Free reference · Updated 30 August 2026

EU AI Act Omnibus 2026 Change Map

A primary-source before/after map for Regulation (EU) 2026/1744: what changed, when it applies, and what an AI governance or security review should update.

Download CSV

Operational before and after

These are application dates, not a recommendation to wait. Classification, inventory and evidence work still need lead time.

AreaBeforeAfter 2026/1744AppliesReview action
New Article 5 prohibitionsEight prohibited-practice points in Article 5(1)(a)–(h).Points (ba) and (bb) add non-consensual intimate material and child sexual abuse material.2 Dec 2026Test purpose, foreseeable reproducible outcomes, safeguards, consent, deployer use and exceptions.
Provider/deployer boundaryNo rules specific to the two new prohibitions.Paragraph 1a separates provider intent/foreseeability/safeguards from purposeful deployer use; paragraph 1b adds a narrow exception.2 Dec 2026Do not classify technical capability or accidental output alone as prohibited.
Annex III high-risk systemsHigh-risk obligations were scheduled for 2 August 2026.Chapter III, Sections 2–5 apply later for Annex III systems.2 Dec 2027Update the milestone while continuing classification and evidence work.
Annex I product-safety systemsArticle 6(1) rules were scheduled for 2 August 2027.Application moves one year later for Article 6(1) systems.2 Aug 2028Confirm the system is actually a safety component under the revised test.
Safety-component boundaryThe route could capture broad assistance features.Non-safety assistance, performance, efficiency, convenience and quality control are excluded unless failure endangers health or safety.2 Aug 2028Record function, failure mode and health/safety consequence.
Article 50 legacy systemsTransition was anchored to the former timetable.Systems placed before 2 August 2026 must meet Article 50(2) by the specific date.2 Dec 2026Inventory legacy systems and verify machine-readable marking.

The citation that matters

Points (ba) and (bb) are the prohibitions.

Paragraphs 1a and 1b define provider and deployer scope, safeguards, purposeful use and exceptions. A system is not automatically prohibited merely because it can technically generate an output.

Apply the boundary to a real system

The deterministic classifier asks about purpose, foreseeable reproducible outcomes, safeguards and actual use.

Open the free classifier

Official sources

Operational reference, not legal advice.