The EUās AI Omnibus is now in force, resetting the timetable for the Artificial Intelligence Actās strictest high-risk requirements. For AI-enabled medical devices and in-vitro diagnostics, the central compliance date is now 2 August 2028. Not 2027, while other AI Act obligations and sectoral medical-device rules continue to apply.
What changed: a binding extension, not a repeal
On 27 July 2026, theĀ EU AI Omnibus entered into force, amending the implementation timetable for parts of the AI Act. The most consequential change for life-sciences and healthcare organisations is the deferral of the AI Actās high-risk requirements for AI systems embedded in regulated products listed in Annex I, including products governed by the Medical Device Regulation (MDR) and In Vitro Diagnostic Medical Devices Regulation (IVDR). Those requirements will now apply fromĀ 2 August 2028.
This is a confirmed legal change, rather than a consultation, policy intention or industry expectation, unlike the earlier EU AI Act delay negotiations that left pharma and medtech organisations assessing several possible implementation scenarios.
It does not remove the high-risk regime; it changes when that regime applies. The Commission describes the extension as part of a targeted simplification package intended to give organisations more implementation support, including standards and guidance, before the relevant obligations take effect, in its overview of the AI Actās regulatory framework.
The AI Omnibus also establishes a separate date for standalone high-risk systems under Article 6(2) and Annex III of the AI Act:Ā 2 December 2027. Annex III covers specified use cases such as employment, education, biometric systems, critical infrastructure, access to certain essential services, law enforcement, migration and justice. That category may be relevant to healthcare providers or life-sciences employers in limited circumstancesāfor example, where AI is used for recruitment or workforce managementābut it is distinct from the product-linked category most relevant to medical devices and IVDs.
Why medical-device AI has a different timetable
The distinction matters because the AI Act does not classify every AI tool used in health or life sciences as high-risk. For product-linked systems, Article 6(1) connects high-risk status to two features: the AI system must be a product, or safety component of a product, covered by listed EU harmonisation legislation; and the product must require third-party conformity assessment. MDR and IVDR sit within that Annex I framework.
In practical terms, an AI-enabled diagnostic, radiology-support product, clinical decision-support software, software as a medical device (SaMD), or AI feature in an IVD may fall into this category where it has a medical intended purpose and is subject to notified-body assessment. The 2028 date therefore has immediate strategic relevance for manufacturers developing machine-learning-enabled imaging software, pathology and genomic interpretation tools, predictive devices, triage tools, or adaptive clinical-support functionality.
However, the extension should not be read as a regulatory holiday. MDR and IVDR obligations remain legally applicable according to their own terms. A manufacturer cannot defer clinical evaluation, performance evaluation, risk management, post-market surveillance, vigilance, cybersecurity controls, quality-system obligations or notified-body engagement simply because the AI Actās product-linked high-risk requirements have moved. The AI Act will add a further layer of AI-specific obligations; it does not displace the existing sectoral framework.
The same caution applies beyond devices. AI used in drug discovery and virtual screening, trial-site selection, eligibility screening, statistical analysis, pharmacovigilance case processing, signal detection, medical information or real-world evidence may not automatically be high-risk under the AI Act.
Its regulatory treatment will depend on its intended purpose, deployment context, role in a regulated decision, applicable GxP controls, personal-data processing and whether it is incorporated into a regulated product or service.
The operating question is lifecycle readiness
For manufacturers and providers of likely Annex I high-risk systems, the extended timetable creates additional preparation timeābut it also makes lifecycle planning more important. The CommissionāsĀ AI Act framework summaryĀ identifies the future high-risk regime as including risk management, data quality, logging, technical documentation, information for deployers, human oversight, accuracy, robustness and cybersecurity. Providers will also need post-market monitoring, while providers and deployers will have responsibilities around serious incidents and malfunctioning.
For a life-sciences AI leader, the practical question is no longer whether governance is needed, but whether it is built into validation, procurement and change control.
Organisations should therefore assess whether their current development, quality and GxP validation workflows can generate evidence suitable for both sectoral and AI Act expectations.
For an AI medical-device manufacturer, this may mean mapping the intended purpose and device classification before treating an AI function as a generic software feature. It may also mean linking model performance claims, clinical evidence, data provenance, risk controls and cybersecurity evidence to the technical documentation already maintained under MDR or IVDR.
