The consolidated version of the EU Artificial Intelligence Act, document reference 02024R1689-20260727, took effect on 27 July 2026, folding in the amendments made by Regulation (EU) 2026/1744. Six days later, on 2 August 2026, the bulk of the regulation became applicable. The combined text hands the European Commission exclusive supervision of artificial intelligence systems built into designated very large online platforms, arms it with inspection and sealing powers, and permits periodic penalty payments of up to 5 percent per day.
The amending act, Regulation (EU) 2026/1744, was adopted on 8 July 2026 and published in the Official Journal on 24 July 2026 under reference L 1744. The consolidated version runs to 165 pages. It carries no legal effect of its own, but it is the first single document showing the AI Act as it stands after the package known in Brussels as the Digital Omnibus.
Much of what the amendment does had been trailed. Council and Parliament negotiators reached a provisional agreement on 7 May 2026 fixing new compliance dates for high-risk systems, after talks collapsed days earlier without touching the August 2026 deadline and following a committee vote of 101 to 9 on 18 March 2026. What the consolidated text adds is the operative wording, and that wording contains changes absent from the headline deadline story.
Enforcement moves from 27 capitals to one
The most consequential structural change for the advertising industry sits in a rewritten Article 75 and four new articles numbered 75a to 75d.
Under the amended Article 75(1), the AI Office is exclusively competent for supervision and enforcement over two categories of system. The first covers AI systems based on general-purpose AI models where the model and the system are developed by the same provider, or by providers forming part of the same undertaking. The second covers AI systems that constitute, or that are integrated into, a very large online platform or very large online search engine designated under the Digital Services Act.
That second limb reaches directly into the advertising stack. The Commission designated its first set of platforms on 25 April 2023, a decision upheld by the General Court in the Zalando case on 3 September 2025. Facebook, Instagram, YouTube, Google Play, Google Maps, Google Shopping, Amazon Store, LinkedIn, TikTok, Google Search and Bing all carry designation. Ranking systems, creative generation tools and automated bidding engines operating inside those surfaces now answer to Brussels rather than to a national market surveillance authority.
The exclusive competence applies to providers. It reaches deployers only where the deployer is also the provider or part of the same undertaking. An advertiser running campaigns on Google or Meta properties therefore stays under its national regulator; the platform operating the underlying system does not.
Four carve-outs stay with national authorities under limb (a): systems tied to Annex I products, critical infrastructure under point 2 of Annex III, systems provided by law enforcement, border authorities and financial institutions, and systems used in the administration of justice.
Powers that read like antitrust procedure
Article 75a gives the AI Office the full toolkit of a market surveillance authority. Officials conducting an inspection may enter business premises, land or property located in the Union; examine books, data and other material regardless of storage medium; take copies or extracts; require oral or written explanations from staff and record the answers; and seal premises, books or records for the duration of the inspection.
Where national judicial authorisation is required for an on-site inspection, the AI Office applies for it and may do so as a precautionary measure. The judge verifies proportionality but, as the text specifies, does not review the necessity of the investigation and cannot demand information from the case file. Legality of the decision is reviewable only by the Court of Justice of the European Union.
Article 75a(1) also authorises the AI Office to fully reclaim from the relevant operator the totality of the costs of its supervision and enforcement activities in instances of non-compliance, including costs for human and technical resources. Investigation, in other words, becomes billable to the investigated party once non-compliance is established.
The 5 percent daily meter
Article 75c(5) permits the AI Office to impose periodic penalty payments to compel an operator to submit to an investigation or inspection, comply with an information request, give correct answers, carry out corrective actions, honour binding commitments, or comply with a non-compliance decision. Those payments must be effective and proportionate and, where applicable, shall not exceed 5 percent of the average daily income or worldwide annual turnover in the preceding financial year per day, calculated from the date appointed by the decision.
That sits alongside the fine ceilings in Article 99, left intact in substance: up to 35 million euros or 7 percent of worldwide annual turnover for the prohibited practices in Article 5, up to 15 million euros or 3 percent for most other infringements, and up to 7.5 million euros or 1 percent for supplying incorrect, incomplete or misleading information. Article 75c(4) extends those tiers to the AI Office and adds a trigger: failure to honour a commitment made binding under Article 75b.
Article 75d(4) requires the AI Office to publish the decisions it adopts under Articles 75b and 75c, naming the parties and setting out the main content including any penalties imposed. The procedural architecture echoes the draft implementing regulation published on 12 March 2026 covering general-purpose model investigations, extended now to systems rather than models alone.
What changed for advertising specifically
The safety component question is settled
A new Article 6(1a) states that AI systems used solely for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control shall not qualify as safety components. Article 6(1b) reinstates the classification where failure or malfunction would endanger health and safety, and Article 6(1c) excludes products that undergo third-party conformity assessment solely for reasons unrelated to health and safety, such as radio spectrum distribution or electromagnetic interference.
