The EU AI Act reaches healthcare through two doors. AI inside a medical device that needs a notified body becomes high-risk on 2 August 2028. A short list of uses, such as emergency triage and health insurance pricing, becomes high-risk on 2 December 2027. Everything else in a hospital, insurer or pharma company carries lighter duties, some of which already apply.1,2

Summary

  1. Most healthcare AI is not high-risk. Letter drafting, scheduling and research tools need AI literacy and, for chatbots, transparency. The heavy duties hit devices and a few Annex III uses.
  2. Four in five certified radiology AI products will be high-risk. Of 306 CE-marked products in the Health AI Register, 250 need a notified body. From 2 August 2028 they carry AI Act duties on top of the MDR.
  3. Hospitals use AI faster than they prepare for it. In a Commission study, 57 percent of hospital representatives were piloting AI. Only 26 percent felt ready for the AI Act.

What does the EU AI Act mean for healthcare?

The Act assigns duties by role. A company that builds an AI system and sells it under its own name is a provider. A hospital, insurer or laboratory that uses it is a deployer. Most healthcare organisations are deployers. Device makers and health tech vendors are providers.1

Three sets of duties already bind healthcare deployers:

  • AI literacy (Article 4). Measures to support the AI literacy of staff who use AI. The Digital Omnibus softened the wording in July 2026 but kept the duty.
  • Prohibited practices (Article 5). Emotion recognition at work is banned, except for medical or safety reasons. Monitoring the mood of nursing staff falls under the ban; monitoring a patient's pain does not.
  • Transparency (Article 50). Since 2 August 2026, a chatbot must tell patients they are talking to AI, unless it is obvious.

Fines reach €35 million or 7 percent of worldwide turnover for prohibited practices, and €15 million or 3 percent for most other breaches.1 The full AI Act timeline after the Omnibus lists every date.

Which healthcare AI systems are high-risk?

Intended purpose decides, not the technology. The same language model is minimal risk when it drafts a discharge letter and high-risk when it sets health insurance premiums. The table maps common healthcare uses to the Act.

Healthcare AI uses under the EU AI Act, as amended

Use case AI Act status Duties from Also check
Emotion recognition of staff Prohibited, unless medical or safety 2 Feb 2025 GDPR
Discharge letter drafts Not high-risk; AI literacy 2 Feb 2025 GDPR Art. 9; MDR if claims
Patient-facing chatbot Transparency, Art. 50 2 Aug 2026 GDPR; MDR if it advises
Class I software device Not high-risk under Art. 6(1) 2 Feb 2025 MDR, self-certified
In-house device, MDR Art. 5(5) Not high-risk under Art. 6(1) 2 Feb 2025 MDR Art. 5(5)
Eligibility for public care High-risk, Annex III 5(a) 2 Dec 2027 GDPR; FRIA, Art. 27
Health insurance pricing High-risk, Annex III 5(c) 2 Dec 2027 GDPR; FRIA, Art. 27
Emergency patient triage High-risk, Annex III 5(d) 2 Dec 2027 GDPR; MDR if a device
Imaging AI, Class IIa to III High-risk, Art. 6(1) 2 Aug 2028 MDR, notified body

Duties apply now Duties start 2027 or 2028

Sources: Regulation (EU) 2024/1689, Articles 4, 5, 6, 27, 50 and Annex III; Regulation (EU) 2026/1744; MDCG 2025-6, Table 1; accessed 29 September 2026. FRIA: fundamental rights impact assessment. Not-high-risk rows: AI literacy and bans apply from 2 February 2025. General information, not legal advice.

Annex III point 5 names three healthcare uses: public bodies deciding who gets healthcare services, risk assessment and pricing in life and health insurance, and emergency patient triage.1 Health insurers and public bodies must also run a fundamental rights impact assessment before use, under Article 27. Hospitals that provide a public service must do the same for Annex III systems such as triage.

Are AI medical devices high-risk under the AI Act?

Only when the device needs a notified body. The Medical Device Coordination Group and the AI Board confirmed this in June 2025. MDR Class IIa, IIb and III qualify, as do sterile or measuring Class I devices. Self-certified Class I software does not. Neither do devices a hospital makes and uses in-house under MDR Article 5(5).3

Radiology shows what that means in practice. The Health AI Register tracks CE-marked AI products for imaging. Exhibit 1 sorts them by risk class.4

Most radiology AI will be high-risk AI

250 of 306 CE-marked radiology AI products need a notified body.

Four in five CE-marked radiology AI products need a notified body, so they become high-risk AI in August 2028.

CE-marked radiology AI products by MDR or MDD risk class, number of products

Class I: usually self-certified Notified body required: high-risk AI
0 50 100 150 200 Class IIa 192 Class IIb 58 Class I¹ 53

¹ Class I devices that are sterile or have a measuring function also need a notified body. Three products with unknown class are not shown. 199 products hold MDR certificates, 107 older MDD certificates.