For adaptive or frequently updated models, versioning, monitoring and AI governance and ModelOps deserve particular attention.
Teams should be able to identify which model, training data, configuration and decision thresholds were used in a given release; determine whether an update changes the validated intended performance or risk profile; and decide whether change control, revalidation, notified-body engagement or post-market action is required. The regulatory texts do not make every model update automatically material, but an undocumented or weakly governed update can create serious auditability and safety problems.
Healthcare providers and clinical-research organisations should similarly separate procurement governance from product classification.
A provider deploying an AI-enabled documentation tool, imaging workflow product, triage platform or clinical decision-support AI tool may not become the manufacturer, but it should understand the intended use, deployment conditions, human-oversight model, local validation evidence, data flows, escalation path and supplier obligations.
Clinical teams should avoid assuming that an AI toolās presence in a regulated workflow proves that its outputs are clinically validated for every local population, setting or use case.
What remains applicable now
The timetable change does not affect all AI Act obligations equally. As the CommissionāsĀ AI Act implementation timeline confirms, prohibited AI practices and AI-literacy obligations have applied since February 2025, while governance rules and obligations for providers of general-purpose AI (GPAI) models became applicable in August 2025.
The Commission also states that transparency rules apply from August 2026. These rules are potentially relevant to healthcare organisations deploying chatbots, patient-facing generative AI, automated content tools or systems producing synthetic audio, image or text. Their application will depend on the specific system and role of the organisation. A clinical organisation should not infer that every internal or patient-facing generative AI use triggers identical disclosure requirements; it should assess the applicable provisions, exemptions and interaction with professional, privacy and sectoral duties.
GPAI model obligations are also relevant to vendors building health and life-sciences applications on third-party foundation models. The AI Act places obligations on GPAI model providers, including transparency and copyright-related requirements, with additional obligations for models posing systemic risk. Downstream application providers and deployers should still undertake supplier due diligence: model documentation, acceptable-use terms, update practices, security controls, training-data transparency where available, and contractual support for risk assessment all affect the ability to govern an application safely.
Global teams face convergence, not uniformity
For international organisations, the EU extension may make programme sequencing easier, but it does not create a single global compliance model. The EUās AI Act adds horizontal AI-specific controls to an established product-safety framework. In the medical-device context, that means AI governance needs to work alongside MDR/IVDR quality management, clinical or performance evaluation, risk management and post-market surveillance.
The practical areas of convergence are substantial: documented intended purpose, evidence of performance, risk controls, traceability, human oversight, cybersecurity, change management and lifecycle monitoring are already familiar concepts in regulated health technology. The divergence lies in legal triggers, formal roles, documentation routes and enforcement structures. Organisations selling across the EU, UK and US should avoid designing a programme around the assumption that one jurisdictionās terminology or submission route automatically satisfies anotherās requirements.
What to watch next
The next confirmed milestone for standalone Annex III high-risk systems isĀ 2 December 2027. This could affect healthcare providers and life-sciences employers where they use AI in a listed high-risk context, such as employment or workforce management, rather than because the use case is healthcare-related.
For Annex I product-linked high-risk systems, including relevant MDR and IVDR products, the confirmed application date isĀ 2 August 2028. Manufacturers should watch for Commission guidance, harmonised standards and notified-body practice that clarify how AI Act evidence will be assessed alongside existing device conformity assessment.
Organisations should also monitor the CommissionāsĀ AI Act implementation materialsĀ on transparency, GPAI and enforcement. The AI Office and Member State authorities have enforcement and supervisory roles under the framework, while the Commission continues to publish guidance, codes and support tools intended to make implementation more operational.
The extension gives affected organisations time to make governance evidence-producing rather than merely policy-based, including through appropriately selected governance, risk and compliance AI tools.
Early classification, quality-system integration, supplier controls and disciplined model change management may reduce avoidable disruption as the 2028 deadline approaches.
HealthyData.Scienceās AI solutions directory tracks AI regulation developments across clinical research, healthcare and life sciences, helping readers understand what each update means in practice.
Author: Stephen
Founder of HealthyData.Science Ā· 20+ years in life sciences compliance & software validation Ā· MSc in Data Science & Artificial Intelligence.
Follow HealthyData.Science on Google Search & AI
Get our latest healthcare and life science AI tool evaluations, regulatory updates, and buyer intelligence in your Google AI Overviews.
Add as Preferred Source