If you have read anywhere in the past few months that the EU AI Act’s high-risk obligations applied in full from August 2026, that guidance is out of date. The deadline moved before it arrived.
What did not move is a smaller obligation that probably applies to your product today, and which most teams missed precisely because they were watching the deadline that changed.
What actually changed
Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It deferred the two high-risk tracks.
| Obligation | Original date | Now |
|---|---|---|
| Annex III standalone high-risk systems | 2 August 2026 | 2 December 2027 |
| Annex I AI embedded in regulated products, including medical devices | 2 August 2027 | 2 August 2028 |
| Article 50(2) synthetic content marking | 2 August 2026 | 2 December 2026 |
| Article 50 general transparency | 2 August 2026 | Unchanged, in force |
| Commission enforcement powers, including fines | 2 August 2026 | Unchanged, in force |
That first row is the one that matters for most people reading compliance content right now: if you scoped a project against an August 2026 high-risk deadline, you have roughly sixteen additional months.
The second row is the one most often gotten wrong even in careful coverage. Software as a medical device generally routes through Annex I, not Annex III, because it is AI embedded in a product already covered by sectoral legislation. So a regulated digital therapeutic is on the 2028 track, not the December 2027 one.
What started on 2 August 2026
Two things, and one of them is cheap to comply with and easy to have missed.
Article 50 transparency. Providers must ensure that people are informed they are interacting with an AI system, unless that is obvious to a reasonably well-informed, observant and circumspect person. The information has to arrive in a clear and distinguishable manner at the latest at the time of the first interaction, and it has to meet accessibility requirements.
In a health product, that means the AI coach, the chatbot, the conversational “ask me about your sleep” surface. If a user could plausibly believe they are messaging a human coach, you owe them a disclosure. If your interface is obviously a machine, the exemption may cover you, but “obviously” is doing real work in that sentence and it is assessed from the user’s perspective rather than yours.
Deployers of emotion recognition or biometric categorisation systems have their own notification duty under the same article, which is worth checking if you do anything with inferred emotional state.
The Commission’s enforcement powers. From the same date, the Commission can request documentation and information, conduct model evaluations, require measures and impose fines. The machinery is live even though the high-risk obligations it will eventually enforce are not.
The practical read: the thing to do this quarter is not a conformity assessment. It is to check whether every AI-facing surface in your product discloses itself, and to fix the ones that do not.
Are you even high-risk?
This is where most health teams over-estimate their exposure, because “we handle sensitive health data” feels like it should mean high-risk. Under the Act it does not. High-risk is a closed list, not a sensitivity judgement.
There are two routes in.
Annex I covers AI embedded in products already regulated by EU sectoral legislation. If your software is a medical device under the MDR, this is your route, and your date is 2 August 2028.
Annex III enumerates standalone use cases: biometrics, critical infrastructure, education, employment, access to essential services, law enforcement, migration, and administration of justice. A consumer app that tells someone how they slept and suggests they walk more is generally not on that list.
So a B2C sleep tracker, a fitness app, a habit product, a wellness companion: absent a medical device classification, most of these sit outside the high-risk regime entirely, and their live obligation is the Article 50 disclosure above.
The line that moves a health score into scope
Here is the part worth internalising, because it is not about your technology at all.
Annex III point 5 covers access to essential private services, and it explicitly names AI systems intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance. Health data and behavioural signals used in insurance models fall inside that description.
Which produces this result: the same sleep score, computed the same way from the same sensors, is outside the Act in a consumer app and inside Annex III when it informs underwriting or premium pricing.
Scope follows the use case, not the algorithm. So the question that determines your exposure is not what does our model do, it is who is our customer and what decision does our output feed. Three products built on identical infrastructure can land in three different places:
| Same health score, different deployment | Likely position |
|---|---|
| Consumer app showing a user their own sleep trend | Outside Annex III |
| Employer wellness programme feeding engagement nudges | Outside Annex III, but check employment use cases if it touches evaluation |
| Insurer using it for risk assessment or pricing | Annex III point 5 |
If you sell into insurance or employer wellness channels, that distinction belongs in your contracts and your documentation now, not in December 2027. It also cuts the other way and is worth saying plainly: a vendor telling an insurance buyer that health scoring is categorically outside the AI Act is giving them bad information.
The escape hatch, and why profiling closes it
Appearing in Annex III is not automatically the end of the analysis. Article 6(3) lets a provider argue its system is not high-risk where it does not pose a significant risk of harm to health, safety or fundamental rights, and where it meets one of four conditions:
- It performs a narrow procedural task.
