Summary
Regulation (EU) 2026/1744 entered into force on 27 July 2026. It amended the AI Act; the original AI Act entered into force on 1 August 2024. Regulation (EU) 2024/1689, art. 113, OJ L 2024/1689, 12.7.2024, p. 123; Regulation (EU) 2026/1744, art. 4, OJ L 2026/1744, 24.7.2026, p. 41.
The new high-risk dates are fixed. The final law does not require a Commission readiness decision. That trigger appeared in COM(2025) 836 final, but the co-legislators removed it.
From 2 December 2027, Chapter III, Sections 1 to 3 apply to Article 6(2) and Annex III systems. Article 6(5) remains outside this delay. The change covers classification, system requirements, and operator duties, not every AI Act rule involving high-risk systems. Regulation (EU) 2026/1744, art. 1(40)(b), OJ L 2026/1744, 24.7.2026, p. 35.
From 2 August 2028, the same sections apply to Article 6(1) and Annex I systems, subject to Section B limits. “Embedded high-risk systems” is useful shorthand, but it is legally incomplete. Article 6(1) also requires a safety component or covered AI product and third-party conformity assessment. Regulation (EU) 2024/1689, art. 6(1), OJ L 2024/1689, 12.7.2024, p. 53; Regulation (EU) 2026/1744, arts. 1(2)(a), 1(40)(b)(ii), OJ L 2026/1744, 24.7.2026, pp. 15, 35.
Amended AI-literacy duties and Articles 102 to 110 apply from 27 July 2026. Most remaining provisions keep the general 2 August 2026 date. Regulation (EU) 2026/1744, arts. 1(5), 1(40)(c), OJ L 2026/1744, 24.7.2026, pp. 16, 35.
The Omnibus extends selected support to qualifying small mid-cap enterprises. It does not confer every SME benefit. The definition requires fewer than 750 persons and specified financial ceilings, after group aggregation. Commission Recommendation (EU) 2025/1099, annex, points 2 to 6, OJ L 2025/1099, 28.5.2025, pp. 6-9.
Sandbox changes have a mixed effect. The AI Office may create a limited Union-level sandbox with priority for SMEs and small mid-caps. Member States must secure national sandbox coverage by 2 August 2027. Qualifying participation in an existing sandbox can satisfy that duty. Regulation (EU) 2024/1689, art. 57(1), OJ L 2024/1689, 12.7.2024, p. 88; Regulation (EU) 2026/1744, art. 1(22)(a), (c), OJ L 2026/1744, 24.7.2026, p. 23.
Providers should keep the 2026 workstream active. They should classify each use, map every duty to its own date, preserve design-change records, and test small mid-cap eligibility. They should not move the entire high-risk programme to 2027 or 2028.
Enactment and legal effect
Regulation (EU) 2026/1744 is final, binding law. The European Parliament and Council adopted it through the ordinary legislative procedure. The Official Journal published it on 24 July 2026. Article 4 set entry into force on the third day after publication. It therefore entered into force on 27 July 2026. It binds every Member State directly. Regulation (EU) 2026/1744, art. 4, OJ L 2026/1744, 24.7.2026, p. 41.
That date belongs to the amending regulation. The original AI Act entered into force on 1 August 2024. Several original provisions already applied before July 2026. Other provisions retain later application dates. Regulation (EU) 2024/1689, art. 113, OJ L 2024/1689, 12.7.2024, p. 123.
The Commission proposal no longer states the operative rule. It proposed a Commission decision confirming adequate compliance support. Annex III duties would apply six months later. Annex I duties would apply twelve months later. The proposal used 2 December 2027 and 2 August 2028 as outside dates. The final regulation replaced that mechanism with fixed dates. COM(2025) 836 final, proposed art. 1(31)(a); Regulation (EU) 2026/1744, art. 1(40)(b), OJ L 2026/1744, 24.7.2026, p. 35.
The revised high-risk dates are fixed and limited
The Annex III date is 2 December 2027. The rule covers Chapter III, Sections 1, 2, and 3, except Article 6(5). Those sections address high-risk classification, system requirements, and operator duties. The affected systems must qualify under Article 6(2) and Annex III. Regulation (EU) 2026/1744, art. 1(40)(b)(i), OJ L 2026/1744, 24.7.2026, p. 35.
