High-risk obligations under the EU AI Act were deferred in 2026. The new dates are 2 December 2027 and 2 August 2028, and the delay is narrower than it sounds.
The Digital Omnibus on AI, proposed by the European Commission on 19 November 2025 and adopted by the European Parliament on 16 June 2026, deferred the AI Act's high-risk obligations. Standalone high-risk systems listed in Annex III now apply from 2 December 2027. High-risk AI embedded in regulated products, which is where most medical devices sit under Annex I, applies from 2 August 2028. The obligations themselves did not change. Only the clock did.
The European Commission proposed the Digital Omnibus on AI on 19 November 2025, a set of targeted amendments to the AI Act. The stated reasons were practical: standards for the high-risk rules were running late, and member states were behind on designating national competent authorities and conformity assessment bodies. The obligations were arriving before the machinery to assess compliance against them existed.
The Council reached a general approach on 13 March 2026. A trilogue agreement followed on 7 May 2026. The European Parliament adopted the package in plenary on 16 June 2026 by 423 votes to 57, with 174 abstentions.
| Category | Applies from |
|---|---|
| Standalone high-risk AI systems (Annex III) | 2 December 2027 |
| High-risk AI embedded in regulated products (Annex I) | 2 August 2028 |
| Marking of AI-generated content, for systems placed on the market before 2 August 2026 | 2 December 2026 |
For medical AI the second row is usually the one that matters. AI that is a medical device, or a safety component of one, is regulated under the Medical Device Regulation or the In Vitro Diagnostic Regulation, which puts it in the Annex I category. Diagnostic imaging software, software as a medical device for patient monitoring, and AI acting as a safety component all sit here.
The substance. The requirements on risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy and robustness are unchanged. So is the fact that AI-specific obligations have to be integrated into the technical file and quality management system you already maintain under MDR or IVDR, rather than kept as a separate compliance exercise running alongside them.
Prohibited practices and the general-purpose AI provisions were on a different timetable and are not affected by the high-risk deferral.
Two failure modes, and we see both.
The first is planning against a dead deadline. If your compliance roadmap was built in 2025 and still targets August 2026, it is working from a superseded timeline. That is a scheduling error rather than a legal exposure, but it distorts budget and hiring decisions for the next two years.
The second is worse: reading the deferral as permission to stop. The delay exists because the conformity assessment infrastructure was not ready, not because the risks turned out to be overstated. The gap analysis against the requirements on data governance, logging and human oversight takes the same amount of work whenever you start it, and organisations that treat 2027 as far away will discover that notified body capacity is finite and that everyone will arrive at once.
Our practical advice: use the deferral to do the boring part properly. Map every AI system you develop or deploy against the risk tiers, decide who owns each one, and find out now whether your existing MDR technical file can absorb the AI Act requirements or whether it needs restructuring. That work is cheap this year and expensive in late 2027.