, reduce the administrative burden, especially for SMEs.

Third, clarify the interaction between the AI Act and existing sector-specific regulation.

Deferred items:

  • High-risk AI system obligations (Annex III standalone): August 2, 2026 → December 2, 2027
  • Product-embedded high-risk systems: August 2, 2027 → August 2, 2028
  • Watermarking/transparency obligations (Article 50(2)): August 2, 2026 → December 2, 2026 (limited to systems already on the market)
  • AI systems in employment and HR: August 2, 2026 → December 2, 2027 (DLA Piper, 2026)

Items that survived intact:

  • All Article 5 prohibited practices: Social scoring, manipulation of vulnerable groups, real-time remote biometric identification in public places, indiscriminate facial scraping, emotion recognition in workplaces and education, etc. already took effect in February 2025 and are not subject to deferral
  • The €35 million / 7% of turnover penalty for violations — the strongest penalty remains as is

Analysis: The EU did not retreat; it is closer to leaving the wall (the prohibitions) in place and lowering the height of the stairs (the obligations) by one step.
Still, since the high-risk obligations were precisely the area industry found most burdensome, the practical compliance pressure is considerably eased.

Consulting-firm estimates run at USD 8–15 million for large enterprises and USD 2–5 million for mid-sized companies (Axis Intelligence / ai2.work, 2026), but these are modeling-based estimates with wide variance by source, and actual costs vary greatly by industry and existing governance infrastructure, which should be kept in mind (SoftwareSeni, January 2026 / Witness Compliance, March 2026 analyses).

2. Real-time vs. retrospective facial recognition — the key boundary

The most sophisticated part of the EU AI Act's facial recognition regulation is the boundary between 'real-time' and 'post-remote' (retrospective) facial recognition. It is the same technology, but its legal status changes completely depending on the time axis in which it is applied.

Real-time remote biometric identification (RBI) — prohibited in principle:

Under Article 5(1)(h), real-time remote biometric identification in public places for law enforcement purposes is prohibited in principle. The exceptions are very limited.

  • Searching for specific missing persons (including children)
  • Preventing a specific, substantial, and imminent threat to the life or physical safety of natural persons or a terrorist attack
  • Locating or identifying suspects of the serious crimes listed in Annex II

Even then, completion of a fundamental rights impact assessment (Article 27) before use, registration in the EU database (Article 49), and prior authorization by a judicial or independent administrative authorityare mandatory conditions (EU AI Act Article 5).

Retrospective remote biometric identification — permitted under a 'high-risk' classification:

This is the part State of Surveillance (March 2026) called a 'sleight of hand'. Retrospective facial recognition, which analyzes recorded footage after the fact, is not banned but classified as a 'high-risk system'. Under Article 26, it may be used if the following requirements are met.

  • Binding prior authorization by a judicial or administrative authority
  • 'Strict necessity' for a specific criminal act
  • No decision producing adverse legal effects on an individual based solely on the AI output
  • No indiscriminate use — cannot be used without a link to a criminal act, proceeding, imminent threat, or the search for a specific missing person
  • Obligation to record and report each instance of use

Put simply, recording a protest and then, days later, matching every face against a database is legal if it passes judicial approval. This is the core weakness of the 'retrospective' category.

Analysis: The dystopian 'chilling effect' covered in Part 1 begins with the weakness of this boundary. Even if a protester thinks 'there is no real-time surveillance now, so I'm safe', because the possibility of after-the-fact analysis remains , self-censorship can arise in the exercise of freedom of expression and assembly.

3. The member-state variable — consistency vs. differentiation

Another complexity of the AI Act is the possibility of differentiated implementation by member state. It is a weakness both State of Surveillance (March 2026) and the Future of Privacy Forum (April 2026) pointed out.

First, each member state may pass laws stricter than the AI Act. That means a scenario is possible in which Germany effectively bans facial recognition outright while Hungary allows broader exceptions.

