Skip to content
    HAQQ
    • Pricing
    Start Free
    Start FreeBook a Demo
    Log in
    Resource Hub

    Browse

    • Legal AI Skills338
    • Blog168
      • EU AI Act Amendments 2026: What Regulation (EU) 2026/1744 Changed
      • Legal AI Benchmark 2026: How HAQQ Performed in an Independent Evaluation
      • Enterprise legal AI: what large organizations check before they trust it
      • Best legal AI for immigration lawyers
      • Citation-backed legal research AI: statutes and cases across jurisdictions
      • Law Firm 3.0: Why Firms Need a Legal Operating System
      • Can AI Replace Lawyers? No - and Here's Why That's the Wrong Question
      • Is AI Legal Advice Safe and Accurate? What to Check Before You Trust a Legal AI
      • Legal AI Hallucination: The Fake Citation That Passes Every Check
      • AI for Divorce Lawyers: The 8-Phase Playbook (2026)
      • Spellbook Alternatives: The Best AI Contract Drafting Tools in 2026
      • San Francisco Legal AI Startups: The 2026 Map (Harvey, Eve, GC AI, Ivo)
      • HAQQ vs Onit: Legal AI vs Enterprise Legal Management (2026)
      • CoCounsel Review 2026: Pricing, Benchmark & Alternatives
      • Harvey vs Legora vs CoCounsel: One 50-Point Rubric
      • View all62
    • Free Tools20
    • How to Use HAQQ27
    • AI Lawyer Certification29
    • Solutions174
    • Whitepapers2
    • Research29
    1. Home
    2. Blog
    3. EU AI Act Amendments 2026: What Regulation (EU) 2026/1744 Changed
    Back to BlogAI & Legal Tech

    EU AI Act Amendments 2026: What Regulation (EU) 2026/1744 Changed

    Regulation (EU) 2026/1744 entered into force on 27 July 2026. High-risk duties moved to December 2027 and August 2028, and the 2 August 2026 transparency deadline did not move. Every change, and what it means for a firm that uses AI.

    July 28, 2026
    13 min read
    |
    HAQQ Team
    EU AI Act Amendments 2026: What Regulation (EU) 2026/1744 Changed

    In short: Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. The high-risk obligations everyone was bracing for slipped to 2 December 2027 and 2 August 2028. The 2 August 2026 transparency deadline did not move. Two new prohibitions land on 2 December 2026. The risk-based architecture of the AI Act is intact. And in a table of administrative codes for notified bodies, Union law names agentic AI for the first time, without defining it.

    What actually happened

    The European Parliament and the Council adopted Regulation (EU) 2026/1744 on 8 July 2026 in Strasbourg. It was published in the Official Journal on 24 July and entered into force on 27 July, on the third day after publication rather than the customary twentieth, because 2 August was too close to leave the text hanging. Its formal job is narrow: amend Regulation (EU) 2024/1689 — the AI Act — along with the Basic Aviation Regulation and the Machinery Regulation. Everyone calls it the Digital Omnibus on AI.

    A regulation amending a regulation applies directly in all 27 member states. No transposition step, no national implementing act to wait for, no drift between Dublin and Warsaw. The AI Act you read last month is a different document today.

    It is not a repeal, and it is not the deregulation some of the lobbying asked for. The risk tiers survived. The prohibited-practice list got longer, not shorter. What moved was the calendar for the single most expensive chapter, plus a handful of obligations that got cheaper to discharge.

    The one date that did not move: 2 August 2026

    This is the part the delay headlines bury, and it is the part that lands first. Article 50, the transparency chapter, still applies from 2 August 2026. If you are reading this the week it published, that is days away, not quarters.

    • Tell people they are talking to a machine. An AI system interacting with natural persons has to make that clear, unless it is obvious from the context.
    • Mark synthetic content in a machine-readable way. Audio, image, video and text generated or manipulated by AI must carry a marking a machine can detect.
    • Label deepfakes. Content that resembles real people, places or events and could mislead has to be disclosed as artificially generated.
    • Disclose AI-generated text published to inform the public on matters of public interest, unless a human took editorial responsibility for it.
    • Emotion recognition and biometric categorisation: deployers must inform the people exposed to the system.

    One concession was granted. Article 50(2) — the machine-readable marking of synthetic output — gets a grace period to 2 December 2026 for systems already on the market before 2 August 2026. New systems get no such runway. The rest of Article 50 arrives on 2 August with no transition at all, and the new enforcement articles switch on the same day.

