Regulation

EU AI Act on 2 August 2026: what now applies to healthcare

The Digital Omnibus is law, and the AI Act's general application date arrives with the healthcare high-risk obligations deferred to 2027 and 2028 — while the Article 50 transparency duties land on schedule. What each date now covers, tied to the amended Regulation. As of August 2026.

By Jonas WeirReviewed by Jonas Weir · editorial reviewUpdated

The short version

  • The Digital Omnibus amending the EU AI Act finished adoption on 29 June 2026 and, per the European Commission, entered into force on 27 July 2026 — the deferred dates are now the law.
  • Standalone high-risk health AI under Annex III moves to 2 December 2027, and AI that qualifies as a medical device under Annex I moves to 2 August 2028.
  • 2 August 2026 still matters: the Article 50 transparency duties — telling people they are interacting with AI and making AI-generated content identifiable — begin on schedule, with systems already on the market given until 2 December 2026 for content marking.

For two years, "2 August 2026" was the date every healthcare AI compliance plan was built around. The date has now arrived — and in the final five weeks before it, the law changed. The Digital Omnibus on AI completed its legislative journey in late June 2026 and entered into force on 27 July 2026, deferring the high-risk obligations that mattered most to health systems while leaving the transparency duties exactly where they were. This page sets out what actually applies from 2 August 2026, what moved, and to when — tied to the amended Regulation and the institutions' own records. It is orientation, and a snapshot of a moving target; confirm the position of any specific product with regulatory counsel. As of August 2026.

What changed in the five weeks before the deadline?

The EU AI Act's enacted timeline put its general application date — including the standalone high-risk obligations of Annex III — at 2 August 2026, with medical-device AI following on 2 August 2027 1. The Digital Omnibus on AI, proposed by the European Commission on 19 November 2025, set out to defer both.

The endgame moved quickly. The European Parliament adopted the agreed text in plenary on 16 June 2026, by 423 votes to 57 with 174 abstentions 3. The Council of the EU gave its final approval on 29 June 2026, completing the ordinary legislative procedure 4. The European Commission's framework page now records the package as having entered into force on 27 July 2026, and states the revised dates as applicable law 2. What was, in July, a "likely but pending" deferral is now simply the timeline.

What still applies on 2 August 2026?

The deferral was surgical. The Omnibus moved the high-risk chapters; it kept the transparency chapter on schedule. From 2 August 2026, the Commission begins enforcing the Act's rules, and the Article 50 transparency obligations apply to systems newly placed on the market 26:

  • Interaction disclosure. People must be made aware when they are interacting with an AI system rather than a human — the duty that reaches every patient-facing chatbot, symptom checker and automated patient-communication channel.
  • Content identifiability. Providers must ensure AI-generated content is identifiable as such, and deepfake-style synthetic content must be clearly labelled 2.
  • A grace period for what is already deployed. Systems placed on the market before 2 August 2026 have until 2 December 2026 to comply with the content-marking obligations 36.

December 2026 also brings something new: the Omnibus added an outright ban on AI systems that generate non-consensual intimate imagery or child sexual abuse material, applying from 2 December 2026 5.

Which healthcare dates moved, and to when?

The two-route structure of the Act is unchanged — what moved are the dates on each route. The table reflects the amended Regulation as recorded by the Commission and the Parliament 23.

WhatRoute into "high-risk"Old dateNew date
AI judging eligibility for essential services, including healthcare; emergency-call triage and dispatchAnnex III point 5 (standalone)2 Aug 20262 Dec 2027
AI that is, or is a safety component of, a medical device requiring third-party conformity assessmentArticle 6(1) via Annex I (MDR/IVDR)2 Aug 20272 Aug 2028
Article 50 transparency (chatbot disclosure, content marking, deepfake labels)Transparency chapter2 Aug 20262 Aug 2026 (unchanged); 2 Dec 2026 for pre-existing systems' content marking
National AI regulatory sandboxes in operationMember-state duty2 Aug 20262 Aug 2027 4

The practical reading for health systems: a CE-marked clinical decision support system or diagnostic tool now has a 2028 AI Act date; an eligibility or emergency-triage system has late 2027; and the conversational front door of your organisation has this week. The software as a medical device classification question — device or standalone system — still decides which row a product sits in, which is why it remains a determination for counsel rather than a datasheet.

What do the transparency duties require of hospitals?

Article 50 lands on deployers as well as providers 1. Three consequences are worth planning for now.

First, inventory the conversational surfaces. Patient-facing triage chatbots, appointment assistants, and any tool drafting messages that reach patients need a clear disclosure that the counterpart is an AI system. Our guide to transparency and labeling requirements covers the design patterns that satisfy disclosure duties without wrecking the experience.

Second, trace the AI-generated content that leaves the building. Marketing material, patient-education text, and synthetic media produced by a clinical LLM or a general-purpose foundation model fall under the identifiability duty — and content from systems deployed before 2 August 2026 has the December 2026 grace date, one worth diarising rather than assuming 6.

