The Regulatory Realignment of Omnibus VII: Implications for European HealthTech and MedTech
- Nelson Advisors

- Jul 1
- 14 min read

The adoption of the "Omnibus VII" legislative package by the Council of the European Union on June 29th, 2026, marks a pivotal juncture in the European Union’s digital governance framework. Driven by strategic evaluations of European competitiveness, principally the landmark reports by former European Central Bank President Mario Draghi and former Italian Prime Minister Enrico Letta, this legislative package executes a targeted simplification agenda designed to reduce administrative duplication. For industries operating at the high stakes intersection of digital technology and healthcare, this package attempts to resolve a core systemic tension: the imperative to foster rapid clinical innovation versus the necessity of maintaining robust fundamental rights and safety safeguards.
Prior to the introduction of Omnibus VII, the rapid implementation of the European Union Artificial Intelligence Act (Regulation (EU) 2024/1689) had provoked widespread warning from the life sciences and medical technology sectors. Industry advocates argued that layering horizontal, uncoordinated AI rules on top of the existing, highly demanding Medical Devices Regulation (Regulation (EU) 2017/745, or MDR) and In Vitro Diagnostic Medical Devices Regulation (Regulation (EU) 2017/746, or IVDR) would paralyze digital health innovation.
The risk of duplicative audits, separate technical documentation structures, conflicting risk-mitigation standards, and severe shortages in Notified Body capacity threatened to further delay patient access to life-saving technologies. By extending transition timelines, introducing regulatory flexibility, and streamlining institutional pathways under the Cyprus presidency, Omnibus VII represents a pragmatic phase of EU AI governance.
However, the refusal of EU co-legislators to grant medical devices a complete sectoral exemption has left the healthtech industry in a complex regulatory position, facing parallel compliance obligations that demand careful, long-term strategic planning.
Structural Postponements and Transition Timelines
Crucially, Omnibus VII does not rewrite the core principles of the AI Act; rather, it radically recalibrates the enforcement timeline to give developers, national competent authorities, and conformity assessment bodies necessary preparation time. Recognizing that crucial harmonized standards and conformity infrastructures were not yet mature, the co-legislators fast-tracked amendments to postpone key compliance deadlines.
The revised timeline distinguishes between stand-alone high-risk AI systems (governed by Annex III of the AI Act) and high-risk AI systems embedded as safety components in products covered by sectoral harmonization legislation (governed by Annex I, which includes medical devices and diagnostics).
AI System Category or Legislative Milestone | Original Application Date | Revised Application Date | Transition Window & Strategic Purpose |
Stand-alone High-Risk AI Systems (Annex III / Article 6(2)) | August 2, 2026 | December 2, 2027 [cite: 1, 2, 14] | 16-Month Extension to finalize national supervisory infrastructures and wait for European harmonized standards. |
Embedded High-Risk AI Systems (Annex I / Article 6(1), including MDR/IVDR) | August 2, 2026 | August 2, 2028 [cite: 1, 2, 14] | 24-Month Extension to align AI requirements with ongoing targeted revisions of the MDR and IVDR frameworks. |
AI Regulatory Sandboxes(National Level) | August 2, 2026 | August 2, 2027 [cite: 2, 3, 6] | 12-Month Postponement allowing national competent authorities to build out operational testing environments. |
Watermarking of Synthetic AI Content (Article 50(2)) | August 2, 2026 | December 2, 2026 [cite: 13, 14, 15] | 4-Month Extension for synthetic content providers, though the post-market implementation grace period was compressed from 6 to 3 months. |
Prohibitions on Non-Consensual Intimate Content (NCII) / CSAM | N/A | December 2, 2026 [cite: 13, 14, 15] | Immediate Ban targeted at "nudifier" applications and non-consensual deepfakes, taking effect late 2026. |
This phased implementation provides significant operational relief. However, manufacturers must recognize that some obligations under the AI Act remain active or have already taken effect. For example, the mandatory AI literacy obligation for providers and deployers of AI systems has applied since February 2025, although Omnibus VII softened its terms from an open-ended mandate to a softer requirement to "take measures to support" staff literacy. Furthermore, key transparency obligations under Article 50, including the mandate to disclose when users are interacting with an AI system, such as a patient-facing triage chatbot, remained locked to their original enforcement date of August 2, 2026.
The Sectoral Integration Debate: Horizontal Safeguards versus Sector-Specific Pathways
The most contentious debate during the negotiation of Omnibus VII centered on how the AI Act should interact with sector-specific product safety regimes. For the life sciences and medical technology sectors, this debate evolved into a legislative clash between two distinct directorates of the European Commission, representing diverging philosophies of regulatory simplification.