- It improves the result of a previously completed human activity.
- It detects decision-making patterns or deviations, without replacing or influencing a human assessment absent proper human review.
- It performs a preparatory task to a relevant assessment.
Then comes the sentence that matters most for anyone building health scoring:
A system that performs profiling of natural persons is always considered high-risk. No derogation.
The Act builds on the GDPR’s meaning of profiling, which covers automated processing used to evaluate personal aspects of a person, in particular to analyse or predict aspects concerning their health, behaviour, location or movements. Health scoring, behavioural segmentation and archetype assignment all sit inside that description, and a team arguing otherwise about its own product should expect to lose that argument.
The consequence is precise and narrower than it first sounds, so it is worth stating carefully. Profiling does not put you into Annex III. A consumer wellness app that profiles heavily is still outside the high-risk regime, because no Annex III use case applies to it. What profiling does is remove your route out of Annex III once a use case has already put you in. If you are selling into insurance risk assessment, the derogation is not available to you.
Note also that claiming the derogation is not a silent internal decision. You must document the assessment before the system is placed on the market, register under Article 49(2), and produce the documentation to national authorities on request.
What is already in force
Worth listing, because the deferral coverage has left an impression that none of the Act has landed yet.
| Date | What applied |
|---|---|
| 1 August 2024 | The Act entered into force |
| 2 February 2025 | Article 5 prohibitions on unacceptable-risk practices; AI literacy obligations |
| 2 August 2025 | Obligations on providers of general-purpose AI models |
| 2 August 2026 | Article 50 transparency; Commission enforcement and fining powers |
| 2 December 2026 | Article 50(2) synthetic content marking |
| 2 December 2027 | Annex III high-risk obligations |
| 2 August 2028 | Annex I high-risk obligations |
What to actually do this quarter
- Audit your AI-facing surfaces for disclosure. Every chat, coach or conversational feature. This is live now and it is the cheapest item on the list.
- Work out which route, if any, applies to you. Medical device under sectoral law is Annex I and 2028. An Annex III use case is December 2027. Neither is most consumer wellness.
- Check your channel, not just your product. If any customer uses your output for insurance risk assessment or pricing, Annex III point 5 is in play regardless of how the feature looks in your own app.
- If you think Article 6(3) saves you, check whether you profile first. If you compute health scores or behavioural segments, assume it does not.
- Diarise 2 December 2026 if you generate synthetic content, which includes LLM-written summaries and coaching text.
- Write down your assessment either way. The documentation requirement attaches to claiming you are out of scope, not only to being in it.
The deferral bought most teams time rather than an exemption, and it did not touch the one obligation that was easiest to overlook. If you do nothing else this quarter, make sure your AI coach says it is an AI coach.
References
- European Union. Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated text. https://eur-lex.europa.eu/eli/reg/2024/1689/oj
- EU Artificial Intelligence Act. Article 50: Transparency obligations for providers and deployers of certain AI systems. Retrieved 26 August 2026. https://artificialintelligenceact.eu/article/50/
- EU Artificial Intelligence Act. Article 6: Classification rules for high-risk AI systems, including the Article 6(3) derogation. Retrieved 26 August 2026. https://artificialintelligenceact.eu/article/6/
- EU Artificial Intelligence Act. Annex III: High-risk AI systems referred to in Article 6(2). Retrieved 26 August 2026. https://artificialintelligenceact.eu/annex/3/
- European Commission. AI Act Service Desk: Annex III. https://ai-act-service-desk.ec.europa.eu/en/ai-act/annex-3
- Mayer Brown. EU AI Act News: Digital Omnibus on AI, new guidance on risk classification, GPAI and transparency obligations, July 2026. https://www.mayerbrown.com/en/insights/publications/2026/07/eu-ai-act-news-digital-omnibus-on-ai-new-guidance-on-risk-classification-gpai-and-transparency-obligations
- Cooley. Digital AI Omnibus delays key deadlines, introduces new rules. https://cdp.cooley.com/digital-ai-omnibus-delays-key-deadlines-introduces-new-rules/
- Future of Privacy Forum. The AI Act implementation timeline: what changes under the AI Omnibus. https://fpf.org/blog/the-ai-act-implementation-timeline-what-changes-under-the-ai-omnibus/
- DLA Piper. The Digital AI Omnibus: proposed deferral of high-risk AI obligations under the AI Act. https://knowledge.dlapiper.com/dlapiperknowledge/globalemploymentlatestdevelopments/2026/The-Digital-AI-Omnibus-Proposed-deferral-of-high-risk-AI-obligations-under-the-AI-Act