Regulation

EU AI Act for healthcare: a living timeline

A dated timeline of the EU AI Act as it lands on healthcare — the exact application dates after the Digital Omnibus entered into force: standalone health AI under Annex III now falls due 2 December 2027, and AI that is a medical device under Annex I on 2 August 2028. Each row tied to the Regulation itself. As of August 2026.

By Jonas WeirReviewed by Jonas Weir · editorial reviewUpdated

The short version

  • The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and applies in stages; its general application date is 2 August 2026.
  • Healthcare AI splits across two dates, both deferred by the Digital Omnibus: standalone high-risk systems in Annex III — including AI used to judge eligibility for healthcare services and AI for emergency-call triage — now fall due 2 December 2027.
  • AI that is itself a medical device, or a safety component of one, is high-risk under Article 6(1) via Annex I (the MDR and IVDR). Those obligations now apply from 2 August 2028.
  • Two duties are already live: since 2 February 2025 the AI-literacy duty (Article 4) and the prohibited-practice ban (Article 5); since 2 August 2025 the rules for general-purpose AI models.
  • The Digital Omnibus is now law: the European Parliament adopted it on 16 June 2026, the Council on 29 June 2026, and the Commission's framework page records it in force since 27 July 2026 — so the deferred dates, not the original 2026/2027 dates, govern.

The EU AI Act is the first horizontal law to govern artificial intelligence across a major market, and it lands on healthcare in an order that surprises many teams. The headline date most people repeat — 2 August 2026 — remains the Act's general application date, but after the Digital Omnibus it no longer carries the high-risk health obligations most teams associate with it. This page is a dated timeline of the Act as it applies to health AI, built from the Regulation itself, with the one distinction that matters kept in the foreground: whether a tool is a standalone high-risk system or a regulated medical device decides which year its obligations begin. It is a status timeline for orientation and general information; confirm the live text and its application to a specific product with regulatory counsel before acting. As of August 2026. For a plain-language read of exactly what did and did not change on deadline day, see what actually applies on 2 August 2026.

The timeline at a glance

Regulation (EU) 2024/1689 was published in the Official Journal on 12 July 2024 and entered into force twenty days later, on 1 August 2024. From there its provisions switch on in stages set by Article 113 1. The European Commission's own summary of the framework mirrors this staggering 2.

DateMilestoneWhat switches on for health AISource
12 Jul 2024Published in the Official JournalThe Regulation text (EU) 2024/16891
1 Aug 2024Entry into forceTwenty days after publication1
2 Feb 2025Chapters I and II applyAI-literacy duty (Art. 4); ban on prohibited practices (Art. 5)1
2 Aug 2025GPAI, governance and penalties applyGeneral-purpose AI models (Chapter V); governance (Chapter VII); penalties (Chapter XII, except Art. 101)1
2 Aug 2026General application dateMost remaining provisions — but the Annex III high-risk obligations were deferred by the Digital Omnibus (below)12
2 Dec 2027Annex III high-risk applies (as amended)Standalone high-risk systems: healthcare-eligibility and emergency-triage AI (Annex III pt 5)23
2 Aug 2028Article 6(1) high-risk applies (as amended)AI that is, or is a safety component of, a medical device under Annex I (MDR/IVDR)23

The last two rows reflect the Digital Omnibus amendments, in force since 27 July 2026 per the Commission's framework page 2. Read the table as the law as it stands, and the Omnibus section below for how the deferral happened.

What decides your compliance date?

For healthcare, the single most useful thing to understand about the AI Act is that "high-risk" is reached by two different routes, and each route carries a different application date.

Route one — Annex III, the standalone systems. Article 6(2) says that the AI systems listed in Annex III are high-risk 1. Annex III point 5 reaches into healthcare in two specific places: AI "intended to be used by public authorities or on behalf of public authorities to evaluate the eligibility of natural persons for essential public assistance benefits and services, including healthcare services," and AI intended "to be used to dispatch, or to establish priority in the dispatching of, emergency first response services, including … emergency healthcare patient triage systems" 1. These are standalone high-risk systems, and their obligations arrive on the general application date of 2 August 2026.

