In short
Regulation (EU) 2026/1744 of 8 July 2026 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It amends the AI Act (EU) 2024/1689: Annex III high-risk duties now bind on 2 December 2027 and Annex I on 2 August 2028 — as unconditional calendar dates.
Table of Contents
- 1.Regulation (EU) 2026/1744 at a glance
- 2.The deadlines side by side: old versus new
- 3.The most important deletion: the standards trigger is gone
- 4.What was not deferred — and why that is the real story
- 5.Two dates, two worlds: Annex III and Annex I
- 6.What a CIO must do this quarter
- 7.What may wait until 2027 — and what may not
- 8.Governance consequences: from a date to a programme
Regulation (EU) 2026/1744 at a glance
Since 27 July 2026 the Digital Omnibus on AI is law in force. Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 was published in the Official Journal on 24 July 2026 and entered into force on the third day following that publication. The binding text sits in the EU primary source, see https://eur-lex.europa.eu/eli/reg/2026/1744/oj — and that source is the only one that counts in a dispute. Every secondary account, this one included, is interpretation.
Formally, 2026/1744 is not a standalone regulation but an amending act. It amends three existing regulations: the AI Act itself, Regulation (EU) 2024/1689 (see https://eur-lex.europa.eu/eli/reg/2024/1689/oj), the civil aviation basic regulation (EU) 2018/1139 (see https://eur-lex.europa.eu/eli/reg/2018/1139/oj) and the machinery regulation (EU) 2023/1230 (see https://eur-lex.europa.eu/eli/reg/2023/1230/oj). Reading only the AI Act amendment misses half the message: the legislator synchronised the AI deadlines and the sectoral product acts in the same move, because one does not work without the other.
For day-to-day work this has an unspectacular but consequential effect. The AI Act text your legal function filed in spring is out of date. From now on, only the consolidated version of 2024/1689 is a valid working basis. Anyone still working from the original 2024 wording is planning against deadlines that no longer exist — an expensive mistake in a compliance context, because it cuts both ways: budgets committed too early as well as programmes started too late.
This article is deliberately the reference page for the regulation itself. The contextual scenario discussion — how it came about and how an organisation handles regulatory uncertainty — sits in the companion piece EU AI Act 2026: what the Digital Omnibus deferral really means. The substantive obligations — risk tiers, value-chain roles, Articles 9 to 15 — remain covered in the EU AI Act Compliance Guide. Here we deal exclusively with what the new regulation does to the dates.
Which of the two new deadlines applies to your systems is answered by the free AI Act readiness check in about three minutes, with no login and no registration.
Regulation (EU) 2026/1744 is an amending act, not a new law. It softens not a single substantive AI Act requirement — it moves two deadlines and leaves four blocks of obligations entirely untouched.
The deadlines side by side: old versus new
The decisive change concerns Chapter III Sections 1 to 3 of the AI Act, the core of the high-risk obligations. Instead of one uniform deadline there are now two, and they differ according to which of the two classification routes puts a system into the high-risk category.
Standalone high-risk systems under Article 6(2) in conjunction with Annex III bind on 2 December 2027. That is the category where most companies find their systems: recruitment, creditworthiness assessment, access to education, access to essential private and public services. Product-embedded high-risk systems under Article 6(1) in conjunction with Annex I bind on 2 August 2028. That covers AI acting as a safety component in an already regulated product, or being such a product itself.
Measured against the original wording, that means roughly 16 additional months for Annex III and roughly 12 additional months for Annex I. Those numbers are the entire gain from the regulation. There is no second, hidden benefit — no reduced documentation depth, no relaxed data quality requirement, no lowered bar for human oversight.
The table below is the version that belongs in your compliance plan. It replaces any timeline drawn up before 24 July 2026.
| Block of obligations | Deadline before 2026/1744 | Deadline since 2026/1744 | Status on 8 August 2026 |
|---|---|---|---|
| Prohibited practices (Chapter II) | 2 February 2025 | unchanged | applicable and enforceable |
| AI literacy of staff (Article 4) | 2 February 2025 | unchanged | applicable and enforceable |
| General-purpose AI models (GPAI) | 2 August 2025 | unchanged | applicable and enforceable |
| Transparency duties (Article 50) | 2 August 2026 | unchanged | applicable for six days |
| High-risk under Article 6(2) / Annex III | 2 August 2026 | 2 December 2027 | roughly 16 months of lead time |
| High-risk under Article 6(1) / Annex I | 2 August 2027 | 2 August 2028 | roughly 24 months of lead time |
The most important deletion: the standards trigger is gone
The Commission draft of November 2025 contained a conditional trigger: the high-risk obligations were only to apply once the harmonised standards and supporting instruments were actually available. That would have made the start of application an event rather than a date — verifiable only in hindsight and dependent on the progress of the European standardisation bodies.
