COMPLIPATHDOC complipath.io/guides/eu-ai-act-healthcareRENDERED 2026-08-23ENGINE 2026-08-09.1CORPUS 2024/1689 + 2026/1744 + Commission guidelines
Guides/Industry ·By Yobel Tzegai ·Updated 22 August 2026

Is healthcare AI high-risk under the EU AI Act?

Updated 9 August 2026 for Regulation (EU) 2026/1744.

Healthcare AI is mostly high-risk under the EU AI Act — by two routes with two dates, both still ahead of you. Public-healthcare eligibility and emergency-triage AI under Annex III is high-risk from 2 December 2027. AI that is a safety component of, or itself, a medical device needing a notified body under the Annex I device regulations is high-risk under Article 6(1) from 2 August 2028.

Quick answer

When does the medical-device route catch AI — and why not yet?

Article 6(1) makes an AI system high-risk where both of its conditions hold. Point (a): the system "is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I". Point (b): that product "is required to undergo a third-party conformity assessment" under that same legislation. Section A of Annex I names both device regulations: Regulation (EU) 2017/745 on medical devices (point 11) and Regulation (EU) 2017/746 on in vitro diagnostic medical devices (point 12).

Applied: a sepsis-prediction model in a patient-monitoring platform, a radiology triage model that is itself software as a medical device, an algorithm interpreting an in vitro assay — each caught where its device needs a notified body under those regulations. Which devices do is answered by the device regulations, not the AI Act.

Article 113, third paragraph, point (c), as replaced by Regulation (EU) 2026/1744, defers the whole of Chapter III, Sections 1, 2 and 3 — the classification rules, the requirements and the operator obligations — "with the exception of Article 6(5)". It also splits the date: 2 December 2027 for systems high-risk "pursuant to Article 6(2) and Annex III", 2 August 2028 for those high-risk "pursuant to Article 6(1) and Annex I". Both are deadlines to plan for, not breaches in progress. The routes stay independent, and the Annex III one now bites eight months earlier: a device-embedded system doing emergency patient triage is caught under Article 6(2) from 2 December 2027, whatever its device route does. Every date: EU AI Act timeline.

When it arrives, the Act folds into the device framework: under Article 43(3), as replaced by Regulation (EU) 2026/1744, the provider follows "the relevant conformity assessment procedure as required in accordance with the relevant Union harmonisation legislation", with the Section 2 AI requirements "part of that assessment". The replacement added a duty the 2024 wording did not carry: "Assessment of the quality management system set out in Article 17 shall also be undertaken", together with points 3, 4.3, 4.4 and 4.5, the fifth paragraph of point 4.6 and point 5 of Annex VII. Article 8(2) lets it live inside existing device documentation; and under Article 25(3) the product manufacturer placing the system on the market under its name or trademark is the provider.

Which hospital systems does Annex III catch?

Point 5 of Annex III carries the two healthcare letters:

(a) AI systems intended to be used by public authorities or on behalf of public authorities to evaluate the eligibility of natural persons for essential public assistance benefits and services, including healthcare services, as well as to grant, reduce, revoke, or reclaim such benefits and services;

(d) AI systems intended to evaluate and classify emergency calls by natural persons or to be used to dispatch, or to establish priority in the dispatching of, emergency first response services, including by police, firefighters and medical aid, as well as of emergency healthcare patient triage systems.

Under Article 6(2), a listed system is high-risk; where it profiles natural persons, Article 6(3) makes it always high-risk. Article 111(2), as replaced by Regulation (EU) 2026/1744, now catches systems placed on the market or put into service "before the date of application of Chapter III referred to in Article 113" — a moving reference, here 2 December 2027 — and only on "significant changes in their designs" as from that date; but providers and deployers of high-risk systems intended to be used by public authorities must comply by 2 August 2030 regardless of any design change. For public hospitals, that backstop, not the design-change trigger, sets the deadline. Boundary calls: how to classify your AI system.

Is emotion recognition in care settings banned?

