For two years, "2 August 2026" was the date every healthcare AI compliance plan was built around. The date has now arrived — and in the final five weeks before it, the law changed. The Digital Omnibus on AI completed its legislative journey in late June 2026 and entered into force on 27 July 2026, deferring the high-risk obligations that mattered most to health systems while leaving the transparency duties exactly where they were. This page sets out what actually applies from 2 August 2026, what moved, and to when — tied to the amended Regulation and the institutions' own records. It is orientation, and a snapshot of a moving target; confirm the position of any specific product with regulatory counsel. As of August 2026.
What changed in the five weeks before the deadline?
The EU AI Act's enacted timeline put its general application date — including the standalone high-risk obligations of Annex III — at 2 August 2026, with medical-device AI following on 2 August 2027 1. The Digital Omnibus on AI, proposed by the European Commission on 19 November 2025, set out to defer both.
The endgame moved quickly. The European Parliament adopted the agreed text in plenary on 16 June 2026, by 423 votes to 57 with 174 abstentions 3. The Council of the EU gave its final approval on 29 June 2026, completing the ordinary legislative procedure 4. The European Commission's framework page now records the package as having entered into force on 27 July 2026, and states the revised dates as applicable law 2. What was, in July, a "likely but pending" deferral is now simply the timeline.
What still applies on 2 August 2026?
The deferral was surgical. The Omnibus moved the high-risk chapters; it kept the transparency chapter on schedule. From 2 August 2026, the Commission begins enforcing the Act's rules, and the Article 50 transparency obligations apply to systems newly placed on the market 26:
- Interaction disclosure. People must be made aware when they are interacting with an AI system rather than a human — the duty that reaches every patient-facing chatbot, symptom checker and automated patient-communication channel.
- Content identifiability. Providers must ensure AI-generated content is identifiable as such, and deepfake-style synthetic content must be clearly labelled 2.
- A grace period for what is already deployed. Systems placed on the market before 2 August 2026 have until 2 December 2026 to comply with the content-marking obligations 36.
December 2026 also brings something new: the Omnibus added an outright ban on AI systems that generate non-consensual intimate imagery or child sexual abuse material, applying from 2 December 2026 5.
Which healthcare dates moved, and to when?
The two-route structure of the Act is unchanged — what moved are the dates on each route. The table reflects the amended Regulation as recorded by the Commission and the Parliament 23.
| What | Route into "high-risk" | Old date | New date |
|---|---|---|---|
| AI judging eligibility for essential services, including healthcare; emergency-call triage and dispatch | Annex III point 5 (standalone) | 2 Aug 2026 | 2 Dec 2027 |
| AI that is, or is a safety component of, a medical device requiring third-party conformity assessment | Article 6(1) via Annex I (MDR/IVDR) | 2 Aug 2027 | 2 Aug 2028 |
| Article 50 transparency (chatbot disclosure, content marking, deepfake labels) | Transparency chapter | 2 Aug 2026 | 2 Aug 2026 (unchanged); 2 Dec 2026 for pre-existing systems' content marking |
| National AI regulatory sandboxes in operation | Member-state duty | 2 Aug 2026 | 2 Aug 2027 4 |
The practical reading for health systems: a CE-marked clinical decision support system or diagnostic tool now has a 2028 AI Act date; an eligibility or emergency-triage system has late 2027; and the conversational front door of your organisation has this week. The software as a medical device classification question — device or standalone system — still decides which row a product sits in, which is why it remains a determination for counsel rather than a datasheet.
What do the transparency duties require of hospitals?
Article 50 lands on deployers as well as providers 1. Three consequences are worth planning for now.
First, inventory the conversational surfaces. Patient-facing triage chatbots, appointment assistants, and any tool drafting messages that reach patients need a clear disclosure that the counterpart is an AI system. Our guide to transparency and labeling requirements covers the design patterns that satisfy disclosure duties without wrecking the experience.
Second, trace the AI-generated content that leaves the building. Marketing material, patient-education text, and synthetic media produced by a clinical LLM or a general-purpose foundation model fall under the identifiability duty — and content from systems deployed before 2 August 2026 has the December 2026 grace date, one worth diarising rather than assuming 6.
Third, put the dates into governance. An AI governance committee should hold the amended timeline as a standing agenda item, because deferral is runway, and the Chapter III obligations — risk management, data governance, human oversight, logging, accuracy and robustness — remain substantial builds that reward an early start 1. The algorithmovigilance muscle a deferral year buys is rarely wasted.
What was already binding before this week?
Two layers of the Act have applied for some time and are untouched by the Omnibus 12. Since 2 February 2025, the AI-literacy duty of Article 4 has bound providers and deployers — a hospital deploying a purchased tool included — and the Article 5 ban on prohibited practices has applied. Since 2 August 2025, the obligations for general-purpose AI (GPAI) models have governed the model layer that most ambient AI scribes and clinical assistants are built on. A deployment that leaned on "nothing applies until 2026" was wrong before the Omnibus and remains wrong after it.
How settled are the new dates?
More settled than at any point since the Omnibus was proposed — the procedure is complete and the package is in force 24 — but three cautions still travel with this page.
The consolidated text matters. Until practitioners work from the amended articles as published, secondary summaries can blur which sub-obligations moved; where this page and the Regulation's text diverge, the text wins 1. Consumer groups have also flagged how much protection now arrives later: BEUC's reading is that people will interact with high-risk systems "for several more years" before the originally expected safeguards bind 5. And the EU is one jurisdiction among several moving at once — the UK is running its own MHRA AI Airlock sandbox, the WHO's guidance on large multi-modal models sits above all of it as advisory, and the cross-border picture lives in our global regulation tracker.
For the deployment reality these rules land on, see our AI in healthcare statistics. Because the Act carries direct obligations and penalties, treat this page as orientation and confirm classification and compliance positions with your regulatory counsel.
Sources and method
Every date here is drawn from the text of Regulation (EU) 2024/1689 on EUR-Lex 1 and the European institutions' own records of the Digital Omnibus: the Commission's framework page stating the package in force on 27 July 2026 with the revised dates 2, the Parliament's Legislative Train record of the 16 June 2026 plenary adoption and the fixed deferral dates 3, and reporting of the Council's 29 June 2026 final adoption 4. BEUC's assessment 5 and Dastra's timeline analysis 6 were used to cross-check what remains on the 2 August 2026 schedule. This page replaces the "pending" status our living timeline carried through July 2026; we revisit both every ninety days and sooner when a tracked trigger fires. Dates and statuses are current as of 1 August 2026.