EU AI Act and agrifood — the Digital Omnibus deferral, the corrected timeline, and why agricultural AI is mostly not high-risk
Europe (EU-27; extends to providers placing systems on the EU market from anywhere)
Content
The July 2026 regulatory scan recorded the AI Act’s September-2026 position as of July and drew agrifood conclusions that this unit corrects. Two corrections matter: the high-risk timeline moved again (the Digital Omnibus on AI is law, in force 27 July 2026), and Annex III does not reach agrifood at all — there is no environmental-monitoring or food-safety category. Agricultural AI’s regulatory exposure runs almost entirely through Article 6(1) safety components inside regulated products, and the Omnibus moved machinery onto a sectoral route.
Headline. The AI Act applies progressively to a 2 August 2028 full roll-out; Annex III high-risk rules now apply 2 December 2027 and Annex I product-embedded rules 2 August 2028; the national sandbox deadline slipped to 2 August 2027; Article 50 transparency duties and enforcement powers are live from 2 August 2026; and after the Omnibus, AI in agricultural machinery complies through the Machinery Regulation, by delegated act due 2 August 2028.
The amendment — Regulation (EU) 2026/1744
Proposed 19 November 2025 (COM(2025) 836); political agreement 7 May 2026; European Parliament endorsement 16 June 2026; Council final adoption 29 June 2026; adopted as Regulation (EU) 2026/1744 of 8 July 2026; published in the Official Journal 24 July 2026; in force 27 July 2026 — the third day after publication rather than the twentieth, because the regulation was written to apply “as a matter of urgency”.
The Commission’s 7 May 2026 statement is the plainest summary: “Rules for systems used in certain high-risk areas — including biometrics, critical infrastructure, education, employment, migration, asylum and border control — will apply from 2 December 2027. For systems integrated into products such as lifts or toys, the rules will apply from 2 August 2028.”
The corrected timeline (amended Article 113)
| Date | What applies |
|---|---|
| 2 February 2025 | Chapters I-II: prohibitions and AI literacy |
| 2 August 2025 | Chapter III Section 4, Chapter V (GPAI), Chapter VII, Art. 78 |
| 27 July 2026 | Arts. 102-110 (amendments to other EU legislation) — new date via Art. 113(d) |
| 2 August 2026 | Article 50 transparency obligations; enforcement starts at EU and national level (prohibitions, GPAI, transparency, AI literacy); innovation-support measures; residual application |
| 2 December 2026 | New prohibitions on nudification and CSAM-generating systems; Article 50(2) marking deadline for generative systems placed on the market before 2 August 2026 |
| 2 August 2027 | Member States must have at least one AI regulatory sandbox operational (Article 57(1), amended) |
| 2 December 2027 | High-risk under Article 6(2) / Annex III (Chapter III Sections 1-3) |
| 2 August 2028 | High-risk under Article 6(1) / Annex I (product-embedded) — full roll-out |
| 2030-2031 | Large-scale IT systems compliance; Article 112(13) enforcement assessment |
The Commission’s own implementation timeline now states: “The EU’s AI Act legislation applies progressively, with a full roll-out of the main application milestones foreseen by 2 August 2028. The timeline takes into account the AI Act amendments introduced by Digital Omnibus on AI.”
Penalties are unchanged: up to €35m or 7% of global annual turnover for prohibited practices; €15m or 3% for other violations including high-risk and GPAI obligations; €7.5m or 1% for supplying incorrect information. Actual fines imposed: none found as of 14 September 2026 — expected, since the sanctioning powers only became exercisable on 2 August 2026.
Other operative amendments that matter for agrifood
- Article 3(14) “safety component” redefined — a component fulfils a safety function where “its intended purpose is to prevent or mitigate risks to health and safety of persons or property”. (Note CEMA’s 2024 objection that including property broadened Article 6 beyond the Machinery Regulation.)
- Machinery Regulation (EU) 2023/1230 moved from Annex I Section A to Section B — the single most consequential change for agrifood; see
units/eu-machinery-regulation-agricultural-ai.md. - New Article 57(3a): a new EU-level sandbox run by the AI Office, with priority access for SMEs, start-ups and small mid-caps.
- New Articles 75a-75e: AI Office enforcement powers — investigations, on-site inspections, binding commitments (75b), non-compliance decisions with fines and periodic penalty payments (75c), CJEU unlimited jurisdiction, five-year limitation periods. The AI Office gains exclusive competence over AI systems built on GPAI models where model and system share a provider, and over AI systems integrated into very large online platforms.
- Article 4 (AI literacy) replaced — an obligation to “take measures to support the development of AI literacy”, expressly not requiring providers or deployers “to guarantee any specific level of AI literacy of any individual”.
- New Article 4a — processing of special-category personal data for bias detection and correction.
- New Article 2(13) — an equivalence clause for Annex I Section A legislation, with delegated acts due by 2 August 2027.
Is agricultural AI high-risk? Mostly not
Annex III does not name agriculture or food, and the peer-reviewed reference — Val, Idse Lucien, “The EU AI Act and the Food System: How the European Union AI Act Applies to Agrifood”, European Journal of Risk Regulation (2025), doi:10.1017/err.2025.10058 — is explicit on both the corpus’s mistaken hypotheses:
- Food-safety AI is not high-risk: “such AI systems are currently not considered high-risk under the AI Act, because they are not covered by any of the listed EU harmonisation legislations listed in Annex I.”
- Annex III(2) critical infrastructure excludes the food system: “Critical infrastructure: AI systems intended to be used as safety components in the management and operation of critical digital infrastructure, road traffic, or in the supply of water, gas, heating or electricity.” Val: “since Annex III (2) does not mention the food system, AI systems managing parts of the food system are not classified as high risk on a literal reading of the AI Act.” The July scan’s suggestion that “environmental monitoring” or “food safety” are Annex III categories touching agrifood is unsupported — no such categories exist.