For adtech vendors embedding optimisation models into connected devices, retail hardware or in-store systems, the wording closes off an argument that campaign optimisation could pull a product into the Annex I high-risk route.
Job advertising stays high-risk, with a later date
Point 4(a) of Annex III still classifies as high-risk any AI system intended for the recruitment or selection of natural persons, and the text names one activity explicitly: placing targeted job advertisements. Creditworthiness evaluation and life and health insurance pricing under points 5(b) and 5(c) remain high-risk. Point 8(b) covers systems intended to influence the outcome of an election or referendum, while excluding tools used to organise, optimise or structure political campaigns from an administrative or logistical standpoint.
The amended Article 113 pushes the application of Chapter III Sections 1, 2 and 3 to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. Recruitment advertising platforms and lead generation systems in credit and insurance therefore gain sixteen further months before documentation, human oversight, logging and conformity assessment duties bite.
Transparency duties arrived on schedule
Nothing in the consolidated text moved the Article 50 date. The transparency obligations covering AI interaction disclosure, machine-readable marking of synthetic output, emotion recognition notification and deep fake labelling became applicable on 2 August 2026, as the Commission set out when it published its Article 50 guidelines and finalised Code of Practice on 20 July 2026 and when it released free labelling icons in early July. The exclusion of persuasive commercial content from the artistic-work carve-out means marketing creative carries the full disclosure duty.
Two amendments do touch the regime. A new Article 50(7) instructs the Commission to encourage codes of practice on detection, marking and labelling, to assess their adequacy taking utmost account of the opinion of the European Artificial Intelligence Board, and to adopt an implementing act specifying common rules if it judges a code inadequate. And Article 111(4), rewritten by the omnibus, gives providers of systems generating synthetic audio, image, video or text that were placed on the market before 2 August 2026 until 2 December 2026 to bring themselves into conformity with Article 50(2).
That window applies to providers, not deployers. A brand publishing synthetic creative through a tool released last year still owes the visible label from 2 August 2026; the tool vendor has until December to deliver the machine-readable mark underneath it.
A conditional gateway for bias testing
Article 4a is new. It permits providers of high-risk systems to process special categories of personal data, as defined in Article 9(1) of the General Data Protection Regulation, where strictly necessary for bias detection and correction under Article 10(2)(f) and (g). Six cumulative conditions apply, among them that the objective cannot be met with synthetic or anonymised data, that pseudonymisation and strict access controls are in place, that no other party receives the data, and that it is deleted once the bias is corrected.
Article 4a(2) extends the same conditional permission to providers and deployers of other AI systems and models, and to deployers of high-risk systems, where the processing is strictly necessary to address biases likely to harm health, safety or fundamental rights, or to produce discrimination prohibited under Union law. The paragraph closes with an explicit disclaimer: it creates no obligation to conduct bias detection or correction.
The provision matters for audience modelling and lookalike expansion, where measuring disparate impact has been legally awkward precisely because the attributes needed to measure it are the ones controllers may not hold. The Council of Europe guidance for equality bodies published in February 2026 flagged the same tension from the enforcement side.
Two new prohibitions from December
Article 5 gains points (ba) and (bb). The first prohibits placing on the market, putting into service or using an AI system that generates or manipulates realistic images, videos, audio or similar material depicting an identifiable person's intimate parts, or that person engaged in sexually explicit activities, without freely given, specific, informed, unambiguous and explicit consent. The second prohibits systems generating or manipulating child sexual abuse material within the meaning of Directive 2011/93/EU.
Article 5(1a) narrows the placing-on-market limb: prohibition applies where such generation is the intended purpose, or where design, training, architecture, capabilities or user-facing functionality make the outcome reasonably foreseeable and reproducible without significant technical modification and the system lacks adequate safeguards. Both prohibitions apply from 2 December 2026 under the amended Article 113, and Article 5 breaches carry the 35 million euro or 7 percent ceiling.
Smaller operators get a lighter file
The amendment threads smaller businesses through the text repeatedly and adds a category. Definition 14b introduces the small mid-cap enterprise, or SMC, as defined in Recommendation (EU) 2025/1099.
Article 11(1) allows SMEs, start-ups and SMCs to supply the Annex IV technical documentation in simplified form using a template the Commission must establish, and obliges notified bodies to accept it. Article 17(2) makes quality management implementation proportionate to organisation size. Article 99(1) instructs Member States to weigh the economic viability of those operators when imposing penalties, and confirms that enforcement may take the form of warnings and non-monetary measures rather than fines alone.
Article 4 on AI literacy also loosened. The obligation to develop staff literacy survives, but the amendment appends a sentence stating that it does not require providers or deployers to guarantee any specific level of AI literacy of any individual.
