Why this guide is current. Within two weeks of July 2026 both the national and the EU landscape changed: on 20.07.2026 Law 5321/2026 (Gazette A΄ 114) was published with the national implementing measures, and on 27.07.2026 Regulation (EU) 2026/1744 (the «Digital Omnibus on AI») entered into force, postponing the high-risk obligations. Anyone planning compliance against the original 2024 timeline is working from an outdated text.

1. The two acts and what changed

Regulation (EU) 2024/1689 (the AI Act) entered into force on 1 August 2024, with staged application. The general application date of 2 August 2026 did not change — the Article 50 transparency obligations already apply. The Digital Omnibus, however, moved the two heavy high-risk waves:

DateWhat appliesWho it concerns
2.2.2025Prohibited practices (Art. 5) and AI literacyEveryone
2.8.2025General-purpose AI (GPAI) obligations, governance, penalty regimeGPAI providers
2.8.2026General application; Article 50 transparency (chatbots, deepfakes, synthetic content); start of enforcementEveryone — already in force
2.12.2026New prohibitions (non-consensual intimate imagery, CSAM); end of the transitional period for machine-readable markingGenerative AI providers
2.8.2027Mandatory operation of a national regulatory sandboxMember States
2.12.2027High-risk obligations of Annex III — standalone systems (deferred from 2.8.2026)Providers and deployers
2.8.2028High-risk obligations of Annex I — AI embedded in regulated products (MDR/IVDR)Product manufacturers
2.8.2030Compliance of pre-existing high-risk systems used by public authorities (Art. 111 of the Regulation)Public sector
The distinction that decides the deadline in healthcare. A triage-support or resource-management system developed standalone falls under Annex III with a December 2027 horizon. An algorithm embedded in an imaging device CE-marked as a medical device falls under Annex I and follows August 2028. Classification is decided by the regulatory pathway of the product, not by its clinical use.

2. The three deadlines to put in your calendar

31.12.2026
Public-Sector AI Registry

Every public body already operating an AI system must declare it «without delay and in any case no later than 31.12.2026» (Law 5321/2026 Art. 25 §2). For new systems the declaration is a prerequisite before operation (Art. 21).

2.12.2027
Annex III

Standalone high-risk systems: full risk-management system, data quality, documentation, human oversight, conformity assessment.

2.8.2030
Legacy public-sector systems

Pre-existing systems of private operators are exempt until a substantial design change — the public sector is not: compliance by 2.8.2030 regardless of modification (Art. 111).

3. Who supervises what in Greece (Law 5321/2026)

BodyRoleProvision
Hellenic DPAMarket surveillance authority for prohibited practices, Annex III high-risk and Article 50 transparency; single point of contact with the Commission; recipient of the single complaints systemArts. 3, 4, 7
EETTNotifying authority for notified bodies; hosts the AI Coordination and Expertise CentreArts. 5, 6
DPA + EETTJoint supervision of the national AI regulatory sandbox — the legal basis was enacted a year ahead of the mandatory deadlineArt. 12
Special Secretariat for AI (Ministry of Digital Governance)Keeper of the Public-Sector AI Systems Registry; AI ObservatoryArts. 21, 22
The practical meaning of this choice. The same authority that enforces the GDPR now also supervises AI. For a healthcare entity this means one supervisory counterpart — but also one line of examination: a data audit can extend into AI matters and vice versa.

4. The Greek particularities — stricter than the Regulation

ProvisionWhat it saysWhy it matters
Real-world testing (Art. 13)Approval is granted «only upon express written permission»; «the expiry of the thirty (30) day period … shall not be deemed to constitute approval»It overrides the tacit approval allowed by Art. 60(4) of the Regulation. A pilot in a clinical setting does not start because the authority stayed silent
Periodic penalty payments (Art. 16)Up to «two percent (2%) of the average daily total worldwide turnover» for non-compliance with an order; ceases upon proof of complianceAn enforcement mechanism on top of the Regulation's fines (up to €35m or 7% for prohibited practices, up to €15m or 3% for other infringements)
Deepfakes (Art. 23)Criminal penalties for removing or altering the Article 50 transparency markings on deepfake contentAlready in force, since it attaches to Article 50 which applies from 2.8.2026
Whistleblowers (Art. 20)AI Act infringements are brought within the scope of Law 4990/2022 (whistleblowing)The organisation's internal reporting channels must be extended to cover AI

5. An incident on an AI system: three reports, one event

For a healthcare entity within NIS2 scope, an incident affecting a high-risk AI system can trigger three parallel notification regimes:

