REFERENCE

EU AI Act deadlines for healthcare AI

The dates, the obligations already in force, and the reliefs that exist on paper but have not yet been granted.

Last reviewed
AUG 12, 2026
Reading time
6 MIN
Category
ai-healthcare

Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July. It moved several high-risk deadlines and left others untouched.

EU AI Act deadlines applying to healthcare AI
ObligationApplies from
Article 5 prohibited practices2 February 2025, in force
General-purpose AI provider obligationsAugust 2025, in force
Article 50 transparency and content-marking duties2 August 2026, in force
Two further prohibitions2 December 2026
Stand-alone high-risk systems, Annex III2 December 2027, moved from 2 August 2026
High-risk AI embedded in regulated products, Annex I, which includes AI-enabled medical devices2 August 2028, moved from 2 August 2027
Pre-existing high-risk systems used by public authorities2 August 2030

The deadlines are now unconditional. The Commission’s November 2025 draft tied them to confirmation that support measures such as harmonised standards were available. The adopted text removed that trigger, so these are fixed calendar dates that cannot move again without a fresh legislative procedure.

What are the EU AI Act deadlines for healthcare AI?

The table above is the whole answer. Regulation (EU) 2026/1744 moved two sets of high-risk deadlines and left three sets of obligations that are already in force exactly where they were. The date that matters to most manufacturers is 2 August 2028, for high-risk AI embedded in regulated products, which is where an AI-enabled medical device sits.

Which EU AI Act obligations apply to healthcare companies right now?

Three sets of obligations are in force today and none of them was deferred.

Article 5 prohibited practices have applied since 2 February 2025. They ban specific uses outright rather than regulating how they are done.

General-purpose AI provider obligations have applied since August 2025. A healthcare company building on a foundation model rather than training its own should establish whether it is a provider or a deployer, because the obligations differ.

Article 50 transparency duties applied from 2 August 2026. Article 4, on AI literacy, was rewritten into a duty to take measures supporting its development rather than a duty to ensure it, and national supervision of it began on 3 August 2026. It binds every deployer, including hospitals.

The practical exposure is not the 2028 date. It is a team that heard “delayed” and stood down work on obligations that were already live.

Does the EU AI Act delay affect Medical Device Regulation obligations?

No. Regulation (EU) 2026/1744 amends the AI Act. It does not touch Regulation (EU) 2017/745 on medical devices or Regulation (EU) 2017/746 on in vitro diagnostics, and no MDR or IVDR obligation, deadline or conformity assessment requirement moved.

An AI-enabled medical device therefore answers to two regimes on separate clocks. The device regime is unchanged and applies now. The AI regime applies from 2 August 2028 for Annex I embedded systems.

The Omnibus did add machinery for reducing duplication between them. Medical devices sit in Annex I Section A, where the AI Act’s high-risk framework applies directly and is intended to be built into existing product compliance systems rather than run alongside them. The Commission may also limit the AI Act’s application through implementing acts where sectoral law already imposes equivalent requirements, and it is now obliged to publish guidance helping Annex I operators comply in a way that minimises the burden.

None of those implementing acts has been adopted and the guidance has not been published. A company planning today cannot rely on relief that has not yet been granted.

Do you need a separate quality management system for the AI Act?

No, and this is the clearest piece of duplication the Omnibus removed.

The AI Act’s quality management obligations for high-risk systems can be implemented through the quality management system already required under the MDR or the IVDR. A single system can satisfy both, which means a manufacturer with a compliant ISO 13485 quality system is extending it rather than building a second one alongside.

That changes the shape of the work. The task is a gap analysis against the AI Act’s additional requirements, principally data governance, technical documentation, risk management, human oversight and post-market monitoring, mapped onto procedures that already exist. It is not a parallel compliance programme, and budgeting for it as one overstates the cost while understating how early it has to start.

Companies already subject to sector-specific rules should build the AI requirements into existing compliance systems rather than creating a separate AI compliance structure.

What does Article 50 of the EU AI Act require?

Article 50 sets transparency obligations that apply regardless of whether a system is high-risk, and they have been in force since 2 August 2026.

