AI in a medical device: which EU AI Act deadline applies?
The system being classified
You build an AI component that is a safety component of a medical device, and that device undergoes third-party conformity assessment under its own product legislation.
High-risk system
Your system falls under Annex III or is a regulated product safety component. The full high-risk obligation set applies from 2 December 2027 (Annex III) or 2 August 2028 (Annex I) — postponed by the 2026 Omnibus. Any Article 50 transparency duties apply already, and the runway is what makes conformity achievable in-house.
This is the classification of the configuration described above, not of your system. One different answer can move it — which is exactly what the comparison further down shows, and what the free assessment settles in about ten minutes.
What produced this verdict
These are the entire inputs. The engine is deterministic, so these answers always produce the verdict above.
Scope and role
- · Provider — you build it or place it on the market under your name
- · Placed on the EU market, or output used in the EU
- · Safety component of an Annex I product subject to third-party conformity assessment
What applies, and from when (13)
Every entry cites the article it comes from and the date it binds. That second column is the part most summaries of the Omnibus get wrong.
| Article | Obligation | Binding from |
|---|---|---|
| Art. 4 | AI literacy Ensure staff dealing with AI systems have a sufficient level of AI literacy (training records recommended). | 2 February 2025 |
| Best practice | AI system inventory Maintain a central register of all AI systems in use, their purpose, risk tier and owner. | Good practice |
| Art. 9 | Risk management system Establish, document and maintain a continuous, iterative risk management process across the system lifecycle. | 2 August 2028 |
| Art. 10 | Data and data governance Training, validation and test data must meet quality criteria: relevance, representativeness, error screening, bias examination and mitigation. | 2 August 2028 |
| Art. 11 + Annex IV | Technical documentation Maintain complete Annex IV technical documentation before placing on the market, kept up to date. | 2 August 2028 |
| Art. 12 | Record-keeping (automatic logs) The system must automatically record events relevant to identifying risks and substantial modifications over its lifetime. | 2 August 2028 |
| Art. 13 | Transparency and instructions for deployers Ship clear instructions for use: capabilities, limitations, accuracy metrics, human oversight measures, expected lifetime and maintenance. | 2 August 2028 |
| Art. 14 | Human oversight by design Design the system so natural persons can effectively oversee it: understand outputs, intervene, and stop the system. | 2 August 2028 |
| Art. 15 | Accuracy, robustness and cybersecurity Achieve and declare appropriate levels of accuracy and robustness; protect against data poisoning, adversarial attacks and model leaks. | 2 August 2028 |
| Art. 17 | Quality management system Documented QMS covering regulatory compliance strategy, design controls, testing, data management and post-market monitoring. | 2 August 2028 |
| Art. 43, 47 + 48 | Conformity assessment, declaration and CE marking Run the applicable conformity assessment procedure (Art. 43), draw up and sign the EU declaration of conformity (Art. 47) and keep it for ten years, then affix CE marking (Art. 48). | 2 August 2028 |
| Art. 72 | Post-market monitoring Documented plan to actively collect and analyse performance data throughout the system lifetime. | 2 August 2028 |
| Art. 73 | Serious incident reporting Process to report serious incidents to market surveillance authorities within 15 days (or faster for severe cases). | 2 August 2028 |
What would change this verdict
Each row below is the same scenario with one answer changed, re-run through the same engine. These are not predictions about your system; they are what our classifier returns when that single fact differs. Where one change to the scenario necessarily moves a second answer with it, the row says which, and why.
The product is self-assessed instead
Becomes minimal riskArticle 6(1) is conjunctive: without a third-party conformity assessment the Annex I route does not make the system high-risk. Class I devices, most toys and machinery outside Annex IV of the Machinery Regulation are commonly self-assessed.
- Obligations: 13 → 2 (-11)
- Key date changes to No dated obligations pending — AI literacy (Art. 4) applies since 2 February 2025; keep the inventory current
It also falls in an Annex III category
Same risk tierA system on both routes takes the earlier date, which is what makes the distinction worth checking rather than assuming.
- Obligations: 13 → 14 (+1)
- Key date changes to 2 December 2027 — Annex III high-risk obligations apply (postponed from 2 August 2026 by the 2026 Omnibus); the Annex I route adds product-legislation duties from 2 August 2028
Flagged for counsel review (1)
The engine refuses to resolve these on its own. They are surfaced rather than silently decided.
Article 6(1)(b): does the product need third-party conformity assessment?
This system reaches high-risk through Article 6(1), which requires BOTH that it is a safety component of (or is itself) a product covered by the Annex I legislation AND that the product undergoes third-party conformity assessment. Verify the second limb against the product's regulatory file — if the product is self-assessed, the Article 6(1) route does not apply and the classification changes.
Your system is not this system
The assessment asks the same questions this page answered for a generic configuration, and produces the verdict, the gap list and the 30-day plan for yours. Ten minutes, free, no sign-up, and it runs entirely in your browser — your answers never reach us.
Classify your own system →Other configurations
A support chatbot is rarely high-risk and never exempt. What Article 50 requires, what it costs to comply, and why the date on this one has already passed.
Synthetic text, image, audio and video carry Article 50 marking duties that have been enforceable since August 2026. What the engine says applies, and from when.
Deploying deepfake content triggers Article 50 disclosure duties that are live now, not in 2027. The engine's verdict for an advertiser using synthetic likenesses.
Inferring emotions from workers is an Article 5 prohibited practice, not a high-risk category with a 2027 runway. What that means for a system already in production.
Produced by rule set 1.6.1, legal state 2026-08-05. The engine is deterministic and contains no language model in the verdict path, and every rule is published at /methodology for you to audit.
AnnexWise is preparation software, not legal advice. This page classifies a described configuration; it is not an opinion on any particular organisation or system.