Guide / EU AI Act

The EU AI Act changed. The operating model still matters.

Regulation (EU) 2026/1744 simplifies parts of the EU AI Act and moves several deadlines. It does not remove the risk-based model, and entry into force does not mean every amendment applies at once.

V Vanderburgh.it EU AI ACT UPDATE

Nine changes, three key dates, and one risk-based framework that remains in place.

Law

2026/1744

Adopted8 July 2026 Published24 July 2026 In force27 July 2026

The amendment is real and directly changes three EU regulations.

Timing

Application is staggered

2026New prohibitions and legacy marking 2027Annex III high-risk requirements 2028Annex I product-related requirements

Entry into force and a provision's application date are different legal moments.

Enterprise impact

More time, not less work

UseRefresh roadmaps and inventories ProofKeep governance evidence moving WatchStandards, guidance, and sector rules

The delay should improve implementation quality, not pause the programme.

Bottom line

The structure remains

Still hereRisk classification and controls ChangedScope details, supervision, timing NeededOwnership and operational evidence

This is targeted simplification, not a repeal of the EU AI Act.

Official Journal 24 July 2026

Regulation (EU) 2026/1744 was published as the Digital Omnibus on AI.

Entry into force 27 July 2026

The Regulation entered into force on the third day after publication.

High-risk requirements 2027 / 2028

Key Chapter III obligations now apply later, depending on the system category.

Application timeline

Three dates enterprises should put on the roadmap

These dates describe when specific amended provisions apply. They should not be read as one universal deadline for the whole AI Act.

01

2 December 2026

The new prohibited-practice provisions concerning non-consensual intimate material and child sexual abuse material apply. Relevant synthetic-content systems placed on the market before 2 August 2026 must also comply with Article 50(2).

02

2 December 2027

Chapter III, Sections 1–3 apply to high-risk systems classified under Article 6(2) and Annex III, except for Article 6(5).

03

2 August 2028

The same parts of Chapter III apply to product-related high-risk systems classified under Article 6(1) and Annex I.

Nine important amendments

What changed, and what that means in practice

Each card separates the legal change from the operating decision it creates. The short version is useful; the exact scope still belongs in the legal and compliance review.

01 / Safety

Prohibited practices

Article 5

  • Before: Eight prohibited AI practices formed the original baseline.
  • Now: New prohibitions address AI systems used to generate or manipulate non-consensual intimate material and child sexual abuse material.
  • The provider rules also address reasonably foreseeable and reproducible harmful outcomes where reasonable and adequate safeguards are missing.
Enterprise read: Review generative-media safeguards, misuse reporting, output controls, and deployer restrictions before 2 December 2026.
02 / Timing

High-risk systems

Article 113

  • Before: Key high-risk requirements were due in August 2026 or August 2027, depending on category.
  • Now: Annex III systems move to 2 December 2027.
  • Annex I product-related systems move to 2 August 2028.
Enterprise read: Re-baseline delivery plans, but keep classification, evidence, data governance, and control design active.
03 / Transparency

Synthetic content

Articles 50 and 111

  • Before: Article 50(2) was due to apply generally from 2 August 2026.
  • Now: Systems placed on the market before that date have until 2 December 2026 to meet the machine-readable marking and detectability obligation.
  • This is a legacy-system extension, not a postponement of every transparency obligation.
Enterprise read: Separate legacy and new systems in the implementation register instead of applying one deadline to both.
04 / Registration

Article 6(3) systems

Article 49 and Annex VIII

  • Before: Providers determining that an Annex III system was not high-risk still had to register it in the EU database.
  • Now: Registration remains mandatory, but the required information is simplified.
  • The provider must still document its assessment before market placement or use.
Enterprise read: Do not treat an Article 6(3) determination as an exemption from evidence or registration.
05 / People

AI literacy

Article 4

  • Before: Providers and deployers had to ensure a sufficient level of AI literacy among relevant staff.
  • Now: They must take measures that support the development of AI literacy.
  • The amended text says this does not require a guaranteed level for every individual.
Enterprise read: The wording is softer, but a defensible training and enablement programme is still a legal expectation.
06 / Data

