The European Union’s AI Act crossed a major enforcement threshold on August 2, 2026, when most obligations for high-risk AI systems entered into application. For health technology companies, the deadline lands directly on AI-powered medical software, which the regulation classifies as high risk under Annex III.
Providers of high-risk systems must now meet requirements covering risk management, data governance, technical documentation, conformity assessment, quality management, post-market monitoring and registration in the EU AI database. Deployers, including hospitals and clinics, must put human oversight in place, retain automated logs for at least six months and conduct fundamental rights impact assessments where required. Penalties for violations can reach €15M or 3 percent of global annual turnover.
Medical device makers get a partial reprieve. AI systems embedded in CE-marked devices under the Medical Device Regulation and In Vitro Diagnostic Regulation, where a notified body is involved, have until August 2027 to comply with the high-risk classification pathway. In practice, that means manufacturers of Class IIb and III devices, and Class C and D IVDs, run on a longer clock than standalone software.
For new AI-enabled software as a medical device entering the EU market, however, the rules are already binding. Notified bodies will fold AI Act checks into MDR and IVDR reviews, and technical documentation must now include AI-specific content covering training data, model validation and human oversight.
The effective date survived a November 2025 European Commission proposal to push some deadlines to late 2027, which was never enacted. Regulators and industry groups alike describe August 2026 as the operative line, and health AI developers selling into Europe are now accountable to both device law and the world’s first comprehensive AI regulation.
