A Deadline That Only Half Arrived
For two years, 2 August 2026 was the date. It was pinned to whiteboards in every compliance function in Europe. It was the day the EU AI Act’s high-risk obligations were meant to bite.
That date came and went last week — and a good chunk of it had already moved.
On 29 June, the Council of the EU gave final approval to the Digital Omnibus on AI, the first substantive amendment to the AI Act since it was adopted in 2024. The headline change: obligations for standalone high-risk systems under Annex III now apply from 2 December 2027, and for AI embedded in regulated products such as medical devices, from 2 August 2028.
Sixteen months of breathing room. Cue a collective exhale across the health tech sector.
I think that exhale is a mistake, and I’ll come back to why. But first, it’s worth being precise about what didn’t move — because a lot of commentary has flattened this into “the EU delayed the AI Act”, and that’s not what happened.
What actually applied on 2 August 2026
The Article 50 transparency obligations were not deferred. From that date, people must be told when they are interacting with an AI system unless it is genuinely obvious. For anyone building or buying a mental health chatbot, that is now a live legal duty, not a roadmap item.
Why Mental Health Isn’t Just Another Use Case
There’s a reason the AI Act treats health AI with more suspicion than, say, a warehouse routing algorithm — and a reason mental health sits at the sharpest end of that.
The people most likely to encounter these tools are, almost by definition, the people least well placed to push back on them. Someone in acute distress at 2am is not conducting a critical appraisal of the model’s validation methodology. Someone waiting eleven months for CAMHS is not weighing the evidence base of the app their GP mentioned. The asymmetry between the system and the person using it is enormous, and it widens exactly when the person is most unwell.
More than 150 million people across the WHO European Region were living with a mental health condition in 2021. Our services are stretched, our workforce is tired, and into that gap has poured an enormous volume of software making therapeutic-sounding promises. Some of it is genuinely useful. A lot of it has never been properly evaluated by anyone.
That’s the environment the AI Act is walking into.
What’s Already Banned — And Has Been Since 2025
Here’s the part that gets lost in the deadline drama. The Act’s outright prohibitions under Article 5 have been in force since 2 February 2025. They didn’t move in the Omnibus. They apply today.
Four of them matter enormously for mental health:
Prohibited practices with a mental health dimension
- Manipulative or deceptive techniques that materially distort behaviour and cause significant harm — and the Commission’s guidance is explicit that “harm” includes causing sustained stress, insomnia or deterioration of mental health
- Exploiting vulnerability based on age, disability, or social and economic situation — which speaks directly to tools aimed at children, older people, or anyone in acute distress
- Social scoring that leads to unjust or disproportionate treatment — with obvious implications for any scheme that scores people’s mental state against access to services or benefits
- Emotion recognition in workplaces and schools, except for medical or safety reasons
That last one deserves a moment. There is a whole product category — employer-commissioned “wellbeing platforms” that claim to detect burnout, disengagement or emotional state from keystrokes, calendar patterns, tone of voice or facial expression — that is now largely unlawful in the EU when deployed on staff or students.
I’ve sat in rooms where these were pitched as duty-of-care innovations. They were always closer to surveillance. The Act has drawn a hard line, and I think it drew it in the right place.
The penalties are not symbolic either:
The Chatbot Question
This is where policy meets most people’s actual experience of AI and mental health.
Millions of people across Europe are already using general-purpose chatbots as something between a diary, a sounding board and a therapist. Not clinical products. Not CE-marked. Just whatever’s on their phone.
The evidence on how that’s going is not reassuring. The American Psychological Association’s 2026 survey of over 1,200 licensed psychologists found that 89% were worried chatbots may inadvertently encourage self-harm, and more than a third reported patients treating AI as an additional mental health professional. Research from Stanford has found that these systems can express more stigma towards conditions such as schizophrenia and alcohol dependence than towards depression — and that newer, larger models were no better than older ones.
Meanwhile, the general-purpose AI obligations that took effect in August 2025 require providers of models with systemic risk to identify and mitigate risks to public mental health, and to report serious incidents including significant harm to a person’s mental health.
And from 2 August, users must be told they’re talking to an AI.
