AI Act: August 2, 2026 was supposed to change everything — here is what actually applies

The AI Regulation was due to reach full application on August 2, 2026. But the Omnibus package voted by the European Parliament on June 16 reshuffled the deck for high-risk systems. An analysis for healthcare players.
August 2, 2026 had been marked in every compliance calendar for two years: the date of general application of Regulation (EU) 2024/1689 on artificial intelligence, including the obligations for high-risk systems under Annex III. But a few weeks before the deadline, the landscape changed: on June 16, 2026, the European Parliament approved the part of the “Digital Omnibus” package that postpones these obligations to December 2, 2027 — a postponement that is now final: Regulation (EU) 2026/1744, which enacts it, was published in the Official Journal on July 24, 2026 and entered into force on July 27. Many organizations are navigating today on outdated information — in one direction or the other.
What remains in force, postponement or not
The postponement does not call into question what has already applied since 2025: the ban on prohibited practices (manipulation, social scoring, certain biometric identification) since February 2025, the AI literacy obligations for professional users, and the regime for general-purpose AI models (GPAI) since August 2025.
In other words: a healthcare organization or software vendor deploying AI must already, today, train its teams, map its uses and check that no prohibited practice has crept into its tools.
Healthcare: two timelines not to be confused
For healthcare, the key distinction is between the two families of high-risk systems. On one side, systems falling under Annex III (for example emergency call triage, or evaluation in access to essential services, including health insurance): these are the ones covered by the postponement to December 2, 2027.
On the other, AI embedded in medical devices covered by the MDR or the IVDR (Annex I): their own deadline — initially set for August 2027, now pushed back to August 2, 2028 by the same package — follows its own logic, articulated with CE marking. A vendor of medical-device software must therefore absolutely not read the “Annex III” postponement as a general reprieve.
Why you should not ease off
First, the postponement only touches the “high-risk” timeline: everything that already applies continues to apply. Second, the GDPR applies in full to algorithmic processing of health data: legal basis, DPIA, transparency, oversight of processors — the CNIL does not need the AI Act to inspect an AI project in healthcare.
Third, hospital purchasers are already writing AI Act requirements into their tenders: anticipated compliance is a commercial advantage, not a deferred constraint.
The 5 actions to take right now
1. Map all AI uses (including generative AI used by your teams). 2. Qualify each system: prohibited practice, high risk under Annex I or III, simple transparency. 3. Document governance: human oversight, risk management, logging. 4. Bring supplier contracts up to standard (responsibilities, AI Act and GDPR warranties). 5. Train your teams — the literacy obligation has applied since February 2025 (softened into an obligation of means by Regulation 2026/1744, it remains binding nonetheless).
Our AI support covers precisely this journey, from diagnostic to defensible documentation.
What does apply as of August 2, 2026
The postponement does not strip August 2, 2026 of its substance. Applying from that date are, in particular: the transparency obligations of Article 50 — clearly informing users that they are talking to an AI (chatbots, conversational agents), marking AI-generated or AI-manipulated content —, detailed in the guidelines published by the Commission on 20 July 2026 (non-binding, but set to guide the supervisory authorities) as well as the enforcement machinery: market surveillance (Chapter IX) and the fines applicable to general-purpose AI models — governance and the general sanctions regime having already been in place since 2 August 2025. Note: the obligation for each Member State to have at least one regulatory sandbox was postponed to 2 August 2027 by Regulation (EU) 2026/1744.
For a healthcare player, the consequence is immediate: an appointment-booking or pre-triage chatbot that does not announce itself as an AI has been, since August 2, 2026, in breach — regardless of any “high-risk” postponement.
Four concrete cases to find your bearings
The reception chatbot of a facility or a teleconsultation platform: transparency obligation (Article 50), applicable today. The report-drafting assistant or ambient voice recognition: interplay between the general-purpose AI model regime (GPAI, applicable since August 2025) and the GDPR — a DPIA is almost systematic where health data is concerned. Diagnostic-support or imaging-quantification software: a medical device, hence an “Annex I” trajectory articulated with CE marking — the Annex III postponement does not concern it. A bed-planning or HR-optimization tool: depending on its function, simple transparency or Annex III — the precise qualification is what decides, and it deserves to be documented.
Official sources
- Regulation (EU) 2026/1744 “Digital Omnibus AI” — EUR-Lex
- Regulation (EU) 2024/1689 “AI Act” — EUR-Lex
- Regulation (EU) 2016/679 “GDPR” — EUR-Lex
- EDPB/EDPS Joint Opinion 2/2026 on the Digital Omnibus — EDPB
Last legal review: August 17, 2026