Source: Health AI Register, radiology products, accessed 29 September 2026; classification rule from MDCG 2025-6, Table 1

For these products the AI Act adds duties on top of the MDR: data governance, logging, human oversight, accuracy and a quality system that covers AI. The notified body checks both in one conformity assessment. In December 2025 the Commission proposed moving medical devices to Section B of Annex I, which would spare them most AI Act duties. The Omnibus left them in Section A. Instead, the Commission may later limit the overlap through implementing acts where the MDR or IVDR protect equally.7

Two clocks now run side by side. 107 of the 306 products still hold certificates under the old Medical Device Directive. For Class IIa and non-implantable Class IIb devices those certificates run until 31 December 2028 at the latest.6 AI Act duties start five months earlier. A separate Commission proposal of December 2025 to revise the MDR and IVDR could change the picture again.8 Hospitals buying imaging AI should ask each vendor for its notified body, its MDR status and its AI Act plan.

Are hospitals ready for the AI Act?

Not by their own account. The European Commission's health directorate commissioned a study on AI deployment, published in July 2025. Its survey asked hospital representatives what they use and how prepared they feel.5 The samples are small, so the figures show direction, not precision.

Use runs ahead of readiness

Over half of hospital respondents pilot or run AI. One in four feels ready for the Act.

Over half of surveyed hospitals already use AI, but only one in four feels ready for the AI Act.

Share of respondents to the Commission's stakeholder survey, 2024, %

Hospital representatives AI developers³
0 20 40 60 80 100 57% 54% 31% 26% 47% Piloting AI¹ Bought and deployed AI¹ Built and deployed AI¹ Ready for the AI Act²

¹ 35 hospital representatives; one respondent can give several answers. ² Share that feels prepared for the obligations of the AI Act; 6 of 25 hospital representatives. ³ 16 of 34 AI developers. Survey launched 10 June 2024; respondents from EU and non-EU countries.

Source: European Commission, DG SANTE, Study on the deployment of AI in healthcare: final report, PwC EU Services and Open Evidence, July 2025

Hospital respondents named cost, hiring skilled staff, and investment in infrastructure and training as the obstacles. AI developers felt readier, at 47 percent, especially those already used to MDR compliance.5 Clinical use is real: a 2024 European Society of Radiology survey cited in the study found 48 percent of 572 respondents using AI in practice.

Deployer duties start on 2 December 2027 for Annex III systems and 2 August 2028 for devices. A deployer must follow the provider's instructions and assign trained human oversight. It must keep the logs it controls for at least six months and report serious incidents. It must tell staff before use, and tell people when an Annex III system helps decide about them.1 These are operational tasks: people, logging infrastructure and procedures. They take longer to set up than a policy.

How do GDPR and the AI Act work together for health data?

GDPR bites first. Health data is a special category under Article 9. Large-scale processing needs a data protection impact assessment before it starts.9 The AI Act does not replace either duty. The European Data Protection Board said in December 2024 that a model trained on personal data is not automatically anonymous.10

The Omnibus added one narrow basis: providers and deployers may process special category data to detect and correct bias, where strictly necessary and with safeguards.2 From March 2029 the European Health Data Space adds a permit route for training and testing algorithms on health data in secure processing environments.11

Where the model runs matters for GDPR, not for the AI Act. A model on the hospital's own servers keeps the full record inside the organisation and outside the reach of foreign data-access laws. The healthcare and life sciences sector page covers NIS2 and national security standards. The self-hosted LLM guide covers running models in-house.

What does the AI Act mean for pharma and medtech R&D?

AI built and used only for scientific research and development falls outside the Act, under Article 2(6).1 Target discovery and trial design models escape AI Act duties while they stay in research. Medicines law fills the gap. The European Medicines Agency's reflection paper of September 2024 sets expectations for AI across the medicine lifecycle, from discovery to post-authorisation.12

Manufacturing is less settled. The draft GMP Annex 22, consulted on in 2025, would keep probabilistic models such as large language models out of critical GMP applications.13 Medtech firms face the MDR and AI Act overlap as providers. For them the AI Act's quality and data governance duties are the main new work.

What should healthcare organisations do before December 2027?

The delay buys time for the high-risk rules. It does not cover what applies today. Lindstead advises this order:

  1. Register every AI system in use, including informal use of chatbots by staff.
  2. Classify each: prohibited, Annex III, medical device class, Article 50, or minimal risk.
  3. Meet today's duties: AI literacy training and chatbot notices for patients.
  4. For devices and Annex III systems, request provider documentation and plan oversight and logging now.
  5. Put AI Act information duties into vendor contracts before the next renewal.

