Direct answer
We use AI in healthcare. Which AI Act rules apply there?
This falls under Annex III: high-risk AI. That obligation applies from 2 December 2027. There is one exception you have to assess yourself.
This could go the other way
- A listed Annex III system may fall outside high-risk under the strict conditions in Article 6(3), except where it profiles. The assessment and registration must be documented.
First step: Justify the Article 6(3) exception against each individual condition.
You describe: AI in a healthcare context, from triage and administrative support to AI in or around medical devices. Likely role: body governed by public law or public service provider.
This applies now
- Article 4: AI literacyApplicable
- Article 50: transparencyApplicable
Coming up
- Annex III: high-risk AIfrom 2 December 2027
- Article 27: FRIAfrom 2 December 2027
Article 27 covers bodies governed by public law and private parties providing public services, among others. If you deploy a high-risk system from Annex III, you assess the impact on fundamental rights beforehand and notify the market surveillance authority of the result. A GDPR data protection impact assessment does not replace that assessment; since the amending regulation you may carry relevant parts of it across.
Your first actions
- Justify the Article 6(3) exception against each individual condition. Name which of the four Article 6(3) conditions you invoke, with facts, and separately justify why the system poses no significant risk of harm to health, safety or fundamental rights and does not materially influence the outcome of decision making.
- Take role- and context-specific AI literacy measures. Determine for each role, system and context which combination of instruction, guidance, practice or training is appropriate.
- Implement the applicable disclosure, marking or label. First determine which paragraph of Article 50 applies, then implement the specific transparency measure.
Record this
- Article 49(2) registration record for the system assessed as not high-risk
- AI literacy measures record
- Test report per touchpoint: disclosure visible, timely and accessible
healthcare
Chatbot answering factual questions from a benefits case handler
A chatbot answers a case handler's factual questions relating to the evaluation of a natural person's application for healthcare benefits, for instance the applicant's age. The case handler can grant or deny the benefits based on those answers.
Provenance: The Commission draft guidelines of 19 May 2026 address this case when determining whether an application falls under Annex III. The document is a consultation version: non-binding and not yet final.
A chatbot that only returns existing facts in structured form falls under the exemption, but once it answers case-specific legal questions it steers the decision and is high-risk.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III
healthcare
Emergency triage system: two routes to high risk
A hospital uses AI to prioritise incoming patients at the emergency department. The question is not whether the system is high-risk but by which route: as a medical device under product legislation, or directly under Annex III.
Provenance: The Commission draft guidelines of 19 May 2026 state that an emergency healthcare patient triage system may qualify as a medical device; where it then meets Article 6(1), it is high-risk via Annex I and sectoral rules apply. A triage system that is not a medical device is high-risk via Article 6(2) and point 5(d) of Annex III. The document is a consultation version: non-binding and not yet final.
First establish whether your triage system is a medical device, because that question decides the whole route: via Annex I the assessment travels with the medical conformity assessment and its date, via Annex III the separate timeline of Article 6(2) applies. Either way the outcome is high-risk, so postponing that determination only creates uncertainty about which regime to set up.
Draft guidelines on high-risk AI classification, 19 May 2026, annex on Annex III, paragraphs (334) and (335)
healthcare
Diagnostic support for clinicians: no disclosure duty, still due care
A hospital deploys an interactive AI system used exclusively by properly trained health professionals to support medical diagnosis and suggest treatments. The question is whether the patient or the clinician must be told it is AI.
Provenance: The Commission guidelines of 20 July 2026 list interactive AI systems intended only for properly trained health professionals to support medical diagnosis and suggest treatments as an example where the obviousness exception in Article 50(1) applies: for that user the AI nature is clear.
The exception attaches to the user, not to the system. The moment the same model also speaks to patients, that ground falls away and the disclosure duty applies as normal. And an exception to Article 50 says nothing about the rest: where it is a medical device or a high-risk application, those regimes continue to apply in full.
Commission Guidelines C(2026) 5054 final, 20.7.2026, paragraph (45), lists with and without the obviousness exception
healthcare
Lawyers learn the technology, developers learn the law
Dedalus Healthcare, which among other things supplies AI that predicts complications for hospital patients, trains its legal staff, data protection officer, compliance function and quality and regulatory affairs department on the technical side. Developers and engineers conversely receive training focused on the legal and compliance aspects of the AI Act. The executive committee received its own session tailored to its role.