Second, the 'serious crimes' that form the exception for real-time RBI are defined in member states' criminal law. This means the same act may be defined as a serious crime in one country, allowing facial recognition, and not in another (Future of Privacy Forum, April 2026).

Third, each member state must designate at least one national competent authority, and these authorities are coordinated through the European AI Board. But the fact that designation of competent authorities and accreditation of notified bodies were themselves running late during the Digital Omnibus negotiations was the core reason for the deferral decision (DLA Piper, 2026).

Analysis: The phrase 'a single EU standard' is not accurate. In reality it is a multi-layered structure with additional member-state regulation stacked on an EU baseline. This layering cuts both ways for the spread of global standards — on one hand it allows fine-grained protection, but on the other there is a risk that the most lenient member state becomes the entry route into the EU market.


Implications for Korea and Asia

As covered in Part 3, Korea enforced its AI Basic Act on January 22, 2026, becoming in practice the country that applied AI regulation in full ahead of the EU. With the EU now deferring high-risk obligations through the Digital Omnibus, the global regulatory landscape is reshaped as follows.

First, the 'Korea is ahead of the EU' configuration persists for a while. While the EU's high-risk obligations are pushed to December 2027–August 2028, Korea's AI Basic Act is already in force. For Korean companies, domestic compliance effectively becomes a head start for entering the EU.

Second, the EU's deferral is an opportunity in the global standards competition. The 16-month gap the EU voluntarily opened is a window of time in which Korea, Japan, Canada, the UK, and others can refine their own regulation. If Korea combines its 'Biometric Information Protection Guide' (December 2024) with the AI Basic Act's enforcement decree to quickly update guidelines aligned with the EU AI Act, the K-AI regulatory model could influence the formation of the global baseline.

Third, the real-time/retrospective facial recognition boundary problem operates identically in Korea. Korea's AI Basic Act, unlike the EU's, has no explicit prohibitions (Part 3 analysis), but as facial recognition use cases grow, the same policy questions will be posed. Concrete cases such as after-the-fact facial recognition on protest and assembly footage, and the appropriateness of real-time facial recognition pilots in public places, are likely to rise onto the policy agenda within the next one to two years.

Fourth, Korean AI companies need a new timing strategy for entering the EU. When Suprema, Alchera, Hanwha Vision, and others enter the EU market, only part of the watermarking and transparency obligations will apply as of August 2026, and full high-risk system certification comes after late 2027. However, the prohibited practices (Article 5) apply immediately, so the EU specifications of facial recognition product lines must already be designed to exclude indiscriminate scraping, emotion recognition, and the like.


Outlook and variables to watch

  • Timing of final adoption of the provisional agreement: The May 7, 2026 provisional agreement needs formal adoption by both the Parliament and the Council. The variable is that, in theory, if it is not finally adopted before August 2, 2026, the original schedule could take effect as is (DLA Piper, April 2026).
  • Additional member-state legislation: Whether Germany, France, the Netherlands, and others introduce additional restrictions at the national level will determine the degree of differentiation within the EU.
  • The first Article 5 violation case: The moment an EU member state imposes the first substantive sanction for the prohibited practices in force since February 2025 will send a global message. It is an indicator to watch in the second half of 2026 to the first half of 2027.
  • Progress on standardization: When European standardization bodies such as CEN-CENELEC complete high-risk AI standards will determine whether the Digital Omnibus's 'sunset date' is triggered. If the standards are completed quickly, the Commission could bring the application date forward (Cooley, November 2025).

Conclusion

Three things the reader should take from this article.

First, the headline 'EU AI Act retreat' is inaccurate. The prohibited practices are alive, and the strongest fine (7% of turnover) remains. What was deferred is the timing of high-risk system obligations, and even that is a realistic adjustment to the absence of standards and certification infrastructure.

Second, the real-time/retrospective facial recognition boundary is the subtlest variable in the dystopian scenario. Even the EU AI Act cannot stop a structure in which after-the-fact facial recognition on protest footage is legalized through judicial approval. Monitoring by civil society and the press will determine how this area actually operates.

