August 2, 2026 was supposed to be the day the EU AI Act’s high-risk rules landed. It wasn’t. The Digital Omnibus pushed most of them to December 2027 — and a lot of healthcare teams have now concluded, wrongly, that they have nothing to do for eighteen months.
1. What Actually Changed on August 2
The original text of the AI Act put the full weight of the high-risk regime — conformity assessment, technical documentation, CE marking, registration in the EU database — on August 2, 2026. Teams building clinical AI have been planning against that date for two years.
Then the Digital Omnibus happened. The short version: standalone high-risk systems listed in Annex III move to 2 December 2027, and high-risk AI embedded in regulated products under Annex I moves to 2 August 2028. That second bucket is the one most healthcare AI actually falls into, because it covers AI inside devices already regulated under the MDR and IVDR.
One caveat worth stating plainly, because it changes how much you should bet on it: the Omnibus was agreed politically and takes legal effect on formal adoption and publication in the Official Journal. If you are making a decision with real money attached, check the current status of the text rather than taking this post — or any post — as the final word. Regulatory timelines in this file have moved once already.
2. What Is In Force Right Now
Here is the part that gets lost in the headlines. The deferral was surgical. It moved the high-risk regime and left everything else exactly where it was.
| Obligation | Status | Applies from |
|---|---|---|
| Article 5 — prohibited practices | In force | 2 Feb 2025 |
| Article 4 — AI literacy duty | In force | 2 Feb 2025 |
| GPAI model obligations | In force | 2 Aug 2025 |
| Article 50 — transparency duties | In force | 2 Aug 2026 |
| Annex III standalone high-risk | Deferred | 2 Dec 2027 |
| Annex I high-risk in regulated products | Deferred | 2 Aug 2028 |
If you build an ambient scribe, a patient-facing chatbot, or anything that generates or manipulates content a patient will read, Article 50 is live and it applies to you today. It was not deferred. I have had three conversations in the last month with founders who assumed otherwise.
3. Which Bucket Is Your Healthcare AI In?
Almost every argument about the AI Act in healthcare is really an argument about classification. Get this wrong and every downstream decision is wrong with it. There are three answers that matter.
Annex I — AI inside a regulated product
Your AI is a component of, or is itself, a medical device requiring Notified Body assessment under the MDR or IVDR. Diagnostic imaging triage, an algorithm that outputs a clinical finding, software classified as a Class IIa device or above. This is the largest bucket in clinical AI and it now has until 2 August 2028.
Annex III — standalone high-risk
Not a medical device, but listed as high-risk anyway. The healthcare-adjacent entries people miss are emergency triage and dispatch systems, and AI used in access to essential services. If you route patients by acuity but never make a clinical claim, read Annex III carefully before assuming you are out. Deadline: 2 December 2027.
Limited risk — transparency only
Scheduling, documentation, admin summarisation, most ambient scribes. No high-risk obligations, but Article 50 requires that people know they are interacting with an AI system and that synthetic content is marked as such. That duty is live now. If you are building in this space, our guide to shipping a HIPAA-compliant AI medical scribe covers the architecture side of the same problem.
A system can sit in more than one bucket over its life. A scribe that starts summarising notes and later starts suggesting a diagnosis has changed category, and nobody will send you a letter about it. That reclassification is the single most common way teams end up non-compliant without doing anything they thought was risky.
4. The Three Obligations That Bite Today
AI literacy (Article 4). Providers and deployers must ensure staff working with AI systems have sufficient understanding of them. There is no certification and no template. In practice, an auditor will ask for evidence: a training record, a dated deck, an onboarding module. Most healthcare teams have nothing. This is the cheapest obligation on the list to close and the one most often left open.
Prohibited practices (Article 5). Emotion inference in the workplace is banned. Healthcare has an exception for medical and safety purposes, but the boundary is narrower than teams assume — a wellbeing feature that infers staff mood from voice is not obviously inside it. Worth an actual read rather than a skim.
Transparency (Article 50). Disclose AI interaction to the human on the other side, and mark synthetic content. For a patient intake bot this is a UI change and a line in your privacy notice. See our patient intake chatbot guide for how this interacts with consent capture.
5. Why the Deferral Is Not the Reprieve It Looks Like
Two reasons, and the second is the expensive one.
