The EU AI Act in Healthcare: Deployer Obligations After the Digital Omnibus
Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), as amended by Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI)
Last updated
Need it signed off?
Thirty free minutes with an analyst on the vendor, the workflow and the rule you are unsure about.
Book an evaluation callRegulator
European Commission AI Office, together with national market surveillance authorities designated by each Member State
Who it applies to
- Deployers of AI systems established or located in the European Union, which includes a hospital, clinic or health service using a tool someone else built
- Providers placing AI systems on the Union market or putting them into service, irrespective of where they are established
- Providers and deployers established in a third country, including the United States, where the output produced by the AI system is used in the Union
- High-risk AI systems under Article 6(1) and Annex I, which includes AI that is a safety component of, or is itself, a product regulated under the Medical Device Regulation (EU) 2017/745 or the In Vitro Diagnostic Regulation (EU) 2017/746 and required to undergo third-party conformity assessment
- High-risk AI systems under Article 6(2) and Annex III, including emergency call triage and dispatch and emergency healthcare patient triage systems, public authority evaluation of eligibility for essential public services including healthcare, risk assessment and pricing for life and health insurance, and employment and workforce systems
- All providers and deployers, for the AI literacy obligation in Article 4 and, where applicable, the transparency obligations in Article 50, regardless of risk classification
Penalties
The AI Act sets ceilings and leaves Member States to set the detail. Infringement of the prohibited practices in Article 5 carries administrative fines of up to EUR 35 000 000 or, for an undertaking, up to 7 percent of total worldwide annual turnover for the preceding financial year, whichever is higher. Most other infringements, including breaches of deployer obligations, carry up to EUR 15 000 000 or 3 percent of total worldwide annual turnover, whichever is higher. Supplying incorrect, incomplete or misleading information to authorities carries a lower ceiling again. Enforcement sits with national market surveillance authorities, with the Commission's AI Office taking a central role for general purpose AI models.
Deadlines
Dates that already bind, and dates still ahead.
| Date | What happens |
|---|---|
| Regulation (EU) 2024/1689 entered into force. | |
| Chapters I and II applied: definitions, scope, the AI literacy obligation in Article 4, and the prohibited practices in Article 5. | |
| Obligations for general purpose AI models, the governance architecture including the AI Office and the Board, and the penalty provisions applied. | |
| Regulation (EU) 2026/1744, the Digital Omnibus on AI, published in the Official Journal. It entered into force on the third day following publication, on 27 July 2026, deliberately ahead of the AI Act's general application date. | |
| General date of application of the AI Act, including the Article 50 transparency obligations and Article 6(5), the Commission's duty to publish guidelines on high-risk classification, which the Omnibus deliberately left out of the deferral. | |
| Two things bite. The new prohibitions inserted at Article 5(1)(ba) and (bb) apply. And providers of systems generating synthetic audio, image, video or text that were placed on the market before 2 August 2026 must comply with the Article 50(2) marking obligation by this date. | |
| Chapter III Sections 1, 2 and 3 apply to AI systems classified as high-risk under Article 6(2) and Annex III. This is the deferred date for standalone high-risk systems, including emergency healthcare patient triage. | |
| Chapter III Sections 1, 2 and 3 apply to AI systems classified as high-risk under Article 6(1) and Annex I, which is the route that catches AI in devices regulated under the Medical Device Regulation and the In Vitro Diagnostic Regulation. | |
| Backstop date by which providers and deployers of high-risk AI systems intended to be used by public authorities must comply, under the amended Article 111(2). |
What changed in 2026
Movement by year, newest first. Where nothing in the text moved, that is recorded too.
2026
The single most important development is Regulation (EU) 2026/1744 of 8 July 2026, the Digital Omnibus on AI, published in the Official Journal on 24 July 2026 and in force from 27 July 2026. It was timed to land days before the AI Act's general application date of 2 August 2026, and it changes the compliance calendar substantially.
The headline is deferral. The amended Article 113 now applies Chapter III Sections 1, 2 and 3 from 2 December 2027 for Annex III high-risk systems and from 2 August 2028 for Annex I high-risk systems. The Omnibus recitals attribute this to the delayed availability of standards, common specifications and guidance, and the delayed establishment of national competent authorities.
