EU AI Act update: Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. Check the consolidated AI Act and route-specific application dates before relying on older timelines. Consolidated AI Act EU AI Act update: Regulation (EU) 2026/1744 is in force; check route-specific application dates. Consolidated AI Act

Blog · EU AI Act status reviewed 2 September 2026 · 7 min read

In force ยท applies 2 Dec 2026Provision-specific review

EU AI Act Nudification Ban: What AI Deployers Should Check

A practical deployer review guide for the Regulation (EU) 2026/1744 provisions covering non-consensual intimate-content generation and AI-created child sexual abuse material.

Reviewed: 2 September 2026.

Current-law source basis: Regulation (EU) 2026/1744 and Regulation (EU) 2024/1689 as consolidated from 27 July 2026. The Commission announcement and Council releases of 7 May 2026 and 29 June 2026 provide legislative history; the Commission AI Act FAQ is an institutional explanation. This page is educational and does not provide legal advice or compliance guarantees.

Quick answer: Regulation (EU) 2026/1744 adds new Article 5 provisions for AI practices involving realistic non-consensual intimate or sexually explicit material and child sexual abuse material. That matters now for vendor screening, internal use-case reviews, content-safety controls and evidence files, while Regulation (EU) 2026/1744 entered into force on 27 July 2026.

Compliance team reviewing AI content safety controls and the Regulation (EU) 2026/1744 Article 5 provisions for non-consensual intimate-content generation
AI content-safety review for vendor due diligence, prohibited-use screening, and evidence retention.

What changed on 7 May 2026

Regulation (EU) 2026/1744 adds prohibitions concerning AI practices involving non-consensual sexual or intimate content and child sexual abuse material. The provisions are in force and apply from 2 December 2026.

That distinction matters: the regulation is in force, while the new Article 5 provisions apply from 2 December 2026. Planning should use the consolidated text without presenting the provisions as already applicable.

What the nudification ban is really about

This is not just a content-labeling issue. It is a prohibited-practices issue. A deployer does not need to operate a consumer "nudification app" to have review work to do.

Risk bucketPractical review question
Fake intimate image or video generationCan the system generate or transform content that creates intimate synthetic media of real people without consent?
Workflow enablementDo templates, shortcuts, plugins, or editing tools make prohibited generation materially easier?
Child sexual abuse materialDo safety controls specifically block child sexual abuse material and ambiguous age-related abuse patterns?
Third-party model exposureCould imported models, wrappers, extensions, or APIs bypass the organisation's normal controls?

What deployers should review now

Vendor due diligence checklist for AI image-generation tools showing safety controls abuse reporting evidence retention and prohibited-use review
Vendor due diligence checklist for image-generation tools, safety controls, abuse reporting, and retained evidence.

Vendor questions to ask

Evidence to retain

Evidence artifactWhy it matters
Feature inventory entryShows the system, owner, purpose, users, data categories, and content-generation capability.
Vendor questionnaire responseRecords what the supplier said about model capability, restrictions, and safety controls.
Safety-control summaryDocuments prompt filtering, upload checks, moderation, abuse reporting, and escalation routes.
Approval or rejection noteShows whether the feature was approved, restricted, disabled, or escalated for legal review.
Regulatory status noteSeparates current published-law decisions from Regulation (EU) 2026/1744 provisions and their application dates.

Common mistakes

The biggest mistake: treating this as a consumer-app issue only. Enterprise teams often use image, avatar, video, design, HR, marketing, and support tools without checking the underlying model capability or plugin path.

What to do next

If a system touches image generation, transformation, face editing, avatar creation, or visual manipulation, review it now. Update the AI system inventory, run vendor due diligence, confirm prohibited-practice exposure, and keep an evidence trail that records what was checked and when.

FAQ

Direct answers on the Regulation (EU) 2026/1744 provisions, deployer review duties, vendor checks, and evidence retention.

No. Regulation (EU) 2026/1744 is already in force. Its new Article 5(1)(ba) and (bb) provisions and related paragraphs apply from 2 December 2026. Use the consolidated AI Act to check scope, conditions and exceptions.

Regulation (EU) 2026/1744 added Article 5 provisions concerning specified realistic non-consensual sexual or intimate content and child sexual abuse material, subject to statutory conditions and exceptions. Use the consolidated AI Act for the final numbering and text.

Deployers still choose vendors, activate features, approve workflows, and expose users to system outputs. A deployer evidence file should record vendor capability checks, safety controls, acceptable-use restrictions, escalation paths, and the decision note explaining whether a feature was approved, restricted, or rejected.

No. The nudification-ban review is not limited to consumer photo apps. Enterprise image, video, avatar, marketing, HR, customer-support, or design workflows can raise review questions if third-party models, plugins, or editing features could enable intimate synthetic-content generation.

An organisation should keep the use-case review, vendor questionnaire, safety-control summary, approval or rejection note, escalation path, and dated legal-status record. The legal-status record should separate current published-law decisions from Regulation (EU) 2026/1744 provisions and their application dates.

Related EU AI Compass resources