The notified body map now names generative and agentic systems
A new Annex XIV, introduced through an amended Article 30(2), sets out the codes conformity assessment bodies must cite when applying for designation. Alongside product codes AIP 0102 to AIP 0112 and biometric codes AIB 0201 to AIB 0203 covering remote biometric identification, biometric categorisation and emotion recognition, the annex adds technology codes. Code AIH 0301 covers generative systems, including those based on general-purpose models. Code AIH 0401 covers other emerging technologies, and names one: Agentic AI.
Notified bodies already designated under the product safety legislation in Section A of Annex I must apply for designation under the AI Act by 28 January 2028, per the amended Article 43(3).
Dates now scattered across five years
The compliance calendar is no longer a single ramp. Articles 102 to 110 applied from 27 July 2026, the general application date was 2 August 2026, and the two new Article 5 prohibitions arrive on 2 December 2026 alongside the Article 111(4) conformity deadline. National AI regulatory sandboxes must be operational by 2 August 2027, a year later than the original text required. High-risk obligations land on 2 December 2027 and 2 August 2028, systems intended for public authorities on 2 August 2030, and Annex X large-scale IT components on 31 December 2030.
Untouched by any of it: the 10 to the power of 25 floating point operations threshold in Article 51(2) that presumes high-impact capabilities in a general-purpose model, and the 10,000 registered business users in Annex XIII(f) that presumes high internal market impact. The Commission set out its interpretation of those thresholds in guidelines dated 18 July 2025, months after receiving the final General-Purpose AI Code of Practice on 10 July 2025.
Why Article 75 matters most to the marketing community
Advertising technology sits at an unusual intersection in this regulation. Most of it is not high-risk. Bid optimisation, creative generation and audience modelling fall outside Annex III unless they touch employment, credit, insurance or elections, and beyond the Article 50 duties the direct burden on a media agency or a brand remains comparatively light.
What the consolidated text changes is who asks the questions. When the systems that run auctions, rank content and generate creative inside designated platforms answer to a single Brussels office with inspection powers, cost recovery, daily penalty meters and a publication duty, the compliance posture of the platforms themselves changes. Documentation demands, contractual warranties and product timelines flow downstream to the advertisers and publishers who depend on those systems. The February 2025 Commission guidance on where influence becomes manipulation under Article 5already described a boundary that behavioural targeting approaches; the amended text puts a Union-level regulator with search-and-seal authority on the platform side of it.
There is a second, quieter effect. Article 25(2), rewritten by the omnibus, spells out what an initial provider owes a downstream party that turns a system into a high-risk one: technical documentation sufficient to assess Article 16 compliance, information about known limitations and failure modes, and targeted technical access for testing and validation. The duty falls away where the initial provider has clearly specified that its system is not to be changed into a high-risk system. Breach of Article 25(2) or (4) now carries the 15 million euro or 3 percent penalty under the new Article 99(4)(da). Vendor contracts for AI tooling in marketing stacks acquire a new clause to negotiate, and a new disclaimer to look for.
The consolidated text also arrives against a backdrop of platform product changes already reshaping creative workflows, including Google Ads restrictions on image assets and text overlay that sit uncomfortably beside visible labelling requirements.
Timeline
- 13 June 2024: The European Parliament and Council adopt Regulation (EU) 2024/1689, the Artificial Intelligence Act
- 1 August 2024: The AI Act enters into force
- 2 February 2025: Chapters I and II, including the original prohibited practices in Article 5, become applicable
- 10 July 2025: The Commission receives the final General-Purpose AI Code of Practice
- 18 July 2025: The Commission publishes general-purpose AI model guidelines setting compute thresholds
- 2 August 2025: Chapter III Section 4, Chapter V, Chapter VII and Chapter XII, plus Article 78, become applicable
- 4 September 2025: The Commission opens its consultation on Article 50 transparency guidelines
- 19 November 2025: The Commission introduces the Digital Omnibus package
- 18 March 2026: Parliament committees adopt report A10-0073/2026 by 101 votes to 9, with 8 abstentions
- 12 March 2026: The Commission publishes a draft implementing regulation on investigating and fining general-purpose model providers
- Early May 2026: Digital Omnibus trilogue talks collapse without moving the August 2026 date
- 7 May 2026: Council and Parliament reach provisional agreement fixing new high-risk deadlines
- 8 July 2026: The European Parliament and Council adopt Regulation (EU) 2026/1744
- 20 July 2026: The Commission publishes Article 50 guidelines and the finalised Code of Practice on Transparency of AI-Generated Content
- 24 July 2026: Regulation (EU) 2026/1744 appears in the Official Journal under reference L 1744
- 27 July 2026: The consolidated text 02024R1689-20260727 takes effect; Articles 102 to 110 become applicable
- 2 August 2026: The general application date of the AI Act, including Article 50 transparency obligations
- 2 December 2026: Article 5(1)(ba) and (bb) prohibitions apply; deadline for existing generative systems to meet Article 50(2)
- 2 August 2027: National AI regulatory sandboxes must be operational; Article 2(13) delegated acts due
- 2 September 2027: Post-market monitoring plan guidance and template due
- 2 December 2027: Chapter III obligations apply to Annex III high-risk systems
- 28 January 2028: Deadline for Annex I Section A notified bodies to apply for AI Act designation
- 2 August 2028: Chapter III obligations apply to Annex I high-risk systems
- 2 August 2030: Deadline for high-risk systems intended for use by public authorities
- 31 December 2030: Deadline for Annex X large-scale IT system components
Related PPC Land coverage
- EU AI Act gets its first real haircut - high-risk deadlines pushed to 2027 reports the 7 May 2026 provisional agreement that set the December 2027 and August 2028 dates now written into Article 113.
