Back to blog
ComplianceAugust 5, 2026·18 min read

The EU AI Act and pharma: what applies now, what moved to 2027, and where to start

The EU AI Act's transparency obligations became applicable on 2 August 2026, while the high-risk rules moved to 2027 and 2028. What Article 50 actually requires, why public-health content can fall within its scope, and the practical steps for pharma teams to take now.

Most of what pharma teams heard about the EU AI Act this summer was that it had been delayed. That is half true, and the half that is wrong is the half that is already in force. On 2 August 2026, the Act's transparency obligations became applicable, and breaches of them became subject to the Act's penalty regime from the same date. What moved to 2027 and 2028 are the high-risk requirements — and many ordinary commercial and medical-content use cases will not be high-risk simply because a pharmaceutical company is running them.

The result is an awkward gap between perception and obligation. Teams that read “delayed” and stood down may be exposed on duties that are live now, and are mostly inexpensive to meet. Teams that read “high-risk” and started building conformity-assessment programs may be preparing for a regime they never enter. This is an orientation for people who need to work out which of those two mistakes they are making.

What actually moved, and what did not

The Digital Omnibus on AI was endorsed by the European Parliament on 16 June 2026 and approved by the Council on 29 June 2026. It was signed on 8 July, published in the Official Journal on 24 July as Regulation (EU) 2026/1744, and entered into force on 27 July 2026 — an unusually compressed timetable, justified in the regulation itself by the fact that the application date it was amending fell on 2 August. It is the first amendment to the AI Act since its adoption, and it deferred the deadlines that were about to bite hardest.

ObligationApplies from
Prohibited practices (Article 5)2 February 2025 — in force
AI literacy (Article 4)2 February 2025 — in force, since amended
General-purpose AI model obligations (Articles 53–55)2 August 2025 — in force; models already on the market before that date have until 2 August 2027
Transparency (Article 50)2 August 2026 — in force
Machine-readable marking, Article 50(2), for generative systems already on the market2 December 2026
High-risk systems under Article 6(2) / Annex III2 December 2027 — moved from 2 August 2026
High-risk AI in regulated products (Annex I)2 August 2028 — moved from 2 August 2027

Read that table twice. The delay was real, it was substantial, and it applied to none of the rows a typical pharma commercial or medical organization is most likely to be caught by. Article 50 in particular was left on its original date, and it applies to any AI system used in the situations it describes, whether or not that system is high-risk.

The two questions that decide everything else

Before any obligation can be answered, two classifications have to be made — per system, not per company.

1. Are you the provider or the deployer?

A provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark. A deployer uses an AI system under its own authority in the course of a professional activity. Nearly every obligation in the Act attaches to one role or the other, so getting the role wrong means answering the wrong question carefully.

The trap here is specific and common. Pharma organizations buy AI capability far more often than they build it, and reasonably assume that makes them deployers of everything. But the provider definition does not turn simply on who wrote the code: an organization can also be a provider where it has an AI system developed and places it on the market or puts it into service under its own name or trademark. A symptom checker, a patient-support assistant, or an HCP-facing chat interface commissioned from a vendor and launched under your own brand therefore deserves a specific provider-or-deployer analysis, rather than an assumption that the vendor carries every obligation. Article 25 deals separately with high-risk systems, where a deployer becomes the provider by putting its name or trademark on the system, substantially modifying it, or changing its intended purpose so that it becomes high-risk. Where your name is on the product, this is a question for counsel rather than for an assumption.

2. Is the system high-risk?

Usually not, and this is where the honest answer is more useful than a confident one. The high-risk categories in Annex III cover biometrics, critical infrastructure, education, employment and worker management, access to essential public and private services, law enforcement, migration, and the administration of justice. Nothing there names pharmaceutical research, medical affairs, or commercial work. The realistic routes into the high-risk regime are Annex I — where AI is a safety component of a product already regulated under EU law, most obviously a medical device — or a use case that happens to sit inside one of the Annex III categories despite not looking like it.

What deserves saying plainly is that the classification of AI in pharmaceutical work has not been definitively settled by the regulators. Industry bodies have argued that most medicines R&D falls outside the high-risk requirements; that reading is reasonable and has not been officially confirmed. The defensible position is not a blanket claim in either direction, but a written analysis per system, with the reasoning recorded and a list of the changes that would require you to revisit it. A reviewer who reads a considered memo responds very differently to one who reads an assertion.

Article 50, the part that is live

Article 50 imposes four duties, split between providers and deployers.

