The EU AI Act is the first horizontal law to govern artificial intelligence across a major market, and it lands on healthcare in an order that surprises many teams. The headline date most people repeat — 2 August 2026 — remains the Act's general application date, but after the Digital Omnibus it no longer carries the high-risk health obligations most teams associate with it. This page is a dated timeline of the Act as it applies to health AI, built from the Regulation itself, with the one distinction that matters kept in the foreground: whether a tool is a standalone high-risk system or a regulated medical device decides which year its obligations begin. It is a status timeline for orientation and general information; confirm the live text and its application to a specific product with regulatory counsel before acting. As of August 2026. For a plain-language read of exactly what did and did not change on deadline day, see what actually applies on 2 August 2026.
The timeline at a glance
Regulation (EU) 2024/1689 was published in the Official Journal on 12 July 2024 and entered into force twenty days later, on 1 August 2024. From there its provisions switch on in stages set by Article 113 1. The European Commission's own summary of the framework mirrors this staggering 2.
| Date | Milestone | What switches on for health AI | Source |
|---|---|---|---|
| 12 Jul 2024 | Published in the Official Journal | The Regulation text (EU) 2024/1689 | 1 |
| 1 Aug 2024 | Entry into force | Twenty days after publication | 1 |
| 2 Feb 2025 | Chapters I and II apply | AI-literacy duty (Art. 4); ban on prohibited practices (Art. 5) | 1 |
| 2 Aug 2025 | GPAI, governance and penalties apply | General-purpose AI models (Chapter V); governance (Chapter VII); penalties (Chapter XII, except Art. 101) | 1 |
| 2 Aug 2026 | General application date | Most remaining provisions — but the Annex III high-risk obligations were deferred by the Digital Omnibus (below) | 12 |
| 2 Dec 2027 | Annex III high-risk applies (as amended) | Standalone high-risk systems: healthcare-eligibility and emergency-triage AI (Annex III pt 5) | 23 |
| 2 Aug 2028 | Article 6(1) high-risk applies (as amended) | AI that is, or is a safety component of, a medical device under Annex I (MDR/IVDR) | 23 |
The last two rows reflect the Digital Omnibus amendments, in force since 27 July 2026 per the Commission's framework page 2. Read the table as the law as it stands, and the Omnibus section below for how the deferral happened.
What decides your compliance date?
For healthcare, the single most useful thing to understand about the AI Act is that "high-risk" is reached by two different routes, and each route carries a different application date.
Route one — Annex III, the standalone systems. Article 6(2) says that the AI systems listed in Annex III are high-risk 1. Annex III point 5 reaches into healthcare in two specific places: AI "intended to be used by public authorities or on behalf of public authorities to evaluate the eligibility of natural persons for essential public assistance benefits and services, including healthcare services," and AI intended "to be used to dispatch, or to establish priority in the dispatching of, emergency first response services, including … emergency healthcare patient triage systems" 1. These are standalone high-risk systems, and their obligations arrive on the general application date of 2 August 2026.
Route two — Article 6(1), the regulated devices. A great deal of clinical AI has nothing to do with benefits eligibility; it is a diagnostic or decision-support product that meets the definition of a medical device. Article 6(1) makes an AI system high-risk when two conditions are both met: it is a safety component of, or is itself, a product covered by the Union harmonisation legislation in Annex I; and that product must undergo third-party conformity assessment before being placed on the market 1. Annex I, Section A lists the Medical Device Regulation (EU) 2017/745 and the IVD Regulation (EU) 2017/746. Because medical devices above the lowest risk class already require a notified body to assess conformity under the MDR 4, AI medical devices satisfy both limbs of Article 6(1) — and Article 113 gives that class a later start: its obligations apply from 2 August 2027.
The practical consequence is easy to state and easy to get wrong. If your tool is a clinical decision support system that is CE-marked as a medical device, the AI Act layer arrives in 2027, not 2026. If your tool judges who is eligible for a service, or triages emergency calls, it can be caught by the 2026 date even if it never touched the device pathway. Many teams plan to the wrong year because they assume "2 August 2026" is universal. It governs the Annex III route; the device route is a year behind it. For the underlying device concept, see our glossary entry on software as a medical device.
What is already live?
Two obligations already bind, and both touch healthcare organisations regardless of whether they build devices.
Since 2 February 2025, Chapters I and II have applied 1. Chapter I carries Article 4, the AI-literacy duty: providers and deployers must take measures to ensure a sufficient level of AI literacy among staff and others who operate their systems on their behalf. A hospital deploying a purchased AI tool is a "deployer," so this is a live duty for care providers as well as vendors. Chapter II carries Article 5, the ban on prohibited practices — the small set of AI uses the Act forbids outright.
