News 13.08.2026 AI governance is becoming hospital governance: what the EU AI Act means for hospital leaders now

The EU AI Act entered a new implementation phase on 2 August 2026. For hospitals, the immediate priority is not simply legal compliance: it is establishing the governance needed to adopt AI safely, transparently and with clear accountability.

European Union | 14 August 2026

On 2 August 2026, the European Union Artificial Intelligence Act moved into a new phase. The transparency obligations under Article 50 became applicable, national authorities assumed broader supervisory responsibilities, and the European AI Office entered a new stage of enforcement.

Only days earlier, on 27 July 2026, the AI Omnibus entered into force, extending the timetable for high-risk AI requirements and introducing several simplifications.

For hospital leaders, the message should be neither panic nor postponement.

Hospitals are already using AI in areas that affect patients, professionals and organisational decisions: diagnostic support, clinical documentation, triage, workforce management, bed planning, procurement, patient communication and administrative workflows.

AI governance is hospital governance

AI is no longer only an IT or innovation question. It affects clinical safety, workforce decisions, patient rights, procurement, cybersecurity, data governance and organisational accountability.

The central management question is therefore not simply “Can we use this system?” It is “Can we explain why we are using it, who is responsible, how it is overseen and what happens when it fails?”

What already applies?

Several relevant parts of the AI Act are already applicable.

Prohibited practices

Certain prohibited practices have been banned since February 2025. These include harmful manipulation, social scoring and, subject to limited exceptions for medical or safety purposes, emotion recognition in the workplace.

Hospitals should ensure that experimental systems, human-resources tools and staff-monitoring applications do not introduce prohibited capabilities.

AI literacy

The AI literacy obligation has also applied since February 2025. Following the AI Omnibus, providers and deployers must still take measures to support AI literacy, but the legislation does not prescribe a uniform level or a single mandatory training format. The appropriate approach depends on the system, its users, the context and the risks involved.

For hospitals, a generic online course will rarely be enough. Clinical professionals using diagnostic support, procurement teams buying AI services, communication teams using generative AI and staff responsible for human oversight require different knowledge and guidance.

Transparency

Since 2 August 2026, Article 50 transparency obligations apply to certain interactive and generative AI systems, deepfakes, emotion-recognition tools and biometric-categorisation systems.

Interact

People must normally be informed when they are interacting directly with an AI system, such as a patient chatbot or virtual assistant.

Mark

Providers of systems generating or manipulating content must enable its artificial origin to be detected through machine-readable marking.

Inform

People exposed to emotion recognition or biometric categorisation must be informed, where those uses are permitted.

Disclose

Deepfakes and certain AI-generated publications on matters of public interest must disclose their artificial origin.

An exception may apply to public-interest text that has undergone meaningful human review or editorial control and for which a person or organisation assumes editorial responsibility.

Hospitals should translate these requirements into practical decisions. Does a patient chatbot identify itself clearly? Is a synthetic voice used in patient communication disclosed? Are AI-generated images or videos appropriately labelled? Is public-facing health information subject to real editorial review rather than a superficial approval?

Not every hospital AI system is high-risk

The classification depends on the intended purpose of the system, its effect on decisions and, in some cases, its classification under other EU product legislation.

An AI system may be high-risk when it is itself a medical device, or a safety component of a medical device, and the relevant product requires third-party conformity assessment. AI-based medical software can therefore be high-risk, but not every digital or AI tool used in a clinical environment automatically falls into this category.

The AI Act also identifies specific high-risk uses outside medical-device regulation. Hospital-relevant examples may include:

  • AI used to evaluate or classify emergency calls, determine dispatch priorities or support emergency healthcare patient triage;
  • systems used by public authorities to determine eligibility for essential public services, including certain healthcare services;
  • AI used for recruitment, candidate selection, task allocation, performance monitoring or other significant employment decisions;
  • certain biometric, emotion-recognition and critical-infrastructure applications, where they are not prohibited.

Some systems listed in Annex III may be exempted from high-risk classification when they do not pose a significant risk and do not materially influence a decision. This requires a documented, case-specific assessment. Systems that profile individuals receive stricter treatment.

Four management categories

  • Prohibited: uses that should not be deployed, including certain emotion-recognition and manipulative systems.
  • Transparency-specific: chatbots, synthetic content, deepfakes and certain biometric or emotion-recognition uses.
  • High-risk: qualifying medical-device AI and specific systems affecting triage, access to services or employment decisions.
  • Other AI: systems that may not be high-risk under the AI Act but remain subject to data protection, cybersecurity, clinical-safety, employment and contractual requirements.

Hospitals are usually deployers — but not always

A hospital that purchases and uses an AI system will generally be a deployer under the AI Act. The technology supplier will generally be the provider.

