← Back to HAQQ Blog

EU AI Act Amendments 2026: What Regulation (EU) 2026/1744 Changed

By HAQQ Team · · 13 min read · Ai-legal-tech

Regulation (EU) 2026/1744 entered into force on 27 July 2026. High-risk duties moved to December 2027 and August 2028, and the 2 August 2026 transparency deadline did not move. Every change, and what it means for a firm that uses AI.

What actually happened

The European Parliament and the Council adopted Regulation (EU) 2026/1744 on 8 July 2026 in Strasbourg. It was published in the Official Journal on 24 July and entered into force on 27 July, on the third day after publication rather than the customary twentieth, because 2 August was too close to leave the text hanging. Its formal job is narrow: amend Regulation (EU) 2024/1689 — the AI Act — along with the Basic Aviation Regulation and the Machinery Regulation. Everyone calls it the Digital Omnibus on AI.

A regulation amending a regulation applies directly in all 27 member states. No transposition step, no national implementing act to wait for, no drift between Dublin and Warsaw. The AI Act you read last month is a different document today.

It is not a repeal, and it is not the deregulation some of the lobbying asked for. The risk tiers survived. The prohibited-practice list got longer, not shorter. What moved was the calendar for the single most expensive chapter, plus a handful of obligations that got cheaper to discharge.

The one date that did not move: 2 August 2026

This is the part the delay headlines bury, and it is the part that lands first. Article 50, the transparency chapter, still applies from 2 August 2026. If you are reading this the week it published, that is days away, not quarters.

One concession was granted. Article 50(2) — the machine-readable marking of synthetic output — gets a grace period to 2 December 2026 for systems already on the market before 2 August 2026. New systems get no such runway. The rest of Article 50 arrives on 2 August with no transition at all, and the new enforcement articles switch on the same day.

The nine changes that matter

Original law on the left, amended position on the right. Article numbers are to the AI Act as amended.

The EU just named agentic AI, and did not define it

The most interesting line in this regulation is not in any Article. It is in a new Annex XIV, a table of nomenclature codes used to designate what a notified body is competent to assess. Alongside vertical codes for application areas, the amendment introduces horizontal AIH codes for the underlying technology. AIH 0401 is agentic AI.

As far as we can tell, that is the first time the phrase appears in binding Union law. Its sibling code is the tell: AIH 0205 covers AI systems that learn from their environment, excluding agentic AI. Someone drafting a table of administrative codes decided agentic systems were a distinct enough class to carve out.

Be careful about what this is. An administrative code is not a legal definition. There is no Article defining an agent, no risk tier keyed to autonomy, no obligation that scales with how many steps a system takes without a human in the loop. Union law has written the word down and left the substance for later.

That gap is the whole problem for anyone building agentic systems in a regulated field. The obligations that will eventually attach are being drafted while the systems are being shipped, which means the only defensible position is to constrain what an agent is able to do rather than to check what it did. That is the argument we made in governance by construction, and it is why Justinian scopes an agent's action space to a jurisdiction before it is allowed to act rather than filtering the answer afterwards. Thomson Reuters put agentic adoption at 15% of professionals in 2026, with 77% expecting it to be central to their workflow by 2030. The rules will land in the middle of that curve.

What changes for a law firm that uses AI

Nearly every client alert on this regulation is written for a compliance officer at a company that builds AI. If you are a firm that uses it, the vocabulary is against you, so start with the distinction. A provider develops an AI system and puts it on the market under its own name. A deployer uses one under its own authority. Most law firms are deployers, and deployer duties are thinner but they are not zero.

We are a legal AI vendor, so read these knowing we have to answer them too. That is rather the point — every one of these has a specific, checkable answer, and a vendor that cannot give you one is telling you something.

What did not change

Our read

The delay is real and it is narrow. One chapter moved, for good reasons that have more to do with the absence of harmonised standards and conformity-assessment infrastructure than with any change of heart. Reading this as the EU backing off gets the next two years wrong.

For vendors, the pressure went up. From 2 August 2026 the AI Office can inspect premises and seal them, impose periodic penalties, and take binding commitments. Registration survived a deletion attempt. Machine-readable marking of synthetic output becomes a product requirement with a hard date. None of that is a lighter touch; it is the same substance with better enforcement and a later invoice on the most expensive part.

The dropped conditional trigger is the underrated detail. The November draft would have let the high-risk dates float on standards availability. The final text fixes them. Anyone who built a plan around further slippage should rebuild it: 2 December 2027 and 2 August 2028 now require a whole new legislative procedure to move, and nobody wants to run this one twice.