That mechanism is not in the adopted text. What remains are two unconditional calendar dates. 2 December 2027 and 2 August 2028 apply regardless of whether the harmonised standards are finished by then, whether the AI Office has published its guidance and whether notified bodies have built sufficient capacity. These dates can now be moved only through a fresh legislative procedure, meaning a renewed agreement between Parliament and Council.
From a governance point of view this is the genuinely good news, and it is routinely lost in the coverage. A conditional trigger would have forced every roadmap into permanent monitoring mode: check standardisation progress quarterly, maintain scenarios, keep budgets in limbo. Two fixed dates, by contrast, are plannable. They allow backward planning with defined milestones, a defensible budget allocation across two fiscal years and clear ownership — exactly what a multi-year compliance programme needs.
The flip side is equally clear: there is no built-in fallback any more. If the harmonised standards are still incomplete in autumn 2027, 2 December 2027 does not shift automatically. The organisation then carries the risk of having to demonstrate conformity against a state of the art that is not yet fully articulated. Anyone concluding from this that another deferral will surely come is betting on a political process whose outcome nobody can credibly forecast. The Commission publishes the ongoing state of standardisation and supporting work, see https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai.
An event-dependent trigger has become two fixed calendar dates. That removes uncertainty from the roadmap — and with it the tacit hope of an automatic extension should the standards not be ready in time.
What was not deferred — and why that is the real story
Four blocks of obligations were left untouched by the regulation, and all four apply today. The prohibitions on unacceptable AI practices have applied since 2 February 2025. The obligation to ensure sufficient AI literacy among staff under Article 4 has likewise applied since 2 February 2025. The obligations for general-purpose AI models have applied since 2 August 2025. The transparency duties under Article 50 have applied since 2 August 2026 — that is, for six days.
This list is not a footnote, it is the core of the situation. What was deferred is precisely the part that mostly operates internally: risk management system, data quality, technical documentation, record-keeping, conformity assessment. What was not deferred is the part that customers, applicants, supervisory authorities and competitors can observe directly: that a chatbot discloses it is an AI, that synthetic content is labelled, that prohibited practices are not in use.
This asymmetry has a practical consequence for the risk profile. A gap in Article 50 is a liability today, not a project task. It is detectable from the outside with no system access at all — a website, a product video or an application portal is enough. What these obligations look like in practice and where the typical gaps sit is covered in detail in the piece on the Article 50 transparency duties.
Internal communication therefore has to be precise. The message "the AI Act has been postponed" is factually wrong and organisationally dangerous. What is correct: a clearly delimited part of the obligations has moved, the rest applies and is being enforced. Passing the news on imprecisely sends a stand-down signal into the business units that stops exactly the work which has no reprieve.
Two dates, two worlds: Annex III and Annex I
The fact that the legislator set two separate dates is not a trilogue compromise; it follows the structure of conformity assessment. The two classification routes differ in what stands between completion and market access.
Standalone high-risk systems under Annex III are as a rule self-assessed by the provider. The organisation controls its own critical path: it can produce data quality, documentation and an oversight concept under its own steam and does not depend on external capacity. That is why the shorter lead time to 2 December 2027 suffices here.
Product-embedded systems under Annex I sit differently. Here the AI Act reaches into legal acts that already require assessment by a notified body — which is precisely why Regulation 2026/1744 also amends the civil aviation basic regulation (EU) 2018/1139 and the machinery regulation (EU) 2023/1230. In those sectors the schedule depends not only on the manufacturer but on the assessment capacity available in the market. 2 August 2028 reflects that dependency.
For organisations holding both system types, a hard planning rule follows: these are two programmes, not one. They have different critical paths, different dependencies and different escalation routes. Running them in a single roadmap with a single target date will either miss the Annex III date or tie up capacity for Annex I that is still needed elsewhere. The separation should already exist in the AI inventory, not first appear in the project plan.
In practice: every row of the inventory gets a field recording the classification route — Article 6(1) or Article 6(2) — and, derived from it, the governing deadline. That field later becomes the sorting logic for budget, resourcing and reporting. Without it, neither deadline is manageable.
What a CIO must do this quarter
The following items belong in the plan for the current quarter — not because urgency should be staged, but because each of them either concerns an obligation that applies today or sits on the critical path to December 2027.
- 1Cut the inventory by classification route: every AI system in the estate is assigned unambiguously to Article 6(1) or Article 6(2), and the governing deadline follows from that. Systems without a clear assignment are not an open question but a finding — they need to be resolved as a priority, because no resource planning is possible without that assignment.