- Brussels AI Act talks collapse - but the August 2026 deadline holds explains why the Digital Omnibus negotiations left the Article 50 transparency date intact.
- EU Parliament committee backs AI Act delay with fixed 2027 deadline covers the March 2026 committee vote that shaped the deadline structure in the consolidated text.
- EU draft reveals how Brussels will probe and fine AI model providers documents the procedural rules for Commission investigations that the new Articles 75a to 75d extend to AI systems.
- EU AI content rules force publishers to label or risk 3% of turnover details the 20 July 2026 Article 50 guidelines and the finalised transparency Code of Practice.
- EU publishes free AI labelling icons ahead of August 2026 deadline sets out the split between provider marking duties and deployer labelling duties.
- Brussels sets AI labeling rules as data errors quietly drain ad budgets analyses the exclusion of persuasive commercial content from the artistic-work carve-out.
- European Commission opens consultation for AI transparency guidelines documents the September 2025 consultation that produced the Article 50 framework.
- EU clarifies AI model thresholds in new regulatory guidelines explains the compute thresholds that distinguish general-purpose AI models under the Act.
- EU publishes final General-Purpose AI Code of Practice reports the July 2025 delivery of the voluntary compliance framework for model providers.
- EU clarifies boundary between influence and manipulation under AI Act examines Article 5 prohibited practices where they intersect with behavioural targeting.
- Council of Europe unveils AI discrimination playbook for regulators covers the guidance for equality bodies on detecting algorithmic discrimination under the Act.
- Court upholds Zalando very large online platform status under EU Digital Services Act reports the September 2025 ruling on the designation regime that now defines AI Office competence.
- Google Ads bans blurry image assets and cuts eligibility to 60-day accounts documents the creative asset restrictions that sit alongside visible AI labelling duties.
Summary
Who: The European Parliament and the Council adopted Regulation (EU) 2026/1744. The European Commission, acting through the AI Office, gains exclusive supervisory competence over AI systems integrated into designated very large online platforms and search engines, and over AI systems built on general-purpose models by the same provider. National market surveillance authorities retain competence elsewhere. Providers, deployers, importers and distributors of AI systems placed on the Union market are covered, as are third-country operators whose system output is used in the Union.
What: A consolidated text of Regulation (EU) 2024/1689 incorporating the Digital Omnibus amendments. Changes include new Articles 75a to 75d granting the AI Office inspection, sealing, cost-recovery and periodic penalty powers of up to 5 percent per day; a new Article 4a permitting conditional processing of special category personal data for bias detection; two new prohibitions on non-consensual intimate imagery and child sexual abuse material; an Article 6(1a) exclusion for optimisation and convenience systems from safety component status; simplified documentation for SMEs, start-ups and small mid-cap enterprises; a new Annex XIV of notified body codes naming generative and agentic AI; and revised application dates across Article 113.
When: The amending regulation was adopted on 8 July 2026 and published in the Official Journal on 24 July 2026. The consolidated text carries the date 27 July 2026. The AI Act became generally applicable on 2 August 2026. The new Article 5 prohibitions and the Article 50(2) conformity deadline for existing generative systems fall on 2 December 2026. High-risk obligations follow on 2 December 2027 and 2 August 2028.
Where: The European Union and, through the EEA relevance clause, the wider European Economic Area. Extraterritorial reach extends to providers and deployers established outside the Union where the output produced by the AI system is used within it.
Why: The amendment responds to delayed harmonised standards and to industry pressure for simplification, while centralising enforcement over the largest platform and model operators in a single Union-level body. For marketing organisations, the practical consequences run through the platforms rather than directly: transparency labelling is already binding, recruitment and credit advertising systems face documented high-risk obligations from December 2027, and the vendors supplying generative creative tools now operate under a regulator with search-and-seal powers and the ability to bill its own investigation costs to a non-compliant operator.
Discussion