EU AI Act Regulation 2026/1744 is binding law, and it moved the high-risk deadlines for many HR and education tools to 2 December 2027 (Annex III uses) and 2 August 2028 (AI inside regulated products). It did not delay the AI literacy duty, which has applied since 2 February 2025, or the Article 50 transparency rules, which apply from 2 August 2026.
This guide ties those EU AI Act deadlines to real training work: AI-generated course content, AI literacy programs, AI in recruitment and assessment, and AI inside regulated products. Each date is labeled by where it comes from, because vendor summaries disagree. Status is as of October 2026. This is not legal advice, so have counsel confirm before you commit budget.
What is Regulation (EU) 2026/1744, and is it binding law?
Regulation (EU) 2026/1744 is the Digital Omnibus on AI. It is binding EU law that amends the AI Act, Regulation (EU) 2024/1689. It was signed on 8 July 2026, published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It is no longer a proposal or a political agreement.
Here is how those dates are sourced. The Official Journal text on EUR-Lex shows publication on 24.7.2026. Recital (46) says the regulation “should enter into force as a matter of urgency on the third day following that of its publication in the Official Journal of the European Union.” Three days after 24 July is 27 July, and White & Case reports the same entry-into-force date.
Our tools could read the recitals and the new Article 4 on EUR-Lex, but not the final articles of the Official Journal text. For the operative provisions below, we quote the consolidated AI Act published by SpringLex (see its consolidated Article 113), which marks each amended article. We cross-checked it against several law-firm and regulator summaries. Check the Official Journal PDF before you cite any date in a board paper.
Which EU AI Act deadlines apply to training teams, and when?
Four date bands matter for learning teams: duties already applying, the 2 December 2026 transition, 2 December 2027 for Annex III high-risk uses, and 2 August 2028 for AI inside regulated products. The table ties each band to a training use case and shows where the date comes from. It is not legal advice.
| Date | What applies | Training use case | Source of the date |
|---|---|---|---|
| Already applying: 2 February 2025 | Article 4 AI literacy and the Article 5 prohibitions (Chapters I and II) | AI literacy measures for staff who use or run AI tools | Article 113(a), consolidated text |
| Already applying: 2 August 2025 | General-purpose AI model duties (Chapter V) | Mostly your model vendor’s duty; ask for its documentation | Article 113(b), consolidated text |
| Already applying: 2 August 2026 | General application date, including Article 50 transparency | AI-generated media in courses; chatbots in learner portals | Article 113, opening sentence, consolidated text |
| 2 December 2026 | Article 50(2) marking for generative systems placed on the market before 2 August 2026; new Article 5 prohibitions on intimate-image and child-abuse material | Vendor tools launched before 2 August 2026 must mark their outputs | Article 111(4) and Article 113(a), consolidated text |
| 2 December 2027 | Chapter III, Sections 1 to 3, for Annex III high-risk systems | Recruitment screening, learning-outcome evaluation, worker performance monitoring | Article 113(c)(i), consolidated text; recital (40) |
| 2 August 2028 | Chapter III, Sections 1 to 3, for Annex I high-risk systems | AI inside regulated products, such as machinery or medical devices, that product-safety teams train on | Article 113(c)(ii), consolidated text; recital (40) |
“Consolidated text” means the SpringLex version of the AI Act as amended. “Recital” means the preamble, which explains intent but is not the operative rule. No row relies on commentary alone.
Is the AI literacy duty still mandatory for L&D teams?
Yes. Article 4 still binds providers and deployers, but the amended text is softer. It requires measures “to support the development of AI literacy” and says it “does not require providers or deployers to guarantee any specific level of AI literacy of any individual.” The duty has applied since 2 February 2025.
The EUR-Lex text of Article 4(1) now reads: “Providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used.” That wording reaches beyond employees, for example to contractors acting on your behalf, and the measures should fit the role. An LMS built for audit evidence can hold the records.
The consolidated Article 99(4) fine tier lists Article 50 but not Article 4. Whether national law attaches penalties to Article 4 is a question for counsel.
Evidence Of Measures
Since the text drops any guaranteed level, log what you did and why it fit each role (audience, content, tools covered, review date) rather than chasing pass marks. A quiz score proves a score; a role-matched curriculum with a review date proves a measure.
Are you a provider or a deployer of your AI course tools?
Most L&D teams are deployers: they use an AI system under their authority. You become a provider if you develop an AI system, or have one developed and place it on the market or put it into service under your own name or trademark. That split decides who owes the Article 50(2) marking duty.
