EU AI Act and agrifood — the Digital Omnibus deferral, the corrected timeline, and why agricultural AI is mostly not high-risk

Europe (EU-27; extends to providers placing systems on the EU market from anywhere)

Content

The July 2026 regulatory scan recorded the AI Act’s September-2026 position as of July and drew agrifood conclusions that this unit corrects. Two corrections matter: the high-risk timeline moved again (the Digital Omnibus on AI is law, in force 27 July 2026), and Annex III does not reach agrifood at all — there is no environmental-monitoring or food-safety category. Agricultural AI’s regulatory exposure runs almost entirely through Article 6(1) safety components inside regulated products, and the Omnibus moved machinery onto a sectoral route.

Headline. The AI Act applies progressively to a 2 August 2028 full roll-out; Annex III high-risk rules now apply 2 December 2027 and Annex I product-embedded rules 2 August 2028; the national sandbox deadline slipped to 2 August 2027; Article 50 transparency duties and enforcement powers are live from 2 August 2026; and after the Omnibus, AI in agricultural machinery complies through the Machinery Regulation, by delegated act due 2 August 2028.

The amendment — Regulation (EU) 2026/1744

Proposed 19 November 2025 (COM(2025) 836); political agreement 7 May 2026; European Parliament endorsement 16 June 2026; Council final adoption 29 June 2026; adopted as Regulation (EU) 2026/1744 of 8 July 2026; published in the Official Journal 24 July 2026; in force 27 July 2026 — the third day after publication rather than the twentieth, because the regulation was written to apply “as a matter of urgency”.

The Commission’s 7 May 2026 statement is the plainest summary: “Rules for systems used in certain high-risk areas — including biometrics, critical infrastructure, education, employment, migration, asylum and border control — will apply from 2 December 2027. For systems integrated into products such as lifts or toys, the rules will apply from 2 August 2028.”

The corrected timeline (amended Article 113)

DateWhat applies
2 February 2025Chapters I-II: prohibitions and AI literacy
2 August 2025Chapter III Section 4, Chapter V (GPAI), Chapter VII, Art. 78
27 July 2026Arts. 102-110 (amendments to other EU legislation) — new date via Art. 113(d)
2 August 2026Article 50 transparency obligations; enforcement starts at EU and national level (prohibitions, GPAI, transparency, AI literacy); innovation-support measures; residual application
2 December 2026New prohibitions on nudification and CSAM-generating systems; Article 50(2) marking deadline for generative systems placed on the market before 2 August 2026
2 August 2027Member States must have at least one AI regulatory sandbox operational (Article 57(1), amended)
2 December 2027High-risk under Article 6(2) / Annex III (Chapter III Sections 1-3)
2 August 2028High-risk under Article 6(1) / Annex I (product-embedded) — full roll-out
2030-2031Large-scale IT systems compliance; Article 112(13) enforcement assessment

The Commission’s own implementation timeline now states: “The EU’s AI Act legislation applies progressively, with a full roll-out of the main application milestones foreseen by 2 August 2028. The timeline takes into account the AI Act amendments introduced by Digital Omnibus on AI.”

Penalties are unchanged: up to €35m or 7% of global annual turnover for prohibited practices; €15m or 3% for other violations including high-risk and GPAI obligations; €7.5m or 1% for supplying incorrect information. Actual fines imposed: none found as of 14 September 2026 — expected, since the sanctioning powers only became exercisable on 2 August 2026.

Other operative amendments that matter for agrifood

Is agricultural AI high-risk? Mostly not

Annex III does not name agriculture or food, and the peer-reviewed reference — Val, Idse Lucien, “The EU AI Act and the Food System: How the European Union AI Act Applies to Agrifood”, European Journal of Risk Regulation (2025), doi:10.1017/err.2025.10058 — is explicit on both the corpus’s mistaken hypotheses:

Other agrifood-touching obligations: livestock emotion recognition is not Annex III high-risk and triggers no Article 50(3) duty (the prohibition covers emotion inference “in workplaces and educational institutions”, and Article 50(3) duties attach to natural persons exposed). Environmental and soil-monitoring AI is not Annex III high-risk. Article 50 does bite on agrifood operations — farm-advisory chatbots (50(1)), AI-generated marketing imagery (50(4)), and AI-generated agronomy text published to inform the public without human editorial review (50(4)).

Sandboxes and enforcement reality

Sandboxes: effectively one. The April 2026 European Parliament Think Tank review, citing Deirdre Ahern (2025): “out of the 27 Member States, only one — Spain — has an AI regulatory sandbox which is up and running. Five are actively implementing their sandboxes, four have declared their intention to do so and 16 have not yet communicated their plans.” Spain’s National AI Sandbox (Royal Decree 817/2023) hosted 12 high-risk AI systems across essential services, biometrics, employment and critical infrastructure. No member-state sandbox has an agrifood track. With the deadline moved to 2 August 2027, most member states now have another year.

National authorities: Spain’s AESIA is the most advanced, publishing high-risk guidance and templates developed through its sandbox; Germany’s Bundesnetzagentur runs a “KI-Service Desk” with a planned KoKIVO coordination centre; the Netherlands has its data protection authority AP plus RDI as sandbox coordinators; Denmark adopted national implementation law in May 2025; Ireland has designated 15 authorities with a National AI Office planned; Belgium published its Article 77 fundamental-rights authorities list. France’s CNIL is active on AI but is not confirmed as the AI Act sandbox operator.

AI Office capacity: a hiring round for 40 new posts (tech, legal, operations) dedicated to AI Act enforcement, with an interest deadline of 8 September 2026.

Agritech compliance activity: none documented. The Code of Practice on Transparency of AI-generated Content has ~190 signatories (including Aleph Alpha, Anthropic, Black Forest Labs, Cohere, Google, Meta, Microsoft, Mistral, OpenAI, Synthesia, plus Getty Images, Iberdrola, Lenovo, Lufthansa) — no identifiable agrifood, agritech or agricultural-machinery company appears, no European agritech vendor was found publishing an AI Act compliance position, and none was found in a named sandbox (G-421).

What this unit is doing in the taxonomy

Anchors the EU regulatory-substrate cell of the corpus — the constraint side of the EU funder layer. Distinguishes from:

Why it matters for talks

Critical context