Lindstead maps AI Act, GDPR, MDR and NIS2 duties to each AI system an organisation runs. It tests open-weight models on clinical language and deploys a first non-device use case on infrastructure the organisation controls. The 2026 European briefing weighs regulation, cost and control.

Frequently asked questions

  • Yes. A hospital that uses an AI system under its own authority is a deployer. AI literacy duties and the bans apply since 2 February 2025, and transparency duties since 2 August 2026. Deployer duties for high-risk systems start on 2 December 2027 for uses such as emergency triage, and on 2 August 2028 for AI medical devices.

  • Only if the device needs a notified body under the MDR or IVDR. That covers MDR Class IIa, IIb and III, and sterile or measuring Class I devices. Self-certified Class I software and in-house devices under MDR Article 5(5) are not high-risk under Article 6(1). The high-risk duties apply from 2 August 2028.

  • In stages. Bans and AI literacy since 2 February 2025; transparency for chatbots and generated content since 2 August 2026. High-risk duties for Annex III uses, such as triage and health insurance pricing, from 2 December 2027. High-risk duties for AI medical devices from 2 August 2028, after the Digital Omnibus delay.

  • Usually not. Tools that draft or summarise records for a clinician who reviews and signs them are not listed in Annex III. They become a medical device, and possibly high-risk, if the maker claims a medical purpose such as suggesting a diagnosis. GDPR Article 9 applies either way.

  • The AI Act adds no legal basis of its own, except a narrow one for bias detection. GDPR Article 9 still governs, and large-scale processing needs an impact assessment. From March 2029 the European Health Data Space adds a permit route for training and testing algorithms in secure processing environments.

Sources

  1. Regulation (EU) 2024/1689 (Artificial Intelligence Act), Official Journal, 12 July 2024. Articles 2, 4, 5, 6, 26, 27, 50, 99 and Annex III. eur-lex.europa.eu/eli/reg/2024/1689/oj
  2. Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal, 24 July 2026; in force 27 July 2026. eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202601744
  3. MDCG 2025-6 / AIB 2025-1, Interplay between the MDR and IVDR and the Artificial Intelligence Act, June 2025, Table 1. health.ec.europa.eu/document/download/b78a17d7-e3cd-4943-851d-e02a2f22bbb4_en?filename=mdcg_2025-6_en.pdf
  4. Health AI Register, CE-marked radiology AI products by risk class and certification pathway, accessed 29 September 2026. healthairegister.com/radiology/products
  5. European Commission, DG SANTE, Study on the deployment of AI in healthcare: final report, PwC EU Services and Open Evidence, released 15 July 2025, doi 10.2875/2169577. op.europa.eu/en/publication-detail/-/publication/9ddf7bf8-62bf-11f0-bf4e-01aa75ed71a1/language-en
  6. Regulation (EU) 2023/607 amending the MDR transitional provisions, 15 March 2023. eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32023R0607
  7. Die Produktkanzlei, Digital Omnibus: medical devices to remain under dual AI regulation, 21 May 2026. www.produktkanzlei.com/en/2026/05/21/digital-omnibus-medical-devices-to-remain-under-dual-ai-regulation/
  8. European Commission, Proposal to amend the MDR and IVDR, COM(2025) 1023, 16 December 2025. health.ec.europa.eu/document/download/25e7ea7c-cab3-40cf-86d9-d11f5e7744d8_en?filename=md_com_2025-1023_act_en.pdf
  9. GDPR, Article 9 (special categories) and Article 35 (data protection impact assessment). gdpr-info.eu/art-9-gdpr/
  10. European Data Protection Board, Opinion 28/2024 on AI models and GDPR principles, 18 December 2024. www.edpb.europa.eu/news/news/2024/edpb-opinion-ai-models-gdpr-principles-support-responsible-ai_en
  11. European Commission, European Health Data Space Regulation (EU) 2025/327, accessed 29 September 2026. health.ec.europa.eu/ehealth-digital-health-and-care/european-health-data-space-regulation-ehds_en
  12. European Medicines Agency, Reflection paper on the use of AI in the medicinal product lifecycle, adopted September 2024. www.ema.europa.eu/en/use-artificial-intelligence-ai-medicinal-product-lifecycle-scientific-guideline
  13. European Commission, Stakeholder consultation on EudraLex Volume 4: Chapter 4, Annex 11 and new Annex 22, 2025. health.ec.europa.eu/consultations/stakeholders-consultation-eudralex-volume-4-good-manufacturing-practice-guidelines-chapter-4-annex_en

Method: legal text from EUR-Lex and MDCG guidance; product counts read from the Health AI Register on 29 September 2026; survey figures from the Commission study. All sources accessed 29 September 2026. General information, not legal advice. Corrections: contact@lindstead.com.