That distinction should not be taken for granted.

A hospital may assume provider responsibilities if it develops a system internally, places its own name or trademark on a system, makes a substantial modification or changes the intended purpose of an existing system. Customising a general-purpose model for a clinical or operational application can also create additional responsibilities.

Procurement and innovation teams should determine the hospital’s legal role before implementation, not after a problem occurs.

A practical 90-day agenda for hospital leaders

Days 1–30

Discover and take control

Create an organisation-wide AI inventory, including purchased systems, embedded software features, pilots, research tools and generative AI used directly by staff.

Screen for prohibited practices, “shadow AI” and Article 50 measures that should already be operational.

Days 31–60

Classify and build capability

Review higher-impact systems through a multidisciplinary group and determine the hospital’s role, the system’s risk category and the evidence required.

Introduce role-based AI literacy for clinical, management, procurement, communication and technical teams.

Days 61–90

Embed oversight and monitoring

Define executive accountability, approval routes, human oversight, performance monitoring and escalation procedures.

Establish a clear process for suspending a system when patient safety, fundamental rights or legal compliance may be at risk.

1. Map the AI already in use

For every use case, the hospital should record the system and supplier, the internal owner, its intended purpose, who uses it, who is affected, the data processed, whether it informs or makes decisions, the consequences of error and its preliminary AI Act category.

The inventory must include “shadow AI”: public tools used without formal approval to summarise records, draft clinical correspondence, translate documents or analyse internal information.

2. Strengthen procurement and contracting

Procurement documentation and contracts should address:

  • intended purpose and AI Act classification;
  • the respective responsibilities of the provider and hospital;
  • conformity status and supporting documentation;
  • evidence of performance, limitations and performance across relevant patient groups;
  • data governance, confidentiality and cybersecurity;
  • model updates, subcontractors and change notification;
  • incident reporting and cooperation;
  • audit, access, data-return, portability and termination rights.

3. Make human oversight operational

Human oversight should not be reduced to the presence of a professional somewhere in the workflow. The hospital should define who is responsible, what information that person receives and whether they have sufficient competence, time and authority to challenge the output.

Staff should know when an AI recommendation must be disregarded, how to intervene or stop the system, how overrides are documented and how automation bias will be addressed.

4. Monitor performance after implementation

Monitoring should cover more than technical availability. Hospitals should track clinical performance, false positives and negatives, subgroup differences, complaints, overrides, unexpected use, cybersecurity events, model changes and signs of performance drift.

Safety, quality, data protection and cybersecurity processes should connect to a single escalation route rather than operate in separate organisational silos.

The implementation timetable

The AI Omnibus provides additional preparation time, particularly for high-risk systems:

Date
Main implication
2 February 2025
Prohibited practices and AI literacy provisions began to apply.
2 August 2025
Governance and general-purpose AI obligations began to apply.
2 August 2026
Article 50 transparency obligations and most remaining general provisions became applicable.
2 December 2026
End of the limited marking transition for certain generative AI systems placed on the market before 2 August 2026.
2 December 2027
High-risk requirements apply to Annex III systems.
2 August 2028
High-risk requirements apply to relevant AI systems covered by Annex I product legislation, including qualifying medical devices.

The extended deadlines should be treated as an implementation runway. Hospitals need time to classify systems, renegotiate contracts, establish assessment processes, collect evidence, train staff and integrate monitoring into clinical and corporate governance.

Public bodies and private organisations providing public services may also need to conduct a fundamental-rights impact assessment before deploying certain high-risk systems. Where a data-protection impact assessment is also required, the two assessments should be coordinated.

Seven questions for every hospital board

  1. Do we know where AI is being used, including tools adopted informally by staff?
  2. Which systems affect clinical, employment or access-to-service decisions?
  3. Who is accountable for approving, monitoring and, if necessary, stopping each system?
  4. Are patients and professionals informed when transparency is required?
  5. Can the hospital demonstrate meaningful human oversight?
  6. Do our contracts give us sufficient evidence, control and protection?
  7. How would we detect and manage an AI-related safety incident?

From compliance to trust

AI can improve diagnosis, reduce administrative burden, support workforce planning and help hospitals use scarce resources more effectively. But value will not result from procurement alone.

Trustworthy adoption requires clear purpose, appropriate evidence, competent professionals, human accountability and continuous monitoring.

The most important first step is also the simplest: know where AI is already being used and who is responsible for it.

Map. Govern. Explain. Oversee. Prepare.

Responsible AI adoption begins with knowing what is already happening inside the organisation.

This article reflects the EU implementation position in August 2026 and provides general information, not legal advice. Healthcare organisations should consider applicable national legislation and obtain case-specific advice where necessary.