Third, Korea has been handed both a window of time and an opportunity. During the 16 months in which global regulatory standards are reshaped by the EU's deferral, if Korea refines EU-aligned guidelines by combining its experience operating the AI Basic Act with the 'Biometric Information Protection Guide', the K-AI regulatory model could have a substantive influence on the formation of the global baseline.


This series is the four-part 'Surveillance Society: Utopia/Dystopia'.

Part 1: Surveillance society 2026 — utopia or dystopia, which are we closer to?
Part 2: China's social credit system 2026 — why the real threat is 'integrated data infrastructure', not a single score
Part 3: Korea's digital trust society — from Incheon Airport's Smart Pass to the AI Basic Act
Part 4: The EU AI Act in August 2026, what really changes — the boundary between real-time and retrospective facial recognition (this post)


Text of the prohibition on real-time remote biometric identification

Requirements for the use of retrospective remote biometric identification

Text of the three-tier penalty structure (€35M/7%, €15M/3%, €7.5M/1%)

Official EU service desk commentary

Official EU commentary on the penalty provisions

⚖️ Digital Omnibus — policy changes

Official information on the Omnibus's legislative progress

Analysis of the plenary vote (569 in favor) and the 'nudifier ban' proposal

Analysis of the formal adoption schedule after the May 7 provisional agreement

Analysis of the legal effect of the provisional agreement and the August 2 deadline

Analysis of the May 7 provisional agreement

? In-depth analysis of real-time/retrospective facial recognition

Analysis of the weakness of the real-time/retrospective boundary

? Compliance, practice, and cost estimates

USD 8–15 million estimate for large enterprises (re-cited from ai2.work)

More conservative estimates such as €30K–100K for SMEs

Practice-based step-by-step cost analysis

Analysis of differentiated provisions such as the SME fine calculation method (lower amount applies)

  • #dystopia
  • #european union
  • #eu ai act
  • #digital omnibus
  • #facial recognition regulation
  • #real-time biometric identification
  • #retrospective facial recognition
  • #high-risk ai systems
  • #global ai regulation
  • #fundamental rights impact assessment
AI Industry Analysis

AI and the future of human relationships and mental health

A clinical trial found an AI chatbot cut depressive symptoms nearly in half, while a study found that the more people rely on AI friends, the lonelier they get, and both landed at the same time. Whether AI becomes a treatment for the mind or a substitute for relationships that deepens isolation: we are at that fork now.

· 7 min

AI Industry Analysis

The AI data center power problem — 'electricity hog' or engine of the green transition? (2026 Utopia vs. Dystopia ⑥)

The GPU drought is over, and the contest is now decided by power. In 2026, the approval rate for data center grid connections in Korea's capital region fell to 1.9%, and in the US a $130 billion project was canceled 'for lack of power'. Is AI devouring the climate, or bringing the energy transition forward? This installment examines both faces with data.

· 8 min

AI Industry Analysis

The age of AI warfare: is a world where machines decide life and death a utopia? — the reality of a battlefield where drones became artillery

In March 2026, 96% of battlefield casualties in Ukraine were caused by drones. In April, for the first time in history, an enemy position was captured by unmanned platforms alone. The way war is fought is changing, but the suffering war brings is not. When the enemy comes with drones, will we fight with hand grenades? Thoughts from a citizen of a divided nation.

· 13 min

AI Industry Analysis

The real front line of the 2026 AI industry isn't models — the rise of the 'token economy' and a three-axis strategy for Korean companies

In 2026, the AI industry is no longer decided by 'which model is smarter'. The Anthropic–SpaceX compute deal, the Pentagon's selection of eight AI vendors, and Goldman Sachs' $7.6 trillion forecast all point one way: the true opening of an 'AI compute economy' in which tokens are the new currency. Korean companies must immediately realign around a three-axis strategy that binds 'token cost, power and chip supply, and use policy', beyond comparing model performance.

· 11 min