Resources // EU AI Act

Annex I or Annex III? Which EU AI Act deadline binds your medical AI.

The Digital Omnibus did not move one deadline. It moved two, to different dates. Annex III standalone systems apply from 2 December 2027 and Annex I embedded systems from 2 August 2028, and Article 6 decides which clock is yours.

Article 6 · classification2 Dec 2027 vs 2 Aug 2028PHI-free · non-device

Published August 24, 2026 · Dates verified against Regulation (EU) 2026/1744

Regulation (EU) 2026/1744 deferred the EU AI Act high-risk obligations to two different dates, not one. AI on the Annex III standalone route applies from 2 December 2027. AI on the Annex I embedded route, which is where medical devices sit, applies from 2 August 2028. Article 6 decides which route you travel, and the deciding condition is not whether your software is medical. It is whether the product it rides inside needs a notified body.

Most coverage of the Digital Omnibus reported a single new deadline. There are two, eight months apart, and a hospital or a manufacturer can be holding both at the same time for different systems. This guide walks the Article 6 test, quotes the two Annex entries that decide it, and covers the condition that determines whether the later date is actually yours.

What Article 6 actually asks

Regulation (EU) 2024/1689 creates two independent ways for an AI system to be high-risk, and Article 6 sets them out separately.

Article 6(1) is the Annex I route. It applies when the AI system "is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I," and that product "is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service."[1] Both conditions are cumulative. One without the other does not put you on this route.

Article 6(2) is the Annex III route. It states simply that "AI systems referred to in Annex III shall be considered to be high-risk."[1] There is no product legislation involved and no conformity assessment condition. If your system does something on the Annex III list, it is high-risk by that fact.

The two routes were always distinct. What changed in July 2026 is that they stopped sharing a date.

Where medical devices sit

Annex I Section A lists the Union harmonisation legislation that triggers the first route. Two entries matter in medicine. Item 11 is "Regulation (EU) 2017/745 of the European Parliament and of the Council of 5 April 2017 on medical devices." Item 12 is "Regulation (EU) 2017/746 of the European Parliament and of the Council of 5 April 2017 on in vitro diagnostic medical devices."[2]

So an AI system that is a medical device, or a safety component of one, satisfies the first condition of Article 6(1). That is the part everyone gets right. The second condition is where the reading usually stops too early.

The condition most summaries skip

Article 6(1) also requires that the product be one that "is required to undergo a third-party conformity assessment." In medical device terms, that means a notified body has to be involved before the product goes to market.

For most AI-enabled devices it is. Software that drives or influences a diagnosis or a therapy generally classifies above the lowest tier under the MDR rules, and above that tier a notified body is required. Those devices travel the Annex I route and their high-risk obligations apply from 2 August 2028.

But a device that the manufacturer self-certifies, with no notified body in the process, does not meet the second condition. It does not become high-risk by the Annex I route at all, because Article 6(1) needs both limbs and only one is present. The flat statement that "medical devices got until 2028" is therefore not reliable as a planning assumption. It is reliable for devices that need a notified body, which is most but not all of them.

Two consequences follow. A self-certified device is not automatically on the 2028 clock, so inheriting that date without checking is a mistake in one direction. And it is not automatically outside the AI Act either, so treating it as exempt is a mistake in the other. It may still be caught by Annex III on its own facts, and the Article 50 transparency duties applied from 2 August 2026 regardless of route, a date that is already behind us.

The Annex III entries that catch healthcare

Annex III has eight categories. Two of them reach into care delivery without the system ever being a medical device.

Point 5(a) covers "AI systems intended to be used by public authorities or on behalf of public authorities to evaluate the eligibility of natural persons for essential public assistance benefits and services, including healthcare services, as well as to grant, reduce, revoke, or reclaim such benefits and services."[3] The phrase "on behalf of" matters, because it pulls in contractors and vendors operating for a public payer, not only the authority itself.

Point 5(d) covers "AI systems intended to evaluate and classify emergency calls by natural persons or to be used to dispatch, or to establish priority in the dispatching of, emergency first response services, including police, firefighters and medical aid, as well as of emergency healthcare patient triage systems."[3] That last clause names emergency healthcare patient triage explicitly.

