The EU AI Act Deadline Moved: What the 2026 Digital Omnibus Changes for Medical Device Software

The Digital Omnibus on AI is a 2026 amendment to the EU AI Act that postpones the application of high-risk AI obligations, including those for AI-enabled medical device software, while leaving the AI Act’s transparency and AI literacy obligations on their original schedule.
The amendment is now law. Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. For MedTech teams, the practical effect is a genuine extension of the heaviest compliance work, paired with two obligations that did not move and are already live. Building a compliance plan around the old high-risk dates now means planning against a timeline that no longer exists, while the near-term duties are already in force.
Atta Systems builds medical device software under an ISO 13485-certified quality management system, including the cloud imaging platform Medicai, and tracks the AI Act timeline because it changes what has to be designed into a device from the first version.

What the Digital Omnibus changed, and what it did not
The Digital Omnibus changed the application dates for high-risk AI obligations but left the AI Act’s core architecture, its transparency obligations, and its AI literacy duty in place. The risk-based classification, the four risk tiers, the conformity assessment regime, and the rules for general-purpose AI models remain unchanged. What moved is when the heaviest obligations start to apply.
The revised timeline, as set by Regulation (EU) 2026/1744:
| Obligation | Original date | Revised date | Moved? |
| Article 50 transparency obligations | 2 August 2026 | 2 August 2026 (now live) | No change |
| Article 4 AI literacy (softened wording) | 2 February 2025 | 27 July 2026 (now live) | Amended, not deferred |
| New Article 5 prohibitions (non-consensual intimate imagery, child sexual abuse material) | (new) | 2 December 2026 | Added |
| Article 50(2) watermarking, legacy synthetic-media systems | 2 August 2026 | 2 December 2026 | Extended |
| National regulatory sandboxes (Article 57) | 2 August 2026 | 2 August 2027 | Extended |
| Annex III standalone high-risk (education, employment, credit) | 2 August 2026 | 2 December 2027 | Extended |
| Annex I embedded high-risk (medical devices under MDR/IVDR) | 2 August 2027 | 2 August 2028 | Extended |
The single most important line in that table for a MedTech team is the last one: high-risk obligations for AI embedded in medical devices now apply from 2 August 2028 rather than 2 August 2027. That is a full extra year on the heaviest part of the work. Just as important are the two obligations that did not move: the transparency obligations and the amended AI literacy duty are both already live.
Why AI in a medical device is high-risk under the AI Act
AI-enabled medical device software is classified as high-risk under the AI Act due to Annex I, not Annex III. Under Article 6(1), an AI system is high-risk when it is a product, or a safety component of a product, that is covered by the EU harmonization legislation listed in Annex I and that requires third-party conformity assessment. Annex I includes the Medical Device Regulation, EU MDR 2017/745, and the In Vitro Diagnostic Regulation, IVDR 2017/746. Any AI that is a medical device, or a safety component of one, and that needs notified-body assessment is therefore high-risk. For how device classification itself works, see Atta Systems on MedTech product development.
In practice, that captures most regulated medical device software. As a practical characterization, devices requiring notified-body involvement—roughly MDR Class IIa and above and IVD Class B and above—are considered high-risk, whereas simple self-certified Class I devices generally fall outside this category. This threshold reading reflects the Commission’s classification guidance, which was still in draft at the time of writing, so it should be treated as a practical guide rather than settled law until that guidance is adopted. Two clear examples of high-risk medical device AI: a standalone algorithm that analyzes scans to flag or diagnose disease, where the software is the device itself, and AI embedded in hardware, such as software that regulates dosing in an infusion pump or controls a surgical robot as a safety component.
Because Annex I is the route to high-risk classification for medical devices, the 2 August 2028 date governs the high-risk obligations for AI-enabled medical device software, not the 2 December 2027 date that applies to standalone Annex III systems. Getting this distinction wrong is the most common planning error because much of the general AI Act coverage focuses on the December 2027 Annex III date, which does not apply to medical devices.