Annex III listing does not always end the classification inquiry. Article 6(3) excludes certain listed systems that pose no significant risk under its conditions. A system that profiles natural persons remains high-risk. A provider claiming the exclusion must document its assessment and register the system. Regulation (EU) 2024/1689, art. 6(3)-(4), OJ L 2024/1689, 12.7.2024, p. 54.
The Annex I date is 2 August 2028. It covers the same Chapter III sections for systems classified under Article 6(1) and Annex I. Amended Article 2(2) limits direct AI Act duties for Section B systems. Regulation (EU) 2026/1744, arts. 1(2)(a), 1(40)(b)(ii), OJ L 2026/1744, 24.7.2026, pp. 15, 35.
The original Annex III date was 2 August 2026 under the general application clause. The original Annex I date was 2 August 2027. The final shifts add 16 months and 12 months, respectively. This calculation compares each original date with its replacement. Regulation (EU) 2024/1689, art. 113, OJ L 2024/1689, 12.7.2024, p. 123; Regulation (EU) 2026/1744, art. 1(40)(b), OJ L 2026/1744, 24.7.2026, p. 35.
The phrase “high-risk obligations” therefore needs a qualifier. Article 113 names three Chapter III sections and excludes Article 6(5). It does not defer every transparency, supervision, testing, penalty, or institutional provision connected with high-risk systems.
Annex I classification requires more than product integration
“Annex I embedded systems” is not the statutory test. Article 6(1) requires two conditions. The AI system must be a safety component of an Annex I product, or itself be that product. The product must also require third-party conformity assessment before being placed on the market or put into service. Regulation (EU) 2024/1689, art. 6(1), OJ L 2024/1689, 12.7.2024, p. 53.
The Omnibus narrows the safety-component inquiry. Non-safety user assistance, performance optimisation, service efficiency, automation, convenience, and quality control do not qualify alone. A system still qualifies if its failure or malfunction would endanger health or safety. A third-party assessment required solely because of risks other than risks to health and safety does not satisfy Article 6(1)(b). Regulation (EU) 2026/1744, arts. 1(4)(a), 1(8), OJ L 2026/1744, 24.7.2026, pp. 16, 18.
Annex I Section B systems receive special treatment. Only Article 6(1), Article 60a, and Articles 102 to 112 apply directly. Articles 57 to 59 apply only insofar as high-risk requirements have been integrated into that legislation. The full Chapter III duty set therefore does not apply directly to every Section B system. Regulation (EU) 2026/1744, art. 1(2)(a), OJ L 2026/1744, 24.7.2026, p. 15.
Section A systems may receive further overlap relief. By 2 August 2027, the Commission must specify qualifying systems and duties through delegated acts. Relief requires equal or stronger protection under the product law. It cannot reduce the AI Act's overall protection. Regulation (EU) 2026/1744, art. 1(3), OJ L 2026/1744, 24.7.2026, p. 16.
These rules make product mapping essential. A provider should identify the Annex I instrument, its section, the safety function, and the conformity route. Product integration by itself does not trigger Article 6(1).
The rest of the AI Act continues
The Omnibus does not create a general moratorium. The original general application date remains 2 August 2026. Only named provisions receive different dates. Regulation (EU) 2024/1689, art. 113; Regulation (EU) 2026/1744, art. 1(40).
The amended AI-literacy duty applies from 27 July 2026. Providers and deployers must support staff and other relevant persons. They need not guarantee any individual's literacy level. Articles 102 to 110 also apply from 27 July 2026. Regulation (EU) 2026/1744, arts. 1(5), 1(40)(c), OJ L 2026/1744, 24.7.2026, pp. 16, 35.
Article 50 transparency duties keep the 2 August 2026 general date. Older content-generating systems receive a limited grace period. Their providers must comply with Article 50(2) by 2 December 2026. The new intimate-content and child-abuse prohibitions also apply from 2 December 2026. Regulation (EU) 2026/1744, arts. 1(7), 1(39)(b), 1(40)(a), OJ L 2026/1744, 24.7.2026, pp. 18, 35.