- 2Close the Article 50 evidence gap: the transparency duties have applied since 2 August 2026. Review every customer-facing AI interaction, every synthetic content generation and every emotion or biometrics-adjacent feature for correct disclosure — and document the result in an audit-proof way. A gap here bites today, not in 2027.
- 3Make the prohibition and literacy evidence audit-proof: prohibited practices and AI literacy under Article 4 have applied since February 2025. The evidence is not a statement of intent but a documented portfolio review plus role-specific training records with curriculum, participants and date.
- 4Re-date the contracts: supplier and integration contracts referencing 2 August 2026 or 2 August 2027 are substantively obsolete. Set Annex III clauses to 2 December 2027 and Annex I clauses to 2 August 2028 — and place supplier evidence deadlines well ahead of those dates, not on the deadline itself.
- 5Redistribute the budget across two fiscal years: the effort has not shrunk, it is spread differently. Handing back the funds earmarked for 2026 in full means re-procuring them in 2027 under time pressure and on worse terms. A deferral with the total volume preserved and defined milestones is the better move.
- 6Consolidate the regulatory calendar: the AI Act is not the only deadline in the house. Place the new dates next to those from NIS2, DORA and the Cyber Resilience Act — the overlaps and the jointly usable evidence are described in the piece on the [2026 regulatory collision](/blog/regulierungs-kollision-2026-nis2-dora-cra-ai-act). Duplicated evidence gathering is the most common avoidable cost block.
What may wait until 2027 — and what may not
What may wait is whatever depends on requirements that are not yet finalised. That includes the final conformity assessment, the concluding technical documentation against then-harmonised standards, formal registration in the EU database and the final design of labelling mechanisms for high-risk systems. Finalising these steps today risks a rework once the standards become more concrete. For interpretation questions during the process the Commission has set up a contact point, see https://digital-strategy.ec.europa.eu/en/policies/ai-act-service-desk.
What may not wait is anything with a long lead time. Data quality and data provenance under Article 10 cannot be produced in a single quarter if training and validation data have grown over years without provenance records. Human oversight under Article 14 is not a documentation task but frequently a product change affecting interface, process and role model. Record-keeping under Article 12 reaches into the architecture and is expensive to retrofit.
That is the real trap in the 16 months. Organisationally they are perceived as slack, while the three work packages named above realistically absorb nine to twelve months — running in parallel, not sequentially. Starting in summer 2027 is starting too late, and not by a narrow margin.
The defensible rule of thumb: anything touching the architecture, the data foundation or the product experience starts now. Anything that amounts to a signature, a registration or a formal assessment against an external reference is prepared and deliberately phased. That dividing line is more precise than sorting by important versus unimportant — and it is defensible in an audit.
Governance consequences: from a date to a programme
With two fixed dates and no conditional trigger, AI Act preparation becomes an ordinary multi-year programme — with everything that entails: named ownership, milestones with acceptance criteria, a budget across two fiscal years and a reporting line that does not stop at IT. That is progress compared with last year's scenario planning, but it demands a different discipline: a programme without interim acceptance runs apparently on plan for two years and is 40 per cent complete three months before the date.
Two reporting points per year at board or executive level are advisable, each with the same set of figures: number of systems per classification route, share with completed classification, share with complete Article 10 data provenance, share with an implemented oversight concept. Four numbers are enough. A reporting structure that changes its cut every quarter produces activity but no steering.
Equally important is documenting the prioritisation decision itself. Record why a given measure runs immediately and which one was deliberately phased. That rationale is itself a governance record in an audit: it demonstrates that the legal position was appraised correctly and the sequence chosen deliberately — rather than work simply having been left undone.
Structural templates for inventory, classification and evidence handling are in the template catalogue; if you want the stocktaking supported externally, the service packages and terms are listed under pricing and packages. For a first no-effort baseline the AI Act readiness check remains the fastest entry point, and the broader IT governance assessment guide places AI compliance within the rest of the control system.
Two years of lead time is a programme window, not slack. The difference shows in whether there are interim acceptance points with criteria — or merely an end date and the assumption that it will somehow be enough.
Key Takeaways
- Regulation (EU) 2026/1744 of 8 July 2026 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It amends the AI Act (EU) 2024/1689 as well as Regulations (EU) 2018/1139 and (EU) 2023/1230.
- New deadlines: 2 December 2027 for high-risk under Article 6(2) and Annex III, 2 August 2028 for high-risk under Article 6(1) and Annex I. Both govern Chapter III Sections 1 to 3.