No — healthcare is where the exception lives. Article 5(1), first subparagraph, point (f) prohibits AI inferring emotions "in the areas of workplace and education institutions, except where the use of the AI system is intended to be put in place or into the market for medical or safety reasons". A system detecting pain or distress in dementia patients for medical reasons is not prohibited — but it remains high-risk under point 1(c) of Annex III, "AI systems intended to be used for emotion recognition", and Article 50(3) requires deployers to inform the persons exposed to it.

The trap is pointing the same capability at staff. Monitoring nurses' stress or fatigue is workplace emotion inference — prohibited since 2 February 2025 (Article 113, third paragraph, point (a)) unless genuinely for medical or safety reasons, a boundary the Regulation does not define. Wellbeing branding is not a safe harbour. The full list: prohibited AI practices.

What do patient-facing symptom checkers owe?

Disclosure, at minimum. Under Article 50(1), providers must design AI "intended to interact directly with natural persons" so those persons know they are interacting with AI, unless that is obvious. A symptom-checker chatbot on a clinic's website owes exactly that — mechanics in limited-risk transparency.

Disclosure is a floor — and the one duty here already live: Article 50 sits in Chapter IV, which took the general application date of 2 August 2026 and kept it. If the tool generates synthetic content and was on the market before that date, Article 111(4) gives it until 2 December 2026 for 50(2). Whether a checker is itself a medical device is decided by Regulation (EU) 2017/745; if it is, and needs third-party assessment, Article 6(1) arrives on 2 August 2028. Deployed as emergency triage, it is point 5(d) high-risk from 2 December 2027.

Can we process patient data to test for bias?

Yes, narrowly — but not under the article most policies still cite. Regulation (EU) 2026/1744 deleted Article 10(5) and moved the regime into a new Article 4a; a policy citing Article 10(5) now cites nothing. Article 4a(1) keeps the provider permission on the same six cumulative conditions, set out one by one in data governance under Article 10. Article 4a(2) is new, and it is the part that reaches a hospital. It extends the same pathway to deployers of high-risk AI systems, on every one of those conditions, where the processing is strictly necessary against biases likely to affect health and safety, harm fundamental rights or lead to discrimination prohibited under Union law. It also says what it does not do: it "does not create any obligation to conduct such bias detection and correction". GDPR applies on top, not instead.

What this means for you

If you're a medtech vendor (provider): classify each system by route and date. Device-embedded AI runs to 2 August 2028 through the integrated Article 43(3) assessment — MDR conformity work is the vehicle, not a separate track. Anything matching an Annex III letter — emergency triage above all — runs to the earlier 2 December 2027 for the Article 16 obligations, the conformity assessment among them. Registration is not on that date: Article 49 sits in Chapter III, Section 5, which point (c) does not defer, so Article 49(1) has applied since 2 August 2026 — point 2 of Annex III registers nationally instead (Article 49(5)), and what moves is the Article 16, point (i) duty to comply. For the point 5 letters, assessment is internal control without a notified body (Article 43(2), covering points 2 to 8 of Annex III); point 1(c) emotion recognition follows Article 43(1) instead, under which a notified body can be required where harmonised standards are not applied. Start from a documented classification per system — Complipath's guided risk classification records the category, provisions and reasoning. Provider breaches: up to €15 million or 3% of worldwide annual turnover (Article 99(4)); a prohibited practice, €35 million or 7% (Article 99(3)).

If you're a hospital or clinic buying AI (deployer): Article 26 binds you for Annex III systems from 2 December 2027, not today (Chapter III, Section 3): use per the instructions, competent human oversight, input-data relevance where you control it, monitoring and suspension on risk, logs for at least six months, and informing affected persons (Article 26(1), (2), (4), (5), (6) and (11)). Deployers that are bodies governed by public law or private entities providing public services owe a fundamental rights impact assessment before first use (Article 27(1)) — between them, the two limbs will catch most hospitals, though the Regulation defines neither term and hospitals' status varies by Member State. Retraining or repurposing a bought system can make you the provider (Article 25(1)) — see provider vs deployer.

Is your clinical tool one of them?

Classify your system now — 7 questions on the main line, plus follow-ups where they apply, no account, and the classification runs in your browser: answers stay there unless you choose to keep the result.