Several changes matter specifically for healthcare. Article 4 on AI literacy was rewritten as an obligation to take measures to support the development of AI literacy, with express text that it does not require guaranteeing any specific level of AI literacy in any individual. A new Article 6(1a) provides that systems solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation, convenience or quality control do not qualify as safety components, though Article 6(1b) preserves the classification where failure would endanger health and safety. A new Article 2(13) allows the requirements in Articles 9 to 15 and 17 to 25 to be limited for Annex I high-risk systems where sectoral legislation already provides equivalent or higher protection, with the Commission to adopt specifying delegated acts by 2 August 2027. For AI inside medical devices, that provision is the one to watch, because it is the mechanism for resolving the overlap with the Medical Device Regulation.
2025
The prohibitions in Article 5 and the AI literacy obligation in Article 4 became applicable on 2 February 2025. On 2 August 2025 the general purpose AI model obligations, the governance provisions and the penalty regime followed. The Commission proposed the Digital Omnibus on 19 November 2025, and the deferral debate ran from that point through to political agreement in 2026.
For healthcare organisations the practical effect of 2025 was narrower than expected. Very little clinical AI is a prohibited practice, and most healthcare deployers found their real 2025 obligation was the unglamorous one: knowing which AI systems they were using and making sure the people operating them understood what they were operating. That remains the right first step, and it is the same inventory work that HIPAA and HTI-1 both push you towards.
2024
The AI Act was published and entered into force on 1 August 2024, with a staged application timetable running to 2027. That original timetable put the Annex III high-risk obligations at 2 August 2026 and the Annex I obligations at 2 August 2027. Both have since moved. Any compliance plan written in 2024 or 2025 against those dates needs to be rebased.
Is the EU AI Act in force, and what actually applies right now?
Yes, and the answer has become more layered than it was. Regulation (EU) 2024/1689 entered into force on 1 August 2024 with a staged application timetable. Its general date of application was 2 August 2026. Days before that date, Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and rewrote several of the deadlines.
What applies today, as of August 2026: the prohibited practices in Article 5, the AI literacy obligation in Article 4 as rewritten, the general purpose AI model obligations, the governance and penalty provisions, and the Article 50 transparency obligations. What has been pushed out: the substantive high-risk requirements and obligations in Chapter III Sections 1, 2 and 3, which now apply from 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems.
One detail is easy to miss and worth knowing. The Omnibus deferred Chapter III Sections 1, 2 and 3 with the express exception of Article 6(5), which is the Commission's duty to publish guidelines on the practical implementation of the high-risk classification rules together with a list of practical examples. That obligation was not deferred, which means the interpretive material should arrive well ahead of the compliance dates. If you are trying to classify a borderline system, watching for those guidelines is more productive than guessing.
What applies when, after the Digital Omnibus?
The timetable below reflects Article 113 as amended by Regulation (EU) 2026/1744. Older summaries circulating online still show 2 August 2026 for Annex III high-risk obligations. That date has moved.
| Date | What applies | Relevance to a healthcare deployer |
|---|---|---|
| 2 February 2025 | Chapters I and II: prohibited practices in Article 5 and AI literacy in Article 4 | Already in force. The AI literacy duty reaches every organisation using AI, at any risk level |
| 2 August 2025 | General purpose AI model obligations, governance, penalties | Falls on model providers rather than on you, but it is why your vendor's foundation model supplier now publishes documentation |
| 27 July 2026 | Digital Omnibus in force. Articles 102 to 110 apply | The amendment that rebased everything below |
| 2 August 2026 | General application, including Article 50 transparency and Article 6(5) | Chatbots and synthetic content obligations bite now, and they touch far more healthcare deployments than the high-risk rules do |
| 2 December 2026 | New Article 5 prohibitions apply. Article 50(2) marking transition ends for systems on the market before 2 August 2026 | A four month transition for generative systems already in the market |
| 2 December 2027 | Chapter III Sections 1, 2 and 3 for Annex III high-risk systems | Emergency triage, public benefit eligibility, health insurance pricing, employment systems |
| 2 August 2028 | Chapter III Sections 1, 2 and 3 for Annex I high-risk systems | AI in CE marked medical devices and in vitro diagnostics requiring third-party conformity assessment |
| 2 August 2030 | Backstop for high-risk systems intended to be used by public authorities | Relevant to public hospitals and national health services |
The grace period in Article 111(2) also received a useful clarification. It applies where the type and model of AI system has already been placed on the market, so if at least one unit was lawfully placed before the relevant date, other units of the same type and model can continue, without additional obligations, for as long as the design remains unchanged. Any significant change to the design triggers full compliance.