  • Systems that interact directly with people must say they are AI (50(1), on providers). The disclosure has to arrive at the latest at the first interaction, and be clear and distinguishable. There is an exception where the AI nature is obvious to a reasonably well-informed, observant, and circumspect person — and the Commission's guidance reads that exception narrowly.
  • Generative systems must mark their outputs (50(2), on providers). Synthetic audio, image, video, and text must be marked in a machine-readable format and detectable as artificially generated. The obligation does not reach systems performing only an assistive function for standard editing, or systems that do not substantially alter the input data or its semantics — a grammar checker is out; a drafting tool is not.
  • Emotion recognition and biometric categorization must be disclosed to the people exposed to them (50(3), on deployers). Note the narrow statutory meaning: an emotion recognition system is one that identifies or infers emotions or intentions on the basis of biometric data. Certain voice- or facial-analysis systems used in research or customer interactions can qualify. Ordinary text sentiment analysis, of the kind that scores survey responses or social posts, generally does not.
  • Deployers must disclose deepfakes and AI-generated public-interest text (50(4)). This is the paragraph that reaches furthest into everyday pharma content work, and it deserves its own section.

Why 50(4) is the one for pharma content teams

Article 50(4) requires a deployer publishing AI-generated or AI-manipulated text to inform the public on matters of public interest to disclose that the text is artificially generated. The obvious question is what counts as a matter of public interest — and the Commission's guidance answers it with a list that includes politics and democratic processes, public administration and services, the administration of justice, fundamental rights, public security, environmental protection, consumer safety, and public health.

Public health is named. That brings a good deal of ordinary pharma output within reach of the paragraph: disease-awareness content, patient education material, unbranded condition information, and much of what sits on a corporate newsroom.

Reach is not the same as capture, though, and the three conditions all have to be met. The text must be AI-generated or AI-manipulated, it must be published, and it must be published with the purpose of informing the public on a matter of public interest. It is not enough that the publisher happens to be a pharmaceutical company: an internal medical summary is not published, and human-written copy is outside the paragraph however it was researched. Purely promotional copy may fall outside the provision where its purpose is commercial rather than to inform the public, but the boundary is fact-specific — particularly where promotional material also communicates health information. The question is asked per piece of content, not per department.

The image, audio, and video limb of 50(4) is narrower than it is usually reported. It applies where the content constitutes a deepfake, which the Act defines as AI-generated or manipulated image, audio, or video that resembles existing persons, objects, places, entities, or events and would falsely appear to a person to be authentic or truthful. So an AI-generated patient testimonial that depicts or imitates a real patient, or that appears to document a real event, may well require disclosure. A clearly synthetic animation, a fictional avatar, or a generic AI voiceover does not fall into the provision merely because AI produced it. That distinction is worth getting right before it drives a labeling policy across a content library.

For text, though, there is an exception, and it is the most useful sentence in the Act for pharma: disclosure is not required where the content has undergone a process of human review or editorial control and a natural or legal person holds editorial responsibility for its publication. The Commission's guidance sets the bar for that review — a deliberate examination of the substance by people with relevant knowledge, plus an editor with the authority to approve or reject. A spell-check does not qualify.

Read that against how pharma already works. Medical, legal, and regulatory review is a substantive examination by qualified reviewers who can and do reject content, with a named approver and an audit trail. A robust MLR process may therefore be unusually well positioned to satisfy this exception — better positioned than the equivalent function in most other industries, which is a rare instance of pharma governance being an advantage rather than a drag.

Two qualifications keep that from becoming an overstatement. The exception is not conferred by having an MLR function in the abstract; the review and the editorial responsibility have to exist for the publication concerned, which means a fast-tracked or waived review is exactly the case where the exception is weakest. And while the Act does not make documentation a separate condition of the exception, an organization that is challenged will need to demonstrate that the conditions were genuinely met — which makes the review record and the approval trail the evidence that decides the question. For most pharma teams, that is a process-documentation exercise rather than a technology project.

The December 2026 date most people have not diarized

Article 50(2)'s marking obligation applied from 2 August 2026, with one transitional carve-out: providers of generative AI systems that were already on the EU market before that date have until 2 December 2026. Anything placed on the market on or after 2 August 2026 complies immediately, with no transition at all — which is a detail worth knowing before launching an AI feature this autumn.

The Act does not prescribe a technique. Watermarks, metadata, cryptographic provenance indicators, and fingerprinting are all contemplated, and the requirement is that the solution be effective, interoperable, robust, and reliable as far as technically feasible. The Commission's Code of Practice on Transparency of AI-generated Content, finalized in June 2026, has been assessed by the Commission and the AI Board as an adequate voluntary means of demonstrating compliance. Adherence is not conclusive proof that you have complied, and providers remain free to use other adequate methods — but if you are a provider with marking to do, the Code is a better starting point than an invented in-house scheme.