Third, put the dates into governance. An AI governance committee should hold the amended timeline as a standing agenda item, because deferral is runway, and the Chapter III obligations — risk management, data governance, human oversight, logging, accuracy and robustness — remain substantial builds that reward an early start 1. The algorithmovigilance muscle a deferral year buys is rarely wasted.

What was already binding before this week?

Two layers of the Act have applied for some time and are untouched by the Omnibus 12. Since 2 February 2025, the AI-literacy duty of Article 4 has bound providers and deployers — a hospital deploying a purchased tool included — and the Article 5 ban on prohibited practices has applied. Since 2 August 2025, the obligations for general-purpose AI (GPAI) models have governed the model layer that most ambient AI scribes and clinical assistants are built on. A deployment that leaned on "nothing applies until 2026" was wrong before the Omnibus and remains wrong after it.

How settled are the new dates?

More settled than at any point since the Omnibus was proposed — the procedure is complete and the package is in force 24 — but three cautions still travel with this page.

The consolidated text matters. Until practitioners work from the amended articles as published, secondary summaries can blur which sub-obligations moved; where this page and the Regulation's text diverge, the text wins 1. Consumer groups have also flagged how much protection now arrives later: BEUC's reading is that people will interact with high-risk systems "for several more years" before the originally expected safeguards bind 5. And the EU is one jurisdiction among several moving at once — the UK is running its own MHRA AI Airlock sandbox, the WHO's guidance on large multi-modal models sits above all of it as advisory, and the cross-border picture lives in our global regulation tracker.

For the deployment reality these rules land on, see our AI in healthcare statistics. Because the Act carries direct obligations and penalties, treat this page as orientation and confirm classification and compliance positions with your regulatory counsel.

Sources and method

Every date here is drawn from the text of Regulation (EU) 2024/1689 on EUR-Lex 1 and the European institutions' own records of the Digital Omnibus: the Commission's framework page stating the package in force on 27 July 2026 with the revised dates 2, the Parliament's Legislative Train record of the 16 June 2026 plenary adoption and the fixed deferral dates 3, and reporting of the Council's 29 June 2026 final adoption 4. BEUC's assessment 5 and Dastra's timeline analysis 6 were used to cross-check what remains on the 2 August 2026 schedule. This page replaces the "pending" status our living timeline carried through July 2026; we revisit both every ninety days and sooner when a tracked trigger fires. Dates and statuses are current as of 1 August 2026.

Questions & answers

  • Did the EU AI Act's 2 August 2026 deadline get delayed?

    Partly. The Digital Omnibus, in force since 27 July 2026 according to the European Commission, moved the standalone Annex III high-risk obligations to 2 December 2027 and the obligations for AI embedded in regulated products — including medical-device AI — to 2 August 2028. The Article 50 transparency duties were kept on the original schedule and apply from 2 August 2026.

  • What applies to hospitals on 2 August 2026?

    The transparency layer. People must be told when they are interacting with an AI system such as a patient-facing chatbot, AI-generated content must be identifiable, and deepfake-style content must be labelled. Systems already on the market before 2 August 2026 have until 2 December 2026 to comply with the content-marking duty. The AI-literacy duty (Article 4) and the prohibited-practice ban (Article 5) have applied since February 2025.

  • When do the high-risk rules reach AI medical devices?

    2 August 2028. AI that is, or is a safety component of, a medical device requiring third-party conformity assessment is high-risk under Article 6(1) via Annex I, and the Omnibus moved that class from 2 August 2027 to 2 August 2028. Standalone Annex III health uses — eligibility decisions and emergency-call triage — moved from 2 August 2026 to 2 December 2027.

  • Are the new dates final?

    The legislative procedure is complete: Parliament adopted the text on 16 June 2026 and the Council on 29 June 2026, and the Commission's framework page records the package as in force since 27 July 2026. Treat the dates as enacted law, and confirm the consolidated text with counsel before relying on any single date for a specific product.

Sources

  1. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Articles 4, 5, 6, 50 and 113; Annex I Section A; Annex III point 5. Official Journal of the European Union, 12 July 2024. eur-lex.europa.eu/eli/reg/2024/1689/oj
  2. European Commission. AI Act — regulatory framework on AI: application timeline including the AI Omnibus amendments. Shaping Europe's Digital Future (accessed 1 August 2026). digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
  3. European Parliament. Legislative Train Schedule: Digital Omnibus on AI — adoption record and revised high-risk deadlines (accessed 1 August 2026). www.europarl.europa.eu/legislative-train/package-digital-package/file-digital-omnibus-on-ai
  4. NicFab. Digital Omnibus on AI: the Council's final green light. 29 June 2026 (accessed 1 August 2026). www.nicfab.eu/en/posts/digital-omnibus-ai-council-adoption/
  5. BEUC (The European Consumer Organisation). EU adopts the AI Omnibus: what it means for consumers. June 2026 (accessed 1 August 2026). www.beuc.eu/news/eu-adopts-ai-omnibus-what-it-means-consumers
  6. Dastra. Digital Omnibus on AI: Parliament votes, deadlines redrawn. 17 June 2026 (accessed 1 August 2026). www.dastra.eu/en/blog/digital-omnibus-on-ai-parliament-votes-deadlines-redrawn/60108