Eunomia perspective · 2026-09-30 · AI & Digital Compliance, Regulatory Updates & Compliance News
The EU AI Act for Pharmaceutical Companies: What Applies and When
Published by Eunomia Pharma Services · Updated
What does the EU AI Act mean for pharmaceutical companies?
The Act entered into force on 1 August 2024. Prohibitions and AI literacy apply from 2 February 2025 and general-purpose AI rules from 2 August 2025. After the 2026 AI Omnibus, high-risk rules apply from 2 December 2027 for Annex III uses such as recruitment, and 2 August 2028 for AI in regulated products such as medical devices.
Practical steps
- List the AI systems you use or plan to use.
- Classify each by risk category.
- Put AI literacy measures and human oversight in place.
- Add AI disclosures where Article 50 applies.
- Connect AI governance to GDPR, vendor due diligence and promotional review.
The practical steps above are Eunomia’s operational guidance. See the source notes below for the scope of the external references.
The EU AI Act, Regulation (EU) 2024/1689, is the first comprehensive EU law on artificial intelligence. It entered into force on 1 August 2024 and applies in stages. In July 2026, an amending regulation, known as the AI Omnibus (Regulation (EU) 2026/1744), changed several dates. This guide explains what matters for pharmaceutical and biotech companies, based on the regulation and the European Commission’s guidance.
Key dates, as amended
| What | Applies from |
|---|---|
| Prohibited AI practices and AI literacy | 2 February 2025 |
| Governance rules and obligations for general-purpose AI models | 2 August 2025 |
| General application of the Act | 2 August 2026 |
| High-risk AI in sensitive use cases (Annex III), such as employment | 2 December 2027 |
| High-risk AI embedded in regulated products (Annex I), including medical devices | 2 August 2028 |
The Commission states that the AI Omnibus entered into force on 27 July 2026. Some new prohibitions it added apply from 2 December 2026.
Which pharma uses could be high-risk?
Under Article 6(1), an AI system is high-risk if it is a safety component of, or is itself, a product covered by the EU harmonisation legislation in Annex I, and that product needs a third-party conformity assessment. Annex I includes the Medical Devices Regulation (EU) 2017/745 and the In Vitro Diagnostic Regulation (EU) 2017/746. AI in software that qualifies as a medical device or diagnostic can therefore fall in scope.
Annex III lists other high-risk areas. For most pharma companies, the most relevant is employment and workers’ management, which covers AI used to place targeted job adverts, filter applications and evaluate candidates.
If you use high-risk AI
Deployers of high-risk systems have obligations under Article 26, including using the system according to its instructions, assigning human oversight to people with the necessary competence, training and authority, monitoring its operation, keeping logs for at least six months, informing workers’ representatives and affected workers before using high-risk AI at work, and using the provider’s information to carry out a data protection impact assessment where required.
Obligations that apply more widely
- AI literacy (Article 4). As amended by the AI Omnibus, providers and deployers must take measures to support the development of AI literacy of their staff and others using AI systems on their behalf. The amended text says this does not require guaranteeing a specific level of AI literacy for any individual.
- Prohibited practices (Article 5). These include manipulative techniques causing significant harm, exploiting vulnerabilities, social scoring and emotion recognition in the workplace, except for medical or safety reasons.
- Transparency (Article 50). People must be told when they are interacting with an AI system, such as a chatbot, unless it is obvious. Providers must ensure AI-generated content is marked as artificially generated in a machine-readable format (for systems already on the market before 2 August 2026, by 2 December 2026), and deployers must disclose deep fakes.
Beyond the AI Act
AI in pharma is also shaped by other rules. The GDPR applies to personal data used in or produced by AI. The European Medicines Agency’s reflection paper on the use of AI in the medicinal product lifecycle, adopted in September 2024, sets out principles for AI and machine learning from drug discovery to post-authorisation. For commercial compliance, AI-generated promotional content still needs review and certification under the ABPI Code.
A practical starting point
- List the AI systems you use or plan to use, including in HR, medical information, content creation and compliance.
- Classify each: prohibited, high-risk, transparency obligations only, or minimal risk.
- Put AI literacy measures and human oversight in place for the people who use them.
- Add chatbot and AI-content disclosures where Article 50 applies.
- Connect AI governance to data protection, vendor due diligence and promotional review.
Our automation service includes AI compliance readiness assessments. This article summarises the AI Act as amended in 2026; it is not legal advice.
Sources and scope
- Regulation (EU) 2024/1689 (EU AI Act)
Articles 4, 5, 6, 26, 50 and 113, and Annexes I and III.
- Regulation (EU) 2026/1744 (AI Omnibus)
Amended application dates and Article 4.
- European Commission: AI Act regulatory framework
Entry into force, application timeline and Omnibus status.
- EMA: Reflection paper on AI in the medicinal product lifecycle
Principles for AI across the medicines lifecycle, adopted September 2024.
External sources accessed 30 September 2026. Check the applicable country rules and current source text for a specific engagement.