AI literacy: softened, but still live

Article 4 has applied since 2 February 2025 and is the obligation most often missed, because it predates the parts everyone was watching. The Digital Omnibus softened it: where providers and deployers previously had to ensure a sufficient level of AI literacy among staff operating AI systems, they must now support its development. That is a duty of effort rather than of result, which lowers the bar and changes the question you will be asked. It is no longer “can you prove your people reached a particular level” but “what measures did you take?” — and you should be able to document the answer.

The other rulebook, which pharma will be asked about first

In practice, an AI governance conversation inside a pharma company rarely opens with the AI Act. It opens with the medicines regulators, and the vocabulary is different.

The EMA's reflection paper on the use of AI in the medicinal product lifecycle, finalized in September 2024 and adopted by both the CHMP and the CVMP, covers the whole lifecycle from discovery through post-authorization pharmacovigilance. Its central expectation is that companies perform a regulatory impact and risk analysis of their AI uses, on a risk-based and human-centred approach. In January 2026 the EMA and the FDA published a joint set of ten guiding principles for good AI practice in drug development — not binding, but a clear signal of the shared framework that future guidance from both agencies will rest on, emphasizing human oversight, risk management, data governance, lifecycle controls, and transparency. Application-specific guidance, including on AI in pharmacovigilance, is still developing.

The two regimes are separate bodies of law and they will not merge, but they point the same way: know what your AI systems do, keep a human accountable for what they produce, validate that they work as claimed, and be able to show your reasoning. A company that can answer the EMA question well is most of the way to answering the AI Act question.

Where to start

For most pharma commercial and medical teams the immediate work is likely to be proportionate rather than programmatic: inventory the systems, establish the roles, identify which Article 50 situations you are actually in, and record the resulting decisions. The exception is Article 50(2) — if you are a provider of a generative system, marking is a genuine technical implementation, not a documentation exercise. In rough order of return on effort:

  • Inventory the AI, including the AI you did not buy as AI. You cannot classify what you have not listed, and in most organizations the majority of AI arrived as a feature of something else — inside the CRM, the content management system, the analytics suite, the agency's production stack. Ask agencies and vendors directly what is generative in what they deliver to you.
  • Record the role for each system: provider or deployer. Then look hard at anything carrying your brand that a third party built, because that is where the answer is most often wrong and most consequential.
  • Label the interfaces people talk to. If a patient, caregiver, or HCP can converse with it, it should say it is AI at the first interaction, clearly. This is the cheapest item on the list and the easiest to be caught on.
  • Decide the policy for AI-generated public-facing text — and make sure MLR can evidence editorial responsibility. Either you disclose, or you rely on the review exception. If you rely on it, you should be able to show a substantive review by qualified people, a named person with authority to reject, and a decision trail. Most pharma review processes already work this way; comparatively few describe themselves in the Act's terms.
  • Put two questions to every AI vendor in writing. Are you the provider of this system, and how do you satisfy the Article 50(2) marking obligation? Get the answers into the contract or the data processing agreement rather than an email thread, and collect them in the same pass as your existing vendor reviews.
  • Diary the two dates. 2 December 2026 for the marking transition, 2 December 2027 for high-risk. The risk of a deferral is not that anyone forgets the date; it is that “delayed” quietly becomes “dropped.”
  • Take — and record — proportionate AI-literacy measures. Identify who uses which systems, what those people need to understand about them, what guidance or training you provide, and how known limitations are communicated. Article 4 asks you to take account of your staff's technical knowledge and training, the context of use, and the people the systems are used on, so the substance is the measures; the written record is what evidences them.
  • Assemble one AI fact sheet. Purpose, models, data seen, human oversight points, classification, and marking approach for each system. AI governance questionnaires have become standard procurement furniture, and answering them from a prepared page is faster than reconstructing the answer each time.

What is still genuinely unsettled

Three things, and it is better to hold them as open than to paper over them. The classification of pharmaceutical AI use cases has not been confirmed by regulators, so reasoned positions are doing work that official guidance will eventually do. The practical standard for machine-readable marking is still consolidating around the Code of Practice rather than a fixed technical specification. And enforcement sits with national market surveillance authorities across 27 member states, so the first real test cases — and the tone they set — will depend on which regulators move first.

Uncertainty of that kind is an argument for documenting your reasoning, not for waiting. For many pharma commercial and medical teams, most of the immediate work is knowing what you are running, disclosing AI where required, and keeping evidence of the decisions and human oversight behind it. Providers subject to Article 50(2) additionally face a genuine technical marking obligation. Pharma is better set up for the rest than most industries — much of it is writing down what you already do.

Common questions

Does the EU AI Act apply to pharmaceutical companies?