Article 3 defines a deployer as an organization “using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity.” Three cases show how this plays out in training:
- You buy a course-authoring tool and generate narration with it: you are probably a deployer, and the tool vendor is probably the provider.
- You build an internal assistant on a model API and release it to learners under your company brand: you may be a provider, so ask counsel.
- Your LMS vendor adds an AI feature that you switch on: the vendor is probably the provider, and you remain a deployer.
Check what AI in an LMS actually does before you decide which role you hold for each feature.
Does Article 50 apply to AI-generated course content?
Article 50(2) puts marking duties on providers of generative AI systems, not on course authors. If your authoring tool generates audio, images, video or text, the vendor owes machine-readable marking. Course owners, as deployers, face Article 50(4) disclosure duties for deep fakes and for public-interest text.
The operative wording of Article 50(2) is: “Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated.” The consolidated Article 111(4) text adds the transition: providers whose systems “have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026.” Recital (38) calls it a four-month transitional period.
Three consequences follow for learning teams:
- A generative tool placed on the market from 2 August 2026 gets no grace period.
- The transition is addressed to providers. It does not mention finished courses, so whether old assets need retroactive labels is a question for counsel.
- Article 3 defines a deep fake as AI content that “resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.” A cloned voice of a real executive is a likelier case than a cartoon presenter.
Breaches of Article 50 fall in the consolidated Article 99(4) tier: up to EUR 15 000 000 or, for an undertaking, 3 % of worldwide annual turnover, whichever is higher. For tool selection, our comparison of AI course authoring tools is the place to start asking vendors how they mark outputs.
Which training uses count as high-risk under Annex III?
Annex III lists high-risk uses in education and in employment. For learning teams, the entries that matter are AI that evaluates learning outcomes, AI used in recruitment and selection, and AI that monitors and evaluates worker performance. Whether corporate training counts as “vocational training” is not settled.
Annex III, point 3(b), covers “AI systems intended to be used to evaluate learning outcomes, including when those outcomes are used to steer the learning process of natural persons in educational and vocational training institutions at all levels.” Point 4 covers systems “intended to be used for the recruitment or selection of natural persons” and systems used “to monitor and evaluate the performance and behaviour of persons in such relationships.”
The open question is the phrase “educational and vocational training institutions.” The Commission’s draft high-risk classification guidelines were published on 19 May 2026 and updated on 23 July 2026. They are a non-binding draft, and we could not retrieve the sections that would settle workplace training. McCann FitzGerald (27 May 2026) offers its own example, not a quotation from the draft: a tool that only gives employees quiz feedback, with no use in performance assessment, is outside high-risk.
So the use of the output is the practical test. A score that only guides a learner is one thing; a score that feeds a promotion decision can move a tool into Annex III. Our guide to quality control for AI-generated assessments covers the assessment side.
What does the 2 December 2027 deferral actually buy you?
It buys planning time, not an exemption. Article 113(c) defers Chapter III, Sections 1 to 3, to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. Provider requirements and deployer duties sit in that block, and the deferral removes none of them.
Deployer duties include Article 26(7): “Before putting into service or using a high-risk AI system at the workplace, deployers who are employers shall inform workers’ representatives and the affected workers that they will be subject to the use of the high-risk AI system.” Article 26 sits in Chapter III, Section 3, so that duty moves with the deferral. Bratby, a law firm, reads the amended Article 113(c) as fixed calendar dates with no confirmation decision and no earlier trigger.
The useful reading is a runway of about 16 months from entry into force on 27 July 2026 to 2 December 2027. Use it for vendor documentation requests, contract changes and conversations with worker representatives.
Intended Purpose Clause
Annex III is written around systems “intended to be used” for listed purposes. Get each vendor’s intended purpose into the contract, and ban wiring training scores into promotion or termination decisions without review. Under Article 25(1)(c), changing a tool’s intended purpose so it becomes high-risk can make you its provider.
What are vendors telling you that is out of date?
Several articles written before the amendment still frame AI literacy as a 2026 deadline, and some summaries mix up the dates of different articles. If a vendor makes any claim below, treat it as out of date. The corrections use the amended text as of October 2026.
- “AI literacy must reach a certified level by August 2026.” The duty has applied since 2 February 2025, and the text no longer guarantees any specific level.
- “High-risk HR and education AI must comply on 2 August 2026.” Annex III uses now apply from 2 December 2027.
- “Article 50 has applied since 2 August 2025.” The general-purpose AI model duties apply from that date. Article 50 applies from 2 August 2026.