- The live route is Article 6(1). Annex I Section B lists Regulation (EU) No 167/2013 (approval and market surveillance of agricultural and forestry vehicles), and the Machinery Regulation covers harvesting robotics, food-processing and sorting machinery and indoor-farming systems. Val’s worked example: an automated tractor using sensors, cameras and AI to avoid collisions — the AI collision-avoidance component is a safety component, hence high-risk.
Other agrifood-touching obligations: livestock emotion recognition is not Annex III high-risk and triggers no Article 50(3) duty (the prohibition covers emotion inference “in workplaces and educational institutions”, and Article 50(3) duties attach to natural persons exposed). Environmental and soil-monitoring AI is not Annex III high-risk. Article 50 does bite on agrifood operations — farm-advisory chatbots (50(1)), AI-generated marketing imagery (50(4)), and AI-generated agronomy text published to inform the public without human editorial review (50(4)).
Sandboxes and enforcement reality
Sandboxes: effectively one. The April 2026 European Parliament Think Tank review, citing Deirdre Ahern (2025): “out of the 27 Member States, only one — Spain — has an AI regulatory sandbox which is up and running. Five are actively implementing their sandboxes, four have declared their intention to do so and 16 have not yet communicated their plans.” Spain’s National AI Sandbox (Royal Decree 817/2023) hosted 12 high-risk AI systems across essential services, biometrics, employment and critical infrastructure. No member-state sandbox has an agrifood track. With the deadline moved to 2 August 2027, most member states now have another year.
National authorities: Spain’s AESIA is the most advanced, publishing high-risk guidance and templates developed through its sandbox; Germany’s Bundesnetzagentur runs a “KI-Service Desk” with a planned KoKIVO coordination centre; the Netherlands has its data protection authority AP plus RDI as sandbox coordinators; Denmark adopted national implementation law in May 2025; Ireland has designated 15 authorities with a National AI Office planned; Belgium published its Article 77 fundamental-rights authorities list. France’s CNIL is active on AI but is not confirmed as the AI Act sandbox operator.
AI Office capacity: a hiring round for 40 new posts (tech, legal, operations) dedicated to AI Act enforcement, with an interest deadline of 8 September 2026.
Agritech compliance activity: none documented. The Code of Practice on Transparency of AI-generated Content has ~190 signatories (including Aleph Alpha, Anthropic, Black Forest Labs, Cohere, Google, Meta, Microsoft, Mistral, OpenAI, Synthesia, plus Getty Images, Iberdrola, Lenovo, Lufthansa) — no identifiable agrifood, agritech or agricultural-machinery company appears, no European agritech vendor was found publishing an AI Act compliance position, and none was found in a named sandbox (G-421).
What this unit is doing in the taxonomy
Anchors the EU regulatory-substrate cell of the corpus — the constraint side of the EU funder layer. Distinguishes from:
- Machinery Regulation (
units/eu-machinery-regulation-agricultural-ai.md) — the sectoral compliance route the Omnibus created for AI-enabled machinery. - European AI Office and governance architecture (
units/european-ai-office-governance-architecture.md) — who enforces, and who is at the table. - GPAI Code of Practice (
units/general-purpose-ai-code-of-practice.md) — the provider-side compliance pathway for the models agritech vendors build on. - CRCF (
units/eu-carbon-removal-certification-framework.md) — the other EU instrument that creates demand for agrifood AI (MRV), through market creation rather than compliance obligation. - OECD 2026 Coordinated Plan review (
units/oecd-2026-progress-eu-coordinated-plan-ai-agriculture.md) — the policy-assessment layer that called for exactly the AI Act / Machinery Regulation guidance this cycle found delivered in sectoral form.
Why it matters for talks
- The corrected dates are the talk. Annex III 2 December 2027; Annex I 2 August 2028; sandboxes 2 August 2027; transparency and enforcement live now. Anyone using the 2026/2027 dates from earlier briefings is out of date.
- “AI in agriculture is mostly not high-risk” is a defensible, sourced claim — and it is counter-intuitive enough to carry a talk: the EU’s strictest AI regime leaves most agricultural AI outside its high-risk tier.
- The high-risk exposure is machine safety, not farming intelligence. A tractor’s collision-avoidance component is high-risk; a soil-monitoring model is not. That is the line to draw.
- Food-safety AI is not high-risk (Val, EJRR 2025) — a peer-reviewed finding that contradicts the intuitive assumption about food regulation.
- Zero fines and zero agritech compliance activity is the honest state of play six weeks into enforcement: architecture binding, practice unproven, agrifood sector absent from the compliance conversation.
- The €35m / 7% penalty structure remains the corpus’s most substantive AI regulatory risk figure globally, and remains untested.
Critical context
- The July scan’s Annex III claims (“environmental monitoring”, “food safety”) are corrected here; no such Annex III categories exist.
- “Most agricultural AI is not high-risk” is a reading of the amended text plus peer-reviewed analysis, not a Commission statement.
- The Article 6 high-risk classification guidelines remain draft (published 19 May 2026), so classification questions are still unsettled (G-423).
- The claim that an EU high-risk AI database applies from 2 August 2026 is unconfirmed by the Commission’s own timeline (G-422).
- No fines and no formal investigations found — an absence of evidence; enforcement only began on 2 August 2026.
- The sandbox state-of-play figure is April 2026 vintage, not current (G-424).
- The 2 August 2029 review and the pending delegated acts (Art. 2(13) equivalence by 2 Aug 2027; machinery AI requirements by 2 Aug 2028) are the next decision points to track.