What actually stops AI in healthcare, and which deadline now applies
The guidance the medtech sector cites most often gives 2 August 2027. That date no longer holds. And the obstacle healthcare regions actually report is neither the regulator nor the technology.

Key insights
- High-risk obligations for Annex I systems, which is where medical devices sit, apply from 2 August 2028. The widely cited MDCG 2025-6 guidance gives 2 August 2027 and was written before the amendment.
- A medical device AI counts as high risk when two conditions hold at once: it is a safety component or is itself a medical device, and it is subject to third-party conformity assessment by a notified body.
- Swedish regional IT directors rank a shortage of their own resources ahead of finances and unclear legislation. Access to data is not among them. SLIT grades on a five-point scale and reports no percentages.
- Of 179 mapped AI initiatives across seventeen regions, twenty-four were fully implemented, thirteen per cent. Ten of eighteen regions have no policy for how AI may be used by clinical staff.
- Another year on the timetable solves neither the resource shortage nor the finances. Those who use the time to build capacity gain from it; those who use it to wait stand in the same place in 2028.
Two things about AI in healthcare no longer match the way they are usually said. One is a date that moved this summer but still stands in the guidance the sector cites. The other is the assumption about what is actually holding development back.
The date in the guidance no longer holds
The joint guidance from the AI Board and the Medical Device Coordination Group, AIB 2025-1 and MDCG 2025-6, is the text most people point to when the interplay between the MDR, the IVDR and the AI Act has to be explained. It was published in June 2025 and gives 2 August 2027 for the Annex I obligations.
Since then, amending Regulation (EU) 2026/1744 has changed Article 113. The text now provides that Chapter III sections 1, 2 and 3 apply from 2 December 2027 for systems classified as high risk under Article 6(2) and Annex III, and from 2 August 2028 for systems classified as high risk under Article 6(1) and Annex I.
Medical devices belong to Annex I. Their date is therefore 2 August 2028, a year later than the guidance states.
- The regulation otherwise begins to applyIncluding the transparency obligations in Article 50.
- High risk under Annex IIIStandalone systems in the listed use areas. Relevant in healthcare where the system is not a medical device.
- High risk under Annex I, medical devicesSystems that are a safety component of, or are themselves, a product covered by union harmonisation legislation. This is where the MDR and IVDR sit.
Source: Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, Article 113
The gap between the two high-risk tracks is eight months, and it is not arbitrary. The whole rescheduling is covered in our review of the new deadlines.
The substance of the guidance still stands. The timing in it does not.
The distinction matters, because the guidance is useful in every other respect. It states plainly when a medical device AI counts as high risk: when it is either a safety component or is itself a medical device, and it is at the same time subject to a third-party conformity assessment by a notified body. Both conditions have to hold. The guidance also describes the relationship between the regimes as a simultaneous and complementary application: the AI Act adds requirements addressing hazards and risks specific to AI systems, and replaces nothing in the MDR or IVDR.
The reported obstacle is not the assumed one
The second assumption is that access to data is what holds development back. It is a reasonable guess, and three Swedish sources point elsewhere.
The SLIT report, compiled by the network of IT directors of Sweden's healthcare regions, ranks the largest obstacles to continued digital development as the same as the year before: a shortage of their own resources, followed by finances and unclear legislation. Access to data does not appear among them. The ranking should be read as exactly that, a ranking. SLIT grades the obstacles on a five-point scale and reports no percentages, and the edition does not state how many of the twenty-one regions submitted input. It says in what order the IT directors place the obstacles, not how large they are.
Two other sources supply the numbers SLIT does not, and they measure something else.
Vårdkartan, AI Sweden's survey from April 2025, counted 179 AI initiatives across seventeen of the twenty-one regions. Twenty-four of them, thirteen per cent, were fully implemented and integrated.
Forty initiatives had no recorded status in the survey and are shown as an entry of their own.
Source: AI Sweden, Vårdkartan. Data collected June to December 2024, report published April 2025
The Swedish Medical Association's survey of the regions, published in June 2025 and including eighteen of the twenty-one regions, shows where it stalls organisationally: ten of the eighteen have no policy for how AI may be used by clinical staff, thirteen call for a national recommendation, and a single region fully agrees that it has sufficient resources and competence.
The SLIT report also describes what is actually in use, and the list runs in two directions. On the administrative side there are chatbots that retrieve information for staff, automatic clinical documentation of the kind known as ambient scribes and AI-supported optimisation of scheduling. On the clinical side there is speech recognition writing straight into the record, introduced in every region to varying degrees, and mammography screening where AI reviews the low-risk images together with a breast radiologist instead of the previous double reading by two radiologists. Region Östergötland has used that solution since 2019.
