EU AI Act for AI providers in healthcare
Last updated 1 August 2026
This guide maps the EU AI Act (Regulation (EU) 2024/1689, as amended by the 2026 Digital Omnibus) to the AI systems AI providers actually run in healthcare: which uses are high-risk, which only carry transparency duties, and what is due by when. It reflects the post-Omnibus dates — the high-risk regime now applies from 2 December 2027 (Annex III) and 2 August 2028 (Annex I), while Article 50 transparency has applied since 2 August 2026.
Are you the provider?
You are a provider if you develop an AI system (or have one developed) and place it on the market or put it into service under your own name or trade mark — including SaaS companies shipping AI features built on third-party models (Article 3(3)).
Providers carry the heaviest obligations: for high-risk systems the full Chapter III regime (risk management, data governance, technical documentation, conformity assessment, CE marking, registration), and for generative systems the Article 50(2) machine-readable marking duty. If your organisation also acts as a deployer, read the companion guide for AI deployers in healthcare too — many companies are both.
Typical AI uses in healthcare
- diagnostic support and medical imaging analysis
- patient triage chatbots and symptom checkers
- clinical documentation and discharge-letter generation
- AI features embedded in medical devices
High-risk triggers in healthcare
The high-risk classification follows the use context (Article 6), not the underlying technology. These are the categories most relevant to this industry:
- Article 6(1) + Annex I (MDR/IVDR): AI that is a safety component of a medical device (or is itself one) under the Medical Device Regulation and undergoes third-party conformity assessment is high-risk — the Chapter III regime applies from 2 August 2028 for these embedded systems.
- Annex III(5)(d): AI used to evaluate and classify emergency calls or to dispatch emergency services (including triage of patients in emergency healthcare) is high-risk — from 2 December 2027.
For high-risk systems, providers carry the full Chapter III regime: risk management (Article 9), data governance (Article 10), technical documentation (Article 11 + Annex IV), logging (Article 12), instructions to deployers (Article 13), human oversight design (Article 14), accuracy and cybersecurity (Article 15), quality management (Article 17), conformity assessment (Article 43), CE marking and EU database registration (Articles 48-49). Note Article 6(3): a system in an Annex III area escapes high-risk status if it only performs a narrow procedural or preparatory task without profiling — document that assessment if you rely on it.
Transparency duties (Article 50) — since 2 August 2026
- Patient-facing chatbots and symptom checkers must disclose they are AI at first interaction (Article 50(1)).
- AI-generated patient communications or health information published to the public may need labelling under Article 50(4) unless a clinician holds editorial responsibility.
Worth knowing
- MDR/IVDR conformity work and AI Act high-risk documentation overlap substantially — plan a single combined technical file.
Your timeline (post-Digital-Omnibus)
- 2 February 2025 — prohibitions (Article 5) and AI literacy (Article 4) apply. Already in force.
- 2 August 2025 — GPAI model rules (Chapter V) apply.
- 2 August 2026 — general application: Article 50 transparency, governance, penalties. In force.
- 2 December 2026 — Article 50(2) marking grace period ends for systems on the market before 2 August 2026; new Omnibus prohibitions apply.
- 2 December 2027 — high-risk obligations for Annex III systems (moved from 2 August 2026 by the Digital Omnibus).
- 2 August 2028 — high-risk obligations for AI embedded in Annex I regulated products (moved from 2 August 2027).
Penalties
Prohibited practices: up to €35,000,000 or 7% of worldwide annual turnover (Article 99(3)). High-risk and transparency breaches: up to €15,000,000 or 3% (Article 99(4)), whichever is higher. See what you actually risk in practice.
Next step: get your specific list
The fastest way to turn this into your own obligation list is the free 3-minute EU AI Act risk self-assessment — risk tier, obligations with article references, personalised timeline and penalty exposure. If your exposure is chatbots or AI-generated content, the Article 50 checker goes clause by clause.
Not sure which obligations apply to you?
Run the free 3-minute Article 50 check