- The link to the availability of harmonised standards contained in the November 2025 draft is not in the final text. These are unconditional calendar dates, movable only through a fresh legislative procedure.
- Not deferred: the prohibitions and AI literacy under Article 4 since 2 February 2025, GPAI obligations since 2 August 2025, Article 50 transparency duties since 2 August 2026.
- Two dates mean two programmes: Annex III is controlled by the organisation itself, Annex I additionally depends on notified bodies and sectoral product law.
- Data provenance, human oversight and record-keeping realistically absorb nine to twelve months. Treating them as slack loses December 2027 during summer 2027.
Related Assessment Templates
Frequently Asked Questions
It is the amending act known as the Digital Omnibus on AI, adopted by the European Parliament and the Council on 8 July 2026. It was published in the Official Journal on 24 July 2026 and entered into force on the third day thereafter, 27 July 2026. The regulation amends three existing acts: the AI Act, Regulation (EU) 2024/1689, the civil aviation basic regulation (EU) 2018/1139 and the machinery regulation (EU) 2023/1230. It is not a standalone rulebook with new obligations; it moves the application dates of the high-risk provisions and aligns the sectoral product acts accordingly. The binding text is at https://eur-lex.europa.eu/eli/reg/2026/1744/oj.
There are two dates. Standalone high-risk systems that fall into the category via Article 6(2) in conjunction with Annex III bind on 2 December 2027. Product-embedded systems via Article 6(1) in conjunction with Annex I bind on 2 August 2028. Both dates govern Chapter III Sections 1 to 3, the core of the high-risk requirements. Which date applies to a given system is decided solely by the classification route — not by the industry and not by how critical the company itself considers the use case.
No. The Commission draft of November 2025 contained such a conditional trigger; the adopted text does not. 2 December 2027 and 2 August 2028 are unconditional calendar dates. They apply regardless of whether the harmonised standards, the AI Office guidance or notified body capacity are fully available by then. They can be moved only through a fresh legislative procedure with renewed agreement between Parliament and Council. Nobody should plan on a further automatic extension.
Four blocks. The prohibitions on unacceptable AI practices have applied since 2 February 2025. The obligation to ensure sufficient AI literacy among staff under Article 4 has applied since 2 February 2025 as well. The obligations for general-purpose AI models have applied since 2 August 2025. The Article 50 transparency duties — disclosure for chatbots, synthetic content and emotion recognition — have applied since 2 August 2026. None of these four blocks was touched by Regulation 2026/1744. Gaps in these areas are a liability today, not a 2027 project task.
Because the conformity routes differ. Standalone systems under Annex III are as a rule self-assessed by the provider, so the organisation largely controls its own critical path. Product-embedded systems under Annex I sit inside products already governed by sectoral law that requires assessment by notified bodies. That is why the regulation amends the civil aviation basic regulation and the machinery regulation in parallel. The later date reflects the dependency on external assessment capacity, which a manufacturer cannot create on its own.
No, a deferral with the total volume preserved is the better move. The effort has not shrunk; it is simply spread over two fiscal years instead of one. Releasing the funds entirely means re-procuring them in 2027 under time pressure — in practice on worse terms and with worse availability, because the whole market will be asking at the same time. The advisable approach is to stretch the budget across both years with defined milestones and to tie the funds to interim acceptance rather than to the end date.
The date applies regardless. Without the deleted conditional trigger there is no automatic extension. The organisation then has to demonstrate conformity against whatever state of the art is available at that point, which in practice means its own carefully reasoned compliance evidence instead of a reference to standard conformity. That is precisely why the rationale behind your implementation decisions should be documented from the outset — in case of doubt it is what an audit will rely on. The Commission publishes progress on standardisation and supporting work at https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai.
Everything with a long lead time and everything already applicable must start: inventory by classification route, Article 50 evidence, the prohibition and literacy review, data provenance under Article 10, the human oversight concept under Article 14 and record-keeping under Article 12. What may wait is whatever depends on external requirements that are not yet final: the concluding conformity assessment, the final technical documentation against harmonised standards and registration in the EU database. The dividing line runs between interventions in architecture, data and product on one side and formal closing acts on the other.
This article is the reference page for Regulation (EU) 2026/1744 itself: anatomy of the act, deadline comparison, quarter plan. The EU AI Act Compliance Guide at /blog/eu-ai-act-compliance-guide remains the reference for the substantive obligations, meaning risk tiers, value-chain roles and Articles 9 to 15. The update at /blog/eu-ai-act-digital-omnibus-update frames the legislative history and the planning logic under uncertainty. The disclosure duties that already apply today are covered at /blog/eu-ai-act-artikel-50-transparenzpflichten-august-2026.