Provenance: This practice was submitted by the organisation itself to the Commission living repository. The repository collects and shares practices; it does not approve them or set them as a standard.
Look for knowledge deliberately outside a single discipline, because the repository names collaboration between industry and academia as one of the ways organisations build AI literacy.
Levend repository van AI-geletterdheidspraktijken, ingediende praktijk van de betrokken organisatie
Article 6 has two separate routes to high-risk
The European Commission's draft guidelines on the classification of high-risk AI of 19 May 2026, which are expressly non-binding, state in paragraph (7) that an AI system is high-risk in two scenarios: first, where it is intended to be used as a safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in Annex I and required to undergo third-party conformity assessment; and second, where it falls within one of the use cases in the areas listed in Annex III. Paragraph (448) of those same draft guidelines notes that the Article 113 application dates have been postponed by the AI Omnibus to 2 December 2027 for the Article 6(2) route and 2 August 2028 for the Article 6(1) route.
Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II, paragraph (7); section V, paragraph (448)
Broadly positioned and general purpose AI systems: a disclaimer is not enough
According to the non-binding draft guidelines of 19 May 2026 on the classification of high-risk AI, paragraph (12) provides that where the instructions for use, contractual arrangements, terms of service, usage policy, promotional and sales materials or technical documentation present the AI system as broadly applicable across a generality of contexts and functions, and do not consistently limit its application or exclude high-risk uses, the system's intended purpose will be deemed to also encompass high-risk use cases and therefore qualify as high-risk. Under these draft guidelines this applies in particular where such uses are feasible and reasonably foreseeable given the system's functionalities and capabilities. The same paragraph states that merely asserting, for example in the terms of service, that high-risk uses are excluded is insufficient where the provider's overall presentation, examples or product positioning effectively provides for or promotes such uses, and that any limitations of use must be described clearly, concretely and coherently across all materials.
Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, section II.2, paragraph (12)
High-risk does not mean prohibited, and not high-risk does not mean permitted
The draft guidelines of 19 May 2026 on the classification of high-risk AI, which are not binding, state in paragraph (3) that the fact an AI system is listed as an example in these guidelines does not mean its use should automatically be considered lawful, since such use would still need to comply with other applicable legislation, and in paragraph (4) that the scope of these guidelines is limited to whether an AI system is high-risk or not. In the Annex III chapter of this draft, paragraph (68) states that classifying systems as high-risk under Article 6(2) does not mean their use is prohibited, but that those systems are subject to appropriate requirements. Paragraphs (82) and (83) of this draft explain the wording in so far as their use is permitted under relevant Union or national law and state that falling within a use case does not necessarily mean the system may lawfully be used in those cases, that in addition to the prohibitions other provisions of Union or national law may restrict use, and that under Article 2(9) the AI Act applies without prejudice to rules on consumer protection, product safety and data protection.
Draft guidelines on high-risk AI classification (19 May 2026), General principles chapter, paragraphs (3) and (4); Annex III chapter, paragraph (68) and section 2.6, paragraphs (82) and (83)
Split and agentic architectures are assessed as a whole
The non-binding draft guidelines of 19 May 2026 provide in paragraphs 75, 76 and 90 that where several AI systems form part of a more complex whole and their combined intended purpose or joint outputs materially influence an individual decision, that configuration is treated as a single AI system for classification. The draft expressly states that split architectures are assessed as a whole to prevent circumvention by system design, that exemptions for individual modules do not apply where the overall configuration influences key aspects of the decision, and that this also extends to complex interconnected setups such as agentic AI systems whose linked actions jointly serve a high-risk purpose. Under the same draft, strictly procedural or preparatory functions do remain eligible for exemption where they are genuinely separable from the system and do not structure or feed outputs that materially influence the examination of an individual case.
Section IV.2.3, paragraphs 75 and 76, and section IV.2.7.1 paragraph 90
General interpretation, not legal advice. Checked against Regulation (EU) 2024/1689 and the Digital Omnibus (EU) 2026/1744; the official source remains authoritative.
Full map for your situationExecution
Record the classification in an AI register
A classification without a register and ownership is not demonstrable. Embed AI guides classification, register and reassessment in a fixed approach.
See the Embed AI approach