

The AI Regulation and the AI Act: Why the Digital Omnibus Helps the Large Medical AI Providers, Not the Small Ones
The Digital Omnibus has once again postponed the substantive requirements of the AI Regulation—known in English as the AI Act, or Regulation (EU) 2024/1689 on Artificial Intelligence—for high-risk AI in the healthcare sector, now to no later than August 2, 2028. At first glance, this sounds like a relief. However, a new economic study by Wiens and Dieler shows that for small medical AI companies, the exact opposite is true.
Teilen Sie diesen Beitrag:
Teilen Sie diesen Beitrag:
What is the Digital Omnibus?
The Digital Omnibus is not a single law, but rather a bundle of EU simplification packages that harmonize several sets of digital regulations. It is important to note that there are currently two parallel strands. The general Digital Omnibus primarily concerns the GDPR and the ePrivacy rules, while the specific Digital Omnibus on AI specifically aligns the deadlines of the AI Regulation—which is the subject of this article. Both packages are moving through the legislative process simultaneously but address different matters.
How the Digital Omnibus Act Is Changing High-Risk AI in the Healthcare Sector
The Digital Omnibus on AI distinguishes between two groups of high-risk AI systems, and this is the crucial point for medical device manufacturers. Standalone high-risk AI systems as defined in Annex III are granted a grace period until December 2, 2027. AI embedded in products that are already regulated—such as medical devices under the MDR—falls under Annex I and will not be subject to these requirements until August 2, 2028, a good two years later than originally planned. By contrast, the transparency requirements under Article 50 remain unchanged and will continue to apply starting August 2, 2026, regardless of the risk class.
For manufacturers of medical AI, this means, specifically, that the substantive requirements for risk management, conformity assessment, and post-market surveillance under the AI Regulation will take effect later, but the obligation to label AI-generated content and automated decisions remains unaffected by the timeline.
The Study: Why Small Medical AI Companies Are Voluntarily Investing in Security
Wiens and Dieler model the conformity assessment process using game theory as a competition between a small or medium-sized enterprise, a Notified Body—that is, the certification body responsible for external auditing—and the regulator. All three also compete for the same scarce resource: qualified AI specialists. The study’s findings may seem surprising at first glance, but upon closer inspection, they make sense: companies voluntarily invest in product safety even though such an obligation does not yet exist.
There are three reasons behind this. First, to protect themselves against future liability risks, which will increase even further with the equally new Product Liability Directive (EU) 2024/2853. Second, a safety-focused unique selling proposition (USP) for customers, precisely because sector-specific standards for AI liability and data security are still lacking—a niche that can be filled. Third, well-calibrated regulatory incentives that reward early investment. The second point is particularly interesting for European providers: those who can present robust security evidence even before the mandatory deadline will stand out from the competition.

When Safety Becomes an Afterthought: The Downside of Procrastination
According to the study, the delay undermines precisely this advantage. If the high-risk requirements do not take effect until 2028, competition will shift away from safety and toward speed. Anyone who brings their product to market before the regulations take effect secures a first-mover advantage without bearing the costs of regulation.
This structurally favors larger competitors and, above all, non-European providers. In AI diagnostics, these are primarily U.S. and Chinese platforms, which launch earlier in their home markets anyway and can secure a customer base and lock-in effects before European SMEs even consider entering the market. The time that the Omnibus Directive supposedly grants is therefore not distributed equally among all market participants.
The real bottleneck isn’t the deadlines, but the testing capacity
The New Small-Mid-Cap Category: Relief with Side Effects
Caution is also warranted when it comes to the SME privileges themselves. The Omnibus Act extends relief regarding fees, documentation, and access to real-world testing facilities to a new category called “Small Mid-Cap Companies”—firms with up to 750 employees and annual revenue of 150 million euros, which is three times the traditional SME threshold. While small and micro-enterprises benefit additionally from a 50 percent or 75 percent reduction in fines, the new, significantly larger category dilutes the targeted support intended specifically for the small, resource-constrained companies for which it was originally designed.

What Medical AI Companies Should Do Now
In practical terms, a few concrete conclusions can be drawn from the study:
- Plan for August 2, 2028, but leave some wiggle room. The history of delays surrounding the AI Regulation speaks for itself; further adjustments cannot be ruled out.
- Don’t view the time until then as a breather—use it proactively. Security by design and a robust, documented risk management practice remain a genuine competitive advantage—not because the law requires it today, but because it will provide a stronger market position once it does.
- Determine early on whether your product falls under Annex I or Annex III, as this determines which deadline actually applies.
- Keep track of your status with the Notified Body. If you submit your application early, you won’t end up at the back of the line as capacity constraints loom closer to the new deadline.
- Do not confuse the AI compliance requirement under Article 4 with the high-risk deadlines; it is already in effect and continues to run independently.
Conclusion
The Digital Omnibus formally gives the industry more time, but not to all market participants equally. Ultimately, market access is not determined by the calendar anyway, but rather by the capacity of the Notified Bodies and the question of who has already invested in a robust safety architecture.