FrameworkRecipientDeadline
Law 5160/2024 Art. 16 (NIS2)National Cybersecurity Authority / CSIRT24 hours early warning · 72 hours notification · 1 month final report
Regulation 2024/1689 (serious incident)Hellenic DPA as market surveillance authorityPer the Regulation — slower
GDPR Art. 33 (if personal data affected)Hellenic DPA as supervisory authority72 hours
Two conclusions no single source states. First, the shortest deadline governs: the 24-hour NIS2 clock sets the response tempo regardless of which framework is conceptually primary. Second, the same authority receives the report in two different capacities and under different deadlines. You need a single response procedure that produces all three reports from the same event — not three independent flows that risk diverging on the facts they declare.

6. AI Act and NIS2: cumulative application, not hierarchy

The Regulation governs the system (design, training data, human oversight, model robustness); NIS2 governs the entity (networks, systems, the organisation's overall risk management). Compliance with one does not discharge the other. Article 15 of the Regulation («accuracy, robustness and cybersecurity») expressly names data and model poisoning, adversarial examples and model evasion — threats the entity's cybersecurity programme must now cover by name.

Mind the citation. An «Article 15» exists both in the AI Regulation (cybersecurity of the system) and in Law 5160/2024 (the entity's ten risk-management measures). The identical numbering is coincidental — the subject matter is entirely different.

7. What did NOT change — the scope of the repeal

Article 26 of Law 5321/2026 provides: «From the entry into force of this law, Chapter B΄ of Part A΄ of Law 4961/2022 is repealed». Chapter B΄ comprises Articles 3–14 — the first national attempt to regulate AI (algorithmic impact assessments, registries etc.), replaced without automatic continuity.

Articles 18–20 of the same law — the Information and Communication Systems Security Officer, duties, risk-analysis plan — belong to Chapter C΄ («Information and network security provisions») and remain fully in force. Everything in the Security Officer Guide is untouched by the new law.

8. Immediate action list for a healthcare entity

#ActionBasis
1Map every AI system in operation — from imaging-support tools to appointment routing and chatbotsPrerequisite for everything below
2Registry declaration for public bodies — existing systems by 31.12.2026, new ones before operationLaw 5321/2026 Arts. 21, 25 §2
3Risk classification per system: prohibited / high-risk (Annex I or III — this decides the deadline) / transparency / minimalReg. 2024/1689 as amended
4Transparency compliance now: user notice for chatbots, marking of synthetic content and deepfakesArt. 50 — in force since 2.8.2026
5Extend whistleblowing channels to cover AI infringementsLaw 5321/2026 Art. 20 → Law 4990/2022
6Unify incident response so one event produces all three reports (NCA 24h, DPA ×2)Law 5160/2024 Art. 16 · Reg. 2024/1689 · GDPR Art. 33
7Add AI threats (data poisoning, adversarial examples, model evasion) to the risk assessment and threat registerReg. 2024/1689 Art. 15 + NIS2 Art. 21
8No real-world pilot of a high-risk system without express written permissionLaw 5321/2026 Art. 13

Sources and references

  • Law 5321/2026 (Gazette A΄ 114 of 20.07.2026) — implementing measures for Regulation (EU) 2024/1689, amendment of Law 4961/2022 and other provisions. In particular Articles 3–7 (authorities), 12–13 (innovation and testing), 16–20 (penalties, whistleblowers), 21–23 (public sector, deepfakes), 25–26 (transitional and repealed provisions).
  • Regulation (EU) 2024/1689 (AI Act), in particular Articles 5, 6 and Annexes I/III, 15, 50, 60, 99, 111.
  • Regulation (EU) 2026/1744 (the «Digital Omnibus on AI») — Official Journal 24.07.2026, in force 27.07.2026. Deferral of high-risk deadlines, new Article 5 prohibitions.
  • Law 4961/2022 (Gazette A΄ 146 of 27.07.2022) — Articles 18–20 (Security Officer) remain in force; only Articles 3–14 (Chapter B΄ of Part A΄) were repealed.
  • Law 5160/2024 (Gazette A΄ 195 of 27.11.2024) — NIS2 transposition; Article 16 on the 24/72-hour notification deadlines.
  • Law 4990/2022 — protection of persons reporting infringements (whistleblowing).
  • All article identifiers verified against the original Gazette texts.
Related tools. For the full Security Officer regime see the Security Officer Guide. For interactive compliance guidance, the NIS2 Advisor.
Produced with the tools of aegiscyber.gr. Removal of this attribution is not permitted.