NEWSLETTER REGULATORY UPDATE

The AI Regulation and the AI Act: Why the Digital Omnibus Helps the Large Medical AI Providers, Not the Small Ones

The Digital Omnibus has once again postponed the substantive requirements of the AI Regulation—known in English as the AI Act, or Regulation (EU) 2024/1689 on Artificial Intelligence—for high-risk AI in the healthcare sector, now to no later than August 2, 2028. At first glance, this sounds like a relief. However, a new economic study by Wiens and Dieler shows that for small medical AI companies, the exact opposite is true.

The AI Regulation and the AI Act: Why the Digital Omnibus Helps the Large Medical AI Providers, Not the Small Ones

The Digital Omnibus has once again postponed the substantive requirements of the AI Regulation—known in English as the AI Act, or Regulation (EU) 2024/1689 on Artificial Intelligence—for high-risk AI in the healthcare sector, now to no later than August 2, 2028. At first glance, this sounds like a relief. However, a new economic study by Wiens and Dieler shows that for small medical AI companies, the exact opposite is true.

Teilen Sie diesen Beitrag:

Teilen Sie diesen Beitrag:

What is the Digital Omnibus?

The Digital Omnibus is not a single law, but rather a bundle of EU simplification packages that harmonize several sets of digital regulations. It is important to note that there are currently two parallel strands. The general Digital Omnibus primarily concerns the GDPR and the ePrivacy rules, while the specific Digital Omnibus on AI specifically aligns the deadlines of the AI Regulation—which is the subject of this article. Both packages are moving through the legislative process simultaneously but address different matters.

How the Digital Omnibus Act Is Changing High-Risk AI in the Healthcare Sector

The Digital Omnibus on AI distinguishes between two groups of high-risk AI systems, and this is the crucial point for medical device manufacturers. Standalone high-risk AI systems as defined in Annex III are granted a grace period until December 2, 2027. AI embedded in products that are already regulated—such as medical devices under the MDR—falls under Annex I and will not be subject to these requirements until August 2, 2028, a good two years later than originally planned. By contrast, the transparency requirements under Article 50 remain unchanged and will continue to apply starting August 2, 2026, regardless of the risk class.

For manufacturers of medical AI, this means, specifically, that the substantive requirements for risk management, conformity assessment, and post-market surveillance under the AI Regulation will take effect later, but the obligation to label AI-generated content and automated decisions remains unaffected by the timeline.

The Study: Why Small Medical AI Companies Are Voluntarily Investing in Security

Wiens and Dieler model the conformity assessment process using game theory as a competition between a small or medium-sized enterprise, a Notified Body—that is, the certification body responsible for external auditing—and the regulator. All three also compete for the same scarce resource: qualified AI specialists. The study’s findings may seem surprising at first glance, but upon closer inspection, they make sense: companies voluntarily invest in product safety even though such an obligation does not yet exist.

There are three reasons behind this. First, to protect themselves against future liability risks, which will increase even further with the equally new Product Liability Directive (EU) 2024/2853. Second, a safety-focused unique selling proposition (USP) for customers, precisely because sector-specific standards for AI liability and data security are still lacking—a niche that can be filled. Third, well-calibrated regulatory incentives that reward early investment. The second point is particularly interesting for European providers: those who can present robust security evidence even before the mandatory deadline will stand out from the competition.

When Safety Becomes an Afterthought: The Downside of Procrastination

According to the study, the delay undermines precisely this advantage. If the high-risk requirements do not take effect until 2028, competition will shift away from safety and toward speed. Anyone who brings their product to market before the regulations take effect secures a first-mover advantage without bearing the costs of regulation.

This structurally favors larger competitors and, above all, non-European providers. In AI diagnostics, these are primarily U.S. and Chinese platforms, which launch earlier in their home markets anyway and can secure a customer base and lock-in effects before European SMEs even consider entering the market. The time that the Omnibus Directive supposedly grants is therefore not distributed equally among all market participants.

The real bottleneck isn’t the deadlines, but the testing capacity

According to the study, the real bottleneck isn’t time anyway, but rather staffing. Companies and Notified Bodies are competing for the same small pool of AI specialists. More time does not create additional qualified inspectors. The standardized application and evaluation procedure enshrined in the Omnibus Regulation helps somewhat in terms of process efficiency because it reduces duplication of effort, but it does not solve the actual capacity problem faced by the Notified Bodies.