The first philosophy, championed by the Directorate-General for Communications Networks, Content and Technology (DG CONNECT), was embodied in the "Digital Omnibus" proposal. This approach sought to preserve the horizontal integrity of the AI Act by maintaining systematic AI Act safeguards over medical technologies by default, while introducing administrative coordination mechanisms to streamline compliance.
The second, more radical philosophy was proposed in December 2025 by the Directorate-General for Health and Food Safety (DG SANTE) as part of a sweeping initiative to simplify the MDR and IVDR. DG SANTE argued for a complete sectoral carve-out, proposing to move the MDR and IVDR from Section A of Annex I (which triggers the direct application of substantive high-risk AI Act requirements) to Section B. Under the Section B model, the substantive requirements of the AI Act would cease to apply directly to medical devices. Instead, the MDR and IVDR would serve as the sole, primary rulebook for medical AI, with the Commission retaining the power to introduce specific AI requirements later via delegated or implementing acts.
During the May 2026 trilogue negotiations, a stark division emerged. Under intense pressure from member states such as Germany, industrial machinery manufacturers successfully secured the Section B shift, moving the Machinery Regulation from Section A to Section B. For a typical manufacturing SME, this carve-out eliminated up to €600,000 in duplicative Year 1 compliance costs. However, the Council of the European Union rejected a similar carve-out for medical technologies. Consequently, medical devices and IVDs were "left behind," remaining under Section A and subject to the full weight of parallel compliance under both the AI Act and the MDR/IVDR.
To soften this regulatory burden, negotiators agreed on a compromise mechanism. Rather than a blanket exemption, the European Commission is empowered to adopt implementing acts to limit the application of specific AI Act requirements where the MDR or IVDR is demonstrated to contain equivalent safeguards. While this "equivalence mechanism" provides a legal pathway to reduce duplication, it introduces transitional uncertainty, as the industry must wait for the Commission to draft and adopt these implementing acts.
Regulatory Dimension | DG CONNECT "Digital Omnibus" (Trilogue Outcome) | DG SANTE "MDR/IVDR Simplification" Proposal |
Annex I Classification | Maintained under Section A (direct applicability of horizontal AI Act requirements). | Proposed shift to Section B (exempting devices from direct substantive AI Act obligations). |
Primary Rulebook | Parallel, overlapping application of the AI Act and MDR/IVDR. | Unified sectoral framework; MDR/IVDR acts as the sole primary rulebook for conformity. |
Conformity Assessments | Streamlined procedures but keeping parallel legislative evaluations. | Single conformity assessment pathway strictly embedded in existing MDR/IVDR processes. |
Legislative Oversight | Joint authority cooperation with a compromise "equivalence mechanism". | Commission delegated powers to write specific AI rules under the MDR/IVDR framework as needed. |
Legislative Status | Formally adopted as part of the Omnibus VII agreement. | Rejected by the Parliament and Council during trilogue negotiations. |
Operational Reality and Compliance Imperatives for SaMD Developers
The failure to achieve a complete sectoral carve-out means that developers of Software as a Medical Device (SaMD) and AI-enabled hardware must navigate two highly demanding regulatory frameworks simultaneously. Because the AI Act classifies any AI-enabled device requiring a third-party conformity assessment as high-risk, this dual compliance regime applies to Class IIa, IIb, and III devices under the MDR, and the vast majority of diagnostics under the IVDR.
This dual-framework structure creates substantial friction because of misaligned definitions and regulatory philosophies. For example, the AI Act requires developers to minimize algorithmic and operational risks "as far as technically feasible," whereas the MDR relies on a "benefit-risk balancing" approach. Furthermore, the AI Act introduces the concept of "substantial modification", which can trigger entirely new conformity assessments for self-learning algorithms—while the MDR relies on the distinct concept of "significant change". These misalignments create deep lifecycle management uncertainties.
The overall financial impact is substantial. Independent assessments indicate that the AI Act could cost the European economy up to €31 billion over five years, leading to an estimated 20% contraction in AI investment. In April 2026, OpenEvidence, a generative AI clinical decision-support platform utilised by approximately 42% of physicians in the United States, withdrew its services from the European market, citing the impossibility of meeting the AI Act's high-risk compliance hurdles under its current operational model. Similar compliance concerns have slowed the deployment of clinical AI scribes, predictive diagnostic tools, and automated imaging assistants across European clinical networks.