Testing provisions follow another path. Expanded real-world testing for Annex I Section A systems starts with the general 2 August 2026 date. Member States may allow Section B testing under Article 60a. The national sandbox coverage duty has a separate 2 August 2027 deadline. Regulation (EU) 2026/1744, arts. 1(22), 1(24)-(25), OJ L 2026/1744, 24.7.2026, pp. 23-25.
Existing systems follow a separate transition rule
Many existing high-risk systems receive conditional relief. Article 111(2) covers systems placed on the market or put into service before the relevant Chapter III date. The AI Act then applies only if their designs undergo significant changes after that date. Providers and deployers of systems intended for public-authority use must comply by 2 August 2030 in all cases. Regulation (EU) 2026/1744, art. 1(39)(a), OJ L 2026/1744, 24.7.2026, p. 35.
Recital 39 explains the operative rule by type and model. One lawfully placed unit can support later unchanged units of that type and model. A significant design change ends that protection. Recital 39 guides interpretation, but Article 111(2) supplies the binding rule. Regulation (EU) 2026/1744, recital 39 and art. 1(39)(a), OJ L 2026/1744, 24.7.2026, pp. 12, 35.
A provider should preserve the first placement date, version records, model identifiers, and design-change decisions. Without that evidence, a provider cannot apply the transition rule safely.
Support for small mid-cap enterprises is targeted
The Omnibus extends selected measures to small mid-cap enterprises, called SMCs. It incorporates the definition in Recommendation (EU) 2025/1099. An SMC is not an SME, employs fewer than 750 persons, and meets one financial ceiling. Annual turnover cannot exceed EUR 150 million, or the balance-sheet total cannot exceed EUR 129 million. Commission Recommendation (EU) 2025/1099, annex, point 2, OJ L 2025/1099, 28.5.2025, p. 6; Regulation (EU) 2026/1744, art. 1(4)(b), OJ L 2026/1744, 24.7.2026, p. 16.
The thresholds do not operate on a stand-alone label. Partner and linked-enterprise rules can aggregate staff and financial data. Public ownership can disqualify an enterprise. Crossing a ceiling changes status only after two consecutive accounting periods. Commission Recommendation (EU) 2025/1099, annex, points 3-6, OJ L 2025/1099, 28.5.2025, pp. 6-9.
Qualifying SMCs gain several specified measures. They may use the future simplified Annex IV documentation form. Article 17 makes quality-system implementation proportionate to provider size, while retaining the required protection. National authorities may give SMCs guidance. Codes and Commission guidance must account for their needs. Regulation (EU) 2026/1744, arts. 1(10)-(11), 1(29), 1(35)-(36), OJ L 2026/1744, 24.7.2026, pp. 19, 26, 34.
The fine rule also changes, but only for named infringements. Article 99(6a) gives SMCs the lower statutory ceiling under paragraphs 4 and 5. Those ceilings are EUR 15 million or 3 percent, and EUR 7.5 million or 1 percent. The lower-of rule does not cover Article 99(3) prohibited-practice fines. Regulation (EU) 2024/1689, art. 99(3)-(5), OJ L 2024/1689, 12.7.2024, pp. 115-116; Regulation (EU) 2026/1744, art. 1(38)(c), OJ L 2026/1744, 24.7.2026, p. 35.
The extension is not blanket. Article 62's national-sandbox priority and fee measures remain SME-specific. Article 63 now offers a simplified quality-system route to certain independent SMEs, not SMCs. SMCs instead receive Article 17 proportionality. Regulation (EU) 2024/1689, arts. 62-63, OJ L 2024/1689, 12.7.2024, pp. 94-95; Regulation (EU) 2026/1744, arts. 1(11), 1(26), OJ L 2026/1744, 24.7.2026, pp. 19, 26.
An enterprise should test SMC status at group level before claiming relief. It should then match each benefit to an amended article. SMC status does not excuse a substantive high-risk requirement.
