All resources

Eunomia perspective · 2026-09-30 · AI & Digital Compliance, Regulatory Updates & Compliance News

The EU AI Act for Pharmaceutical Companies: What Applies and When

Published by Eunomia Pharma Services · Updated

What does the EU AI Act mean for pharmaceutical companies?

The Act entered into force on 1 August 2024. Prohibitions and AI literacy apply from 2 February 2025 and general-purpose AI rules from 2 August 2025. After the 2026 AI Omnibus, high-risk rules apply from 2 December 2027 for Annex III uses such as recruitment, and 2 August 2028 for AI in regulated products such as medical devices.

Practical steps

  1. List the AI systems you use or plan to use.
  2. Classify each by risk category.
  3. Put AI literacy measures and human oversight in place.
  4. Add AI disclosures where Article 50 applies.
  5. Connect AI governance to GDPR, vendor due diligence and promotional review.

The practical steps above are Eunomia’s operational guidance. See the source notes below for the scope of the external references.

The EU AI Act, Regulation (EU) 2024/1689, is the first comprehensive EU law on artificial intelligence. It entered into force on 1 August 2024 and applies in stages. In July 2026, an amending regulation, known as the AI Omnibus (Regulation (EU) 2026/1744), changed several dates. This guide explains what matters for pharmaceutical and biotech companies, based on the regulation and the European Commission’s guidance.

Key dates, as amended

WhatApplies from
Prohibited AI practices and AI literacy2 February 2025
Governance rules and obligations for general-purpose AI models2 August 2025
General application of the Act2 August 2026
High-risk AI in sensitive use cases (Annex III), such as employment2 December 2027
High-risk AI embedded in regulated products (Annex I), including medical devices2 August 2028

The Commission states that the AI Omnibus entered into force on 27 July 2026. Some new prohibitions it added apply from 2 December 2026.

Which pharma uses could be high-risk?

Under Article 6(1), an AI system is high-risk if it is a safety component of, or is itself, a product covered by the EU harmonisation legislation in Annex I, and that product needs a third-party conformity assessment. Annex I includes the Medical Devices Regulation (EU) 2017/745 and the In Vitro Diagnostic Regulation (EU) 2017/746. AI in software that qualifies as a medical device or diagnostic can therefore fall in scope.

Annex III lists other high-risk areas. For most pharma companies, the most relevant is employment and workers’ management, which covers AI used to place targeted job adverts, filter applications and evaluate candidates.

If you use high-risk AI

Deployers of high-risk systems have obligations under Article 26, including using the system according to its instructions, assigning human oversight to people with the necessary competence, training and authority, monitoring its operation, keeping logs for at least six months, informing workers’ representatives and affected workers before using high-risk AI at work, and using the provider’s information to carry out a data protection impact assessment where required.

Obligations that apply more widely

  • AI literacy (Article 4). As amended by the AI Omnibus, providers and deployers must take measures to support the development of AI literacy of their staff and others using AI systems on their behalf. The amended text says this does not require guaranteeing a specific level of AI literacy for any individual.
  • Prohibited practices (Article 5). These include manipulative techniques causing significant harm, exploiting vulnerabilities, social scoring and emotion recognition in the workplace, except for medical or safety reasons.
  • Transparency (Article 50). People must be told when they are interacting with an AI system, such as a chatbot, unless it is obvious. Providers must ensure AI-generated content is marked as artificially generated in a machine-readable format (for systems already on the market before 2 August 2026, by 2 December 2026), and deployers must disclose deep fakes.

Beyond the AI Act

AI in pharma is also shaped by other rules. The GDPR applies to personal data used in or produced by AI. The European Medicines Agency’s reflection paper on the use of AI in the medicinal product lifecycle, adopted in September 2024, sets out principles for AI and machine learning from drug discovery to post-authorisation. For commercial compliance, AI-generated promotional content still needs review and certification under the ABPI Code.

A practical starting point

  • List the AI systems you use or plan to use, including in HR, medical information, content creation and compliance.
  • Classify each: prohibited, high-risk, transparency obligations only, or minimal risk.
  • Put AI literacy measures and human oversight in place for the people who use them.
  • Add chatbot and AI-content disclosures where Article 50 applies.
  • Connect AI governance to data protection, vendor due diligence and promotional review.

Our automation service includes AI compliance readiness assessments. This article summarises the AI Act as amended in 2026; it is not legal advice.

Sources and scope

External sources accessed 30 September 2026. Check the applicable country rules and current source text for a specific engagement.

Put this into practice