AI Act Disclosure Kit

← All guides

EU AI Act for AI deployers in healthcare

Last updated 1 August 2026

This guide maps the EU AI Act (Regulation (EU) 2024/1689, as amended by the 2026 Digital Omnibus) to the AI systems AI deployers actually run in healthcare: which uses are high-risk, which only carry transparency duties, and what is due by when. It reflects the post-Omnibus dates — the high-risk regime now applies from 2 December 2027 (Annex III) and 2 August 2028 (Annex I), while Article 50 transparency has applied since 2 August 2026.

Are you the deployer?

You are a deployer if you use an AI system under your own authority in the course of business — e.g. running a vendor's screening tool, chatbot or scoring model on your own customers, staff or applicants (Article 3(4)).

Deployers must use high-risk systems per the provider's instructions with competent human oversight, monitor operation and keep logs (Article 26), and carry the user-facing transparency duties of Article 50(1), (3) and (4) — chatbot disclosure, emotion-recognition notices and deep-fake labels. If your organisation also acts as a provider, read the companion guide for AI providers in healthcare too — many companies are both.

Typical AI uses in healthcare

  • diagnostic support and medical imaging analysis
  • patient triage chatbots and symptom checkers
  • clinical documentation and discharge-letter generation
  • AI features embedded in medical devices

High-risk triggers in healthcare

The high-risk classification follows the use context (Article 6), not the underlying technology. These are the categories most relevant to this industry:

  • Article 6(1) + Annex I (MDR/IVDR): AI that is a safety component of a medical device (or is itself one) under the Medical Device Regulation and undergoes third-party conformity assessment is high-risk — the Chapter III regime applies from 2 August 2028 for these embedded systems.
  • Annex III(5)(d): AI used to evaluate and classify emergency calls or to dispatch emergency services (including triage of patients in emergency healthcare) is high-risk — from 2 December 2027.

For high-risk systems, deployers must use the system according to the provider’s instructions, assign competent human oversight, ensure input-data quality, monitor operation and keep logs (Article 26) — and public bodies and certain private deployers must complete a fundamental-rights impact assessment before first use (Article 27). Note Article 6(3): a system in an Annex III area escapes high-risk status if it only performs a narrow procedural or preparatory task without profiling — document that assessment if you rely on it.

Transparency duties (Article 50) — since 2 August 2026

  • Patient-facing chatbots and symptom checkers must disclose they are AI at first interaction (Article 50(1)).
  • AI-generated patient communications or health information published to the public may need labelling under Article 50(4) unless a clinician holds editorial responsibility.

Worth knowing

  • MDR/IVDR conformity work and AI Act high-risk documentation overlap substantially — plan a single combined technical file.

Your timeline (post-Digital-Omnibus)

  • 2 February 2025 — prohibitions (Article 5) and AI literacy (Article 4) apply. Already in force.
  • 2 August 2025 — GPAI model rules (Chapter V) apply.
  • 2 August 2026 — general application: Article 50 transparency, governance, penalties. In force.
  • 2 December 2026 — Article 50(2) marking grace period ends for systems on the market before 2 August 2026; new Omnibus prohibitions apply.
  • 2 December 2027 — high-risk obligations for Annex III systems (moved from 2 August 2026 by the Digital Omnibus).
  • 2 August 2028 — high-risk obligations for AI embedded in Annex I regulated products (moved from 2 August 2027).

Penalties

Prohibited practices: up to €35,000,000 or 7% of worldwide annual turnover (Article 99(3)). High-risk and transparency breaches: up to €15,000,000 or 3% (Article 99(4)), whichever is higher. See what you actually risk in practice.

Next step: get your specific list

The fastest way to turn this into your own obligation list is the free 3-minute EU AI Act risk self-assessment — risk tier, obligations with article references, personalised timeline and penalty exposure. If your exposure is chatbots or AI-generated content, the Article 50 checker goes clause by clause.

← All role & industry guides

This tool and its content are provided for general information only and do not constitute legal advice. Consult a qualified lawyer for advice on your specific situation. Primary source: Regulation (EU) 2024/1689 (EU AI Act), Official Journal of 13 June 2024 — EUR-Lex.

Not sure which obligations apply to you?

Run the free 3-minute Article 50 check