The three sources point the same way, and mammography settles the data question. If access to sensitive data were what held development back, the application working on the most sensitive images of all would be the one that never reached service. It is in service, and has been since 2019. That half the initiatives sit as ongoing and only thirteen per cent as finished, while ten of eighteen regions have no policy for how AI may be used, describes an organisational bottleneck instead: more is being built than is being put into service, and what is built often lacks the governance that would allow it to go live.
What the observations mean together
Another year on the timetable sounds like relief. It is relief only for whoever uses the time.
Moving a deadline does not solve a resource shortage, and it does not solve finances. What moves is only the outer limit for when the Chapter III requirements must be met, and for most organisations that was not the binding constraint to begin with. The third item on the regions' list, unclear legislation, is partly a question of knowledge, and there a year makes a difference if it is spent working out which systems are actually covered.
There is also a risk in the extra time that is worth stating plainly. The requirements in the MDR and IVDR are unchanged. An organisation that defers its work by pointing at the AI Act's new date is not deferring anything that applies under medical device law, and that is where the bulk of the documentation effort sits.
Three steps that need no new deadline
- Establish which AI systems are already in use. Including those that entered the organisation as a feature of a system you already had. The inventory is the precondition for everything else.
- Decide your role for each of them. Provider and deployer are different things under the AI Act and carry different obligations. A care provider that builds its own tools can be both, for different systems.
- Check which are subject to a third-party conformity assessment. That condition, together with the product characteristic, is what decides the high-risk question for medical devices. Without that answer there is no way to know which of the two dates is yours.
The classification in any given case is settled together with the notified body, and that assessment has to be made before the timetable is set.
Common questions
From 2 August 2028. Medical devices fall under Annex I of the AI Act, and through amending Regulation (EU) 2026/1744 Chapter III sections 1, 2 and 3 apply to Annex I systems from that date. Systems under Annex III have an earlier date, 2 December 2027. The gap between the two is eight months.
No. The guidance AIB 2025-1 and MDCG 2025-6 on the interplay between the MDR, the IVDR and the AI Act was published in June 2025 and gives 2 August 2027 for the Annex I obligations. That date was subsequently changed to 2 August 2028 by amending Regulation (EU) 2026/1744. The substance of the guidance still stands; the timing in it does not.
According to MDCG 2025-6, two conditions must hold at the same time. The system must either be a safety component of a product or itself be a medical device, and it must be subject to a third-party conformity assessment by a notified body. If only one condition holds, the system is not high risk on that basis.
No. The guidance describes a simultaneous and complementary application of the MDR and IVDR alongside the AI Act for medical devices containing one or more high-risk AI systems. The AI Act adds requirements addressing hazards and risks specific to AI systems. It removes nothing that already applies under medical device law.
A shortage of their own resources, followed by finances and unclear legislation. This comes from the SLIT report, compiled by the network of IT directors of Sweden's healthcare regions and published in 2025, which also notes that the obstacles are the same as the year before. The figure is a ranking and not a measurement: SLIT grades the obstacles on a five-point scale, reports no percentages and does not state how many regions submitted input. Access to data is not named among the obstacles, which is worth noting because data access is often assumed to be the main problem.
AI Sweden's Vårdkartan survey, published in April 2025, counted 179 AI initiatives across seventeen of the twenty-one regions. Twenty-four of them, thirteen per cent, were fully implemented and integrated. Half sat as ongoing. The Swedish Medical Association's survey of the regions from June 2025 shows at the same time that ten of eighteen regions have no policy for how AI may be used by clinical staff.
The SLIT report names both administrative and clinical applications. Administrative: chatbots that retrieve information for staff, automatic clinical documentation of the kind known as ambient scribes, and AI-supported optimisation of scheduling. Clinical: speech recognition writing straight into the record, introduced in every region to varying degrees, and mammography screening where AI reviews the low-risk images together with a breast radiologist. Region Östergötland has used that solution since 2019.
No, for two reasons. Medical device law applies regardless, and its requirements are often the most labour-intensive. And the obstacles the regions themselves report, meaning resources and finances, are not solved by moving a deadline. An extra year is worth something to an organisation that uses it to build capacity and nothing to one that uses it to wait.
Establish which AI systems are already in use and what role the organisation holds for each of them, meaning whether it is a provider or a deployer. Then check which of them are subject to a third-party conformity assessment, because that is the condition that decides the high-risk question for medical devices. The inventory is the precondition for everything else and it needs no new deadline.
If this lands on your desk, we should talk.
Ampliro Insights
New analysis, roughly weekly.
We write when the rules change and when something turns out to work in practice. One piece at a time, no sequences, and you can leave from any issue.
We store your address to send Ampliro Insights, and for nothing else. More in the privacy policy.