To mitigate these bottlenecks, Omnibus VII introduces a unified designation pathway for conformity assessment bodies. Under the new Article 29(4), independent Notified Bodies can submit a single application and undergo a unified assessment procedure to obtain joint designation under both the AI Act and the MDR/IVDR. This administrative streamlining aims to accelerate the availability of AI-competent Notified Bodies, helping to prevent the severe certification bottlenecks that delayed MDR implementation.
High-Risk AI Act Expectation | Corresponding MDR/IVDR Requirement | Integrated Compliance Strategy under Omnibus VII |
Conformity Assessment | Annex IX/X/XI third-party audits by a designated Notified Body. | Leverage the unified application pathway to select a Notified Body with joint AI Act and MDR/IVDR credentials. |
Risk Management System | ISO 14971 continuous risk management across the product lifecycle. | Embed AI-specific risk profiles (e.g., automation bias, model drift) directly into the existing ISO 14971 file. |
Technical Documentation | Annex II and III comprehensive technical files proving safety and performance. | Consolidate documentation into a single technical file under the AI Act Article 11 / Annex II integration allowance. |
Cybersecurity Controls | Annex I General Safety and Performance Requirements (GSPR) on software security. | Leverage the Cyber Resilience Act alignment: compliance with CRA Article 12 satisfies AI Act Article 15. |
Post-Market Surveillance | Active Post-Market Clinical Follow-up (PMCF) and periodic safety reporting. | Integrate AI drift tracking into PMCF; benefit from the removal of the rigid, standalone AI Act PM plan. |
The Concurrent Overhaul of the MDR and IVDR
As European medical technology companies grapple with the direct application of the AI Act, they must simultaneously navigate a sweeping parallel overhaul of the underlying MDR and IVDR frameworks. The European Commission’s simplification proposals, expected to reach formal adoption between summer 2026 and mid-2027, represent a massive effort to streamline product certification, alleviate chronic device shortages, and lower barriers to entry for smaller developers.
This health-sector reform introduces fundamental changes that significantly lighten the administrative load. Key among these is the relaxation of the Person Responsible for Regulatory Compliance (PRRC) requirements. Under the original MDR, small and micro-enterprises were forced to maintain a PRRC "permanently and continuously". The upcoming amendments soften this standard, requiring only that the PRRC be "available". Additionally, health institutions will gain the flexibility to share "home brew" in-house in vitro diagnostics with other legally independent hospitals if it serves public health, eliminating the previous restriction that limited such devices only to cases where no market alternative existed.
Crucially, the update also lowers the administrative reporting burden. The frequency for updating Periodic Safety Update Reports (PSUR) has been cut in half: updates are required only every two years—rather than annually—for Class IIb/III medical devices and Class C/D IVDs, and "as necessary" for Class IIa systems. Manufacturers will also benefit from targeted adaptations of classification rules, allowing certain reusable surgical instruments, active implant accessories, and specific clinical software algorithms to be reclassified into lower-risk tiers. Furthermore, to help alleviate the financial strain on early-stage innovators, Notified Bodies will be legally mandated to apply substantial fee discounts: at least a 50% reduction for micro-enterprises, 25% for small enterprises, and 50% for developers of orphan medical devices.
To bring commercial predictability to the notoriously slow CE-marking process, the European Commission adopted Implementing Regulation 2026/977 on May 4, 2026. This regulation establishes strict maximum assessment timelines for Notified Bodies, creating a standardised operational rhythm.
Conformity Assessment Activity | Maximum Permitted Timeline under Regulation 2026/977 |
Initial Application Review | 30 Days |
Quality Management System (QMS) Audit | 120 Days |
Product Design and Verification Assessment | 90 Days |
Final Certificate Issuance | 20 Days |
While these strict caps do not apply to existing contracts signed before February 25th, 2027, or to recertifications expiring before November 25th, 2027, they provide a long-awaited framework for scheduling and commercial planning.
Meanwhile, the global landscape is fragmenting. In the United Kingdom, the government has published its draft Medical Devices (Amendment) Regulations 2026, targeting a December 2026 adoption. This framework proposes a risk-proportionate classification system and introduces an international reliance pathway. Under this reliance model, UK approved bodies can rely on pre-market approvals already granted by comparable regulators in the United States (FDA), Canada (Health Canada), and Australia (TGA) to grant market access. For European healthtech companies, this creates a stark operational contrast: while the EU remains anchored in a parallel-compliance model under Section A of the AI Act, the UK is leveraging unilateral recognition pathways to accelerate market entry and secure its supply chain.

