Regulatory guide · European UnionUpdated October 8, 2026

The EU AI Act and clinical trials: what it means for trial software

How Regulation (EU) 2024/1689 sorts AI systems by risk, which dates now apply after the 2026 omnibus amendment, and how to think about AI features in EDC, ePRO and study build tools. General information, not legal advice.

  • Updated for the 2026 omnibus
  • Risk classes explained
  • Not legal advice

Free sandbox · No credit card · 21 CFR Part 11 aligned

AI Act application dates (as amended)
12345

Year

In force

1 Aug 2024

Prohibitions, AI literacy

2 Feb 2025

General-purpose AI models

2 Aug 2025

Transparency (Art. 50)

2 Aug 2026

High-risk, Annex III

2 Dec 2027

High-risk, Annex I products

2 Aug 2028

Dates for high-risk systems as amended by Regulation (EU) 2026/1744, in force 27 July 2026. Check EUR-Lex for the consolidated text.

Key points

  • Not legal advice. This is a plain-language summary as of October 2026. Classification under the AI Act depends on the exact intended purpose of a system; take specialist advice.
  • The AI Act, Regulation (EU) 2024/1689, entered into force on 1 August 2024. Prohibited practices and AI literacy applied from 2 February 2025; general-purpose AI model rules from 2 August 2025.
  • The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026. It moved high-risk obligations to 2 December 2027 for Annex III uses and 2 August 2028 for AI in products covered by Annex I legislation, such as the Medical Device Regulation.
  • Medicine development is not an Annex III use case. AI that is, or is a safety component of, a medical device needing notified body assessment is the main high-risk route relevant to trials.
  • AI that drafts eCRFs from a protocol for human review is a productivity feature, not a clinical decision tool. GCP expectations on validation and review still apply to whatever it produces.

How the Act works

Four tiers of risk, two kinds of actor

The AI Act regulates AI systems by what they are used for. At the top are prohibited practices under Article 5, such as manipulative techniques that cause significant harm or social scoring. Next are high-risk systems, which carry the heaviest duties: risk management, data governance, technical documentation, logging, transparency to users, human oversight, accuracy and robustness, and a conformity assessment. Then come transparency duties under Article 50, for example telling people they are dealing with an AI system or labelling synthetic content. Everything else is minimal risk, with no specific obligations beyond AI literacy. General-purpose AI models, such as large language models, have their own separate chapter.

Duties also depend on your role. A provider develops an AI system and places it on the market or puts it into service under its own name. A deployer uses an AI system under its authority in a professional setting. A sponsor that buys an EDC with an AI feature is normally a deployer of that feature; a vendor that builds it is the provider. Deployers of high-risk systems must use them according to the instructions, assign competent human oversight and keep the logs they control.

What makes a system high-risk

There are two routes. Under Article 6(1), an AI system is high-risk if it is a product, or a safety component of a product, covered by the EU harmonisation legislation in Annex I and that product needs third-party conformity assessment. The Medical Device Regulation and the In Vitro Diagnostic Regulation are in Annex I, so AI-enabled devices that need a notified body fall here. Under Article 6(2), systems used in the areas listed in Annex III are high-risk. Annex III covers areas such as biometrics, employment, education, access to essential services and emergency triage. It does not list clinical research or drug development as such.

Applied to trials

How common AI uses in clinical research are likely to map

A starting point for discussion with your regulatory and legal advisers, not a classification.

AI use in a trialLikely AI Act angleWhat to check
AI-enabled medical device under investigationAnnex I route if the device needs notified body assessment; high-risk duties from 2 August 2028MDR class, the device's intended purpose, rules on testing in real-world conditions
AI that drafts forms or schedules from a protocol for human reviewNot an Annex III use; usually minimal riskVendor documentation, human review step, GCP validation of the resulting study build
AI that suggests data queries or flags outliersNot an Annex III use as suchValidation, error rates, who decides on each flag
AI for patient-facing chat or informationArticle 50 transparency: people should know they are interacting with AIDisclosure wording, ethics committee review of materials
AI used purely for scientific research and developmentArticle 2(6) excludes systems developed and put into service solely for scientific R&DWhether the use is really limited to research
General-purpose model used inside a vendor toolGPAI duties sit with the model providerVendor's contracts and data handling

Classification turns on intended purpose and facts. The same model can be minimal risk in one product and high-risk in another.