    The nine changes that matter

    Original law on the left, amended position on the right. Article numbers are to the AI Act as amended.

    • 1. High-risk timing (Article 113). Was: stand-alone Annex III systems from 2 August 2026, AI embedded in regulated products under Annex I from 2 August 2027. Now: 2 December 2027 for Annex III, 2 August 2028 for Annex I Section A. Legacy high-risk systems already in use by public authorities get until 2 August 2030. The Commission's November 2025 draft had tied these dates to a conditional standards-readiness trigger; the final text dropped it, so these are unconditional calendar dates that cannot slip again without a fresh legislative procedure.
    • 2. New prohibitions (Article 5). Was: eight prohibited practices, applicable since 2 February 2025. Now: two more — generating or manipulating intimate material without freely given, specific, informed, unambiguous and explicit consent, and child sexual abuse material. Applicable from 2 December 2026, in the top penalty tier of up to €35 million or 7% of worldwide annual turnover. New Article 5(1a) splits provider and deployer liability: a provider is caught where that generation is the intended purpose, or is reasonably foreseeable and reproducible without significant technical modification. Providers are expected to document real technical safeguards — refusal training, prompt guardrails, content filtering, abuse detection.
    • 3. Transparency marking (Article 50(2)). Was: applicable 2 August 2026, no transition. Now: same date for new systems, with a grace period to 2 December 2026 for systems placed on the market before 2 August 2026.
    • 4. AI literacy (Article 4). Was: providers and deployers shall ensure a sufficient level of AI literacy among staff. Now: take measures to support the development of AI literacy, with explicit language that no specific level has to be guaranteed. Softer in substance, and it applies from 27 July 2026. It still applies to deployers, which means it applies to law firms.
    • 5. Bias-detection data (new Article 4a). Was: a narrow legal basis for high-risk providers to process special categories of personal data to detect and correct bias. Now: extended to all providers and all deployers of AI systems and general-purpose models, under a strict-necessity standard with safeguards. If GDPR was blocking your fairness testing, this is the unlock.
    • 6. High-risk classification and machinery (Articles 6, Annex I). Was: a broad safety-component test that pulled in a lot of ordinary product AI. Now: new Article 6(1a)–(1c) excludes systems used for non-safety functions — user assistance, performance optimisation, service efficiency, automation, convenience, quality control — and reinstates an objective criterion for what counts as a safety component. AI in machinery moved from Annex I Section A to Section B, so Articles 9–15 and 17–25 no longer apply to it directly; equivalent requirements come via delegated acts under the Machinery Regulation, due by 2 August 2027.
    • 7. Registration survived (Article 6(3), Annex VIII). Was: providers self-assessing a system as not high-risk must still register it in the EU database. The Commission proposed deleting this. Now: kept, on the reasoning that it is crucial for market surveillance, with two data points removed from Annex VIII Section B to slim the filing. Authorities keep their access.
    • 8. Sandboxes (Article 57). Was: member states had to have at least one AI regulatory sandbox operational by 2 August 2026. Now: 2 August 2027, plus a new Union-level sandbox run through the AI Office with priority access for SMEs.
    • 9. Enforcement and penalties (Articles 75, 75a–75d, 99). Was: supervision split, with the AI Office focused on general-purpose models. Now: the AI Office gets exclusive competence over AI systems built on a general-purpose model by the same undertaking, and over AI integrated into very large online platforms and search engines. New Articles 75a–75d give it investigative powers including on-site inspections and sealing premises, the ability to accept binding commitments, a non-compliance procedure with periodic penalties of up to 5% of average daily turnover, a five-year limitation period, and defence rights. Article 99 gains a capped fine tier for small mid-caps (a new Article 3 definition, per Commission Recommendation (EU) 2025/1099) and explicit room for warnings and non-monetary measures. Simplified quality-management obligations widened from micro-enterprises to SMEs generally. All from 2 August 2026.

    The EU just named agentic AI, and did not define it

    The most interesting line in this regulation is not in any Article. It is in a new Annex XIV, a table of nomenclature codes used to designate what a notified body is competent to assess. Alongside vertical codes for application areas, the amendment introduces horizontal AIH codes for the underlying technology. AIH 0401 is agentic AI.

    As far as we can tell, that is the first time the phrase appears in binding Union law. Its sibling code is the tell: AIH 0205 covers AI systems that learn from their environment, excluding agentic AI. Someone drafting a table of administrative codes decided agentic systems were a distinct enough class to carve out.

