August 27, 2026 · 10 min read · Sugam Budhraja

The EU AI Act for Health Apps: The August 2026 Deadline Moved, but One Obligation Started Anyway

The Digital Omnibus deferred high-risk obligations to December 2027 and August 2028, but Article 50 transparency and the Commission's fining powers began on 2 August 2026. What applies to a health app now, and what puts you in scope later.

Not legal advice. This is a developer-facing summary of dated primary sources, written to help you work out which questions to take to counsel. Regulatory scope decisions, and especially the Article 6(3) assessment described below, need a lawyer who knows your product.

If you have read anywhere in the past few months that the EU AI Act’s high-risk obligations applied in full from August 2026, that guidance is out of date. The deadline moved before it arrived.

What did not move is a smaller obligation that probably applies to your product today, and which most teams missed precisely because they were watching the deadline that changed.


What actually changed

Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It deferred the two high-risk tracks.

ObligationOriginal dateNow
Annex III standalone high-risk systems2 August 20262 December 2027
Annex I AI embedded in regulated products, including medical devices2 August 20272 August 2028
Article 50(2) synthetic content marking2 August 20262 December 2026
Article 50 general transparency2 August 2026Unchanged, in force
Commission enforcement powers, including fines2 August 2026Unchanged, in force

That first row is the one that matters for most people reading compliance content right now: if you scoped a project against an August 2026 high-risk deadline, you have roughly sixteen additional months.

The second row is the one most often gotten wrong even in careful coverage. Software as a medical device generally routes through Annex I, not Annex III, because it is AI embedded in a product already covered by sectoral legislation. So a regulated digital therapeutic is on the 2028 track, not the December 2027 one.

Deferred is not cancelled. The obligations themselves were not weakened, only the dates. Anything you were building toward for August 2026 is still required, and Annex III systems already on the market when the date arrives do not get an exemption. The correct response to sixteen extra months is a calmer plan, not a shelved one.

What started on 2 August 2026

Two things, and one of them is cheap to comply with and easy to have missed.

Article 50 transparency. Providers must ensure that people are informed they are interacting with an AI system, unless that is obvious to a reasonably well-informed, observant and circumspect person. The information has to arrive in a clear and distinguishable manner at the latest at the time of the first interaction, and it has to meet accessibility requirements.

In a health product, that means the AI coach, the chatbot, the conversational “ask me about your sleep” surface. If a user could plausibly believe they are messaging a human coach, you owe them a disclosure. If your interface is obviously a machine, the exemption may cover you, but “obviously” is doing real work in that sentence and it is assessed from the user’s perspective rather than yours.

Deployers of emotion recognition or biometric categorisation systems have their own notification duty under the same article, which is worth checking if you do anything with inferred emotional state.

The Commission’s enforcement powers. From the same date, the Commission can request documentation and information, conduct model evaluations, require measures and impose fines. The machinery is live even though the high-risk obligations it will eventually enforce are not.

The practical read: the thing to do this quarter is not a conformity assessment. It is to check whether every AI-facing surface in your product discloses itself, and to fix the ones that do not.


Are you even high-risk?

This is where most health teams over-estimate their exposure, because “we handle sensitive health data” feels like it should mean high-risk. Under the Act it does not. High-risk is a closed list, not a sensitivity judgement.

There are two routes in.

Annex I covers AI embedded in products already regulated by EU sectoral legislation. If your software is a medical device under the MDR, this is your route, and your date is 2 August 2028.

Annex III enumerates standalone use cases: biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration, and administration of justice. A consumer app that tells someone how they slept and suggests they walk more is generally not on that list.

So a B2C sleep tracker, a fitness app, a habit product, a wellness companion: absent a medical device classification, most of these sit outside the high-risk regime entirely, and their live obligation is the Article 50 disclosure above.


The line that moves a health score into scope

Here is the part worth internalising, because it is not about your technology at all.

Annex III point 5 covers access to essential private services, and it explicitly names AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance. Health data and behavioural signals used in insurance models fall inside that description.

Which produces this result: the same sleep score, computed the same way from the same sensors, is outside the Act in a consumer app and inside Annex III when it informs underwriting or premium pricing.

Scope follows the use case, not the algorithm. So the question that determines your exposure is not what does our model do, it is who is our customer and what decision does our output feed. Three products built on identical infrastructure can land in three different places:

Same health score, different deploymentLikely position
Consumer app showing a user their own sleep trendOutside Annex III
Employer wellness programme feeding engagement nudgesOutside Annex III, but check employment use cases if it touches evaluation
Insurer using it for risk assessment or pricingAnnex III point 5

If you sell into insurance or employer wellness channels, that distinction belongs in your contracts and your documentation now, not in December 2027. It also cuts the other way and is worth saying plainly: a vendor telling an insurance buyer that health scoring is categorically outside the AI Act is giving them bad information.