Since 2 August 2025, the obligations for general-purpose AI models under Chapter V have applied 1. A foundation model that a health system builds on is governed at the model layer from that date, even though the high-risk obligations on the clinical system built from it arrive later. Penalties under Chapter XII also began on that date, with the exception of Article 101 (the specific fine regime for GPAI providers). The Regulation sets its ceiling for the most serious infringements at up to €35 million or 7% of worldwide annual turnover, whichever is higher 12.
What actually lands on the date?
It helps to be concrete about what "the high-risk obligations apply" means, because a date is only as meaningful as the duties it switches on. For a high-risk AI system, Chapter III of the Regulation sets out a substantial set of requirements: a risk-management system maintained across the lifecycle, data-governance and data-quality controls, technical documentation and automatic record-keeping, transparency and instructions for use, human oversight designed into the system, and an appropriate level of accuracy, robustness and cybersecurity — the obligations in Articles 9 to 15 1. Providers must also operate a quality-management system and complete the relevant conformity assessment; deployers — the hospitals and clinics that use the system rather than build it — carry their own duties, including using the system in line with its instructions and ensuring the human oversight the provider designed for is actually exercised. Little of this can be retrofitted in a weekend. That is why the application date matters less as a single cliff-edge and more as the end of a build-and-document runway that, for a 2027 obligation, is already underway.
The Digital Omnibus — now in force
Here is the reason this page carries a ninety-day cadence rather than a one-time publish. On 19 November 2025 the European Commission proposed a Digital Omnibus on AI, a package deferring the high-risk application dates 3. The procedure is now complete.
| Deferral | Original enacted date | Date now in force | Source |
|---|---|---|---|
| Standalone high-risk (Annex III) — incl. healthcare eligibility, emergency triage | 2 Aug 2026 | 2 Dec 2027 | 23 |
| Product-embedded high-risk (Annex I) — incl. medical-device AI | 2 Aug 2027 | 2 Aug 2028 | 23 |
The endgame moved quickly. A provisional trilogue agreement was reached on 7 May 2026, member-state ambassadors approved it on 13 May 2026, the European Parliament adopted the agreed text in plenary on 16 June 2026 — by 423 votes to 57, with 174 abstentions — and the Council gave its final approval on 29 June 2026 3. The Commission's framework page now records the package as in force since 27 July 2026 and states the revised dates as applicable law 2. The deferral is settled: plan against 2 December 2027 for Annex III systems and 2 August 2028 for medical-device AI — and treat the extra time as a build-and-document runway that is already underway.
How to read this timeline
Five cautions travel with every row.
First, status is perishable, and this Act is unusually so. The Omnibus moved two headline dates within a single summer; guidelines, delegated acts, and corrigenda can still reshape details. That is precisely why this page is dated and revisited.
Second, the two-route split is about classification, not marketing labels. Whether a given tool is a "medical device," an "Annex III system," both, or neither turns on its intended purpose and the legislation it falls under — a determination to make with counsel, not from a product datasheet.
Third, the AI Act sits on top of existing device law, it does not replace it. An AI medical device still needs its MDR or IVDR conformity assessment; the AI Act adds requirements rather than substituting for them 4. The dates here govern when the AI Act layer applies.
Fourth, transitional provisions exist. Article 111 of the Regulation sets out how systems already placed on the market before the applicable dates are treated 1; whether a legacy deployment is caught can depend on whether it undergoes significant changes. Confirm the transitional position for any live system rather than assuming the headline date applies cleanly.
Fifth, this is an EU instrument, and healthcare AI is global. A tool placed on the EU market is caught regardless of where it was built, while the same tool faces different rules elsewhere — the UK runs its own device route and the MHRA AI Airlock sandbox, and the WHO's guidance on large multi-modal models sits over all of them as advisory rather than binding. The cross-jurisdiction picture lives in our global AI in health regulation tracker.
Because the AI Act carries direct legal obligations and penalties, treat this timeline as orientation only and confirm the classification and compliance position of any specific product with your regulatory counsel or compliance function before you rely on a date.
Sources and method
Every date on this page is drawn from a primary source: the text of Regulation (EU) 2024/1689 on EUR-Lex — Articles 4, 5, 6 and 113, Annex I Section A, and Annex III point 5 1 — cross-checked against the European Commission's own framework summary 2; the Medical Device Regulation (EU) 2017/745 for the conformity-assessment condition that pulls devices into Article 6(1) 4; and the European Parliament's Legislative Train record for the status of the Digital Omnibus 3. This page was refreshed on 1 August 2026 when the Omnibus's entry into force (27 July 2026) satisfied its own top freshness trigger. We revisit it every ninety days and whenever a tracked date changes status. Dates and statuses are current as of August 2026.