The Product Boundary of the Defence Exemption
Where the Artificial Intelligence Act’s military exclusion ends when one technical platform serves military and non-military customers
On 27 July 2026 Regulation (EU) 2026/1744 entered into force and changed the timetable of the Artificial Intelligence Act without touching its scope provision. Six days later, on 2 August 2026, Regulation (EU) 2024/1689 became generally applicable, while the substantive duties for high-risk systems listed in Annex III moved to 2 December 2027 and those for systems covered by the product legislation in Annex I to 2 August 2028. Against those dates stand the ceilings the same Regulation sets: administrative fines of up to €35 million or 7 per cent of total worldwide annual turnover for the prohibited practices in Article 5, up to €15 million or 3 per cent for the operator duties listed in Article 99(4), and, for providers of general-purpose AI models, fines under Article 101(1) of up to 3 per cent of annual total worldwide turnover or €15 million, whichever is higher. The structural constraint sits in Article 2(3): the exclusion attaches to the purpose for which an identifiable system is placed on the market, put into service or used, and not to the identity of the supplier. What the disclosed material does not settle is the point at which one product becomes two systems.
The report proceeds in twelve sections and a conclusion. The first reads Article 2(3) and recital 24 of Regulation (EU) 2024/1689 against the Commission’s Guidelines on prohibited artificial intelligence practices. The second sets national security against public security using Article 4(2) of the Treaty on European Union and the judgments in Privacy International, La Quadrature du Net and Others and Latvijas Republikas Saeima. The third builds six evidential layers from Article 3(12) and Annex IV and reads them against the European Defence Agency’s white paper on trustworthiness for AI in defence. The fourth sets out the application dates introduced by Regulation (EU) 2026/1744 and the investigatory powers created by Commission Implementing Regulation (EU) 2026/1755. The fifth applies the layers to nine dual-use product pathways drawn from Annex III. The sixth treats the value-chain roles and Article 25. The seventh addresses general-purpose AI models, the Commission’s guidelines on their scope and the Code of Practice. The eighth examines corporate separation. The ninth reads the procurement file against Article 23 of Directive 2009/81/EC. The tenth separates export control, data protection and cybersecurity law, including the exclusion in Regulation (EU) 2024/2847. The eleventh sets out the financial consequences of scope classification. The twelfth describes the division of enforcement, with the European Parliamentary Research Service’s count of designated contact points, the role of the European Data Protection Supervisor, Special Report 08/2024 of the European Court of Auditors and Law No 132 of 23 September 2025. The report does not value undertakings, does not assess securities and does not quantify the cost of compliance for any named supplier.