Route two — Article 6(1), the regulated devices. A great deal of clinical AI has nothing to do with benefits eligibility; it is a diagnostic or decision-support product that meets the definition of a medical device. Article 6(1) makes an AI system high-risk when two conditions are both met: it is a safety component of, or is itself, a product covered by the Union harmonisation legislation in Annex I; and that product must undergo third-party conformity assessment before being placed on the market 1. Annex I, Section A lists the Medical Device Regulation (EU) 2017/745 and the IVD Regulation (EU) 2017/746. Because medical devices above the lowest risk class already require a notified body to assess conformity under the MDR 4, AI medical devices satisfy both limbs of Article 6(1) — and Article 113 gives that class a later start: its obligations apply from 2 August 2027.

The practical consequence is easy to state and easy to get wrong. If your tool is a clinical decision support system that is CE-marked as a medical device, the AI Act layer arrives in 2027, not 2026. If your tool judges who is eligible for a service, or triages emergency calls, it can be caught by the 2026 date even if it never touched the device pathway. Many teams plan to the wrong year because they assume "2 August 2026" is universal. It governs the Annex III route; the device route is a year behind it. For the underlying device concept, see our glossary entry on software as a medical device.

What is already live?

Two obligations already bind, and both touch healthcare organisations regardless of whether they build devices.

Since 2 February 2025, Chapters I and II have applied 1. Chapter I carries Article 4, the AI-literacy duty: providers and deployers must take measures to ensure a sufficient level of AI literacy among staff and others who operate their systems on their behalf. A hospital deploying a purchased AI tool is a "deployer," so this is a live duty for care providers as well as vendors. Chapter II carries Article 5, the ban on prohibited practices — the small set of AI uses the Act forbids outright.

Since 2 August 2025, the obligations for general-purpose AI models under Chapter V have applied 1. A foundation model that a health system builds on is governed at the model layer from that date, even though the high-risk obligations on the clinical system built from it arrive later. Penalties under Chapter XII also began on that date, with the exception of Article 101 (the specific fine regime for GPAI providers). The Regulation sets its ceiling for the most serious infringements at up to €35 million or 7% of worldwide annual turnover, whichever is higher 12.

What actually lands on the date?

It helps to be concrete about what "the high-risk obligations apply" means, because a date is only as meaningful as the duties it switches on. For a high-risk AI system, Chapter III of the Regulation sets out a substantial set of requirements: a risk-management system maintained across the lifecycle, data-governance and data-quality controls, technical documentation and automatic record-keeping, transparency and instructions for use, human oversight designed into the system, and an appropriate level of accuracy, robustness and cybersecurity — the obligations in Articles 9 to 15 1. Providers must also operate a quality-management system and complete the relevant conformity assessment; deployers — the hospitals and clinics that use the system rather than build it — carry their own duties, including using the system in line with its instructions and ensuring the human oversight the provider designed for is actually exercised. Little of this can be retrofitted in a weekend. That is why the application date matters less as a single cliff-edge and more as the end of a build-and-document runway that, for a 2027 obligation, is already underway.

The Digital Omnibus — now in force

Here is the reason this page carries a ninety-day cadence rather than a one-time publish. On 19 November 2025 the European Commission proposed a Digital Omnibus on AI, a package deferring the high-risk application dates 3. The procedure is now complete.

DeferralOriginal enacted dateDate now in forceSource
Standalone high-risk (Annex III) — incl. healthcare eligibility, emergency triage2 Aug 20262 Dec 202723
Product-embedded high-risk (Annex I) — incl. medical-device AI2 Aug 20272 Aug 202823

The endgame moved quickly. A provisional trilogue agreement was reached on 7 May 2026, member-state ambassadors approved it on 13 May 2026, the European Parliament adopted the agreed text in plenary on 16 June 2026 — by 423 votes to 57, with 174 abstentions — and the Council gave its final approval on 29 June 2026 3. The Commission's framework page now records the package as in force since 27 July 2026 and states the revised dates as applicable law 2. The deferral is settled: plan against 2 December 2027 for Annex III systems and 2 August 2028 for medical-device AI — and treat the extra time as a build-and-document runway that is already underway.

How to read this timeline

Five cautions travel with every row.

