The ground moved under medical-device AI compliance this summer.
The Digital Omnibus on AI — Regulation (EU) 2026/1744, in force since 27 July 2026 — re-dated the EU AI Act's high-risk obligations while Article 50 transparency went live. Any MDR × AI-Act position delivered before July now has a delta. This page is about finding yours.
Three clocks where there used to be one
| Obligation set | Position before July | Position now |
|---|---|---|
| Annex I embedded high-risk (incl. MDR/IVDR-route devices) | 2 August 2026 | 2 August 2028 — Reg (EU) 2026/1744, Recital (40) |
| Annex III standalone high-risk | 2 August 2026 | 2 December 2027 — Reg (EU) 2026/1744, Recital (40) |
| Article 50 transparency (chatbots, generated content, deepfake labelling) | 2 August 2026 | In force since 2 August 2026 — unchanged, and widely skipped past |
The omnibus also narrowed Article 6 classification, rewired parts of conformity assessment (including the 28 January 2028 notified-body deadline), largely moved machinery-embedded AI out of scope, and left Commission GPAI enforcement powers live. For a boutique advising on AiMD, the double burden didn't get lighter — it got re-dated, unevenly. A roadmap drawn in June points at the wrong dates in three directions at once.
The same thing happened in the US, worse
Colorado repealed SB 24-205 before a single obligation ever bound anyone, and reenacted a different statute at the same section numbers — SB 26-189, effective 1 January 2027. The successor contains no reasonable-care duty, no impact-assessment requirement, and no NIST safe harbour. Old 6-1-17xx citations still resolve — to text that says something else. Any control mapping citing the old sections is now pointing at the wrong provisions, and nothing about it announces itself as broken.
In our database, the predecessor's 24 obligations are flagged superseded — with the dated, sourced reason — and the successor's 53 obligations sit alongside them. Superseded obligations are never deleted, because the difference between the two statutes is the useful part.
What ReguLume does with this
ReguLume maintains 2,993 current obligations across 16 AI and data regulations — including all 334 from the EU AI Act as amended — decomposed to individual, enforceable obligation points from the legal text. Every obligation carries the verbatim source excerpt, the source link, and its article reference. When law moves, obligations are flagged superseded, never deleted. Cross-regulation references connect the frameworks — the layer that answers what an MDR-conformity position covers, and doesn't cover, under the AI Act.
We track this continuously as a subscription. How we decompose, verify, and keep it current — including the limits of our pipeline — is published openly on our methodology page.
Get your delta readout — free
We're running a research study on how boutique medical-device regulatory teams track post-omnibus regulatory change. Twenty minutes of your experience; in return you get the aggregate findings and a personalized delta readout — what changed across the regulations you advise on, at obligation level, with the amending text linked for every entry.
Request the readout Browse the obligation library
ReguLume provides regulatory intelligence, not legal advice. Verify against the cited primary sources — Reg (EU) 2026/1744 (EUR-Lex) and Colorado Session Law ch. 131 — before relying on any date or obligation on this page.