Sandboxes and real-world testing expand on different terms
The sandbox claim is directionally correct, but it needs two limits. The AI Office may establish a Union-level sandbox for Article 75(1) systems. The word “may” makes creation discretionary. Eligible SMEs, start-ups, and SMCs receive priority access if the Office creates it. Regulation (EU) 2026/1744, art. 1(22)(c), OJ L 2026/1744, 24.7.2026, p. 23.
The national deadline moved in the opposite direction. Each Member State must secure national sandbox coverage by 2 August 2027. It can participate in an existing sandbox offering equivalent national coverage. The prior date was 2 August 2026. Regulation (EU) 2024/1689, art. 57(1), OJ L 2024/1689, 12.7.2024, p. 88; Regulation (EU) 2026/1744, art. 1(22)(a), OJ L 2026/1744, 24.7.2026, p. 23.
The Omnibus also broadens supervised experimentation. Article 60 now covers Annex III and Annex I Section A systems outside sandboxes. New Article 60a lets Member States permit Section B testing under national rules. Section B testing remains optional for each Member State. Both routes retain plans, safeguards, supervision, and other applicable Union law. Regulation (EU) 2026/1744, arts. 1(24)-(25), OJ L 2026/1744, 24.7.2026, pp. 24-25.
A sandbox is not a compliance exemption. It offers controlled development, training, testing, and validation under an agreed plan. It may include supervised real-world testing. Participants remain liable for third-party damage. A prospective provider receives limited fine protection when it observes the plan, participation terms, and authority guidance in good faith. Regulation (EU) 2024/1689, art. 57(11)-(12), OJ L 2024/1689, 12.7.2024, p. 89; Regulation (EU) 2026/1744, art. 1(22)(d), OJ L 2026/1744, 24.7.2026, p. 23.
Compliance Roadmap
The revised roadmap should track each system, duty, and transition rule separately.
On 27 July 2026, Regulation (EU) 2026/1744 entered into force. Amended Article 4 and Articles 102 to 110 also began to apply. Organizations should update their legal inventories, refresh AI-literacy measures, and assign owners for the new supervision and enforcement rules.
On 2 August 2026, the AI Act's general application date remains in place. Article 50 and the expanded real-world testing routes apply from that date. Organizations should complete non-high-risk workstreams and check transparency, notices, marking, testing plans, and existing GPAI duties.
On 2 December 2026, the new Article 5 prohibitions apply. The Article 50(2) grace period for older generators also ends. Providers and deployers should block the prohibited practices applicable to their roles. Providers should complete machine-readable marking changes for covered legacy generators.
By 1 August 2027, the Commission must issue product-law guidance under Article 96(1)(g). Providers should recheck their Annex I mappings against that guidance.
By 2 August 2027, the Commission must adopt the Article 2(13) delegated acts. Member States must also secure national sandbox coverage. Providers should review the adopted acts and the relevant national sandbox entry terms.
By 2 September 2027, the Commission must issue post-market monitoring guidance. Providers should compare their monitoring plans with that guidance and its voluntary template.
On 2 December 2027, Chapter III, Sections 1 to 3 apply to Article 6(2) and Annex III systems, except Article 6(5). Providers should finish the Annex III technical file, controls, operator allocation, assessments, registration, and conformity work.
On 2 August 2028, the same sections apply to Article 6(1) and Annex I systems, subject to Article 2(2) for Section B. Providers should finish the applicable product-linked work and account for Section A relief and Section B product-law integration.
By 2 August 2030, providers and deployers of covered legacy systems intended for public-authority use must comply. Organizations should close any remaining public-sector transition plan.
The first task is a system-level classification register. It should record role, intended purpose, Annex route, safety function, and conformity route. It should also record first placement, later design changes, and the applicable Article 113 date.
The second task is a date-by-duty matrix. It should separate Article 4, Article 50, GPAI duties, testing rules, and high-risk Chapter III duties. One blanket “high-risk deadline” will miss obligations that apply earlier.
The third task is evidence preservation. Providers should retain group-size calculations, product classifications, design histories, and testing approvals. These records support SMC claims, transition treatment, and regulatory review.