The escape hatch, and why profiling closes it

Appearing in Annex III is not automatically the end of the analysis. Article 6(3) lets a provider argue its system is not high-risk where it does not pose a significant risk of harm to health, safety or fundamental rights, and where it meets one of four conditions:

  1. It performs a narrow procedural task.
  2. It improves the result of a previously completed human activity.
  3. It detects decision-making patterns or deviations, without replacing or influencing a human assessment absent proper human review.
  4. It performs a preparatory task to a relevant assessment.

Then comes the sentence that matters most for anyone building health scoring:

A system that performs profiling of natural persons is always considered high-risk. No derogation.

The Act builds on the GDPR’s meaning of profiling, which covers automated processing used to evaluate personal aspects of a person, in particular to analyse or predict aspects concerning their health, behaviour, location or movements. Health scoring, behavioural segmentation and archetype assignment all sit inside that description, and a team arguing otherwise about its own product should expect to lose that argument.

The consequence is precise and narrower than it first sounds, so it is worth stating carefully. Profiling does not put you into Annex III. A consumer wellness app that profiles heavily is still outside the high-risk regime, because no Annex III use case applies to it. What profiling does is remove your route out of Annex III once a use case has already put you in. If you are selling into insurance risk assessment, the derogation is not available to you.

Note also that claiming the derogation is not a silent internal decision. You must document the assessment before the system is placed on the market, register under Article 49(2), and produce the documentation to national authorities on request.


What is already in force

Worth listing, because the deferral coverage has left an impression that none of the Act has landed yet.

DateWhat applied
1 August 2024The Act entered into force
2 February 2025Article 5 prohibitions on unacceptable-risk practices; AI literacy obligations
2 August 2025Obligations on providers of general-purpose AI models
2 August 2026Article 50 transparency; Commission enforcement and fining powers
2 December 2026Article 50(2) synthetic content marking
2 December 2027Annex III high-risk obligations
2 August 2028Annex I high-risk obligations

What to actually do this quarter

  1. Audit your AI-facing surfaces for disclosure. Every chat, coach or conversational feature. This is live now and it is the cheapest item on the list.
  2. Work out which route, if any, applies to you. Medical device under sectoral law is Annex I and 2028. An Annex III use case is December 2027. Neither is most consumer wellness.
  3. Check your channel, not just your product. If any customer uses your output for insurance risk assessment or pricing, Annex III point 5 is in play regardless of how the feature looks in your own app.
  4. If you think Article 6(3) saves you, check whether you profile first. If you compute health scores or behavioural segments, assume it does not.
  5. Diarise 2 December 2026 if you generate synthetic content, which includes LLM-written summaries and coaching text.
  6. Write down your assessment either way. The documentation requirement attaches to claiming you are out of scope, not only to being in it.

The deferral bought most teams time rather than an exemption, and it did not touch the one obligation that was easiest to overlook. If you do nothing else this quarter, make sure your AI coach says it is an AI coach.

References

  1. European Union. Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated text. https://eur-lex.europa.eu/eli/reg/2024/1689/oj
  2. EU Artificial Intelligence Act. Article 50: Transparency obligations for providers and deployers of certain AI systems. Retrieved 26 August 2026. https://artificialintelligenceact.eu/article/50/
  3. EU Artificial Intelligence Act. Article 6: Classification rules for high-risk AI systems, including the Article 6(3) derogation. Retrieved 26 August 2026. https://artificialintelligenceact.eu/article/6/
  4. EU Artificial Intelligence Act. Annex III: High-risk AI systems referred to in Article 6(2). Retrieved 26 August 2026. https://artificialintelligenceact.eu/annex/3/
  5. European Commission. AI Act Service Desk: Annex III. https://ai-act-service-desk.ec.europa.eu/en/ai-act/annex-3
  6. Mayer Brown. EU AI Act News: Digital Omnibus on AI, new guidance on risk classification, GPAI and transparency obligations, July 2026. https://www.mayerbrown.com/en/insights/publications/2026/07/eu-ai-act-news-digital-omnibus-on-ai-new-guidance-on-risk-classification-gpai-and-transparency-obligations
  7. Cooley. Digital AI Omnibus delays key deadlines, introduces new rules. https://cdp.cooley.com/digital-ai-omnibus-delays-key-deadlines-introduces-new-rules/
  8. Future of Privacy Forum. The AI Act implementation timeline: what changes under the AI Omnibus. https://fpf.org/blog/the-ai-act-implementation-timeline-what-changes-under-the-ai-omnibus/
  9. DLA Piper. The Digital AI Omnibus: proposed deferral of high-risk AI obligations under the AI Act. https://knowledge.dlapiper.com/dlapiperknowledge/globalemploymentlatestdevelopments/2026/The-Digital-AI-Omnibus-Proposed-deferral-of-high-risk-AI-obligations-under-the-AI-Act

Related