Interoperability with Other Digital Regulations
The simplified AI rules under Omnibus VII must also be evaluated within the broader context of the EU’s "Digital Omnibus" regulation, which simultaneously amends a constellation of data protection, cybersecurity, and electronic communications laws.
The Digital Omnibus introduces essential alignment between the General Data Protection Regulation (GDPR) and the NIS2 Directive on cybersecurity. Historically, developers faced different reporting timelines and documentation requirements when a personal data breach also qualified as a critical cybersecurity incident. The new rules align these reporting structures, establishing a single, coordinated notification timeline that dramatically reduces administrative duplication.
Furthermore, the Digital Omnibus amends the Data Act to provide enhanced protections for proprietary trade secrets, particularly in scenarios where public authorities request access to medical or connected-device data during emergencies. Legacy medical technologies are also explicitly exempted from the Data Act’s strict data-access obligations, protecting historical device portfolios from retroactive and costly engineering overhauls. Additionally, the regulation introduces a revised definition of personal data under the GDPR: pseudonymised data will no longer be classified as personal data if the holder lacks a reasonable, realistic path to re-identify the underlying individuals. This change lowers the regulatory burden for training, validating, and testing healthcare AI models.
For developers of connected medical devices, the package also provides essential clarifications regarding the Radio Equipment Directive. Historically, there was significant concern that standard consumer products incorporating basic AI-driven safety elements, such as a smart cooktop using AI to distinguish between a finger and water droplets, would trigger full, high-risk AI Act compliance assessments. By clarifying that AI components that merely assist users or optimize non-safety performance are excluded, the co-legislators have protected standard connected devices from accidental high-risk classifications.
The Ethical, Clinical and Civil Backlash
While the business community has welcomed the postponement of timelines and the reduction of compliance burdens, the regulatory relaxations under the Omnibus VII package have triggered sharp resistance from civil society and clinical organizations. The decision to delay binding compliance requirements for high-risk systems to late 2027 and mid-2028 has drawn intense criticism. A coalition of more than 127 civil society organizations, including European Digital Rights (EDRi), Amnesty International EU, the European Center for Not-for-Profit Law (ECNL), the European Disability Forum (EDF), and the European Network Against Racism (ENAR), has condemned the proposal as the largest rollback of digital fundamental rights safeguards in the Union's history. They argue that delaying these strict rules leaves vulnerable populations exposed to unvetted, potentially biased algorithmic decision-making in critical areas like emergency triage, public health resource allocation, and clinical diagnostics.
These concerns are echoed by the Standing Committee of European Doctors (CPME), which has raised alarms over the medical privacy implications of the package. CPME’s opposition focuses on the new Article 4a, which allows developers to bypass the standard GDPR Article 9 prohibition and process sensitive medical histories for bias detection and correction. CPME argues that this "deregulatory" shift risks eroding patient trust and violating medical confidentiality. They caution that the expanded use of pseudonymized or anonymised health data under the revised definition of personal data could allow commercial developers to train clinical algorithms without explicit patient consent, potentially leading to unauthorized data reuse and undermining the doctor-patient relationship.
Clinicians also emphasize that clinical AI solutions with valid CE markings can yield widely varying results in real-world environments. For example, minor software updates in AI diagnostics can introduce performance drift, potentially leading to false positives or missed diagnoses. Consequently, clinical groups argue that weakening horizontal oversight in favour of slower, sector-specific MDR/IVDR processes could expose patients to algorithmic errors, emphasising that human clinical oversight must remain the final safeguard in patient care.
Strategic Playbook for Healthcare AI and MedTech Executives
Despite the extended timelines, the core requirement of parallel compliance under both the AI Act and the MDR/IVDR remains a reality. Healthtech executives and regulatory compliance officers must utilize this newly granted transition window to build unified, highly efficient compliance frameworks.
Step 1: Execute a Dual-Classification Audit
Manufacturers must immediately classify all software and hardware models under both regimes. The key is evaluating clinical algorithms against the newly clarified Article 3(14) "safety function" exemptions. If a software module merely assists a clinician or optimises administrative workflow without autonomously making diagnostic or treatment decisions, it should be documented as falling outside the high-risk classification, avoiding duplicative conformity assessments.
Step 2: Navigate High-Risk Exemptions and Register
Under the provisional agreement, even if a provider believes their AI system is exempted from high-risk requirements under Article 6(3) of the AI Act, they are still subject to a mandatory registration requirement. This means companies must register these systems in the central EU database for high-risk AI, ensuring full regulatory transparency even when claiming an exemption.