The obligations that did not move: transparency and AI literacy, already live
Two obligations did not move and are already in force regardless of the high-risk extension: the Article 50 transparency obligations, which apply from 2 August 2026, and the amended Article 4 AI literacy duty, which applies from 27 July 2026. For medical device software, these are the near-term obligations that the headline “deadline delayed” coverage obscures, and both are live now.
Transparency, live since 2 August 2026
The Article 50 transparency obligations apply to any AI system that interacts directly with people or generates or manipulates content, regardless of whether the system is high-risk. Because the date has passed, these are enforceable now, not in the future. What they require in a MedTech product:
- AI that interacts with patients or clinicians. A system that communicates with users, such as a conversational triage tool or an AI assistant inside a clinical application, must make it clear to people that they are interacting with an AI system, unless it is obvious from the context.
- AI that generates or manipulates content. A system that produces synthetic text, images, audio, or video must mark that output as artificially generated or manipulated, in a machine-readable form where applicable. Systems already on the market before 2 August 2026 have until 2 December 2026 for the machine-readable marking.
AI literacy, live since 27 July 2026
The amended Article 4 requires providers and deployers to take measures that support AI literacy among the staff and others who operate AI systems on their behalf. The Digital Omnibus softened the original duty (from ensuring a level of literacy to supporting its development), but it did not defer it: the amended version has been in effect since 27 July 2026. It binds not only providers but also deployers, which, in the context of medical device AI, includes the hospitals and clinics that use the software. A MedTech team should be able to show the measures it takes for its own staff and, where relevant, support its deployer customers in meeting their own duty.
The practical risk is not the 2028 date. It is a team that read “the AI Act was delayed,” stood down its compliance work, and missed the transparency and AI literacy obligations that are already live.
What MedTech teams should do with the extra year
The extra year to 2 August 2028 is preparation time, not idle time, because the high-risk obligations for medical device AI are substantial and cannot be assembled in the final quarter before a deadline. The work of classification, data governance, technical documentation, human oversight, and conformity assessment takes far longer than the documentation templates suggest.
Where the time is best spent between now and 2 August 2028:
- Confirm the classification of each AI feature. Decide, and document in writing, whether each AI component is a medical device or a safety component under the MDR or IVDR, and therefore whether it is high-risk under Annex I. A defensible written classification is the foundation everything else rests on.
- Confirm you are already compliant with the live obligations. The transparency duty (since 2 August 2026) and the amended AI literacy duty (since 27 July 2026) are now in force, not upcoming. Rather than planning to meet them, verify that current products and staff practices already satisfy them, because these obligations no longer have a runway.
- Integrate AI Act requirements into the existing QMS. The AI Act’s requirements for quality management, data governance, record-keeping, human oversight, and technical documentation overlap with, but are not identical to, an existing ISO 13485 QMS. Map the gaps and extend the QMS rather than building a parallel system.
- Plan for dual CE marking through a common assessment. High-risk medical device AI requires CE marking under both the AI Act and the MDR or IVDR. The assessment is meant to be conducted together by the same notified body, so plan the two conformity routes as one process rather than two.
- Build the technical documentation as you go. The AI Act’s documentation requirements, including training datasets, validation methods, robustness, and bias control, are more detailed than those of the MDR alone. Capturing these during development is far cheaper than reconstructing them before a 2028 submission.
One open question is worth watching as you plan two years out. The regulation empowers the Commission, through implementing acts, to disapply overlapping AI Act requirements where the MDR and IVDR already cover the same ground, and a separate, ongoing MDR revision could move medical devices out of Annex I Section A altogether. If either step is taken, some of the high-risk obligations described here could be narrowed or, in their current form, never apply to medical devices at all. Nothing is settled, and the device regime itself (MDR and IVDR) is unchanged and applies now regardless, so this is a reason to build the compliance file efficiently rather than a reason to delay it. It is worth tracking, not banking on.
Atta Systems builds medical device software under an ISO 13485-certified QMS and treats AI Act obligations as part of the device design rather than a separate compliance track, so classification, transparency, and documentation are handled during development rather than retrofitted before submission.
FAQ about the AI Act omnibus and medical device software
The high-risk obligations for AI-enabled medical device software are delayed, from 2 August 2027 to 2 August 2028, by the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force 27 July 2026). The AI Act’s transparency obligations (Article 50) and its amended AI literacy duty (Article 4) are not delayed and are already live. So the heaviest requirements are deferred, but two near-term obligations are in force now.
High-risk AI obligations apply to AI-enabled medical devices from 2 August 2028. Medical device AI is high-risk under Annex I of the AI Act (because MDR and IVDR devices require notified-body conformity assessment), and Annex I embedded high-risk obligations were moved to 2 August 2028. This is a different date from 2 December 2027 that applies to standalone Annex III high-risk systems such as education or employment tools.
Two are already live. The Article 50 transparency obligations have applied since 2 August 2026, requiring disclosure when users interact with an AI system and marking of AI-generated content. The amended Article 4 AI literacy duty has been in effect since 27 July 2026, requiring providers and deployers to take measures to support AI literacy among their staff. Both apply regardless of the high-risk extension to 2 August 2028.
The 2 December 2027 date applies to standalone high-risk AI systems listed in Annex III, such as AI used in education, employment, or credit scoring. The 2 August 2028 date applies to high-risk AI because it is embedded in a product regulated under Annex I, which includes medical devices under the MDR and IVDR. MedTech teams should plan against 2 August 2028 for their high-risk device obligations, not the more widely reported December 2027 date.
Possibly. The regulation lets the Commission disapply overlapping AI Act requirements through implementing acts where the MDR and IVDR already cover the same ground, and a separate MDR revision could move medical devices out of Annex I Section A. If either happens, some high-risk obligations could be narrowed or not apply in their current form. This is an open question rather than a settled outcome, and the MDR and IVDR device regime applies now regardless, so it is worth tracking rather than relying on.
The Digital Omnibus is final. It was adopted on 8 July 2026, published in the Official Journal as Regulation (EU) 2026/1744 on 24 July 2026, and entered into force on 27 July 2026. The dates in this article are the ones in force. Later Commission implementing guidance or harmonized standards can affect the practical details, and the duplication mechanism above could narrow some medical device obligations, so teams should track AI Office and medical device coordination guidance, but the application dates themselves are settled law.
Atta Systems builds AI-enabled medical device software under an ISO 13485-certified QMS, including the Medicai cloud imaging platform, treating AI Act classification, transparency, and technical documentation as part of the device design from the first version.
Atta Systems focuses on regulated medical device software where the AI Act and MDR obligations are designed in from the start, rather than general-purpose AI products outside a regulated device context or wellness software that falls below the medical device threshold.
Related Articles


