1. EU Digital Omnibus on AI Enters Into Force - Confirms Deeper Deferral of High-Risk AI Obligations for AI-Enabled Medical Devices
Regulation (EU) 2026/1744 (the “Digital Omnibus on AI”) was published in the Official Journal of the European Union on 24 July 2026 and entered into force on 27 July 2026, three days later. It is the first formal set of amendments to the EU AI Act since its 2024 adoption, and it finalizes into binding law the postponement of high-risk AI obligations that Aktriva’s 26 July briefing flagged as a provisional political agreement.
What changed this week
The enacted text confirms - and in one respect extends beyond - what was previously reported. Compliance obligations for stand-alone high-risk AI systems under Annex III (certain use cases in employment, education, critical infrastructure, and law enforcement) are deferred from the original 2 August 2026 date to 2 December 2027, a 16-month extension. Separately, obligations for high-risk AI systems embedded in products already subject to third-party conformity assessment under EU sectoral safety law - Annex I, which captures AI-enabled medical devices assessed under MDR/IVDR, along with machinery, lifts, and civil aviation equipment - are deferred to 2 August 2028. That is 12 months later than the “2 August 2027” figure reported under the May 2026 political agreement and carried in Aktriva’s prior briefing; the final legislative text pushed the Annex I date a full year further than initially proposed.
Manufacturer relevance
This is a formal correction to a deadline Aktriva has been tracking: AI-enabled medical devices assessed under MDR/IVDR now have until 2 August 2028, not 2 August 2027, before full AI Act high-risk obligations - conformity assessment, risk management system, data governance, technical documentation, human oversight, and the Article 15 accuracy/robustness/cybersecurity requirements - become mandatory. The underlying obligations were not softened, only the application dates moved, and organizations are cautioned against treating the extra runway as a reason to delay building risk management frameworks, technical documentation, and governance structures that take considerable time to stand up. Manufacturers of AI-enabled devices should update internal compliance timelines to reflect 2 August 2028 and continue designing Article 15 cybersecurity requirements into products now rather than retrofitting them later.
Sources: Digital Omnibus on AI: Regulation (EU) 2026/1744 Is Published in the Official Journal - NicFab; The Digital Omnibus on AI enters into force today - Lewis Silkin; EU AI Act Omnibus Agreement - Postponed High-Risk Deadlines and Other Key Changes - Gibson Dunn; EU Digital Omnibus on AI Enters Into Force - Hunton Andrews Kurth
2. European Commission Publishes First Official Cyber Resilience Act Implementation Guidance
On 27 July 2026, the European Commission published its first formal guidance on applying the Cyber Resilience Act (CRA), issued as Communication C(2026) 5252 with an accompanying annex, alongside 67 practical examples, use cases, flowcharts, and graphs aimed particularly at microenterprises and SMEs.
What it covers
Per the Commission’s own announcement, the guidance clarifies when products fall within CRA scope (including remote data processing solutions and free and open-source software), what constitutes a “substantial modification” triggering reassessment, how support periods should be understood and applied, and how to meet reporting obligations and risk-assessment requirements. The Commission confirmed that the CRA’s main obligations apply from 11 December 2027, with reporting obligations already applying from 11 September 2026.
Manufacturer relevance
Medical devices regulated under MDR/IVDR remain excluded from the CRA’s own product requirements, since they are already subject to sectoral cybersecurity obligations. That exclusion does not extend to a manufacturer’s software supply chain: third-party components, libraries, and standalone software products that are not themselves medical devices (general-purpose operating systems, connectivity middleware, non-medical companion apps, and similar) can fall within CRA scope, and their suppliers must meet the CRA’s 24-hour early-warning and 72-hour notification obligations once reporting duties begin on 11 September 2026 - five weeks away as of this issue. Manufacturers should use this guidance now to map which suppliers and components in their bill of materials are CRA in-scope and confirm contractually that those suppliers are prepared to meet the September reporting deadline.
Sources: Commission publishes new guidance to support timely Cyber Resilience Act implementation - European Commission, Shaping Europe’s Digital Future (27 July 2026); On 27 July 2026, the Commission Published Its First Official Guidance on Applying the Cyber Resilience Act - cyberresilienceact.eu
3. Sector Intelligence - Craneware and AnMed Incidents Reinforce Software-Supply-Chain and Hospital-Environment Risk
On 20 July 2026, Craneware plc, an Edinburgh-based healthcare financial-performance software vendor whose Trisus platform underpins pricing and billing operations at roughly 2,000 US hospitals and health systems and 10,000 pharmacies and clinics, disclosed a cybersecurity incident resulting in unauthorized access to and exfiltration of a subset of its data environment, including employee and customer/partner records. The company notified the FBI, engaged external forensic specialists, and reports the incident is now contained with no residual indicators of compromise. Separately, on 26 July 2026, South Carolina health system AnMed confirmed a malware-driven disruption that forced temporary closure of roughly 79 of its 106 facilities, with computer systems, phone lines, and internet connectivity down and recovery still ongoing as of this issue.
Manufacturer relevance
Neither incident targeted medical devices directly, but both illustrate the continued volume and severity of attacks against the software vendors and provider organizations that sit alongside manufacturers’ devices in the same hospital environments - reinforcing the third-party and data-exposure risk themes in Health-ISAC’s Q2 Heartbeat covered in Aktriva’s 26 July briefing. Manufacturers should treat billing, EHR, and other hospital-side software vendors as part of their extended risk surface when assessing where connected devices are deployed, and should expect continued scrutiny from hospital customers evaluating vendor security posture during procurement in the wake of these incidents.
Sources: Hospital software vendor Craneware discloses cybersecurity incident - Becker’s Hospital Review; Hackers steal customer data from major hospital software vendor - Cybersecurity Dive; AnMed Closes Almost 80 Facilities While it Grapples with Cyberattack - HIPAA Journal; Cyberattack forces temporary closure of 83 AnMed facilities - TechTarget
Disclaimer: This briefing is prepared by Aktriva for informational purposes only and does not constitute legal, regulatory, or compliance advice. Information is drawn from publicly available sources; while we aim for accuracy, errors or omissions may occur despite our review process. Readers should independently verify developments against primary regulatory sources and consult qualified advisors before making compliance decisions.
Want this tailored to your regulatory strategy?
Talk to our team about what this week's developments mean for your specific device and timeline.