Is medical AI high-risk under the EU AI Act?
Some of it, by two quite different routes, and the distinction determines your deadline.
Route one, Article 6(1) and Annex I. An AI system is high-risk where it is intended to be used as a safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in Annex I, and where that product must undergo third-party conformity assessment. Annex I Section A includes the Medical Device Regulation (EU) 2017/745 at point 11 and the In Vitro Diagnostic Regulation (EU) 2017/746 at point 12. In practice this catches AI inside CE marked medical devices above the self-certification classes. Obligations apply from 2 August 2028.
Route two, Article 6(2) and Annex III. Certain standalone systems are high-risk by listing. The healthcare relevant entries sit in Annex III point 5: systems used by or on behalf of public authorities to evaluate eligibility for essential public assistance benefits and services including healthcare services, and to grant, reduce, revoke or reclaim them; systems used for risk assessment and pricing in life and health insurance; and systems that evaluate and classify emergency calls or dispatch or prioritise emergency first response, expressly including emergency healthcare patient triage systems. Annex III point 4 on employment also catches recruitment, promotion, termination, task allocation and performance monitoring tools, which is where many health systems first meet the regulation. Obligations apply from 2 December 2027.
Article 6(3) provides a derogation from Annex III classification where a system does not pose a significant risk of harm, and it applies where the system performs a narrow procedural task, improves the result of a previously completed human activity, detects decision-making patterns or deviations without replacing or influencing a previously completed human assessment without proper human review, or performs a preparatory task. A system that performs profiling of natural persons is always high-risk regardless. A provider relying on the derogation must document its assessment before placing the system on the market and is subject to the registration obligation in Article 49(2), so ask to see that documentation rather than accepting the conclusion.
What does the Act require of a deployer, not a provider?
Most healthcare organisations are deployers. Article 26 is therefore the operative provision, and it applies to high-risk systems from the deferred dates above. It requires:
- Use in accordance with the instructions for use, with appropriate technical and organisational measures to ensure that happens.
- Human oversight assigned to named natural persons who have the necessary competence, training and authority, as well as the necessary support. Authority and support are the words most often ignored. A clinician who can technically override an output but has no time and no institutional backing to do so is not oversight.
- Input data control where the deployer exercises control over it, ensuring it is relevant and sufficiently representative for the intended purpose.
- Monitoring in operation, informing the provider or distributor and the market surveillance authority and suspending use where the system appears to present a risk, and immediately reporting serious incidents.
- Retention of automatically generated logs under the deployer's control for a period appropriate to the intended purpose and at least six months.
- Informing workers and their representatives before putting a high-risk system into service in the workplace.
- Informing natural persons that they are subject to the use of a high-risk Annex III system where it makes or assists in making decisions about them.
- Using the provider's Article 13 information to support a data protection impact assessment under Article 35 of the GDPR.
Article 27 adds a fundamental rights impact assessment before first use, for deployers that are bodies governed by public law or private entities providing public services, and for deployers of Annex III points 5(b) and (c). A private hospital delivering publicly funded care should assume this can reach it and take advice rather than assume it cannot. Where a data protection impact assessment already covers an element, the fundamental rights assessment complements it rather than duplicating it.
Do scribes, phone agents and intake tools fall in scope?
They are in scope of the regulation, and generally not high-risk. That is a different thing from being unregulated, and the distinction trips people up.
An ambient documentation tool, a patient intake agent, an AI phone agent or scheduling automation is not listed in Annex III and is not a safety component of a regulated device, so Chapter III does not attach. Three obligations still do.
