All articles

EU AI Act: what Regulation (EU) 2026/1744 actually changed

The Digital Omnibus on AI was published on 24 July 2026. It defers high-risk AI deadlines and adds two new prohibitions — but it did NOT defer the Article 50 transparency obligations.

6 min read
ComplianceForge AI

Correction notice (29 July 2026). An earlier version of this article claimed that the European Parliament voted on a package called "Omnibus VII" on 26 March 2026, and that the Article 50 transparency deadline had moved to November 2026. Both claims were wrong, as were several of the sources cited. The article has been rewritten from the text of Regulation (EU) 2026/1744 as published in the Official Journal on 24 July 2026. If you planned your compliance work against the earlier version, check your Article 50 deadline — it is 2 August 2026, not November.

Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It is the first and only amendment to the EU AI Act since its adoption.

If you use AI in your business, the single most important point in this article is this: the high-risk deadlines were deferred, the transparency obligations were not.

Deadlines after the amendment

CategoryDeadlineChange
Prohibited practices (Art. 5, points a–h)2 February 2025unchanged — already active
AI literacy (Art. 4)2 February 2025unchanged — already active
GPAI models2 August 2025unchanged — already active
Transparency (Art. 50)2 August 2026unchanged
Art. 50(2) marking — systems on the market before 2 Aug 20262 December 2026new transitional period
New prohibitions (Art. 5(1)(ba) and (bb))2 December 2026new
High-risk standalone (Annex III)2 December 2027deferred from 2 Aug 2026
High-risk embedded (Annex I)2 August 2028deferred from 2 Aug 2027

Source: Regulation (EU) 2026/1744, Official Journal

Article 50 was not deferred — and this is the costly misreading

Transparency obligations apply from 2 August 2026. Regulation 2026/1744 left them untouched. That means:

  • Art. 50(1) — if you provide a system that interacts directly with people, users must know they are talking to an AI
  • Art. 50(3) — if you use emotion recognition or biometric categorisation, you must inform the people exposed to it
  • Art. 50(4) — if you publish deep fake content or AI-generated text to inform the public, you must label it

There is one transitional period, and it is narrow. The new Art. 111(4) gives you until 2 December 2026 only if you are a provider, only for the machine-readable marking obligation in Art. 50(2), and only for systems placed on the market before 2 August 2026.

If you are a deployer — you use AI tools rather than build them — you get no transitional period at all. Your date is 2 August 2026.

The high-risk deferral is unconditional

The dates 2 December 2027 and 2 August 2028 are fixed calendar dates.

This is worth stressing because the Commission's proposal COM(2025) 836 contained a mechanism under which application would have depended on the Commission confirming that harmonised standards were ready. That mechanism was not adopted. Some commentary published before the final text still describes it as if it were in force — it is not.

The reason for the deferral is the delay in CEN and CENELEC harmonised standards for high-risk systems. Without them, businesses cannot know exactly how to demonstrate conformity.

Two new prohibitions — Art. 5(1)(ba) and (bb)

The regulation adds two new points to Art. 5(1), applying from 2 December 2026:

  • (ba) — AI systems that generate or manipulate realistic intimate material depicting an identifiable real person without their explicit consent
  • (bb) — the same, for child sexual abuse material within the meaning of Directive 2011/93/EU

The scope is narrower than it looks. Two paragraphs were added alongside the prohibitions (Art. 5(1a) and 5(1b)) that substantially narrow liability:

  • a provider is caught only if this is the system's intended purpose, or if such an outcome is reasonably foreseeable and reproducible without significant technical modification — and at the same time the system lacks effective technical safeguards. If you have working safeguards and a mechanism to correct reported misuse, you have a defence.
  • a deployer is caught only if they use the system for that purpose. Incidental generation does not trigger the prohibition.

Recital 47 states explicitly that the prohibition should not prevent providers from developing the technical capabilities as such.

We draw no conclusion on penalties for these two points. Art. 5 breaches fall within the highest tier under Art. 99(3), but the date from which the new points become enforceable is not expressly stated, and the available expert analyses cite conflicting figures. Get legal advice for a concrete assessment.

Three categories that are already active

Prohibited practices (Art. 5, points a–h) — since February 2025

Social scoring, manipulative AI exploiting vulnerabilities, untargeted scraping of biometric data from the internet, emotion recognition in the workplace — all already prohibited.

AI literacy (Art. 4) — since February 2025

Every organisation using AI must take measures so that its staff understand the capabilities, limitations and risks of the tools they use.

Regulation 2026/1744 softened the wording — from "ensure a sufficient level" to "take measures to support the development" of AI literacy, with an explicit statement that no specific level of literacy needs to be guaranteed for any individual. The new wording applies from 27 July 2026. The obligation itself dates from February 2025.

GPAI models — since August 2025

Providers of general-purpose models must meet transparency obligations, including documentation of training data and copyright policy. This applies primarily to providers, but check whether yours publishes compliance documentation.

What to do

If you generate or publish AI content: your deadline is 2 August 2026, not November. If you planned against older information, check that plan now.

If you have high-risk systems: you have until December 2027 or August 2028, but a risk management system and technical documentation take months of work.

If you simply use AI day to day: Art. 4 and Art. 5 are already in force.


Note: a consolidated official text of the AI Act with the amendments incorporated does not yet exist. This article is based on the source texts of Regulation (EU) 2024/1689 and Regulation (EU) 2026/1744 as published in the Official Journal. At the time of publication, artificialintelligenceact.eu and the European Commission's AI Act Service Desk had not been updated and still showed pre-omnibus deadlines.

Sources: Regulation (EU) 2026/1744 · Regulation (EU) 2024/1689 (AI Act) · European AI Office

Want to know your compliance status?

Free questionnaire, AI classification and compliance score in 30 minutes.