Category: AI Regulation | Reading time: 9 minutes

What happened, and the three dates that get confused
Regulation (EU) 2026/1744 of the European Parliament and of the Council, dated 8 July 2026, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026.1 It amends Regulation (EU) 2024/1689, the Artificial Intelligence Act.
Those three dates matter because they are routinely collapsed into one. The Regulation is dated 8 July, published 24 July and in force from 27 July. If you cite the wrong one in a board paper, the person checking will find the discrepancy before they find your argument.
The consolidated text incorporating the amendment carries the identifier 02024R1689-20260727 and runs to 151 pages.2 Every statement in this article is taken from that document rather than from commentary about it.
The amendment is not light. There are 75 amendment markers through the consolidated text, and they include the whole of Article 113, which sets the application timetable, plus a new Article 4a on processing special categories of personal data for bias detection.2
The timetable, as it now reads
Article 113 as amended provides that the Regulation applies from 2 August 2026, with the following exceptions.2
Chapters I and II apply from 2 February 2025, with the exception of Article 5(1), first subparagraph, points (ba) and (bb), and Article 5(1a) and (1b), which apply from 2 December 2026.
Chapter III Section 4, Chapter V, Chapter VII and Chapter XII and Article 78 apply from 2 August 2025, with the exception of Article 101.
Chapter III, Sections 1, 2 and 3, with the exception of Article 6(5), apply from 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III, and from 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I.
Articles 102 to 110 apply from 27 July 2026.
What actually moved
Two shifts, and they are different sizes.
Annex III high-risk moved by sixteen months. These systems previously fell under the general 2 August 2026 application date. They now apply from 2 December 2027.
Annex I high-risk moved by twelve months. These are AI systems that are safety components of products already covered by Union harmonisation legislation, or products in their own right. They were scheduled for 2 August 2027 and now apply from 2 August 2028.
The distinction is worth holding onto, because "the high-risk deadline moved by sixteen months" is only true of one of the two categories. If your firm is dealing with AI embedded in a regulated product rather than a stand-alone system, your date moved by a year, not sixteen.
The new prohibitions, and the part that is being reported loosely
The 2 December 2026 date attaches to two new prohibitions inserted into Article 5. It is being reported in places as though Article 5 prohibitions begin then. They do not. The original prohibitions have applied since 2 February 2025 and are unchanged.
The new Article 5(1)(ba) prohibits the placing on the market, putting into service or use of an AI system that generates or manipulates realistic images, videos, audio or similar material of an identifiable natural person's intimate parts, or of an identifiable natural person engaged in sexually explicit activities, without that person's freely given, specific, informed, unambiguous and explicit consent for that generation or manipulation.2
The new Article 5(1)(bb) prohibits the same acts in relation to material or performance within the meaning of Article 2, points (c) and (e), of Directive 2011/93/EU, except where a "without right" defence applies under national law.2
Both are then qualified, and this is the part almost nobody is covering.
Under the new Article 5(1a), placing on the market or putting into service such a system is only prohibited where that generation or manipulation is the intended purpose of the system, or where the system's design, training, architecture, capabilities or user-facing functionalities make that generation a reasonably foreseeable and reproducible outcome without requiring significant technical modification, and the system does not have reasonable and adequate technical safety measures and other safeguards to reliably prevent it, taking into account reasonably foreseeable misuse, and to correct observed or reported misuse.2
Use is only prohibited where the deployer uses the system for the purpose of generating or manipulating such material.2
Article 5(1b) adds that manipulation which does not increase the exposure of any depicted intimate parts, or alter the nature of any depicted sexually explicit activities, does not constitute manipulation for the purposes of point (ba).2
The practical effect is that these are not blanket prohibitions on general-purpose image or video models. They turn on intended purpose, on foreseeability without significant modification, and on the adequacy of safeguards. A summary that says "the AI Act now bans deepfake tools" is not describing what the text says.
The distinction that catches people out
The consolidated text is the practical way to read the current wording, because it merges the original and the amendment into one document. It is not the law.
EUR-Lex is explicit about this, and so is the document itself. Its header states that the text is meant purely as a documentation tool and has no legal effect, that the Union's institutions do not assume any liability for its contents, and that the authentic versions of the relevant acts are those published in the Official Journal.2
For a governance document, the correct practice is to read the consolidated text, cite the authentic Official Journal instrument, and name the amending Regulation where a date or a provision has changed. Citing only the consolidated text is convenient and slightly wrong. Citing only the original is now out of date.
The numbering problem, which predates all of this
Separately from the amendment, there is a numbering trap that has been catching people since 2024.
The article numbers changed substantially between the Commission's 2021 proposal and the final Regulation. In the final text, post-market monitoring by providers is Article 72,2 and reporting of serious incidents is Article 73.2 In the 2021 proposal, those subjects sat at Articles 61 and 62.
In the final Regulation, Article 61 concerns informed consent to participate in testing in real world conditions outside AI regulatory sandboxes, and Article 62 concerns measures for providers and deployers, in particular SMEs including start-ups.
If you are holding a mapping document or a policy that cites Articles 61 and 62 for post-market monitoring and incident reporting, it may rest on the 2021 proposal, or it may simply contain a citation error. Either way it is worth establishing which version it was written against before relying on it.
What to do with this
Three checks, in order of how quickly they can be done.
Check the dates in your own material. Any AI policy, compliance matrix or vendor assessment citing 2 August 2026 for high-risk obligations predates 27 July 2026. That does not make the rest of the document wrong, but it tells you when it was last reviewed.
Check the article numbers. Post-market monitoring is 72. Serious incident reporting is 73. Record-keeping is 12, which is frequently omitted from mapping tables altogether and is the natural citation for logging and traceability.
Record what you checked against, and when. This is the one that pays off later. A governance document that states the version and date it was verified against ages visibly. One that does not simply goes stale, and nobody finds out until someone else checks.
The bottom line
Nothing in this amendment is difficult. The dates moved, two prohibitions were added, and the qualifying paragraphs are narrower than the headlines suggest.
The difficulty is that regulatory material decays quietly. A policy written in June was accurate in June. It is now wrong about a deadline by sixteen months, and there is nothing in the document itself to tell a reader that.
The habit worth building is not reading every amendment. It is recording, on every document that cites a rule, which version was checked and on what date. That single line is what turns a document that ages into a document that tells you it has aged.
References
The authentic instrument. Regulation (EU) 2024/1689, Official Journal version, permanent identifier: http://data.europa.eu/eli/reg/2024/1689/oj
This article is general guidance, not legal advice. Whether and how the AI Act applies to a specific system in your organisation depends on your role in the AI value chain, the classification of the system and your jurisdiction. That is a question for your compliance function and legal counsel.
Footnotes
Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026, recorded in the consolidated text of Regulation (EU) 2024/1689 as the amending instrument, published at OJ L 1744, 24 July 2026. Available via EUR-Lex: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32026R1744 ↩
Regulation (EU) 2024/1689, consolidated text as at 27 July 2026, CELEX 02024R1689-20260727. All article wording, application dates and the documentation-tool notice are taken from this document, read in full on 11 August 2026. Available via EUR-Lex: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02024R1689-20260727 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11