Article 4, AI literacy. Applicable since 2 February 2025 and rewritten by the Omnibus, it requires providers and deployers to take measures to support the development of AI literacy among staff and others operating AI systems on their behalf, proportionate to their knowledge, experience and context. The Omnibus text is explicit that this does not require guaranteeing any specific level of literacy in any individual, which makes it a training and documentation obligation rather than an assessment one. It is the easiest thing on this page to evidence and the most commonly forgotten. Our staff training programmes are built around exactly this evidence problem.
Article 50, transparency. Applicable from 2 August 2026. Systems interacting directly with people must make clear they are AI, and providers of systems generating synthetic audio, image, video or text must mark that output in a machine readable way. A patient facing phone or chat agent sits squarely in the first limb. Systems placed on the market before 2 August 2026 have until 2 December 2026 for the Article 50(2) marking obligation.
Article 5, prohibitions. Rarely relevant to administrative agents, but worth a single check against emotion recognition in the workplace and any inference about protected characteristics, both of which occasionally appear in workforce analytics without anyone having decided to buy them.
What should a US-based organisation note?
Four things, in order of how often they surprise people.
Extraterritorial reach is real but narrower than the headlines. Article 2 extends the regulation to providers and deployers established in a third country where the output produced by the AI system is used in the Union. A US health system treating a patient who happens to be an EU citizen, in the United States, is not producing output used in the Union. A US organisation running a telehealth service into a Member State, or operating an EU subsidiary, or supplying software used by EU clinicians, is a different case entirely. Draw the line on where the output is used, not on patient nationality.
The GDPR runs in parallel and usually bites first. For most US organisations touching EU patients, data protection is the immediate obligation and the AI Act is the later one. Article 26(9) explicitly points deployers back to their Article 35 GDPR impact assessment duty. Do not let an AI Act project displace a data protection project that is already overdue.
Medical device regulation is separate. A tool cleared by FDA is not thereby CE marked, and the EU conformity assessment route under the Medical Device Regulation is its own exercise. The AI Act sits on top of that, not instead of it, and the new Article 2(13) is the mechanism intended to stop the two regimes duplicating each other for Annex I systems.
The deferral is not a reprieve for the parts that already apply. AI literacy and Article 50 transparency are live obligations now. They are also the cheapest to satisfy, which makes leaving them undone a poor trade.
How is it enforced, and what are the penalties?
Enforcement is national. Each Member State designates market surveillance authorities, and the Commission's AI Office plays a central role for general purpose AI models. The Digital Omnibus strengthened that central role. Penalty ceilings sit at up to EUR 35 000 000 or 7 percent of total worldwide annual turnover for prohibited practices, and up to EUR 15 000 000 or 3 percent for most other infringements, whichever is higher in each case.
Two practical observations. First, the deferral of Chapter III means the obligations that could be enforced against a healthcare deployer through 2026 and most of 2027 are the transparency, literacy and prohibition provisions, not the high-risk ones. Second, the fines are ceilings applied through national procedures, and early enforcement across new EU digital regulation has generally started with information requests and corrective orders rather than headline penalties. Plan for the information request. It arrives asking which systems you operate, what they do and who oversees them, and an organisation that cannot answer that quickly has a problem independent of any fine.
That is the same answer we give about HIPAA enforcement in the United States, and for the same reason. The register is the deliverable.
What should you do, and by when?
Sequenced against the amended dates.
- Now: determine whether you are in scope at all. Is output from any AI system you provide or deploy used in the Union. If the honest answer is no, document that conclusion once and revisit it when you open an EU service line. Do not spend a year on a regulation that does not reach you.
- Now: build the inventory, classifying each system as prohibited, Annex I high-risk, Annex III high-risk, subject only to Article 50, or none of these. Record the reasoning, including any reliance on the Article 6(3) derogation and the provider's documented assessment behind it.
- Now: satisfy Article 4. Role appropriate training for everyone operating an AI system, with a record of who received what and when. This obligation has been live since February 2025.