The New Small-Mid-Cap Category: Relief with Side Effects

Caution is also warranted when it comes to the SME privileges themselves. The Omnibus Act extends relief regarding fees, documentation, and access to real-world testing facilities to a new category called “Small Mid-Cap Companies”—firms with up to 750 employees and annual revenue of 150 million euros, which is three times the traditional SME threshold. While small and micro-enterprises benefit additionally from a 50 percent or 75 percent reduction in fines, the new, significantly larger category dilutes the targeted support intended specifically for the small, resource-constrained companies for which it was originally designed.

What Medical AI Companies Should Do Now

In practical terms, a few concrete conclusions can be drawn from the study:

  • Plan for August 2, 2028, but leave some wiggle room. The history of delays surrounding the AI Regulation speaks for itself; further adjustments cannot be ruled out.
  • Don’t view the time until then as a breather—use it proactively. Security by design and a robust, documented risk management practice remain a genuine competitive advantage—not because the law requires it today, but because it will provide a stronger market position once it does.
  • Determine early on whether your product falls under Annex I or Annex III, as this determines which deadline actually applies.
  • Keep track of your status with the Notified Body. If you submit your application early, you won’t end up at the back of the line as capacity constraints loom closer to the new deadline.
  • Do not confuse the AI compliance requirement under Article 4 with the high-risk deadlines; it is already in effect and continues to run independently.

Conclusion

The Digital Omnibus formally gives the industry more time, but not to all market participants equally. Ultimately, market access is not determined by the calendar anyway, but rather by the capacity of the Notified Bodies and the question of who has already invested in a robust safety architecture.

FAQ: Frequently Asked Questions About the AI Regulation, the AI Act, and the Digital Omnibus

The Digital Omnibus is a bundle of EU simplification packages for digital regulations. One strand concerns the GDPR and ePrivacy rules, while the other—referred to as the Digital Omnibus on AI—adjusts the deadlines in the AI Regulation.

No. These are two parallel initiatives that are distinct in terms of content. If you’re looking for changes to the AI Regulation, you need the Digital Omnibus on AI; for changes to the GDPR, the general Digital Omnibus applies.

No. AI systems embedded in products that are already regulated, such as medical devices, fall under Annex I of the AI Regulation (AI Act) and must comply with the substantive obligations no later than August 2, 2028. For standalone high-risk AI systems as defined in Annex III, however, a shorter grace period applies, extending until December 2, 2027.

Article 50 of the AI Regulation requires providers and operators to disclose the use of certain AI systems as well as AI-generated content. This transparency requirement will remain in effect as of August 2, 2026, and is not affected by the postponement of the high-risk obligations.

No. The AI competency requirement under Article 4 has been in effect since February 2, 2025, and applies to all professional uses of AI, not just high-risk systems. It is independent of any deadline extensions under the Digital Omnibus.

Small medical AI companies have so far used early investments in safety as a competitive advantage over larger and non-European providers. If the requirement changes, this advantage will shift as well, while larger competitors gain time to enter the market more quickly.

A new category of companies with up to 750 employees or 150 million euros in annual revenue, which benefits from simplified documentation and other concessions originally intended for significantly smaller SMEs.

Both sets of regulations often apply in parallel whenever an AI system processes personal data—for example, in the context of risk assessments, transparency requirements, or automated decisions. Those who already conduct a data protection impact assessment under the GDPR can reuse parts of it for the compliance assessment under the AI Regulation; however, the two assessments are not mutually exclusive.

Determine early on which annex and deadline apply; contact the relevant Notified Body in a timely manner; do not confuse the ongoing AI competence requirement under Article 4 with the high-risk deadlines; and continue to pursue “security by design” as a competitive advantage, regardless of the effective date.

Contact Us

Are you developing AI-based medical devices and looking for an experienced contract manufacturer to guide you through risk management, conformity assessment, and the new deadlines under the AI Regulation? Contact us for a no-obligation consultation.

More exciting news for you

  • 23. September 2026

    The AI Regulation and the AI Act: Why the Digital Omnibus Helps the Large Medical AI Providers, Not the Small Ones

  • 23. September 2026

    Digital Services Act: EU Commission Tightens Requirements

  • 24. August 2026

    Health Data and the GDPR in Workplace Chats: When a Diagnosis Becomes “Information for Everyone”