Tech
The EU AI Act's Big Deadline Just Passed — and Drug Discovery Got a Reprieve
August 2, 2026 was supposed to be the day the EU AI Act's toughest rules hit high-risk systems. Then the Digital Omnibus moved the goalposts. Here's what actually changed, and what it means for AI in drug discovery.
If you build AI for a living, you probably had August 2, 2026 circled in red. For two years, it was the date the European Union's landmark AI law would finally sink its teeth into "high-risk" systems — the hiring tools, the credit scorers, and, depending on who you asked, some of the software now designing tomorrow's medicines. The date arrived this week. The teeth, mostly, did not.
That's the short version of a story that has kept compliance lawyers, biotech founders, and machine-learning teams glued to Brussels all summer. The longer version is more interesting, and it matters a great deal if your work sits anywhere near the intersection of AI and drug development.
What actually happened#
The EU AI Act entered into force on August 1, 2024, as the world's first comprehensive, horizontal law for artificial intelligence, with its rules rolling out in deliberate phases (Article 113, EU AI Act). The bans on "unacceptable-risk" uses landed first, in February 2025. Obligations for general-purpose AI models followed in August 2025. And August 2, 2026 was pencilled in as the moment the framework became broadly applicable — most notably for the high-risk systems listed in Annex III (Gibson Dunn client alert).
Then reality intervened. By late 2025, the supporting machinery — standards, guidance, national supervisory bodies — simply wasn't ready. So on November 19, 2025, the European Commission tabled a package known as the Digital Omnibus on AI, and its centrepiece was a delay (Gibson Dunn). After a round of failed trilogue talks in late April, negotiators reached a provisional political deal in early May 2026, Member State representatives confirmed it days later, and by summer both the Parliament and the Council had signed off (Secure Privacy analysis; Legal Nodes).
Here's the new map. Stand-alone high-risk systems under Annex III — recruitment, credit scoring, biometric identification, law enforcement, education — now have until December 2, 2027 to comply, a delay of roughly sixteen months. AI baked into regulated products under Annex I, a bucket that explicitly includes medical devices, machinery, and vehicles, gets even longer: until August 2, 2028 (Gibson Dunn).
So August 2 wasn't a non-event. The transparency rules under Article 50 still switched on as planned — the requirement to tell people when they're talking to an AI, and to mark AI-generated content with machine-readable watermarks. Systems already on the market got a four-month grace period, to December 2, 2026, before the watermarking duty bites (Gibson Dunn). The Omnibus also folded in a fresh prohibition on AI "nudifiers" and child sexual abuse material, with its own transitional window. But the marquee event — full high-risk obligations covering risk management, data governance, technical documentation, human oversight, and cybersecurity — got kicked down the road.
Why it matters for AI in biology and drug discovery#
For anyone doing computational drug design, the headline is reassuring, if a little anticlimactic. Most of the tools that dominate the field — generative chemistry models, protein-structure predictors, target-identification engines running over genomics and literature — never sat squarely in the high-risk bucket to begin with. The Act carves out an exemption for AI developed and used solely for scientific research, along with research, testing, and development that happens before a system is placed on the market (Article 2, via Pinsent Masons). A model that proposes candidate molecules in a lab, and never touches a patient or a regulatory submission, largely lives outside the Act's heaviest reach.
The friction was always going to appear where AI crosses from the bench toward the clinic. Software that supports diagnosis, that steers a clinical trial's design, or that ships inside a regulated medical device — that's where Annex I and the medical-device rules converge, and where "high-risk" starts to mean something concrete. Pharmaceutical companies have spent months asking Brussels for a clean line between low-risk early discovery and high-risk regulatory-facing applications, and that line is still being drawn (Pinsent Masons). The Omnibus doesn't answer the question so much as buy everyone time to answer it: medical-device AI now has until August 2028.
The delay lands at a pivotal moment for the field, because the technology has finally started producing clinical evidence rather than just press releases. The clearest example is Insilico Medicine's rentosertib, a TNIK inhibitor for idiopathic pulmonary fibrosis whose target was identified by AI and whose molecule was designed by generative models. In 2025, Nature Medicine published the Phase IIa results: patients on the 60 mg once-daily dose saw mean lung function (forced vital capacity) improve by +98.4 mL at 12 weeks, against a −20.3 mL decline in the placebo group (Nature Medicine publication, via PR Newswire). It is widely described as the first peer-reviewed Phase IIa readout for a molecule whose target and structure both came from generative AI, and the program has since advanced into a Phase III trial (Insilico Medicine).
That is exactly the kind of program that would eventually run into the Act's high-risk provisions once it produces software or evidence feeding a regulatory decision. A sixteen-month extension is nothing when you're trying to build a compliance function from scratch while also running a Phase III.