Timeline

The 2026 omnibus: what moved and what did not

When the AI Act was adopted, Annex III high-risk duties were due on 2 August 2026 and Annex I product duties on 2 August 2027. On 19 November 2025 the European Commission proposed to delay them as part of its digital omnibus package. Parliament and Council reached a provisional deal in May 2026, Parliament adopted it in June, Council approved it on 29 June, and the amending act, Regulation (EU) 2026/1744 of 8 July 2026, was published in the Official Journal on 24 July and entered into force on 27 July 2026.

The new dates are fixed: 2 December 2027 for Annex III systems and 2 August 2028 for AI covered by Annex I legislation, which includes AI-enabled medical devices. The Article 50 transparency duties were not delayed and have applied since 2 August 2026. The omnibus also narrowed the concept of a safety component, added a prohibition on AI that generates non-consensual intimate imagery or child sexual abuse material, and reframed the AI literacy duty so that the Commission and Member States support organisations in building it. Check the consolidated text on EUR-Lex before relying on any detail.

See AI drafting with a human in the loop

Upload a protocol in the free sandbox, review every drafted visit and form, then approve what you keep. No credit card; pay only when you go live.

Start free in the sandbox

For sponsors and QA

Questions to ask about AI features in trial software

Whatever the AI Act class, GCP still expects you to understand and control the systems you use.

What exactly does the AI do?

Get a written description of the intended purpose, inputs and outputs. Classification follows from this.

Where is the human decision?

Confirm that AI output is a draft or suggestion and that a named user accepts it before it affects study data or configuration.

Is AI output traceable?

Ask whether accepted output passes through the normal approval and audit trail, so an inspector can see who approved what and when.

Can it touch live data?

Check whether AI can change records in a live study, or only work on draft configuration.

What data does the model see?

Ask which documents are sent to which model provider, where they are processed and whether they are used for training. Record this in your DPIA.

How is it validated for your use?

Treat the study built with AI help like any other build: test it against the protocol before go-live and keep the evidence.

Where Capture fits

How Capture's AI drafting is designed

Capture's AI study builder reads a protocol (PDF, DOCX or DOC) and drafts the visit schedule and forms. It can also draft questions or a lab table from a description or an uploaded file. Nothing is saved without human review, and the AI only works on draft forms. Forms then move through a draft to approved lifecycle, approved forms are locked for live use, and every change to study data is recorded in the field-level audit trail with the user, time, old value, new value and reason. The AI study builder page shows the flow.

We do not claim an AI Act classification or conformity status for Capture. The design choice that matters for any regulatory framework is that a qualified person reviews and approves what the AI drafts, and that the approved study is tested before participants are enrolled. The AI in clinical data capture GxP checklist and the computer system validation guide cover how to evidence that. For EU trial rules beyond AI, see EU CTR clinical trial software.

FAQ

Questions teams ask before they switch

Something not covered here? Ask us directly.

Does the EU AI Act apply to clinical trials?

It applies to AI systems placed on the EU market or used in the EU, including those used in trials. Whether a given system has obligations depends on its intended purpose and risk class. Many trial tools are minimal risk; AI-enabled medical devices needing notified body assessment are high-risk.

When do high-risk AI obligations apply?

After the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force 27 July 2026), from 2 December 2027 for Annex III systems and from 2 August 2028 for AI in products covered by Annex I legislation such as medical devices.

Is there a research exemption?

Article 2(6) excludes AI systems and models developed and put into service solely for scientific research and development, and Article 2(8) excludes research, testing and development before a system is placed on the market, except testing in real-world conditions. Whether your use qualifies needs case-by-case advice.

Is AI that drafts eCRFs high-risk?

Drafting forms for human review is not an Annex III use and is not a medical device function, so it is usually minimal risk. GCP still requires you to validate the resulting study build before use.

Are sponsors providers or deployers?

A sponsor using a vendor's AI feature is usually a deployer. A sponsor that develops its own AI system and puts it into service could be a provider. Roles can change if you substantially modify a system.

Does Capture claim AI Act compliance?

No. Capture does not claim an AI Act classification or conformity status. Its AI drafts visits and forms from a protocol, nothing is saved without human review, and it works only on draft forms.

AI drafts, your team decides

Try the AI study builder in the free sandbox with every feature. No credit card; pay only when you go live.

Start free in the sandbox