First, status is perishable, and this Act is unusually so. The Omnibus moved two headline dates within a single summer; guidelines, delegated acts, and corrigenda can still reshape details. That is precisely why this page is dated and revisited.

Second, the two-route split is about classification, not marketing labels. Whether a given tool is a "medical device," an "Annex III system," both, or neither turns on its intended purpose and the legislation it falls under — a determination to make with counsel, not from a product datasheet.

Third, the AI Act sits on top of existing device law, it does not replace it. An AI medical device still needs its MDR or IVDR conformity assessment; the AI Act adds requirements rather than substituting for them 4. The dates here govern when the AI Act layer applies.

Fourth, transitional provisions exist. Article 111 of the Regulation sets out how systems already placed on the market before the applicable dates are treated 1; whether a legacy deployment is caught can depend on whether it undergoes significant changes. Confirm the transitional position for any live system rather than assuming the headline date applies cleanly.

Fifth, this is an EU instrument, and healthcare AI is global. A tool placed on the EU market is caught regardless of where it was built, while the same tool faces different rules elsewhere — the UK runs its own device route and the MHRA AI Airlock sandbox, and the WHO's guidance on large multi-modal models sits over all of them as advisory rather than binding. The cross-jurisdiction picture lives in our global AI in health regulation tracker.

Because the AI Act carries direct legal obligations and penalties, treat this timeline as orientation only and confirm the classification and compliance position of any specific product with your regulatory counsel or compliance function before you rely on a date.

Sources and method

Every date on this page is drawn from a primary source: the text of Regulation (EU) 2024/1689 on EUR-Lex — Articles 4, 5, 6 and 113, Annex I Section A, and Annex III point 5 1 — cross-checked against the European Commission's own framework summary 2; the Medical Device Regulation (EU) 2017/745 for the conformity-assessment condition that pulls devices into Article 6(1) 4; and the European Parliament's Legislative Train record for the status of the Digital Omnibus 3. This page was refreshed on 1 August 2026 when the Omnibus's entry into force (27 July 2026) satisfied its own top freshness trigger. We revisit it every ninety days and whenever a tracked date changes status. Dates and statuses are current as of August 2026.

Questions & answers

  • When do the EU AI Act rules apply to health AI?

    It depends on what the tool is. Standalone high-risk systems listed in Annex III — such as AI used by public authorities to judge eligibility for healthcare services, or AI for emergency-call triage — now fall due on 2 December 2027. AI that is itself a medical device, or a safety component of one, is high-risk under Article 6(1) via Annex I, and those obligations now apply from 2 August 2028. Both dates reflect the Digital Omnibus, which entered into force on 27 July 2026.

  • Is a CE-marked medical device covered by the AI Act?

    If it uses AI and is required to undergo third-party conformity assessment under the Medical Device Regulation or the IVD Regulation, then yes — it is a high-risk AI system under Article 6(1). The AI Act's obligations for that class apply from 2 August 2028 following the Digital Omnibus deferral, layered on top of the existing device rules rather than replacing them.

  • What is already in force under the EU AI Act?

    Two things touch healthcare organisations now. Since 2 February 2025 the AI-literacy duty in Article 4 and the ban on prohibited practices in Article 5 have applied. Since 2 August 2025 the obligations for general-purpose AI models have applied. The high-risk obligations that most clinical tools care about arrive later, in December 2027 or August 2028 depending on the classification path.

Sources

  1. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Articles 4, 5, 6 and 113; Annex I Section A; Annex III point 5. Official Journal of the European Union, 12 July 2024. eur-lex.europa.eu/eli/reg/2024/1689/oj
  2. European Commission. Regulatory framework on AI — application timeline including the AI Omnibus amendments. Shaping Europe's Digital Future (accessed 1 August 2026). digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
  3. European Parliament. Legislative Train Schedule: Digital Omnibus on AI — adoption record and revised deadlines (accessed 1 August 2026). www.europarl.europa.eu/legislative-train/package-digital-package/file-digital-omnibus-on-ai
  4. Regulation (EU) 2017/745 of the European Parliament and of the Council of 5 April 2017 on medical devices (MDR). Official Journal of the European Union. eur-lex.europa.eu/eli/reg/2017/745/oj