Neither of those is a medical device in the ordinary case. Both are high-risk. Both apply from 2 December 2027, which is the earlier of the two dates.

Find your route

Three questions decide it. This mirrors the structure of the Article 6 test and is intended to orient you before a conversation with counsel, not to replace one.

Which EU AI Act route does your system travel? 0 of 3 answered
Question 1 Product legislation

Is the AI system a safety component of, or itself, a product regulated under the Medical Device Regulation (EU) 2017/745 or the IVDR (EU) 2017/746?

Question 2 Third-party conformity assessment

Does that product require a notified body to assess it before it is placed on the market or put into service?

Question 3 The Annex III list

Does the system evaluate eligibility for public healthcare benefits or services on behalf of a public authority, or evaluate, triage or prioritize emergency care?

Answer the three questions above.

Each answer maps to one limb of the Article 6 test. Your route and its date appear here once all three are set.

Educational guidance that mirrors the structure of the Article 6 classification test. It is not legal or regulatory advice, and classification is a determination for your regulatory counsel. For the separate question of whether your software is a medical device under FDA rules, use our FDA clinical decision support tool.

One hospital, two dates

Consider a mid-sized hospital that adopted three AI systems in the same procurement cycle. An AI-assisted imaging tool that is a Class IIa device assessed by a notified body. An emergency department triage system that ranks incoming patients by acuity. An ambient scribe that drafts notes for clinician review.

The imaging tool travels Annex I and applies from 2 August 2028. The triage system sits in Annex III point 5(d) and applies from 2 December 2027. The scribe is likely on neither route, though the Article 50 transparency duties and any general-purpose AI obligations still reach it on their own schedule.

The system with the earliest deadline is the one least likely to have a regulatory owner. The imaging device already sits inside a quality system, with a regulatory affairs function that tracks its notified body. The triage system was bought as software. It has an IT owner and a clinical champion, and frequently no one whose job description includes the AI Act. That asymmetry, not the eight months, is what makes the earlier date the harder one.

Why the earlier date is the one that catches people

The Digital Omnibus was reported almost everywhere as a delay to 2028. For anyone who read the headline and moved on, the 2 December 2027 date does not exist. It is the date attached to systems that were never framed as regulated products, held by teams who were not watching for it, and it arrives eight months first.

There is a second reason the earlier date deserves attention. The stated reason for the deferral, in Recital 40 of Regulation (EU) 2026/1744, is that "the delayed availability of standards, common specifications, and alternative guidance and the delayed establishment of national competent authorities lead to challenges that jeopardise the effective entry into application of those obligations."[4] The obligations were not judged unnecessary. The apparatus for assessing them was not ready. That is a schedule change, not a change of direction, and it says nothing about the substance being softened later.

What to do before either date

Determine the route first, with counsel, because it sets your clock and because the two limbs of Article 6(1) are easy to conflate. Write the determination down with the reasoning, since the question you will be asked later is not only what you concluded but on what basis.

Then start the one Chapter III obligation that cannot be produced retroactively. Article 12 requires that a high-risk system technically allow the automatic recording of events over the lifetime of the system. Technical documentation can be assembled before an assessment. A risk management file can be written up. A lifetime log cannot: a record of what your system did in 2027 cannot be authored in 2028. We covered that asymmetry in Article 12 logging and the 2028 deadline, and it applies identically on the 2027 clock, with eight months less warning.

If your route is Annex III, that is the practical takeaway. The deadline you were not tracking is the earlier one, and the duty inside it is the one that has to be running before the date rather than satisfied at it.

What we are careful never to claim

RankShieldMD does not determine your classification, and nothing on this page is legal advice. Article 6 is a legal test and the answer belongs to your regulatory counsel. We are not a medical device, we do not render or score clinical decisions, and we never see PHI.

What we do is narrower and checkable. Once you know which obligations apply, we produce tamper-evident, externally anchored, PHI-free evidence that supports them, chiefly the record-keeping duty in Article 12. Evidence supports an obligation. It is not compliance, not a conformity assessment, and not a substitute for a notified body.

