EU AI Act compliance for healthtech and medical AI companies
Health is the area where the AI Act interacts most closely with existing product regulation. AI that is a medical device, or a safety component of one, is high-risk through Annex I rather than Annex III, and it follows the medical device conformity route.
That distinction matters for your timeline. Annex I embedded high-risk AI moved to 2 August 2028 under the Omnibus package, while standalone Annex III systems moved to 2 December 2027.
Are you a provider or a deployer?
Building medical AI makes you a provider. Hospitals and clinics using it are deployers. Where the product is a regulated medical device, AI Act conformity is assessed through the medical device framework rather than separately.
How this is classified under the Act
AI intended as a medical device, or as a safety component of one, is high-risk under Article 6(1) and Annex I because it already requires third-party conformity assessment under Regulation (EU) 2017/745. Non-device health software needs its own assessment and may fall outside Annex III.
What changes the answer: Emergency triage and dispatch AI is separately high-risk under Annex III point 5(d). Health insurance risk assessment and pricing is high-risk under point 5(c).
Want this checked against your own setup?
Run the free 6-question check →Documents you need
- AI Literacy Policy Article 4
A written policy covering which AI tools you use, which roles interact with them, what those people need to understand, who owns the document, and how it gets updated. Enforceable since 2 February 2025.
- Risk Classification Memo Articles 6, 9 and Annex III
A documented assessment placing each AI system in the Act’s risk tiers, including the Article 5 prohibited-practice check and the Article 6(3) exception assessment, with article citations.
- Usage Policy for Deployers Article 26
Defines permitted and prohibited uses, human oversight arrangements, input data standards, logging, and incident reporting for a high-risk AI system you deploy.
- Transparency Disclosure Article 50
Informs people when they are interacting with an AI system and labels AI-generated or manipulated content. Article 50 applies from 2 August 2026. The narrower Article 50(2) duty on general-purpose models generating synthetic content applies from 2 December 2026.
Obligations that apply
- Article 6(1) Establish which annex applies
Determine whether your system is high-risk through Annex I as a regulated device or through Annex III as a standalone system. The route and the deadline both depend on it.
- Article 8(2) Integrate with device compliance
Where both regimes apply, AI Act requirements should be met within the existing medical device quality management and technical documentation rather than duplicated.
- Article 10 Clinical data governance
Training and validation data must be examined for bias and representativeness across patient populations, which sits alongside clinical evaluation duties.
- Article 4 Literacy for your team and guidance for clinicians
Your own staff need literacy now. Clinician-facing instructions for use are how your hospital customers meet their oversight obligations.
Common mistakes
- Running two parallel compliance programmes instead of integrating AI Act requirements into the existing device QMS.
- Assuming a CE mark under medical device regulation already covers AI Act obligations.
- Classifying wellness or administrative health software as high-risk when it is neither a device nor named in Annex III.
- Validating models only on the population present in the training data.
Where the deadlines stand
The AI literacy obligation under Article 4 and the Article 5 prohibitions have been enforceable since 2 February 2025. General-purpose AI model rules applied from 2 August 2025. The Omnibus, published in the Official Journal on 24 July 2026, moved the high-risk dates: standalone high-risk systems under Annex III to 2 December 2027, and high-risk AI embedded in regulated products under Annex I to 2 August 2028. Article 50 transparency obligations still apply from 2 August 2026. Only the narrower Article 50(2) duty on general-purpose models generating synthetic content moved, to 2 December 2026, which is also when the new prohibition on AI-generated intimate imagery and child sexual abuse material takes effect.
The delay applies to the high-risk obligations. It does not move Article 4, which is why a written AI literacy policy is the document most companies are missing today.
Generate your 4 documents in about 30 minutes
Answer a short questionnaire and get every document above, pre-filled with your company details and article citations, in 11 EU languages. Preview free, download for €99 one-time. No subscription.
This page describes obligations under Regulation (EU) 2024/1689 as amended by the Omnibus published in the Official Journal on 24 July 2026, and was verified on 29 July 2026. It is general information rather than legal advice, and classification depends on your specific configuration and use. Review by qualified legal counsel is recommended before formal adoption of any compliance document.