Blog

EU delays high-risk medical device AI rules

Developers of AI-enabled medical devices in Europe have been given an additional two years to meet high-risk requirements under the EU AI Act, following the entry into force of the European Union’s AI Omnibus.

The changes delay the application of high-risk AI requirements for systems embedded in regulated physical products, including medical devices, to 2 August 2028.

The European Commission said the extension was needed to allow more time for the development of standards and other tools required to support implementation of the AI Act.

The rules had previously been due to apply from August 2026.

Under the AI Act, an AI system can be classified as high-risk where it is a safety component of a product covered by specified EU product safety legislation, or is itself such a product, and is required to undergo a third-party conformity assessment.

This includes certain AI systems covered by the EU’s medical device and in vitro diagnostic medical device regulatory frameworks.

The Commission has acknowledged the need to avoid unnecessary duplication between the AI Act and existing sector-specific product regulation, with further guidance expected on the interaction between high-risk AI requirements and sectoral legislation.

The Commission said the AI Omnibus was consistent with its separate proposed revision of the Medical Devices Regulations and would not affect that proposal.

The changes form part of the broader Digital Omnibus package proposed by the Commission in November 2025 to simplify implementation of the EU’s digital regulatory framework.

The AI Omnibus also extends the implementation timeline for other high-risk AI systems, with requirements for stand-alone systems now applying from 2 December 2027.

The Commission said delays in the development of harmonised technical standards had put the previous August 2026 implementation timetable at risk.

European standards organisations CEN and CENELEC were originally mandated to develop standards supporting the high-risk requirements, but the work was not completed within the expected timeframe.

The standards are intended to provide developers with a clearer pathway for demonstrating compliance with requirements covering areas including risk management, data governance, technical documentation, record keeping, human oversight, accuracy, robustness and cybersecurity.

The AI Omnibus also introduces a range of measures aimed at reducing the administrative burden associated with the AI Act, including simplified obligations for smaller companies and changes to registration and post-market monitoring requirements.

The Omnibus entered into force in July following political agreement between the European Parliament and Council in May, while the AI Act itself entered into force in August 2024, with its requirements being progressively introduced.

While the high-risk requirements have been delayed, other elements of the legislation have continued to take effect, including governance and general-purpose AI requirements.

The Commission said the revised timetable would allow the high-risk requirements to be introduced with clearer standards and implementation support in place.

About the author

Asonblog

Add Comment

Click here to post a comment