By Rafael Luque Ocaña

A classification made in June cites a calendar that no longer exists

The Digital Omnibus rewrote articles and moved dates in the AI Act. Decisions made before that stayed on file exactly as they were, because a record keeps the conclusion, not the text it was based on.

That sources change is well known. What's almost never said — and it's a further step, not the same idea — is that when a source changes, the decisions made on it stop being correct without anyone touching them.

This isn't a theoretical warning. It happened this summer, at scale, and it's still happening.

What changed, and what it left behind

Regulation (EU) 2026/1744, published in the Official Journal of the EU on 24 July 2026, didn't just adjust details of the AI Act. Among other things:

  • It set the application of Annex III at 2 December 2027 (the 2024 text said 2 August 2026), and that of Annex I at 2 August 2028.
  • It replaced Article 4 in its entirety, changing the duty to ensure a sufficient level into a duty to take measures to support the development, with a closing clause that expressly denies any obligation to guarantee anyone's level.
  • It inserted two new points into the list of prohibited practices in Article 5, each with its own date of application.
  • And it withdrew a date that Article 111(2) contained, replacing it with a cross-reference.

Now take a diligent organisation that did its work in June. It classified its systems, noted what applied to each one and by which date, and documented its literacy measures using the Article 4 test as it stood then.

All of that work was done properly. And today, part of it is wrong. Not because it was done badly, but because the text it was based on no longer says the same thing.

Why re-reading the file doesn't catch it

Here's the mechanism, and it's what sets this problem apart from a simple "needs updating".

A classification record keeps the conclusion: this system falls into such a category, this obligation applies to it, from such a date. What it doesn't keep — almost never — is which exact wording of which article that conclusion rested on.

Without that link, when the article changes there's no way to trace the path back. The system's file still looks impeccable: well written, dated, with an owner, with its conclusion. An expired entry looks exactly like a current one.

And that's why the defect doesn't surface by reviewing what's written, which is what anyone would do. It surfaces when someone compares what's written against the regulation currently in force — which means, when there's already a reason to compare.

What the organisation would need to see it

Consider what it would take to answer this question: "the Omnibus changed Article 4 and the Annex III date; which of my decisions relied on that?"

You need to know, for every recorded decision, which articles it rested on. Not a mention in prose — "the AI Act was taken into account" — but an explicit link between the conclusion and its grounds.

With that, the question is answered in a moment: list the decisions that cite the affected articles and review only those. Without it, the options are reviewing everything — which no one does — or reviewing nothing — which is what usually happens.

That link is exactly what a spreadsheet doesn't keep, and not because the tool falls short: a spreadsheet records rows, and this is a relationship between rows and an external text that changes on its own.

What can be done without changing anything

Three things, and all three are a matter of discipline, not technology.

Note the articles, not just the conclusion. Every classification should state what it rests on. A column with the references is enough to turn review into something targeted instead of exhaustive.

Note the date of the source, not just the date of the decision. "Classified on 12 June 2026 under Article 6 as worded at the time" allows something that "classified on 12 June 2026" doesn't.

And have a trigger tied to the regulation. Not reviewing "every six months" — that gets skipped without anyone noticing — but reviewing when an amendment is published. The Official Journal has a date; the work is linking it to your own records.

Why this matters more than it seems

Because a classification isn't a document: it's the basis on which you decided what to do and what not to do.

If you concluded that a system didn't require certain measures because the obligation was arriving in 2026 and it now arrives in 2027, the conclusion still holds — with more room to spare. But if you concluded something relying on wording that was replaced in its entirety, as happened with Article 4, what you have on file describes a duty that no longer exists in that form.

Neither case is serious today. Both would become serious the day someone asks why a given decision was made, and the answer is written against a text that can no longer be cited.

Content in accordance with Articles 4, 5 and 111 and Annexes I and III of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (Official Journal of the EU, 24 July 2026).

This article is for informational purposes only and does not constitute legal advice.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (CIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es). More information in the privacy policy.