- “Everything AI-generated needs a label by 2 December 2026.” That date is the transition for providers of generative systems already on the market, not a deadline for course authors.
- “Embedded-product AI applies from August 2027.” Annex I systems now apply from 2 August 2028.
Where do the explainers disagree, and which should you trust?
The sources agree on the headline dates but differ on details. Where they split, trust the operative text of the amended articles over any summary. These are the three differences we found.
| Point | One account | Other accounts and the text |
|---|---|---|
| Date of the new Article 5 prohibitions | One July 2026 timeline we read places them on 2 August 2026 | Article 113(a), consolidated, sets 2 December 2026; Bratby and AKOS agree |
| Length of the marking transition | CMS describes a three-month window | Recital (38) says four months; Article 111(4) says 2 December 2026 |
| Wording of Article 4 | White & Case quotes “a sufficient level of AI literacy” | The amended Article 4(1) says “support the development of AI literacy” |
What should an L&D action checklist look like for 2026 to 2028?
Work in date order and keep one inventory as the base for every step. The list below moves from what already applies to what is coming. Each step produces a record you can show an auditor, a regulator or a works council.
- Now: list every AI tool in learning, hiring and assessment, with its vendor, its purpose, whether it generates content, and whether its output influences decisions about people.
- Now: run an AI literacy program matched to roles, and keep the evidence described above.
- Before 2 December 2026: ask each generative-tool vendor, in writing, when the tool was placed on the market and how outputs are marked.
- Before 2 December 2026: find AI-generated assets already published, using the versioning and retirement habits in LMS course versioning and retirement governance.
- During 2027: classify each person-affecting use against Annex III with counsel, and add intended-purpose and documentation clauses to contracts.
- Before 2 December 2027: plan how you will inform workers and their representatives about any high-risk system used at work.
- Before 2 August 2028: if your sector trains on products with embedded AI, check the Annex I position with product-safety counsel.
What should you do next?
Start with the inventory in step one and send each vendor three questions: when was this tool placed on the market, how does it mark generated outputs, and which Annex III purposes do you intend it for? Written answers tell you your provider or deployer role and your 2 December 2026 exposure.
Then book a short session with counsel using the table in this post. Bring the inventory, the vendor answers and one open scope question: whether corporate training tools fall under “vocational training.” Ask counsel to confirm each date against the Official Journal.
This post summarizes law and commentary as of October 2026 and is not legal advice. Recheck the Commission’s guidance each quarter, because the classification guidelines were still a draft when we read them.
FAQ
Q1. Is Regulation (EU) 2026/1744 in force yet?
Yes. It was signed on 8 July 2026, published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. Recital (46) provides for entry into force on the third day after publication. It amends the AI Act rather than replacing it, so most original duties and dates still apply as of October 2026.
Q2. Is AI literacy training still required under the EU AI Act?
Yes, in a softer form. Article 4 now requires providers and deployers to take measures to support the development of AI literacy of their staff and other persons acting on their behalf. It does not require them to guarantee any specific level of AI literacy of any individual. The duty has applied since 2 February 2025, so it was not delayed.
Q3. When do the high-risk rules apply to HR and education AI?
Under Article 113(c) as consolidated, the high-risk requirements in Chapter III, Sections 1 to 3, apply from 2 December 2027 for Annex III systems, which include recruitment and learning-outcome evaluation uses. They apply from 2 August 2028 for Annex I systems. Counsel should confirm which of your tools fall inside these categories.
Q4. Do I have to label AI-generated course content by 2 December 2026?
Not necessarily. The 2 December 2026 date in Article 111(4) is a transition for providers of generative systems placed on the market before 2 August 2026, covering the Article 50(2) machine-readable marking duty. Course authors who only use such tools are usually deployers, with narrower duties for deep fakes and public-interest text. Ask counsel about your role.
Q5. Does the EU AI Act apply to employers outside the EU?
Possibly. Article 2(1) covers providers placing AI systems on the Union market, deployers located in the Union, and providers and deployers in third countries where the output of the system is used in the Union. A non-EU employer with EU staff or EU learners should have counsel check whether its tools fall within that scope.
Q6. What are the fines for breaching the Article 50 transparency rules?
Under Article 99(4) in the consolidated text, breaching Article 50 can bring administrative fines of up to EUR 15 000 000 or, for an undertaking, up to 3 % of total worldwide annual turnover for the preceding financial year, whichever is higher. The Article 5 prohibitions carry a higher tier of EUR 35 000 000 or 7 %.