- Now: satisfy Article 50. Any patient facing agent must disclose it is AI. Confirm marking of synthetic output with your vendor, and note the 2 December 2026 backstop for systems placed on the market before 2 August 2026.
- Through 2027: build the Article 26 operating model for anything you have classified as Annex III high-risk. Named oversight owners with real authority, six month log retention, an incident route to the provider and the authority, and worker notification where the system is used in the workplace. Add an Article 27 fundamental rights impact assessment if you are a public body or a private entity providing public services.
- By 2 December 2027 and 2 August 2028 respectively, have Annex III and Annex I systems operating under that model, and watch for the Commission delegated acts under Article 2(13), due by 2 August 2027, which will shape how the medical device overlap is resolved.
Steps two and five are where the work is, and both produce artefacts that are useful well beyond the EU. A single AI register with owners, classifications and oversight arrangements answers questions from a market surveillance authority, an OCR investigator and your own board with the same document. Building that register once, so it serves all three, is the work in our AI governance and compliance engagement.
Official sources
Primary documents from the issuing authority. Where a summary and the source disagree, the source is right.
- EURegulation (EU) 2024/1689 (Artificial Intelligence Act), full text (opens in a new tab)
- EURegulation (EU) 2026/1744 (Digital Omnibus on AI), full text (opens in a new tab)
- EUAI Act, European Commission regulatory framework for AI (opens in a new tab)
- EUEuropean AI Office, European Commission (opens in a new tab)
- OtherEthics and governance of artificial intelligence for health, World Health Organization (opens in a new tab)
- NISTAI Risk Management Framework, NIST (opens in a new tab)
Questions we get asked
Has the EU AI Act been delayed?
Parts of it. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and moved the high-risk obligations in Chapter III Sections 1, 2 and 3 to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. The prohibitions, the AI literacy obligation, the general purpose AI model rules and the Article 50 transparency obligations were not deferred.
Is an AI medical scribe high-risk under the EU AI Act?
Generally no. A scribe is not listed in Annex III and is not a safety component of a regulated medical device, so the high-risk obligations do not attach. The AI literacy obligation in Article 4 applies to it, and if it interacts directly with patients or generates synthetic content the Article 50 transparency obligations apply from 2 August 2026.
Does the EU AI Act apply to a US hospital?
Only where the output produced by the AI system is used in the Union. Treating an EU citizen in the United States does not bring you in scope. Running a telehealth service into a Member State, operating an EU entity, or supplying software used by clinicians in the Union does. Document the conclusion either way rather than leaving it open.
What is the difference between a provider and a deployer?
A provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name. A deployer uses one under its own authority. Most healthcare organisations are deployers, so Article 26 is the operative provision. You can become a provider by substantially modifying a system or putting your own name on it, which is a real risk with heavily customised internal tools.
Do we need a fundamental rights impact assessment?
Article 27 requires one before first use of an Annex III high-risk system, for deployers that are bodies governed by public law or private entities providing public services, and for deployers of the credit scoring and insurance pricing entries at Annex III points 5(b) and (c). A private provider delivering publicly funded healthcare should take advice rather than assume it is excluded. Where a GDPR data protection impact assessment already covers elements of it, the two are complementary.
How does the EU AI Act interact with the Medical Device Regulation?
They stack. AI that is a safety component of, or is itself, a device requiring third-party conformity assessment under Regulation (EU) 2017/745 or 2017/746 becomes high-risk under Article 6(1), with obligations from 2 August 2028. The Digital Omnibus added Article 2(13), which permits limiting AI Act requirements where the sectoral legislation already provides equivalent or higher protection, with Commission delegated acts specifying the detail due by 2 August 2027.
Make it a formal evaluation
Everything we publish is free to read and free to argue with. When the decision has to be signed, dated and defended to a board, we run the evaluation against your own estate. We take no vendor commissions.
- A 30 minute evaluation call with an analyst, no pitch deck.
- A read on the vendors and the rules in play, and the use cases we would not touch yet.
- A written proposal with scope, sequence and a fixed fee.
- No obligation
- Direct with an analyst, not a sales rep
- BAA available before any PHI discussion