First, conformity assessment for an Annex I product is not a task you start eighteen months out. If your AI sits inside a device needing Notified Body review, you are queuing for capacity that is already scarce. The 2028 date is not when you begin; it is when you must already have finished, with the certificate in hand.
Second — and this is what actually catches people — the AI Act is not the only regulation in the room. GDPR applies to the same system today, with no deferral. The MDR applies today. If you serve US patients, HIPAA applies today. In practice, the technical controls these regimes want overlap heavily: data minimisation, access control, audit logging, documented risk management, human oversight. Building those for GDPR and the MDR gets you most of the way to the AI Act’s technical file. Teams that treat the deferral as permission to stop are not saving eighteen months of work; they are deferring work they already owe someone else.
We wrote about the same pattern in a different jurisdiction in our FDA 21 CFR Part 11 guide — the audit trail and validation evidence Part 11 demands is close kin to the AI Act’s record-keeping and logging duties. And if you are handling EU patient data at all, GDPR for US healthcare apps is the more urgent read of the two.
6. Running a Gap Assessment That Is Worth the Afternoon
A useful EU AI Act gap assessment answers four questions in order. Most of the paid assessments I have seen answer the fourth one at length and skip the first three, which is backwards.
- Are you a provider or a deployer? Different obligations. If you build the model, you are a provider. If you buy one and put it in front of clinicians, you are a deployer — and if you materially modify it or put your name on it, you have just become a provider.
- Which risk tier, under which annex? Section 3 above. Write down the reasoning, not just the conclusion; you will be asked to defend it.
- Which obligations are live today versus deferred? Section 2. Separate the two lists so nobody conflates them in a planning meeting.
- What evidence exists right now? Not what is planned. What could you hand an auditor this afternoon.
You can work through this on a whiteboard. If you would rather not, our free EU AI Act compliance checker walks the same four questions and returns your risk tier, the obligations live for you today, and the gaps in your current evidence — no account required to see the result. It is the same engine behind our EU AI Act framework reference, and if your product is also a medical device you will want the EU MDR overview alongside it.
For teams building the underlying system rather than assessing one they already have, VertiComply generates healthcare applications with the access control, audit logging, and human-oversight hooks these frameworks expect already wired in — which is the boring half of the technical file you would otherwise assemble by hand. Our guide to HIPAA-compliant AI covers the architecture patterns in more depth.
7. Frequently Asked Questions
Is the EU AI Act delayed?
Partly. The Digital Omnibus deferred the high-risk obligations — Annex III standalone systems to 2 December 2027 and Annex I AI in regulated products to 2 August 2028. The prohibitions in Article 5, the AI literacy duty in Article 4, the GPAI model rules, and the Article 50 transparency duties were not deferred and apply now.
What is the best EU AI Act compliance tool for healthcare?
The useful ones start with classification rather than a checklist, because your obligations depend entirely on whether you are Annex I, Annex III, or limited risk. VertiComply’s EU AI Act checker is free, healthcare-specific, and returns a risk tier plus the live-versus-deferred obligation split. Generic AI Act tools tend to assume a hiring or credit-scoring use case and misclassify medical software.
Does the EU AI Act apply to a US healthcare company?
Yes, if your AI system is placed on the EU market or its output is used in the EU. Extraterritorial reach works much the way GDPR’s does. A US telehealth product with EU patients is in scope even with no EU entity.
Is an AI medical scribe high-risk under the EU AI Act?
Usually not, if it only transcribes and summarises for documentation. It typically sits in limited risk, where Article 50 transparency applies. It becomes high-risk the moment it produces clinical conclusions rather than recording them — and that line is easier to cross with a prompt change than most teams expect.
How does the EU AI Act interact with the MDR?
If your AI is part of a device requiring Notified Body assessment, the AI Act requirements are folded into the existing MDR conformity assessment rather than run as a parallel process. That is the reason Annex I got the longer runway to 2 August 2028 — the assessment infrastructure has to absorb it.
What happens if we do nothing until 2027?
You will still be non-compliant today on AI literacy and transparency, both of which are in force. You will also be starting conformity assessment inside the window where Notified Body capacity is most constrained. The deferral moved a deadline; it did not reduce the work.
Last reviewed 3 August 2026. The Digital Omnibus amendments take legal effect on formal adoption and publication in the Official Journal — verify current status before relying on the dates above for a regulatory filing.