    Be careful about what this is. An administrative code is not a legal definition. There is no Article defining an agent, no risk tier keyed to autonomy, no obligation that scales with how many steps a system takes without a human in the loop. Union law has written the word down and left the substance for later.

    That gap is the whole problem for anyone building agentic systems in a regulated field. The obligations that will eventually attach are being drafted while the systems are being shipped, which means the only defensible position is to constrain what an agent is able to do rather than to check what it did. That is the argument we made in governance by construction, and it is why Justinian scopes an agent's action space to a jurisdiction before it is allowed to act rather than filtering the answer afterwards. Thomson Reuters put agentic adoption at 15% of professionals in 2026, with 77% expecting it to be central to their workflow by 2030. The rules will land in the middle of that curve.

    What changes for a law firm that uses AI

    Nearly every client alert on this regulation is written for a compliance officer at a company that builds AI. If you are a firm that uses it, the vocabulary is against you, so start with the distinction. A provider develops an AI system and puts it on the market under its own name. A deployer uses one under its own authority. Most law firms are deployers, and deployer duties are thinner but they are not zero.

    • AI literacy is yours, and it is live. Article 4 binds deployers as well as providers. The amendment softened it to supporting the development of literacy rather than guaranteeing a level, effective 27 July 2026. That is a lower bar, not an absent one, and there is still no exemption for small firms.
    • If you screen CVs with AI, you deploy a high-risk system. Recruitment sits in Annex III point 4. The obligations that came with that were due 2 August 2026 and are now due 2 December 2027. Sixteen extra months is the single most valuable thing this regulation gives an ordinary law firm.
    • If you publish AI-drafted commentary, disclose it. Article 50(4) covers text published to inform the public on matters of public interest, and the exemption runs on human editorial responsibility. Firm-blog content generated at volume without a named human reviewer is exactly the case it describes. From 2 August 2026.
    • If you run a client-facing chatbot, say it is a machine. Article 50(1), from 2 August 2026, unless it is obvious.
    • If you build internally, you may have become a provider. Put a tool into service under your own name and the full provider stack can attach, including registration where Article 6(3) applies. Firms building their own workflow layers on top of a model should get this assessed rather than assumed.
    • Fairness testing got easier. New Article 4a gives deployers a lawful basis to process special-category data strictly to detect and correct bias. Useful if a client has been asking whether your intake triage disadvantages anyone and GDPR was the reason you could not check.
    • Extraterritoriality has not changed. Article 2 reaches providers and deployers outside the Union where the output is used inside it. A firm in Dubai or Beirut serving EU clients is inside the perimeter. The Act follows the output, not the postcode.

    Eight questions for your legal AI vendor

    We are a legal AI vendor, so read these knowing we have to answer them too. That is rather the point — every one of these has a specific, checkable answer, and a vendor that cannot give you one is telling you something.

    • For anything we do with you, are you the provider of an Annex III high-risk system, and which point of Annex III?
    • Which Article 50 obligations does the product discharge for us, and which stay with us as deployer? Name them individually.
    • Do you mark AI-generated output in a machine-readable way today, and if not, will you before 2 December 2026?
    • Where Article 6(3) self-assessment applies to you, are you registered in the EU database, and can we see the entry?
    • What does your Article 4 support consist of — actual training and materials, or a PDF and a webinar?
    • Which of the two new Article 5 prohibitions could our use of your tool foreseeably trip, and what technical safeguards do you document against them?
    • Who is your authorised representative in the Union, and which market surveillance authority supervises you?
    • If your system is built on your own general-purpose model, is the AI Office now your exclusive supervisor under the rewritten Article 75?

    What did not change

    • General-purpose AI obligations. Articles 51 to 55, in force since 2 August 2025, untouched. Systemic-risk thresholds and model-provider duties stand.
    • The original prohibitions. Social scoring, subliminal manipulation, certain biometric categorisation and the rest have applied since 2 February 2025 and were not reopened.
    • Annex III itself. The classification list is unchanged. A system that was high-risk in June is still high-risk. Only the date it has to comply by moved, and assessments already done still stand.
    • The top and mid penalty tiers. Up to €35 million or 7% for prohibited practices, and the tier below it, are as they were.
    • The architecture. Risk tiers, conformity assessment, the notified-body route, the database, market surveillance. The EU is still the only jurisdiction on earth with a comprehensive horizontal AI law, and this amendment leaves that intact.

