EU AI Act for AI deployers in healthcare
Last updated 1 August 2026
This guide maps the EU AI Act (Regulation (EU) 2024/1689, as amended by the 2026 Digital Omnibus) to the AI systems AI deployers actually run in healthcare: which uses are high-risk, which only carry transparency duties, and what is due by when. It reflects the post-Omnibus dates — the high-risk regime now applies from 2 December 2027 (Annex III) and 2 August 2028 (Annex I), while Article 50 transparency has applied since 2 August 2026.
Are you the deployer?
You are a deployer if you use an AI system under your own authority in the course of business — e.g. running a vendor's screening tool, chatbot or scoring model on your own customers, staff or applicants (Article 3(4)).
Deployers must use high-risk systems per the provider's instructions with competent human oversight, monitor operation and keep logs (Article 26), and carry the user-facing transparency duties of Article 50(1), (3) and (4) — chatbot disclosure, emotion-recognition notices and deep-fake labels. If your organisation also acts as a provider, read the companion guide for AI providers in healthcare too — many companies are both.
Typical AI uses in healthcare
- diagnostic support and medical imaging analysis
- patient triage chatbots and symptom checkers
- clinical documentation and discharge-letter generation
- AI features embedded in medical devices
High-risk triggers in healthcare
The high-risk classification follows the use context (Article 6), not the underlying technology. These are the categories most relevant to this industry:
- Article 6(1) + Annex I (MDR/IVDR): AI that is a safety component of a medical device (or is itself one) under the Medical Device Regulation and undergoes third-party conformity assessment is high-risk — the Chapter III regime applies from 2 August 2028 for these embedded systems.
- Annex III(5)(d): AI used to evaluate and classify emergency calls or to dispatch emergency services (including triage of patients in emergency healthcare) is high-risk — from 2 December 2027.
For high-risk systems, deployers must use the system according to the provider’s instructions, assign competent human oversight, ensure input-data quality, monitor operation and keep logs (Article 26) — and public bodies and certain private deployers must complete a fundamental-rights impact assessment before first use (Article 27). Note Article 6(3): a system in an Annex III area escapes high-risk status if it only performs a narrow procedural or preparatory task without profiling — document that assessment if you rely on it.
Transparency duties (Article 50) — since 2 August 2026
- Patient-facing chatbots and symptom checkers must disclose they are AI at first interaction (Article 50(1)).
- AI-generated patient communications or health information published to the public may need labelling under Article 50(4) unless a clinician holds editorial responsibility.
Worth knowing
- MDR/IVDR conformity work and AI Act high-risk documentation overlap substantially — plan a single combined technical file.
Your timeline (post-Digital-Omnibus)
- 2 February 2025 — prohibitions (Article 5) and AI literacy (Article 4) apply. Already in force.
- 2 August 2025 — GPAI model rules (Chapter V) apply.
- 2 August 2026 — general application: Article 50 transparency, governance, penalties. In force.
- 2 December 2026 — Article 50(2) marking grace period ends for systems on the market before 2 August 2026; new Omnibus prohibitions apply.
- 2 December 2027 — high-risk obligations for Annex III systems (moved from 2 August 2026 by the Digital Omnibus).
- 2 August 2028 — high-risk obligations for AI embedded in Annex I regulated products (moved from 2 August 2027).
Penalties
Prohibited practices: up to €35,000,000 or 7% of worldwide annual turnover (Article 99(3)). High-risk and transparency breaches: up to €15,000,000 or 3% (Article 99(4)), whichever is higher. See what you actually risk in practice.
Next step: get your specific list
The fastest way to turn this into your own obligation list is the free 3-minute EU AI Act risk self-assessment — risk tier, obligations with article references, personalised timeline and penalty exposure. If your exposure is chatbots or AI-generated content, the Article 50 checker goes clause by clause.
Not sure which obligations apply to you?
Run the free 3-minute Article 50 check