References

  1. [1] EU Artificial Intelligence Act. Article 6: Classification Rules for High-Risk AI Systems. artificialintelligenceact.eu/article/6
  2. [2] EU Artificial Intelligence Act. Annex I: List of Union Harmonisation Legislation (Section A, items 11 and 12). artificialintelligenceact.eu/annex/1
  3. [3] EU Artificial Intelligence Act. Annex III: High-Risk AI Systems Referred to in Article 6(2) (points 5(a) and 5(d)). artificialintelligenceact.eu/annex/3
  4. [4] Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 (Digital Omnibus on AI), OJ 24 July 2026. eur-lex.europa.eu/eli/reg/2026/1744
  5. [5] Gibson Dunn. EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes. gibsondunn.com
Answer engine

Ask the founder.

Straight answers about verifiable healthcare AI. Tap a question, or type your own.

Jamie Kloncz, founder of RankShieldMD
Jamie Kloncz, founderverified human
Ask me anything about proving your clinical AI. I built RankShieldMD so a small practice can prove its AI, not just be asked to trust it.
What is the difference between the Annex I and Annex III routes?
They are the two ways an AI system becomes high-risk under Regulation (EU) 2024/1689, and they now carry different dates. Article 6(1) is the Annex I route: the AI is a safety component of, or is itself, a product covered by the Union harmonisation legislation listed in Annex I, and that product must undergo a third-party conformity assessment. Both conditions have to be met. Article 6(2) is the Annex III route: systems in the Annex III list are high-risk in their own right, regardless of any product legislation. After Regulation (EU) 2026/1744, Annex III systems apply from 2 December 2027 and Annex I systems from 2 August 2028.
Which route do medical devices travel?
The Annex I route, in most but not all cases. Annex I Section A lists Regulation (EU) 2017/745 on medical devices at item 11 and Regulation (EU) 2017/746 on in vitro diagnostic medical devices at item 12. So an AI system that is a medical device, or a safety component of one, meets the first condition of Article 6(1). It only becomes high-risk by that route if it also meets the second condition, which is that the product requires a third-party conformity assessment. That is the condition most summaries leave out.
What happens to a self-certified Class I device?
It does not become high-risk through the Annex I route, because Article 6(1) requires both conditions and the second one is not met. A Class I device that the manufacturer self-certifies without a notified body does not undergo a third-party conformity assessment. This does not mean the AI Act ignores it. It may still be caught by Annex III if it does something on that list, and the Article 50 transparency duties and any general-purpose AI obligations apply on their own schedule. It means the 2 August 2028 date is not automatically yours.
Can one organization hold both dates at once?
Yes, and this is the practical trap. A hospital can run an AI-enabled imaging device that travels the Annex I route and applies from 2 August 2028, and at the same time run an emergency patient triage system that sits in Annex III point 5(d) and applies from 2 December 2027. Those are eight months apart. The earlier date belongs to the system that is less likely to have a regulatory owner inside the building, because it is not a device and no one is already managing it as one.
Which healthcare systems are named in Annex III?
Two entries matter most in a care setting. Point 5(a) covers AI used by public authorities, or on their behalf, to evaluate eligibility for essential public assistance benefits and services, including healthcare services, and to grant, reduce, revoke or reclaim them. Point 5(d) covers AI that evaluates and classifies emergency calls, or that dispatches or sets priority in dispatching emergency first response services, and it names emergency healthcare patient triage systems explicitly. Both fall on the 2 December 2027 date.
What should we do before either date?
Determine your route first, because it sets your clock, and treat that determination as a regulatory decision to make with counsel rather than a reading of a blog post. Then start the one obligation that cannot be produced retroactively. Article 12 asks that a high-risk system technically allow the automatic recording of events over its lifetime. A record of what your system did in 2027 cannot be authored in 2028, whichever date binds you.
Does RankShieldMD determine our classification?
No. Classification under Article 6 is a legal determination for your regulatory counsel, and nothing here is legal advice. RankShieldMD is not a medical device and does not render clinical decisions. What we do is produce tamper-evident, PHI-free evidence that supports specific obligations once you know which ones apply, chiefly the record-keeping duty in Article 12. Evidence supports an obligation. It is not compliance and it is not a conformity assessment.