The catch: a reprieve is not a repeal#
It's tempting to read the delay as Brussels blinking. That reading is too neat. The lawyers who dissected the Omnibus are blunt about it: this is "a deferral rather than a dismantling," and the Act's core architecture — its risk tiers, its governance structure, its central obligations — is fully intact (Gibson Dunn).
Three caveats deserve to be pinned to the wall.
First, the new dates only bind once the Omnibus is formally adopted and published in the Official Journal. Until that ink is dry, the old timeline technically still governs, which is a strange limbo to plan around (Gibson Dunn). Second, the penalty regime is already live, and it is not gentle: prohibited-use violations can draw fines of up to €35 million or 7% of worldwide annual turnover, whichever is greater; high-risk non-compliance runs to €15 million or 3%; and even feeding regulators bad information tops out at €7.5 million or 1% (Article 99, EU AI Act). Third — and this one is easy to miss — the Omnibus quietly broadened the legal basis for processing sensitive personal data to detect and correct bias, extending it from high-risk providers to all AI systems and general-purpose models, under a strict necessity test (Gibson Dunn).
That last point is where the regulatory story loops back to a debate I care about: the ethics of the data we train on. Bias detection in health AI is only as honest as the data underneath it, and models trained on lopsided clinical datasets can quietly encode who gets studied and who gets ignored. The Act's growing focus on data governance is a reminder that "move fast" and "train on whatever we can scrape" are not costless defaults, even when the near-term compliance clock has been paused.
There's also a strategic risk hiding in the reprieve. Extra runway invites teams to defer the unglamorous work — data lineage, documentation, human-oversight design — until the deadline looms again. The advice from every compliance shop reading the tea leaves is the same: treat 2027 and 2028 as headroom to build properly, not permission to wait (Gibson Dunn). A compliance framework, like a Phase III trial, takes longer to stand up than anyone budgets for.
What to do with this if you're building#
If your AI stops at candidate generation and never leaves the research setting, breathe easy and keep documenting your methods anyway — good data hygiene is its own reward. If your roadmap runs toward diagnostics, clinical decision support, or a regulated device, use the 2028 window to map which parts of your stack land in Annex I, and start the risk-management and documentation work now rather than in the frantic quarter before the date. And whatever you're building, assume the transparency and data-governance expectations are the floor, not the ceiling. The direction of travel in Europe is clear even when the dates keep sliding.
FAQs#
Did the EU AI Act's high-risk rules take effect on August 2, 2026? No. The Article 50 transparency obligations took effect on schedule, but the full high-risk obligations for Annex III systems were deferred to December 2, 2027, and for AI embedded in regulated products under Annex I to August 2, 2028, via the Digital Omnibus (Gibson Dunn).
Does the Act regulate AI used in drug discovery? Mostly not at the discovery stage. AI developed and used solely for scientific research and pre-market R&D is exempt. Regulation kicks in when AI moves toward clinical use, regulatory submissions, or medical devices (Pinsent Masons).
What are the penalties for getting it wrong? Up to €35 million or 7% of global annual turnover for prohibited uses; up to €15 million or 3% for high-risk non-compliance; up to €7.5 million or 1% for supplying incorrect information (Article 99, EU AI Act).
Is there real clinical evidence that AI-designed drugs work? There's early, peer-reviewed evidence. Insilico Medicine's rentosertib, an AI-discovered and AI-designed TNIK inhibitor, showed a mean +98.4 mL forced vital capacity improvement versus a −20.3 mL placebo decline in a Phase IIa trial published in Nature Medicine, and has advanced to Phase III (PR Newswire; Insilico Medicine). One positive Phase IIa is a proof point, not proof — the field needs many more readouts.
Are the delayed dates final? They bind only once the Omnibus is formally adopted and published in the EU's Official Journal. Until then, plan against the possibility that the original timeline still applies (Gibson Dunn).
Sources#
- Article 113: Entry into force and application — EU AI Act Service Desk (European Commission)
- Article 99: Penalties — EU Artificial Intelligence Act
- EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes — Gibson Dunn (client alert)
- Pharmaceutical companies face wait on EU AI regulation question — Pinsent Masons
- EU AI Act Digital Omnibus: The New High-Risk AI Deadlines After Council Approval — Secure Privacy
- EU AI Act 2026 Updates: Compliance Requirements and Business Risks — Legal Nodes
- Insilico Medicine Announces Nature Medicine Publication of Phase IIa Results for Rentosertib — PR Newswire (peer-reviewed study in Nature Medicine, 2025)
- Insilico Initiates Phase III Clinical Trial for Rentosertib — Insilico Medicine