Potentially yes. Pharma is not exempt, but the Act regulates AI systems by role and by use rather than by industry, so whether a given obligation applies depends on the system, the organization's role, and the use case. A pharma company will commonly be a deployer when it uses an AI system under its own authority for professional purposes, and can be a provider where it develops a system, or has one developed, and places it on the market or puts it into service under its own name or trademark. There are scope exclusions, including for AI developed and put into service solely for scientific research and development, and for research, testing, or development activity before a system is placed on the market. The Act also reaches beyond the EU: it applies to providers and deployers located in a third country where the output produced by the system is used in the Union, so a Swiss, UK, or US company serving EU affiliates can be in scope.

What changed on 2 August 2026?

The transparency obligations in Article 50 became applicable and enforceable on 2 August 2026. They cover four situations: AI systems that interact directly with people must disclose that they are AI; providers of generative AI must mark synthetic outputs in a machine-readable format; deployers of emotion-recognition and biometric categorization systems must inform the people exposed to them; and deployers must disclose deepfakes and AI-generated text published to inform the public on matters of public interest. These duties are not limited to high-risk systems.

Was the EU AI Act delayed?

Parts of it were, and the headlines overstated it. The Digital Omnibus — endorsed by the European Parliament on 16 June 2026 and approved by the Council on 29 June 2026 — deferred the high-risk obligations for stand-alone Annex III systems from 2 August 2026 to 2 December 2027, and for AI embedded in regulated products under Annex I to 2 August 2028. It did not defer Article 50 transparency, which took effect on schedule, and it did not touch the prohibited practices or the AI-literacy duty that have applied since February 2025.

Is AI used in pharma classified as high-risk under the AI Act?

Usually not, but the position is genuinely unsettled and should be reasoned through rather than assumed. Nothing in Annex III — the stand-alone high-risk list covering areas such as biometrics, employment, essential services, law enforcement, and justice — names pharmaceutical or life-science use cases. The realistic routes into high-risk are Annex I, where AI is a safety component of a product already regulated under EU law such as a medical device, or a use that happens to fall inside an Annex III category. Industry bodies have argued that most medicines R&D sits outside the high-risk regime, and that reading has not been officially confirmed. Treat classification as a documented analysis per system, not a blanket answer.

Do pharma companies have to label AI-generated marketing and medical content?

Sometimes, and the test is narrower than it is often reported. Article 50(4) requires deployers who publish AI-generated or AI-manipulated text with the purpose of informing the public on matters of public interest to disclose that the text is artificially generated, and the European Commission's guidance names public health as one of those matters. All three elements must be present: the text must be AI-generated or manipulated, published, and published to inform the public on such a matter. There is an important exception: disclosure is not required where the content has undergone a process of human review or editorial control and a natural or legal person holds editorial responsibility for its publication, which a substantive MLR process may be well positioned to satisfy. For image, audio, and video, the duty applies where the content constitutes a deepfake — AI-generated or manipulated content resembling existing persons, objects, places, entities, or events that would falsely appear authentic or truthful — not to every synthetic asset.

What is the deadline for machine-readable marking of AI-generated content?

Article 50(2) applies from 2 August 2026, with one transitional carve-out: providers of generative AI systems that were already on the EU market before that date have until 2 December 2026 to meet the marking and detection requirement. Systems placed on the market on or after 2 August 2026 have no transition period and must comply immediately. The Commission's Code of Practice on Transparency of AI-generated Content, finalized in June 2026, has been confirmed by the Commission and the AI Board as an adequate voluntary route to demonstrating compliance.

Who is a provider and who is a deployer under the AI Act?

A provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark. A deployer uses an AI system under its own authority, other than in a purely personal non-professional activity. The distinction decides which obligations you carry, and it is not always what an organization assumes: commissioning a system from a vendor and launching it under your own brand can make you the provider, so a branded assistant deserves a specific analysis rather than an assumption that the vendor carries everything. Article 25 sets out separately how a deployer becomes the provider of a high-risk system — by applying its name or trademark to it, by substantially modifying it, or by changing its intended purpose so that it becomes high-risk.

What are the penalties for breaching the AI Act transparency rules?

Breaches of Article 50 can attract fines of up to €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher; for SMEs and start-ups the lower of the two applies. Enforcement is decentralized to the national market surveillance authorities designated by each member state, so the intensity of enforcement will vary across the Union. Article 50 became applicable on 2 August 2026, and breaches from that date are subject to the Act's penalty regime.


This article is general information about a developing regulatory landscape, accurate as at 5 August 2026. It is not legal advice, and classification under the AI Act depends on the specifics of each system and each deployment. Confirm your position with qualified counsel before relying on it.