In outline, a person interacting with an AI system must be told they are doing so, unless it is obvious. Synthetic audio, image, video and text output must be marked in a machine-readable format as artificially generated or manipulated. Deployers of emotion recognition or biometric categorisation systems must inform the people exposed to them. Deep fake content must be disclosed as such.

For healthcare the duties reach further than most teams assume. A patient-facing assistant, a clinical documentation tool that drafts text, and generative output used in clinical communication can each fall within Article 50 without the product being high-risk at all.

What happens if an AI medical device undergoes a significant design change?

This is the provision most often missed when the deferral is read as a reprieve.

Transitional relief for systems already placed on the market before the new application date is conditional rather than permanent. Where a system undergoes a significant change in its design after that point, the relief ceases and the obligations apply.

For a static device that is a genuine reprieve. For an adaptive model, or any product on a normal release cadence, it is a clock that an ordinary engineering decision can stop. A company relying on the 2028 date should establish which of its planned releases would constitute a significant design change, and should hold that assessment in writing rather than in the judgement of whoever approves the release.

The threshold is not defined with a bright line, which makes the assessment itself a documented decision rather than an obvious one.

What is the difference between Annex I and Annex III high-risk AI?

The distinction decides which deadline applies, and healthcare products appear in both. The Commission’s Draft Guidelines on the Classification of High-Risk AI Systems, published 19 May 2026, are the working reference for the boundary.

Annex I covers AI that is a safety component of, or is itself, a product already regulated under existing EU product legislation. An AI-enabled medical device regulated under the MDR sits in Section A of that annex, where the full high-risk framework applies directly. These systems moved to 2 August 2028.

Annex III lists stand-alone high-risk use cases. In health these include systems that infer health status from physical or biological signals, assess access to healthcare, price or assess risk for health or life insurance, and prioritise emergency care. These moved to 2 December 2027.

A company can hold both. A manufacturer selling an AI-enabled device and also running a stand-alone triage or insurance-pricing tool has two deadlines eight months apart, governed by different annexes, in the same organisation.

Related reading

The current edition of Vital Signs: AI Healthcare covers how these deadlines are landing in practice, including the reliefs that exist on paper but have not been granted. If you are establishing which obligations reach your product, that is the work our EU Launchpad does.

References

Primary sources

  • Regulation (EU) 2026/1744 of 8 July 2026, the Digital Omnibus on AI. Published in the Official Journal 24 July 2026, in force 27 July 2026. eur-lex.europa.eu/eli/reg/2026/1744/oj/eng
  • Regulation (EU) 2024/1689 of 13 June 2024, the Artificial Intelligence Act. eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
  • European Commission, Draft Guidelines on the Classification of High-Risk AI Systems, 19 May 2026. digital-strategy.ec.europa.eu
  • Council of the European Union, Artificial intelligence: Council gives final green light to simplify and streamline rules, 29 June 2026. consilium.europa.eu
  • European Commission AI Act Service Desk, frequently asked questions, including a Digital Omnibus category. ai-act-service-desk.ec.europa.eu/en/faq

Secondary analysis

  • Mayer Brown, EU AI Act News: Digital Omnibus on AI, New Guidance on Risk Classification, GPAI, and Transparency Obligations, July 2026.
  • Gibson Dunn, EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes, 27 May 2026.
  • Hunton, EU Digital Omnibus on AI Enters Into Force, August 2026.
  • Sidley Austin, EU Digital Omnibus Implications for MedTech Companies, December 2025.

Last reviewed 12 August 2026. Maintained by HealthSeed AG. Not legal advice.

PUBLISHED BY

HealthSeed AG

Swiss healthcare venture studio. Market intelligence and operator perspectives from 30+ European markets. Operator-led execution with shared-risk pricing for biotech, medtech, diagnostics, and digital health companies entering and scaling in European markets.

GET MORE LIKE THIS

Subscribe to Vital Signs.

Five sector-specific briefings every week. Real-time intelligence for health innovation leaders.

TALK TO US

Considering EU market entry?

30-minute discovery call. We will cover your product, target markets, and whether HealthSeed is the right partner.

Book a Discovery Call →