We are not an EU-established company. We build from Beirut and our clients are concentrated across the Middle East and Europe, which puts us squarely inside Article 2 and outside the comfort of thinking this is somebody else's regulation. So we read the consolidated text on the day it published rather than waiting for a summary, and we would rather publish the dates plainly than sell anyone a compliance panic. The honest position on 28 July 2026 is that most firms have one deadline four days out and one twenty-eight months out, and confusing the two in either direction is the expensive mistake.

FAQ

What is Regulation (EU) 2026/1744?

Regulation (EU) 2026/1744 is the amending regulation known as the Digital Omnibus on AI. It was adopted by the European Parliament and the Council on 8 July 2026, published in the Official Journal on 24 July 2026, and entered into force on 27 July 2026. It amends Regulation (EU) 2024/1689 (the EU AI Act) along with the Basic Aviation Regulation and the Machinery Regulation. Because it is a regulation, it applies directly in all 27 member states with no transposition into national law.

Did the 2 August 2026 EU AI Act deadline move?

No. The general application date and the Article 50 transparency obligations still apply from 2 August 2026. That includes telling people they are interacting with an AI system, labelling deepfakes, and disclosing AI-generated text published to inform the public on matters of public interest. The only concession is Article 50(2), the machine-readable marking of synthetic content, which gets a grace period to 2 December 2026 for systems already placed on the market before 2 August 2026. New systems get no transition.

What are the new EU AI Act high-risk deadlines?

Stand-alone high-risk systems listed in Annex III now have to comply by 2 December 2027, moved from 2 August 2026. AI embedded in regulated products under Annex I Section A has until 2 August 2028, moved from 2 August 2027. High-risk systems already in use by public authorities have until 2 August 2030. The Commission's November 2025 draft had tied these dates to a conditional standards-readiness trigger, but the final text removed it, so they are unconditional calendar dates that cannot slip without a new legislative procedure.

What new prohibitions did the Digital Omnibus on AI add?

Two, added to Article 5 and applicable from 2 December 2026: generating or manipulating intimate material without freely given, specific, informed, unambiguous and explicit consent, and generating or manipulating child sexual abuse material. Both sit in the top penalty tier of up to 35 million euros or 7% of worldwide annual turnover. A new Article 5(1a) limits provider liability to cases where such generation is the intended purpose, or is reasonably foreseeable and reproducible without significant technical modification, and providers are expected to document technical safeguards such as refusal training, prompt guardrails, content filtering and abuse detection.

Does the EU AI Act apply to law firms that only use AI rather than build it?

Yes, but with thinner obligations. A firm that uses an AI system under its own authority is a deployer. Article 4 on AI literacy binds deployers as well as providers and applies now, in its softened form, from 27 July 2026. Article 50 disclosure duties apply to deployers from 2 August 2026, including client-facing chatbots and AI-generated text published to inform the public. A firm using AI to screen job applicants is deploying a high-risk system under Annex III point 4, and that obligation now falls due on 2 December 2027 instead of 2 August 2026. A firm that puts its own tool into service under its own name may become a provider, with the full provider obligations.

Did the EU AI Act's AI literacy obligation change?

Yes, in substance rather than in timing. Article 4 previously required providers and deployers to ensure a sufficient level of AI literacy among staff. The amended text requires them to take measures to support the development of AI literacy, and states explicitly that no specific level has to be guaranteed. It applies from 27 July 2026. The duty is lower but it has not been removed, and there is no exemption for small organisations.

Does the EU AI Act regulate agentic AI?

Not substantively. The amendment introduces a new Annex XIV containing nomenclature codes used to designate what a notified body is competent to assess, and one of the new horizontal technology codes, AIH 0401, is agentic AI. This appears to be the first time the phrase is named in binding Union law. It is an administrative code, not a legal definition: there is no article defining an AI agent, no risk tier keyed to autonomy, and no obligation that scales with how many steps a system takes without human involvement. A sibling code, AIH 0205, covers systems that learn from their environment excluding agentic AI, which suggests the drafters treated agentic systems as a distinct class.

What did not change in the EU AI Act?

The general-purpose AI obligations in Articles 51 to 55, in force since 2 August 2025, are untouched. The original Article 5 prohibitions, applicable since 2 February 2025, were not reopened. Annex III itself is unchanged, so a system that was high-risk before is still high-risk and existing classification assessments stand. The top and mid penalty tiers are as they were. The risk-based architecture, conformity assessment, the notified-body route, the EU database and market surveillance all remain, and the registration duty for systems self-assessed as not high-risk under Article 6(3) survived a proposal to delete it.