Bias correction

New Article 4a

  • Before: The exceptional legal basis focused on providers of high-risk AI systems.
  • Now: Strictly necessary processing can also cover deployers of high-risk systems and providers or deployers of other AI systems and models.
  • Detailed necessity, security, access, deletion, and documentation safeguards still apply.
Enterprise read: This is a bounded route for bias work, not a broad permission to process sensitive data.
07 / Supervision

AI Office powers

Article 75

  • Before: Exclusive EU-level competence was narrower where a GPAI model and downstream system were involved.
  • Now: It also covers systems and models developed by providers within the same undertaking.
  • Exceptions preserve national or sector supervision for listed product, infrastructure, law-enforcement, financial, and justice uses.
Enterprise read: Map the provider group structure and system category before assuming which authority leads supervision.
08 / Proportionality

Small mid-caps

Articles 3 and 99

  • Before: Several proportionality measures and lower-of-two penalty caps were focused on SMEs.
  • Now: Small mid-cap enterprises are defined and included in targeted support and penalty proportionality.
  • For specified fines, an SMC is capped at the applicable percentage or fixed amount, whichever is lower.
Enterprise read: Confirm formal SMC status; it is a defined category, not a general description of company size.
09 / Products

AI-enabled machinery

Annex I and Regulation 2023/1230

  • Before: The Machinery Regulation sat in Section A of Annex I, bringing direct AI Act high-risk requirements alongside product rules.
  • Now: It moves to Section B and the direct application of the AI Act is limited.
  • Equivalent AI-related health and safety requirements are to be integrated into the machinery framework.
Enterprise read: This is a sectoral compliance route, not the disappearance of AI requirements for machinery.

The easy mistake

Entry into force is not the same as application

The Regulation became part of EU law on 27 July 2026. That does not make every newly amended obligation immediately enforceable from that date. Article 113 and the amending provisions set different application dates for different requirements.

For programme owners, the useful question is not simply “Is the law in force?” It is “Which provision applies to which system, entity, and activity, from which date?”

What did not change

The AI Act remains a horizontal, risk-based framework. System classification, provider and deployer roles, technical controls, documentation, human oversight, monitoring, and evidence still determine the compliance workload.

Enterprise action plan

Use the extra time to improve the operating model

A delayed date is valuable only when it produces better inventory, ownership, controls, and evidence.

Inventory

Reconfirm classification

Map Annex I, Annex III, Article 6(3), GPAI, legacy synthetic-content, and machinery systems separately.

Roadmap

Reset dates precisely

Update each control plan against its actual provision and application date instead of moving one global milestone.

Evidence

Keep the proof moving

Continue technical documentation, data governance, testing, logging, human oversight, and post-market monitoring work.

Change

Watch the implementation layer

Track standards, Commission guidance, national enforcement arrangements, and sector-specific delegated acts.

URLs and official resources

Go from the summary to the source

Use the enacted regulation for legal detail and the Commission resources for implementation guidance, exploration, and practical questions.

  1. Enacted amendment Regulation (EU) 2026/1744

    The final Digital Omnibus on AI text published in the Official Journal.

    eur-lex.europa.eu/eli/reg/2026/1744/oj/eng/html
  2. Base regulation Regulation (EU) 2024/1689

    The original EU AI Act, including its articles, annexes, and recitals.

    eur-lex.europa.eu/eli/reg/2024/1689/oj/eng/html
  3. Commission overview EU AI Act policy page

    The risk model, implementation timeline, current guidance, and policy updates.

    digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
  4. Practical help AI Act Service Desk

    AI Act Explorer, compliance checker, FAQs, and access to the official Service Desk.

    ai-act-service-desk.ec.europa.eu/en

How to use the links

Start with the enacted text

This guide is based on the final Regulation published in the Official Journal, not on the earlier Commission proposal or negotiation drafts. The Commission pages are useful navigation and implementation resources, but EUR-Lex remains the primary legal source.

Scope note

This is a practical editorial guide, not legal advice. Apply the enacted text to the facts of the organisation, system, role, and sector, and involve qualified legal counsel where the classification or obligation is material.

The short version

The dates moved. Accountability did not.

Regulation (EU) 2026/1744 gives enterprises more implementation time and simplifies selected obligations. The strongest response is to use that time to improve system inventories, control ownership, technical evidence, and the connection between legal interpretation and live AI operations.