← Back to Articles
The short answer

The Digital Omnibus on AI, proposed by the European Commission on 19 November 2025 and adopted by the European Parliament on 16 June 2026, deferred the AI Act's high-risk obligations. Standalone high-risk systems listed in Annex III now apply from 2 December 2027. High-risk AI embedded in regulated products, which is where most medical devices sit under Annex I, applies from 2 August 2028. The obligations themselves did not change. Only the clock did.

What actually changed

The European Commission proposed the Digital Omnibus on AI on 19 November 2025, a set of targeted amendments to the AI Act. The stated reasons were practical: standards for the high-risk rules were running late, and member states were behind on designating national competent authorities and conformity assessment bodies. The obligations were arriving before the machinery to assess compliance against them existed.

The Council reached a general approach on 13 March 2026. A trilogue agreement followed on 7 May 2026. The European Parliament adopted the package in plenary on 16 June 2026 by 423 votes to 57, with 174 abstentions.

The new dates

CategoryApplies from
Standalone high-risk AI systems (Annex III)2 December 2027
High-risk AI embedded in regulated products (Annex I)2 August 2028
Marking of AI-generated content, for systems placed on the market before 2 August 20262 December 2026

For medical AI the second row is usually the one that matters. AI that is a medical device, or a safety component of one, is regulated under the Medical Device Regulation or the In Vitro Diagnostic Regulation, which puts it in the Annex I category. Diagnostic imaging software, software as a medical device for patient monitoring, and AI acting as a safety component all sit here.

What did not move

The substance. The requirements on risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy and robustness are unchanged. So is the fact that AI-specific obligations have to be integrated into the technical file and quality management system you already maintain under MDR or IVDR, rather than kept as a separate compliance exercise running alongside them.

Prohibited practices and the general-purpose AI provisions were on a different timetable and are not affected by the high-risk deferral.

Our view

Two failure modes, and we see both.

The first is planning against a dead deadline. If your compliance roadmap was built in 2025 and still targets August 2026, it is working from a superseded timeline. That is a scheduling error rather than a legal exposure, but it distorts budget and hiring decisions for the next two years.

The second is worse: reading the deferral as permission to stop. The delay exists because the conformity assessment infrastructure was not ready, not because the risks turned out to be overstated. The gap analysis against the requirements on data governance, logging and human oversight takes the same amount of work whenever you start it, and organisations that treat 2027 as far away will discover that notified body capacity is finite and that everyone will arrive at once.

Our practical advice: use the deferral to do the boring part properly. Map every AI system you develop or deploy against the risk tiers, decide who owns each one, and find out now whether your existing MDR technical file can absorb the AI Act requirements or whether it needs restructuring. That work is cheap this year and expensive in late 2027.

Sources

  1. European Parliament, Legislative Train Schedule, "Digital Omnibus on AI". europarl.europa.eu
  2. Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated text. eur-lex.europa.eu

Governing AI You Did Not Build

Programmes for the executives and clinicians who have to sign off on AI deployment decisions.

Start a Conversation →