LinkedInInstagramXTikTok

The AI Act’s research exemption ends when your pilot goes live

The Omnibus moved the deadline, not the starting line

Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and pushed the compliance date for stand-alone high-risk AI systems listed in Annex III from 2 August 2026 to 2 December 2027. Many companies read that as breathing room for their internal AI projects. It is not. The Omnibus amended Article 2(2) and Article 2(7) of Regulation (EU) 2024/1689 and added Article 2(13), but left the research and development exclusions in Article 2(6) and Article 2(8) untouched.

Those two provisions are the ones most often invoked and least often read. The assumption in most organisations is that anything called a pilot sits outside the AI Act until formal launch. The Regulation draws the line earlier than people expect.

What does the scientific research exclusion cover?

Article 2(6) provides that the Regulation does not apply to AI systems or AI models, including their output, specifically developed and put into service for the sole purpose of scientific research and development. Every word is load-bearing.

A model built to test a scientific hypothesis qualifies. A model built to find out whether a commercial idea works does not, because its purpose is the commercial idea. Recital 25 confirms the narrowness, stating that the exclusion is without prejudice to compliance where a system is placed on the market or put into service as a result of that research. In practice this is a provision for universities.

When does an AI system stop being pre-market?

Article 2(8) is the one businesses should read. It excludes any research, testing or development activity regarding AI systems or AI models prior to their being placed on the market or put into service, and adds that such activities must still comply with applicable Union law.

The exclusion therefore lasts exactly as long as the system has been neither placed on the market nor put into service. Article 3(9) defines placing on the market as the first making available of a system on the Union market. Article 3(11) is what catches people out: putting into service means the supply of an AI system for first use directly to the deployer or for own use in the Union for its intended purpose. Own use counts. The moment your internal tool is handed to the team it was built for and used for the job it was built to do, it has been put into service.

Why real world testing is treated separately

The final sentence of Article 2(8) states that testing in real world conditions is not covered by the exclusion. This closes the obvious gap. A company cannot run a high-risk system on live subjects, gather live outcomes and call it development.

Real world testing has its own regime in Article 60, open to providers and prospective providers of high-risk systems listed in Annex III or covered by Section A of Annex I. Article 60(4)(f) caps a testing plan at six months, extendable once by a further six after notification to the market surveillance authority. Article 61 requires informed consent, dated and documented.

A worked example

A Swedish logistics company builds an internal tool that scores applicants for warehouse roles. For four months a data team trains and evaluates it against historical applications, with no live candidate affected. During that period Article 2(8) applies and the AI Act does not, although the GDPR does.

In month five, HR starts using the tool to rank real applicants. That is supply for own use for its intended purpose under Article 3(11), so the system has been put into service. Because the company developed the tool and put it into service under its own name, it is the provider on the Article 3(3) definition as well as the deployer. Candidate screening sits in Annex III, point 4(a), so the requirements in Chapter III bite on 2 December 2027.

Common mistakes

The first is treating the word pilot as a legal category. It is not one. The Regulation asks whether the system has been placed on the market or put into service, and that is answered by conduct, not by internal labels or budget lines.

The second is assuming the exclusion covers data protection too. Article 2(8) expressly requires development activity to comply with other applicable Union law, and training a model on employee or applicant records engages the GDPR from day one. The third is confusing Article 2(6) with Article 2(8), when the sole purpose test is rarely met commercially.

Recommended actions

Start by writing down, for each AI project, the date on which the system was or will be first used for its intended purpose by anyone inside or outside the organisation. That date, not the launch date in the product plan, is when the AI Act begins to apply, and it should be recorded before it passes rather than reconstructed later.

Then classify each project against Annex III while it is still genuinely pre-market, because reclassifying after go-live costs far more. Keep development activity documented and separable from live use. If you intend to run a high-risk system on real people before placing it on the market, treat that as Article 60 testing and plan for its limits and consent requirement.

Frequently asked questions

Does the AI Act apply to a model we only use internally?

Yes. Article 3(11) defines putting into service to include supply for own use in the Union for the system’s intended purpose. Internal deployment is deployment, and it ends the exclusion in Article 2(8) even though nothing has been sold or made available externally.

Did the Digital Omnibus widen the research exemption?

No. Regulation (EU) 2026/1744 amended Article 2(2) and Article 2(7) and inserted Article 2(13), but the wording of Article 2(6) and Article 2(8) is unchanged. What moved were the application dates for high-risk obligations, not the scope provisions.

Can we test a high-risk system on real users before launch?

Only under Article 60. Testing in real world conditions is expressly carved out of the Article 2(8) exclusion, so it requires a testing plan, registration, a maximum of six months extendable by six more, and informed consent under Article 61.

Conclusion

The Digital Omnibus bought companies time on the high-risk requirements. What it did not buy is time on the threshold question of whether the AI Act applies at all, because Article 2 is unchanged and Article 3(11) still counts internal use as putting into service. The organisations comfortable in December 2027 will be the ones treating their pilots as regulated systems in waiting.

At Lawgent, we help companies work out when the AI Act starts to apply to a given system, document the development phase properly, and structure real world testing under Articles 60 and 61. Get in touch if you would like us to review where your AI projects sit against Article 2.

Leave a Reply

Your email address will not be published. Required fields are marked *


0Cart0,00 

No products in the cart.

Return to shop