    Our read

    The delay is real and it is narrow. One chapter moved, for good reasons that have more to do with the absence of harmonised standards and conformity-assessment infrastructure than with any change of heart. Reading this as the EU backing off gets the next two years wrong.

    For vendors, the pressure went up. From 2 August 2026 the AI Office can inspect premises and seal them, impose periodic penalties, and take binding commitments. Registration survived a deletion attempt. Machine-readable marking of synthetic output becomes a product requirement with a hard date. None of that is a lighter touch; it is the same substance with better enforcement and a later invoice on the most expensive part.

    The dropped conditional trigger is the underrated detail. The November draft would have let the high-risk dates float on standards availability. The final text fixes them. Anyone who built a plan around further slippage should rebuild it: 2 December 2027 and 2 August 2028 now require a whole new legislative procedure to move, and nobody wants to run this one twice.

    We are not an EU-established company. We build from Beirut and our clients are concentrated across the Middle East and Europe, which puts us squarely inside Article 2 and outside the comfort of thinking this is somebody else's regulation. So we read the consolidated text on the day it published rather than waiting for a summary, and we would rather publish the dates plainly than sell anyone a compliance panic. The honest position on 28 July 2026 is that most firms have one deadline four days out and one twenty-eight months out, and confusing the two in either direction is the expensive mistake.

    This is a summary of a regulation, not legal advice, and it is not a substitute for reading the text. Dates and article references are taken from Regulation (EU) 2026/1744 as published in the Official Journal on 24 July 2026 and from published analyses of it. If a decision turns on any of this, verify against the consolidated text and take advice from a qualified lawyer in the relevant jurisdiction. HAQQ is not a law firm and does not provide legal representation.

    • Regulation (EU) 2026/1744 on EUR-Lex
    • European Commission AI Act Service Desk
    • Freshfields — the final Digital Omnibus on AI
    • Gibson Dunn — postponed high-risk deadlines and other key changes
    • Thomson Reuters — 2026 AI in Professional Services Report
    • Governance by construction — constraining what an agent can do
    • How HAQQ handles security and compliance
    • Justinian — jurisdiction-scoped legal AI
    • Why human review is a designed feature
    • How to become an AI-native law firm

    Try HAQQ AI Free

    Experience AI-powered legal drafting and research

    H

    HAQQ Team

    Regulatory

    Related Resources

    Governance by constructionSecurity and complianceJustinian — the engineHuman review in legal AI

    Related Posts

    Can Lawyers Use AI? A Country-by-Country Tracker (2026)

    Can Lawyers Use AI? A Country-by-Country Tracker (2026)

    AI Ethics in Law: ABA Opinion 512, the EU AI Act and What Lawyers Must Do

    AI Ethics in Law: ABA Opinion 512, the EU AI Act and What Lawyers Must Do

    Legal AI Market Report 2026: Sanctions & $11B Valuations

    Legal AI Market Report 2026: Sanctions & $11B Valuations

    Frequently asked questions

    What is Regulation (EU) 2026/1744?

    Regulation (EU) 2026/1744 is the amending regulation known as the Digital Omnibus on AI. It was adopted by the European Parliament and the Council on 8 July 2026, published in the Official Journal on 24 July 2026, and entered into force on 27 July 2026. It amends Regulation (EU) 2024/1689 (the EU AI Act) along with the Basic Aviation Regulation and the Machinery Regulation. Because it is a regulation, it applies directly in all 27 member states with no transposition into national law.

    Did the 2 August 2026 EU AI Act deadline move?

    No. The general application date and the Article 50 transparency obligations still apply from 2 August 2026. That includes telling people they are interacting with an AI system, labelling deepfakes, and disclosing AI-generated text published to inform the public on matters of public interest. The only concession is Article 50(2), the machine-readable marking of synthetic content, which gets a grace period to 2 December 2026 for systems already placed on the market before 2 August 2026. New systems get no transition.

    What are the new EU AI Act high-risk deadlines?

    Stand-alone high-risk systems listed in Annex III now have to comply by 2 December 2027, moved from 2 August 2026. AI embedded in regulated products under Annex I Section A has until 2 August 2028, moved from 2 August 2027. High-risk systems already in use by public authorities have until 2 August 2030. The Commission's November 2025 draft had tied these dates to a conditional standards-readiness trigger, but the final text removed it, so they are unconditional calendar dates that cannot slip without a new legislative procedure.

    What new prohibitions did the Digital Omnibus on AI add?

