Regulation (EU) 2026/1744 deferred the EU AI Act high-risk obligations to two different dates, not one. AI on the Annex III standalone route applies from 2 December 2027. AI on the Annex I embedded route, which is where medical devices sit, applies from 2 August 2028. Article 6 decides which route you travel, and the deciding condition is not whether your software is medical. It is whether the product it rides inside needs a notified body.
Most coverage of the Digital Omnibus reported a single new deadline. There are two, eight months apart, and a hospital or a manufacturer can be holding both at the same time for different systems. This guide walks the Article 6 test, quotes the two Annex entries that decide it, and covers the condition that determines whether the later date is actually yours.
What Article 6 actually asks
Regulation (EU) 2024/1689 creates two independent ways for an AI system to be high-risk, and Article 6 sets them out separately.
Article 6(1) is the Annex I route. It applies when the AI system "is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I," and that product "is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service."[1] Both conditions are cumulative. One without the other does not put you on this route.
Article 6(2) is the Annex III route. It states simply that "AI systems referred to in Annex III shall be considered to be high-risk."[1] There is no product legislation involved and no conformity assessment condition. If your system does something on the Annex III list, it is high-risk by that fact.
The two routes were always distinct. What changed in July 2026 is that they stopped sharing a date.
Where medical devices sit
Annex I Section A lists the Union harmonisation legislation that triggers the first route. Two entries matter in medicine. Item 11 is "Regulation (EU) 2017/745 of the European Parliament and of the Council of 5 April 2017 on medical devices." Item 12 is "Regulation (EU) 2017/746 of the European Parliament and of the Council of 5 April 2017 on in vitro diagnostic medical devices."[2]
So an AI system that is a medical device, or a safety component of one, satisfies the first condition of Article 6(1). That is the part everyone gets right. The second condition is where the reading usually stops too early.
The condition most summaries skip
Article 6(1) also requires that the product be one that "is required to undergo a third-party conformity assessment." In medical device terms, that means a notified body has to be involved before the product goes to market.
For most AI-enabled devices it is. Software that drives or influences a diagnosis or a therapy generally classifies above the lowest tier under the MDR rules, and above that tier a notified body is required. Those devices travel the Annex I route and their high-risk obligations apply from 2 August 2028.
But a device that the manufacturer self-certifies, with no notified body in the process, does not meet the second condition. It does not become high-risk by the Annex I route at all, because Article 6(1) needs both limbs and only one is present. The flat statement that "medical devices got until 2028" is therefore not reliable as a planning assumption. It is reliable for devices that need a notified body, which is most but not all of them.
Two consequences follow. A self-certified device is not automatically on the 2028 clock, so inheriting that date without checking is a mistake in one direction. And it is not automatically outside the AI Act either, so treating it as exempt is a mistake in the other. It may still be caught by Annex III on its own facts, and the Article 50 transparency duties applied from 2 August 2026 regardless of route, a date that is already behind us.
The Annex III entries that catch healthcare
Annex III has eight categories. Two of them reach into care delivery without the system ever being a medical device.
Point 5(a) covers "AI systems intended to be used by public authorities or on behalf of public authorities to evaluate the eligibility of natural persons for essential public assistance benefits and services, including healthcare services, as well as to grant, reduce, revoke, or reclaim such benefits and services."[3] The phrase "on behalf of" matters, because it pulls in contractors and vendors operating for a public payer, not only the authority itself.
Point 5(d) covers "AI systems intended to evaluate and classify emergency calls by natural persons or to be used to dispatch, or to establish priority in the dispatching of, emergency first response services, including police, firefighters and medical aid, as well as of emergency healthcare patient triage systems."[3] That last clause names emergency healthcare patient triage explicitly.
Neither of those is a medical device in the ordinary case. Both are high-risk. Both apply from 2 December 2027, which is the earlier of the two dates.
Find your route
Three questions decide it. This mirrors the structure of the Article 6 test and is intended to orient you before a conversation with counsel, not to replace one.