Regulation (EU) 2026/1744 is dated 8 July 2026. It appeared in the Official Journal on 24 July and entered into force on 27 July. Nine days later, on 2 August, the transparency provisions of the AI Act became applicable and every technology desk in Europe wrote the same story about chatbots having to identify themselves.
The more consequential document was the one from the week before, and almost nobody covered it that way.
What 2026/1744 does is amend Regulation (EU) 2024/1689, the AI Act itself, and move the compliance deadline for stand-alone high-risk systems listed in Annex III from 2 August 2026 to 2 December 2027. Systems embedded in regulated products under Annex I moved from 2 August 2027 to 2 August 2028. That is a slip of roughly sixteen months for the first group and a year for the second, granted six days before the original deadline arrived.
What Annex III Actually Covers
Annex III is not an abstraction. It is the list of eight domains the AI Act treats as high risk: biometrics, critical infrastructure, education, employment, access to essential public and private services, law enforcement, migration and border control, and the administration of justice.
Read that list against the obligations that were supposed to attach to it. A provider of an Annex III system would have had to build a risk management system under Article 9, meet data governance requirements under Article 10, design human oversight into the product under Article 14, produce technical documentation under Article 11, obtain CE marking under Articles 47 through 49, and register the system in an EU database under Article 71. Deployers would have had to run effective human oversight, retain logs for six months, notify affected individuals, and, if a public body, complete a fundamental rights impact assessment under Article 27.
None of that binds anybody until December 2027.
What Did Land On Sunday
Article 50 survived intact, along with the Article 5 prohibitions and the general purpose AI obligations. In practice that means three duties are now live and enforceable.
A person interacting with an AI system has to be told they are interacting with an AI system. Artificially generated or manipulated image, audio and video content has to be identified as such, which covers deepfakes. Emotion recognition and biometric categorisation systems have to notify the people exposed to them.
Those are real requirements and they will change how products look. They are also, all three, disclosure duties. Article 50 governs what a system must say about itself. It does not govern whether the system works, whether it was tested, whether a human can override it, or whether the person it just rejected for a mortgage has any way of finding out why.
The rule that became binding on Sunday requires a hiring algorithm to admit it is an algorithm. The rule that would have required it to be documented, tested, logged and overseen by a human was moved to December 2027 the previous week.
The Grace Periods Inside The Grace Period
Even the parts that landed came with softening. Generative systems already deployed before 2 August 2026 have until 2 December 2026 to satisfy the machine readable marking requirement, a four month cushion for anything already in the market. The omnibus also introduced a new prohibition covering systems whose reasonably foreseeable output is non consensual intimate imagery or child sexual abuse material, and attached a transitional period to that as well, running to 2 December 2026.
A ban on tools built to generate child sexual abuse material arrives with a four month runway. There is presumably a procedural reason for that, and it is still a sentence that should be read twice.
The penalty architecture, at least, was left alone. Prohibited practices under Article 5 carry fines of up to 35 million euros or 7 percent of global annual turnover. High risk violations under Article 99(4) carry up to 15 million euros or 3 percent. Supplying incorrect information to authorities carries up to 7.5 million euros or 1 percent. For comparison, the GDPR tops out at 20 million euros or 4 percent, so the AI Act's ceiling is genuinely higher than the law that made European privacy enforcement famous.
A ceiling only matters when something underneath it is binding. The 3 percent tier attaches to high risk obligations that no longer apply for another sixteen months.
The Case For What Brussels Did
The argument on the other side is stronger than the outrage version admits, and it deserves stating properly.
The harmonised technical standards that Annex III providers were meant to build against were not finished. Conformity assessment bodies were not accredited in sufficient numbers. Member states had not all designated their market surveillance authorities. Enforcing a documentation and CE marking regime with no agreed standards to conform to, and no bodies to assess conformity, would have produced a compliance theatre in which small European firms paid consultants to guess and large American ones absorbed the cost as a rounding error. Regulators asked for time because the machinery was not built, and that is a real reason rather than a lobbying one.
Second, nothing in the omnibus repeals anything. The obligations are deferred, not deleted, and the Article 5 prohibitions on unacceptable practices have been in force since February 2025. The AI literacy duty under Article 4 has applied since the same date. This is a schedule change to a law that still exists.
Third, an unenforceable deadline that arrives and is universally ignored damages a regulator more than an honest postponement does. Brussels chose the embarrassment it could survive.
What that defence does not answer is the timing. The regulation was dated 8 July, published on 24 July and in force on 27 July, which is to say the change landed close enough to the original deadline that any organisation which had spent two years and real money preparing for 2 August 2026 got the news with days to spare. Firms that treated the deadline as serious are now sixteen months ahead of a market where nobody else had to bother. That is the lesson being taught, and it will be remembered in December 2027.
The Verdict
Regulation (EU) 2026/1744 entered into force on 27 July 2026 and moved the AI Act's high risk obligations for Annex III systems to 2 December 2027 and for Annex I embedded systems to 2 August 2028. On 2 August 2026 the Article 50 transparency duties went live on schedule. Europe now requires an AI system to introduce itself, and will not require it to be documented, tested or humanly overseen for another sixteen months.