Step 3: Establish a Integrated Quality Management System (QMS)
Rather than maintaining separate, parallel compliance tracks, developers should integrate AI Act quality management rules directly into their existing ISO 13485 structures. Risk management protocols under the AI Act can be merged directly into the ISO 14971 risk files. Crucially, cyber compliance can be streamlined by leveraging the Cyber Resilience Act alignment: proving compliance with CRA Article 12 automatically satisfies the cybersecurity requirements of AI Act Article 15.
Step 4: Leverage Sandbox and Testing Opportunities
SMCs and early-stage startups should actively seek access to the newly established Union-level AI sandboxes, managed directly by the European AI Office. Furthermore, developers should exploit the expanded allowance for "real-world testing" under Article 60. This allows high-risk medical AI systems to be tested under real-world clinical conditions before formal market placement, providing valuable clinical performance data while accelerating the path to certification.
Step 5: Engage Dual-Designated Notified Bodies
When scheduling conformity assessments, manufacturers should specifically target Notified Bodies that have utilised the unified application pathway under Article 29(4). Engaging an auditor designated under both the AI Act and the MDR/IVDR allows for a single, integrated audit process. This eliminates duplicative testing and significantly reduces overall certification costs.
Conclusion and Future Outlook
The simplified AI rules under Omnibus VII provide a critical transition window for the European healthtech and medtech sectors, but they do not resolve the structural challenges of dual regulation. While the extension of compliance deadlines to August 2028 provides immediate breathing room, companies must recognise that this delay is a preparation window, not a deregulation of medical AI.
The long-term regulatory environment will be heavily shaped by two key factors. First is the European Commission’s use of its newly granted powers to adopt implementing acts to limit AI Act requirements where equivalent MDR/IVDR safeguards exist. Second, the ongoing targeted revisions to the MDR and IVDR represent the final, critical opportunity for the industry to lobby for complete sectoral integration. If these revisions successfully embed AI-specific safeguards directly into the medical device regulations, Europe can establish a unified, predictable, and competitive framework for medical AI. Until then, healthtech executives must proactively integrate their compliance systems, leveraging the transition period to build robust, scalable, and audit-ready products.
Nelson Advisors > European MedTech and HealthTech Investment Banking
Nelson Advisors specialise in Mergers and Acquisitions, Partnerships and Investments for Digital Health, HealthTech, Health IT, Consumer HealthTech, Healthcare Cybersecurity, Healthcare AI companies. www.nelsonadvisors.co.uk
Nelson Advisors regularly publish Thought Leadership articles covering market insights, trends, analysis & predictions @ https://www.healthcare.digital
Nelson Advisors publish Europe’s leading HealthTech and MedTech M&A Newsletter every week, subscribe today! https://lnkd.in/e5hTp_xb
Nelson Advisors pride ourselves on our DNA as ‘Founders advising Founders.’ We partner with entrepreneurs, boards and investors to maximise shareholder value and investment returns. www.nelsonadvisors.co.uk
#NelsonAdvisors #HealthTech #DigitalHealth #HealthIT #Cybersecurity #HealthcareAI #ConsumerHealthTech #Mergers #Acquisitions #Partnerships #Growth #Strategy #NHS #UK #Europe #USA #VentureCapital #PrivateEquity #Founders #SeriesA #SeriesB #Founders #SellSide #TechAssets #Fundraising #BuildBuyPartner #GoToMarket #PharmaTech #BioTech #Genomics #MedTech
Nelson Advisors LLP
Hale House, 76-78 Portland Place, Marylebone, London, W1B 1NT
Meet Nelson Advisors @ 2026 Events
Digital Health Rewired > March 2026 > Birmingham, UK
NHS ConfedExpo > June 2026 > Manchester, UK
HLTH Europe > June 2026, Amsterdam, Netherlands
HIMSS AI in Healthcare > July 2026, New York, USA
Bits & Pretzels > September 2026, Munich, Germany
World Health Summit 2026 > October 2026, Berlin, Germany
HealthInvestor Healthcare Summit > October 2026, London, UK
HLTH USA 2026 > October 2026, USA
Barclays Health Elevate > October 2026, London, UK
Web Summit 2026 > November 2026, Lisbon, Portugal
MEDICA 2026 > November 2026, Düsseldorf, Germany
Venture Capital World Summit > December 2026 Toronto, Canada




































Comments