FAQ

When does the EU AI Act apply to AI medical devices? The Article 6(1) route — AI as a safety component of, or itself, a device under the Annex I-listed regulations needing third-party assessment — applies from 2 August 2028 (Article 113, third paragraph, point (c)(ii), as amended by Regulation (EU) 2026/1744). Annex III uses apply from 2 December 2027 under point (c)(i); prohibitions since 2 February 2025.

Is emergency patient triage AI high-risk? Yes. Point 5 (d) of Annex III lists AI evaluating and classifying emergency calls, dispatching or prioritising emergency first response services, "as well as of emergency healthcare patient triage systems". It carries no public-authority limitation, and the obligations apply from 2 December 2027 (Article 113, third paragraph, point (c)(i), as amended by Regulation (EU) 2026/1744).

Is emotion recognition with patients prohibited? No. Article 5(1), first subparagraph, point (f) bans emotion inference in workplaces and education institutions, except for medical or safety reasons — patient-facing medical use sits in that exception. It remains high-risk under point 1(c) of Annex III, and Article 50(3) requires deployers to inform exposed persons.

Does a symptom checker need CE marking under the AI Act? Only if it is high-risk. The AI Act itself requires Article 50(1) disclosure that the user is talking to AI, and that duty is live now. CE marking (Article 16, point (h)) follows from 2 December 2027 if the checker is an Annex III system, or from 2 August 2028 if it qualifies as a medical device requiring third-party assessment, which Regulation (EU) 2017/745 decides.


Sources: Regulation (EU) 2024/1689 (EUR-Lex), Articles 4a, 5, 6, 8, 10, 16, 25, 26, 27, 43, 49, 50, 99, 111, 113, Annex I, Annex III and Annex VII. Article 113, third paragraph, point (c), Article 111(2) and Article 43(3) are cited as replaced by Regulation (EU) 2026/1744 (EUR-Lex), in force 27 July 2026, which also deleted Article 10(5) and inserted Article 4a in its place (Article 1, points (6), (9)(b), (19), (39)(a) and (40)). Article 49 was not amended and sits in Chapter III, Section 5, which point (c) does not defer: it keeps the general 2 August 2026 date in Article 113, second paragraph. The dates on this page for the Article 5 prohibitions (2 February 2025), Article 50 transparency (2 August 2026) and the Article 111(2) public-authority backstop (2 August 2030) were not amended — but Article 111(4), added by the same act, gives providers of synthetic-content systems on the market before 2 August 2026 until 2 December 2026 for Article 50(2). How a registration duty operates while the Section 1 classification rules that decide its scope do not yet apply is not answered by either text. Which devices require third-party conformity assessment is governed by Regulation (EU) 2017/745 and Regulation (EU) 2017/746, cited here only as listed in Annex I — device-classification questions are outside this guide's source base. Unsettled at the time of writing: where "medical or safety reasons" ends under Article 5(1), first subparagraph, point (f) — the Regulation does not define it; what counts as "significant changes in their designs" under Article 111(2); and whether a given hospital falls among the "public authorities" of point 5(a) of Annex III or the "bodies governed by public law" of Article 27(1) — the Regulation defines neither term, and hospitals' legal status varies by Member State.

← All guides
Complipath

Complipath is EU AI Act compliance software for AI-heavy software companies without a compliance team — an AI system register, deterministic risk classification, the obligations that follow, and the evidence behind every decision.

Complipath is built by Yobel Tzegai in Gothenburg, Sweden.

Complipath provides legal information, not legal advice. Every guide cites its source on EUR-Lex — Regulation (EU) 2024/1689, and Regulation (EU) 2026/1744 where that has amended it; where the law is still settling, the guide says so.

We measure page views with Vercel Web Analytics. It uses no third-party cookies. Visitors are identified by a hash derived from the incoming request, which is discarded after 24 hours, and no identifier is stored that could follow a visitor to another site. What is collected: the time of the visit, the URL, the referring page, filtered query parameters, city-level location, operating system, browser and device type.