Does disclosure actually work?
I’m not convinced a label solves this. Someone who has formed a genuine emotional attachment to a chatbot over six months does not un-form it because a banner says “AI-generated”. Transparency is necessary. It is nowhere near sufficient.
The genuinely difficult cases sit in the middle. A wellness app that carefully avoids clinical claims may fall outside medical device rules entirely, while still being the primary mental health support in someone’s life. That gap is where I’d expect the next few years of regulatory argument to happen.
The Evidence Problem Nobody Enjoys Discussing
Regulation assumes there’s something worth regulating. On the research side, the picture is shakier than the marketing suggests.
WHO/Europe’s review of AI in mental health research between 2016 and 2021 found the field heavily skewed towards depression and psychotic disorders, with thin coverage elsewhere. More importantly, it found serious methodological problems throughout: poor handling of high-dimensional data, infrequent validation, weak bias assessment, and reporting so opaque that replication was often impossible.
Most models and datasets remain proprietary. Collaboration is limited. Performance claims are frequently over-optimistic.
So we have a field with a modest evidence base, strong commercial incentives, and a user population that is uniquely vulnerable to being let down. If you were designing conditions for a governance failure, you’d struggle to do better.
The counter-argument is that the AI Act’s data governance requirements — representative datasets, documented bias assessment, real technical documentation — could drag research practice upwards. I think that’s right, but only if regulators and funders actually enforce it rather than accepting a folder of paperwork.
Ireland Has Moved Faster Than Most People Realise
Here’s what I find genuinely interesting: while everyone was watching Brussels, Ireland quietly assembled most of a national framework in about five months.
Ireland’s 2026 timeline
- 20 February — Minister Mary Butler launches the Sharing the Vision Digital Mental Health Strategy 2026–2030, Ireland’s first standalone digital mental health strategy, with €1m from Budget 2026 bringing total digital mental health investment past €7m
- 11 March — Minister Jennifer Carroll MacNeill publishes AI for Care 2026–2030, Ireland’s first national AI strategy for health and social care, built on four pillars and committing to full alignment with the EU AI Act
- 15 July — The Regulation of Artificial Intelligence Bill 2026 passes the Seanad, establishing the AI Office of Ireland and designating competent authorities
- 29 July — HIQA publishes Ireland’s first National Guidance for the Responsible and Safe Use of AI in Health and Social Care Services
That’s a strategy, a sector strategy, a regulator and a governance framework inside half a year. For a system that is not always famous for pace, it’s a genuinely strong showing.
Two things stand out to me.
First, the HIQA guidance is structured around four principles for person-centred care: accountability, a human rights-based approach, safety and wellbeing, and responsiveness. Not a compliance checklist. That framing matters, because it asks a different question — not “is this permitted?” but “is this right for this person?”
Second, the Regulation of AI Bill implements the EU AI Act without adding national requirements. That’s a deliberate choice, and a defensible one. But it does mean Ireland’s mental health–specific safeguards will have to come from HIQA guidance, HSE governance and professional practice rather than from legislation.
The Digital Mental Health Strategy’s emphasis on access and equity is the piece I’d protect most fiercely. Digital tools tend to reach the digitally confident first. If we scale without watching that closely, we’ll widen the gap we’re trying to close and call it progress.
What This Means If You Buy, Build or Run These Services
Practical version, for the people who actually have to make decisions this quarter.
Questions worth asking now
- Is this system high-risk under Annex III — and if the vendor says no, what’s their reasoning in writing?
- Where does it sit relative to the Medical Device Regulation, and is it CE-marked?
- Has it been validated in mental health populations, or extrapolated from general health data?
- What does subgroup performance look like — by age, ethnicity, language, and diagnosis?
- What is the human override mechanism, and has anyone actually used it?
- How does the system behave when someone discloses risk, and who reviews those interactions?
- If it interacts with service users directly, does it disclose that it’s AI, in plain language, at the right moment?
Two of those aren’t in any regulation. They’re the ones I’d ask first.
The Delay Is Not a Reprieve
Back to that sixteen-month extension.
