Regulation (EU) 2026/1744: What Actually Applied on 2 August 2026
On 2 August 2026 a large part of the EU AI Act became applicable. In the weeks since, a lot of published guidance has said that this was the date “full enforcement for high-risk AI systems” began. It was not. Six days earlier, an amendment had moved that regime to December 2027.
The amendment is Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026, published in the Official Journal on 24 July 2026 and in force from 27 July 2026. It amends Regulation (EU) 2024/1689 — the AI Act — along with Regulation (EU) 2018/1139 on civil aviation and Regulation (EU) 2023/1230 on machinery.
Three days between publication and entry into force is unusually short. The ordinary interval is twenty. The reason is visible in the timing: the amendment had to be law before 2 August, or the dates it was moving would have arrived first.
This is a clause-by-clause read of what it changed. Everything below is quoted or paraphrased from the text of the regulation itself, not from secondary coverage.
The dates, before and after
The operative change is to Article 113 of the AI Act, the article that sets out when each part applies. Its third paragraph was rewritten. Rows in green did not move.
| Obligation | Was | Now |
|---|---|---|
| Prohibited practices (Art. 5) | 2 February 2025 | 2 February 2025 — unchanged |
| New prohibitions: Art. 5(1) points (ba) and (bb), with Art. 5(1a) and (1b) | did not exist | 2 December 2026 |
| General-purpose AI models (Art. 53, 55) | 2 August 2025 | 2 August 2025 — unchanged |
| Article 50 transparency | 2 August 2026 | 2 August 2026 — unchanged |
| Art. 50(2) marking, systems already on the market | 2 August 2026 | 2 December 2026 |
| High-risk, stand-alone (Art. 6(2) and Annex III) | 2 August 2026 | 2 December 2027 |
| High-risk, embedded in regulated products (Art. 6(1) and Annex I) | 2 August 2027 | 2 August 2028 |
The replacement text of Article 113(c) reads, in the regulation’s own words, that Chapter III Sections 1, 2 and 3 — with the exception of Article 6(5) — apply from “2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III” and “2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I”.
What did not move: Article 50
The transparency obligations were not touched by this amendment and have applied since 2 August 2026. They are also the part of the AI Act that reaches the largest number of companies, because they do not depend on being a high-risk provider. They apply if you:
- run a system that interacts with people — a chatbot, an assistant — which must disclose that it is AI, unless that is obvious to a reasonably well-informed person (Art. 50(1));
- generate or manipulate synthetic audio, image, video or text, which must be marked in a machine-readable format detectable as artificially generated (Art. 50(2));
- run emotion recognition or biometric categorisation, and must inform the people exposed to it (Art. 50(3));
- publish deepfakes, which must be labelled (Art. 50(4)).
Breach carries fines up to €15 million or 3% of worldwide annual turnover, whichever is higher. The €35 million / 7% tier belongs to the Article 5 prohibitions, which are a different thing.
If you want to see whether one specific page of yours shows an AI signal without a disclosure, there is a free Article 50 check that will tell you in a few seconds — and, more usefully, tell you which parts of Article 50 no scanner can assess from outside.
Two different things land on 2 December 2026
This is the date most likely to be missed, because two unrelated obligations share it.
First, the marking of legacy synthetic content. The regulation inserts a transitional period of four months: providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content that were placed on the market before 2 August 2026 “shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026”. Note the narrowness: the grace period covers the machine-readable marking duty only. The rest of Article 50 already applies to those systems.
Second, two new prohibitions. Article 5(1) gains points (ba) and (bb), together with qualifying paragraphs 5(1a) and 5(1b), and these apply from 2 December 2026. They concern AI systems that generate or manipulate intimate or sexually explicit material. The qualifiers matter and are worth reading in full: under 5(1a) the prohibition on placing such a system on the market bites only where that generation is the intended purpose of the system, or where the system’s “design, training, architecture, capabilities or user-facing functionalities make that generation or manipulation a reasonably foreseeable and reproducible outcome, without requiring significant technical modification” and adequate safeguards are absent. For a deployer, the prohibition applies where they use the system for that purpose.
The high-risk perimeter also narrowed
The postponement got the headlines, but the amendment also changes who is high-risk in the first place, and this has had far less coverage.
A new paragraph is inserted into Article 6 clarifying that AI systems solely used for non-safety-related functions are not caught. The recital is explicit that the category “does not include AI systems which are intended to solely fulfil functions related to user assistance, performance optimisation, service efficiency, automation, convenience, or non-safety related aspects for quality control operations”. It then adds the sentence that will settle a great many internal arguments: “The mere fact that an AI system is integrated into or operates within a product that is subject to Union harmonisation legislation does not, in itself, mean that it fulfils a safety function.”
A safety component is defined by reference to intended purpose: a component fulfils a safety function “where its intended purpose is to prevent or mitigate risks to health and safety of persons or property”.
Article 4 on AI literacy was rewritten
The original Article 4 imposed an obligation on all providers and deployers to ensure AI literacy of their staff. The replacement softens it into an obligation to “take measures to support the development of AI literacy”, calibrated to technical knowledge, experience, education, training and context — and states that it “does not require providers or deployers to guarantee any specific level”.
If you built a training programme against the original wording, you have not wasted the effort, but the compliance bar you were aiming at has moved.
Smaller changes worth knowing
- Two new definitions. “SME” by reference to Recommendation 2003/361/EC, and “small mid-cap enterprise” (SMC) by reference to Recommendation (EU) 2025/1099. Expect these to carry proportionality carve-outs elsewhere in the regime.
- Real-world testing extended. Articles 57, 58 and 60 are amended so that real-world testing outside regulatory sandboxes reaches high-risk systems covered by Annex I harmonisation legislation, not only Annex III. Where a sandbox project also involves real-world testing, the testing plan is folded into the sandbox plan.
- A Union-level sandbox becomes possible. The AI Office may establish one for systems covered by Article 75(1).
- Overlapping conformity assessment clarified. Where a high-risk system falls under both Annex I Section A harmonisation legislation and an Annex III use case, the regulation clarifies which procedure the provider follows.
Why it moved
Recital 40 gives the reason plainly, and it is not a change of policy. For the Chapter III high-risk obligations, “the delayed availability of standards, common specifications, and alternative guidance and the delayed establishment of national competent authorities lead to challenges that jeopardise the effective entry into application of those obligations”.
In other words: the harmonised standards that providers were meant to conform to did not exist yet, and in several member states neither did the authority that would assess them. That is worth holding on to, because it tells you the direction of travel. The obligations were not weakened. They were postponed until the machinery to comply with them exists.
What to do with this
- Check your published dates. If any of your documentation, marketing or board reporting says high-risk enforcement began in August 2026, it is now wrong. This is the most common error currently in circulation.
- Treat Article 50 as live, because it is. Inventory every user-facing AI surface and decide which paragraph applies to each.
- Put 2 December 2026 in the calendar twice. Once for legacy marking under Art. 50(2), once for the new prohibitions.
- Re-run your high-risk classification. The Article 6 change may take systems out of scope that your earlier assessment put in, and a classification done before July 2026 was done against different text.
- Use the extra time on standards. December 2027 is thirteen months of runway for Annex III, and the reason it exists is that the standards were not ready. They will be.
Sources
- Regulation (EU) 2026/1744 — CELEX 32026R1744 — EUR-Lex
- Regulation (EU) 2024/1689 (AI Act) — CELEX 32024R1689 — EUR-Lex
Dates verified against EUR-Lex on 2026-08-05. CompliPilot is not a law firm and this article is not legal advice. Where the wording of an obligation matters to a decision you are making, read the regulation.