    Two, added to Article 5 and applicable from 2 December 2026: generating or manipulating intimate material without freely given, specific, informed, unambiguous and explicit consent, and generating or manipulating child sexual abuse material. Both sit in the top penalty tier of up to 35 million euros or 7% of worldwide annual turnover. A new Article 5(1a) limits provider liability to cases where such generation is the intended purpose, or is reasonably foreseeable and reproducible without significant technical modification, and providers are expected to document technical safeguards such as refusal training, prompt guardrails, content filtering and abuse detection.

    Does the EU AI Act apply to law firms that only use AI rather than build it?

    Yes, but with thinner obligations. A firm that uses an AI system under its own authority is a deployer. Article 4 on AI literacy binds deployers as well as providers and applies now, in its softened form, from 27 July 2026. Article 50 disclosure duties apply to deployers from 2 August 2026, including client-facing chatbots and AI-generated text published to inform the public. A firm using AI to screen job applicants is deploying a high-risk system under Annex III point 4, and that obligation now falls due on 2 December 2027 instead of 2 August 2026. A firm that puts its own tool into service under its own name may become a provider, with the full provider obligations.

    Did the EU AI Act's AI literacy obligation change?

    Yes, in substance rather than in timing. Article 4 previously required providers and deployers to ensure a sufficient level of AI literacy among staff. The amended text requires them to take measures to support the development of AI literacy, and states explicitly that no specific level has to be guaranteed. It applies from 27 July 2026. The duty is lower but it has not been removed, and there is no exemption for small organisations.

    Does the EU AI Act regulate agentic AI?

    Not substantively. The amendment introduces a new Annex XIV containing nomenclature codes used to designate what a notified body is competent to assess, and one of the new horizontal technology codes, AIH 0401, is agentic AI. This appears to be the first time the phrase is named in binding Union law. It is an administrative code, not a legal definition: there is no article defining an AI agent, no risk tier keyed to autonomy, and no obligation that scales with how many steps a system takes without human involvement. A sibling code, AIH 0205, covers systems that learn from their environment excluding agentic AI, which suggests the drafters treated agentic systems as a distinct class.

    What did not change in the EU AI Act?

    The general-purpose AI obligations in Articles 51 to 55, in force since 2 August 2025, are untouched. The original Article 5 prohibitions, applicable since 2 February 2025, were not reopened. Annex III itself is unchanged, so a system that was high-risk before is still high-risk and existing classification assessments stand. The top and mid penalty tiers are as they were. The risk-based architecture, conformity assessment, the notified-body route, the EU database and market surveillance all remain, and the registration duty for systems self-assessed as not high-risk under Article 6(3) survived a proposal to delete it.

    What's Next?

    Try HAQQ AI Free

    Experience AI-powered legal drafting and research

    Calculate Your ROI

    See how much time and money HAQQ saves your firm

    Browse 380+ Legal Prompts

    Ready-to-use prompts for every legal task

    Back to Blog

    Previous article

    Legal AI Benchmark 2026: How HAQQ Performed in an Independent Evaluation

    Next article

    How to Become an AI-Native Law Firm: The Operating Model, Not the Tool List

    Put this to work

    Ask HAQQ the question this article raised for you.

    HAQQ across all devices
    HAQQ Legal AI Platform Logo

    Your Legal AI Twin & Practice Management System for drafting, billing, and winning.

    Download on theApp StoreGet it onGoogle Play

    Product

    • HAQQ Legal AI Chat
    • HAQQ eFirm
    • Mobile App
    • HAQQ eBar
    • HAQQ eWallet
    • Justinian AI Engine
    • Enterprise
    • Security
    • Pricing

    Solutions

    • All Solutions
    • By Role
    • For You
    • By Use Case
    • By Feature
    • By Firm Size
    • By Country
    • By City
    • Specialized
    • Compare Us
    • ROI Calculator

    Resources

    • Blog
    • HAQQ Academy
    • Prompt Library
    • Clause Library
    • Document Library
    • Legal AI Skills
    • Free Tools
    • Legal AI Index
    • Changelog
    • Status

    Company

    • Meet the Team
    • Careers
    • Press & Events
    • Partnership
    • Students
    • Startup Program
    • Contact
    • Support
    • Localesar en fr es it de pt
    • Contactinfo@haqq.ai
    • Statusoperational·grounded
    • Terms of Service
    • Privacy Policy
    • Cookie Policy
    • Data Processing
    • humans.txtlawyers.txtsecurity.txt
    © 2026 HAQQ Inc. All rights reserved.Product engineered in-house by HAQQ. Website built with modern web tools.