The obligations haven’t changed. Not one of them. What changed is when you’ll be assessed against them. Every organisation that hasn’t yet catalogued its AI systems, established clinical governance for them, or worked out who is accountable when one gets something badly wrong — you have been handed time, not absolution.
And the underlying reason for the delay is worth sitting with. The rules were postponed partly because harmonised standards weren’t ready and national authorities weren’t designated. That’s not a story about overzealous regulation. It’s a story about a regulatory framework arriving faster than the machinery to run it.
Ireland has the strategies. It now has the guidance and, shortly, the regulator. The question is whether that becomes real governance in mental health services, or a very well-written shelf.
The question I keep coming back to
The AI Act asks whether a system is safe, accurate and overseen. Those are the right questions. But nowhere does it ask whether the person on the other end of the interaction felt heard. In mental health, that’s not a soft outcome — it is very often the outcome.
The best possible version of this is AI that takes documentation, triage and administration off clinicians so they have more time to sit with people. The worst version is AI that becomes the thing we offer instead of a person, because a person costs more.
Both are technically compliant. Only one is worth building.
What’s your read — is the delay giving Irish services the time they needed, or the excuse they’ll take?
If you’re struggling, support is available. Samaritans can be reached free on 116 123, or you can text HELLO to 50808 to reach Text About It.
References
- Regulation (EU) 2024/1689 — the EU Artificial Intelligence Act
- EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes — Gibson Dunn
- The Final Digital Omnibus on AI — Key Amendments to the AI Act — Freshfields
- EU Legislators Agree to Delay for High-Risk AI Rules — Hogan Lovells
- AI Act Rules on High-Risk AI Delayed as AI Digital Omnibus Agreed — Winston Taylor
- First EU AI Act Guidelines: When Is Health AI Prohibited? — ICT&health
- AI Therapy Under the EU AI Act — EU Artificial Intelligence Act
- AI Act Risk Classification for Mental Health Tools — Tandem Health
- The EU AI Act Lands on Mental Health: What Changes on 2 August 2026 — PsyReflect
- Artificial Intelligence in Mental Health Research: New WHO Study on Applications and Challenges — WHO/Europe
- Methodological and Quality Flaws in the Use of Artificial Intelligence in Mental Health Research — JMIR Mental Health
- Ethics and Governance of Artificial Intelligence for Health — WHO Guidance
- Health and Wellbeing in the Age of Artificial Intelligence — European Parliamentary Research Service
- Navigating the European Union Artificial Intelligence Act for Healthcare — npj Digital Medicine
- EU Health Policy Platform Thematic Network on AI and Health — European Commission
- Artificial Intelligence in Healthcare — European Commission, Public Health
- Patients Are Bringing AI to Therapy: 2026 Chatbots and Mental Health Survey — American Psychological Association
- Exploring the Dangers of AI in Mental Health Care — Stanford HAI
- The European Union’s Artificial Intelligence Act and Trust — Law, Innovation and Technology
Irish context
- Minister for Health Publishes Ireland’s First National AI for Care Strategy — Government of Ireland
- AI for Care: The Artificial Intelligence Strategy for Healthcare in Ireland 2026–2030 — Department of Health
- The AI Strategy for Healthcare in Ireland 2026–2030 (full PDF) — Health Tech Ireland
- Launch of the AI Strategy for Healthcare in Ireland — HSE
- Minister for Mental Health Mary Butler Launches the National Digital Mental Health Strategy — Government of Ireland
- Ireland Launches Digital Strategy to Increase Mental Health Support — Digital Health
- €1 Million National Digital Mental Health Strategy for Ireland — HTN Health Tech News
- HIQA Publishes First National Guidance on AI in Healthcare — Pulse+IT
- National Guidance for the Responsible and Safe Use of Artificial Intelligence in Health and Social Care Services — HIQA
- AI Use in Health System Must Be Deemed Safe — RTÉ
- AI in Health and Social Care: A New Era of Governance — Beauchamps
- Digital for Care: A Digital Health Framework for Ireland 2024–2030 — HSE
- Sláintecare: Latest News — Government of Ireland
- Big Data Analytics and Artificial Intelligence in Mental Health — WHO/Europe