The EU modifies the timetable for applying new obligations to high-risk AI systems

The European Union has modified the implementation timeline and introduced new obligations for Regulation (EU) 2026/1744 on Artificial Intelligence, known as the Digital Omnibus Regulation on AI. The regulation entered into force on July 27, with the aim of simplifying the European digital regulatory framework and facilitating compliance.

One of the main changes is the postponement of obligations applicable to high-risk AI systems, initially scheduled to take effect on August 2, 2026. The obligations for autonomous high-risk AI systems included in Annex III of the regulation must now be met from December 2, 2027, while those for systems governed by legislation have until August 2, 2028.

This change aims to reduce the administrative burden on companies and give organizations more time to adapt their systems, processes, and control mechanisms to European requirements.

Use of sensitive data to detect and correct biases

The new regulation incorporates Article 4 bis into the AI ​​Regulation, a change with direct implications for data protection. This new provision allows the processing of sensitive personal data when strictly necessary to detect and correct biases in high-risk AI systems.

This processing must be carried out with appropriate safeguards and may be performed by both the system providers and the organizations responsible for their deployment.

The reform also expands the application of real-world testing. These provisions may be applied to high-risk AI systems regulated by European harmonisation legislation, beyond the systems included in Annex III.

In the healthcare sector, the expansion affects systems linked to the European Medical Devices Regulation and the Regulation on in vitro diagnostic medical devices. This significantly broadens the cases in which testing can be carried out under real-world conditions.

AI literacy becomes an organizational obligation

The Digital Omnibus Directive also redefines the obligation of AI literacy. Organizations will continue to have a duty to promote staff training, but the regulation is no longer interpreted as a requirement to guarantee individual competencies or formally accredit specific training.

The obligation is now framed as a duty of care and the provision of reasonable resources, adapted to the risk, context, and size of each organization.

Simplifications for SMEs and the healthcare sector

Among the other modifications, the regulation redefines the concept of a high-risk component to prevent certain systems from receiving this classification, simplifies obligations for small and medium-sized enterprises (SMEs), and limits the application of some requirements when sector-specific regulations already guarantee an equivalent level of protection.

This last provision may have a particular impact on the healthcare sector, where medical devices are already subject to specific European regulations regarding safety, supervision, and market surveillance.

More details of the news can be found by clicking on the link in the following DPD Health article.

  • The European Omnibus Digital Regulation on AI extends adaptation deadlines, allows sensitive data to be processed to correct biases with guarantees and redefines AI training obligations