🎯 Signal of the Week

On Sunday the EU AI Act had obligations. On Monday it has enforcement.

Welcome to Issue 01,

I wanted the first Signal to be something you can act on the same week you read it, and the calendar handed me a good one. Yesterday, 2 August 2026, the European Commission's supervision and enforcement powers over general-purpose AI (GPAI) model providers came into force. The obligations themselves are a year old. What changed this weekend is that the Commission can now use them.

Most of the coverage led with the number: fines up to 3% of global annual turnover, or 15 million euros, whichever is higher. That is the attention-grabbing line, and it is real. It is also, for a Medical Affairs leader, the least useful sentence in the announcement, because you do not provide a foundation model. Someone else does. The sentence that should move your Monday is buried in Articles 91 to 93.

What actually switched on

Three powers went live. Under Article 91 the Commission can compel a GPAI provider to hand over the technical documentation and training-data summaries behind a model. Under Article 92 it can demand direct access to the model itself to run its own evaluations. Under Article 93 it can order risk-mitigation measures and, at the far end, force a provider to restrict, withdraw, or recall a model from the EU market. Article 101 attaches the fines. Refusing any of the first three is itself a finable offense.

Read that again from the deployer's chair. The regulator now has a legal lever to pull a general-purpose model out of the EU market. You are not the target of that lever. You are downstream of it.

The read that matters: your embedded Medical Affairs AI stack inherits your model provider's regulatory exposure. If the insight engine, the medical-information drafting assistant, or the literature-monitoring agent you rely on sits on one foundation model, and that model gets throttled, restricted, or withdrawn in the EU, your workflow does not degrade gracefully. It stops..

Why this lands on Medical Affairs specifically

Two reasons. First, Medical Affairs has spent the last eighteen months moving from experiments to production. The tools that classify field insights, triage medical-information inquiries, and draft first-pass response letters are no longer pilots you can switch off without anyone noticing. They are load-bearing. Load-bearing systems are exactly the ones where a supply-side shock is expensive.

Second, most of these systems were bought, not built. When you license an embedded vendor, you also license their model dependency, usually without seeing it. The vendor's contract rarely tells you which foundation model sits underneath, whether that provider signed the GPAI Code of Practice, or what happens to your workflow if that provider draws a Commission evaluation. On Sunday that was an abstract governance question. On Monday it is a continuity question.

What I would do this week

Nothing dramatic. One email. Ask each Medical Affairs AI vendor three things: which foundation model or models power the product, whether that provider adheres to the GPAI Code of Practice, and what the fallback is if a given model becomes unavailable in the EU. You are not trying to catch anyone out. You are trying to find out whether your most-used workflow has a single point of failure that a regulator in Brussels can now touch. If the vendor cannot answer in one paragraph, that is your answer.

The firms that treated the AI Act as a legal department problem spent the last year writing policies. The firms that treated it as an architecture problem spent it mapping dependencies. Starting this week, only one of those two groups can tell you what breaks if a model goes away.

🧠 Framework of the Week

The Deployer Exposure Map

The Signal ends with a question: which of your AI use cases actually carry the risk the AI Act just made enforceable? Not all of them do, and treating them as equal wastes the one thing Medical Affairs leaders never have enough of, which is attention. Here is the map I use to sort them.

Plot every Medical Affairs AI use case on two axes. The vertical axis is workflow criticality: how much breaks, and how fast, if this tool goes dark tomorrow. The horizontal axis is model-provider concentration: does the tool depend on a single foundation model, or can it run on several. The interesting corner is the upper right.

How to read the four quadrants

Act first (critical, single-provider). This is your exposure. A production workflow your team depends on, riding on one model you do not control. For each of these, get the Article 53 documentation from the vendor, confirm a second model can be substituted, and write down how long the swap would take. If the honest answer is "we do not know," you have found this quarter's most important governance task.

Diversify slowly (critical, multi-provider). Important, but already model-agnostic. The work here is maintenance: keep the fallback provider tested and warm so it stays a fallback rather than a fire drill.

Watch the vendor (low criticality, single-provider). Convenient tools that are not load-bearing yet, but get stickier the more your team leans on them. Track the dependency so a "nice to have" does not quietly become an "act first" without anyone deciding it should.

Monitor (low criticality, multi-provider). Low stakes, low lock-in. Review at contract renewal and spend your attention elsewhere.

One pass through this map, done honestly with your vendors in the room, tells you more about your real AI Act exposure than any policy document. Most teams discover they have two or three genuine "act first" cases and a long tail of noise. Name the two or three. Ignore the noise.

The point of the map is not to slow anything down. It is to concentrate your governance effort where a supply-side shock would actually hurt, and to let everything else keep moving. Governance that treats every use case as high-risk is just a slower way of getting nothing done.

📚 5 THINGS WORTH READING

Five reads, all paywall-free

  • 01

    artificialintelligenceact.eu (Future of Life Institute)

    The clearest plain-language walk-through of exactly which powers switched on this weekend, article by article. If you read one thing behind this issue's Signal, read this.

🔧 TOOL OF THE WEEK

OpenEvidence

What it is. A clinical evidence engine that answers medical questions in plain language, grounded in peer-reviewed sources (NEJM, JAMA, NCCN, Cochrane, PubMed) with citations attached to every claim. It crossed one million clinician consultations in a single day earlier this year and is now used by roughly 860,000 verified US clinicians. It recently added a hands-free voice mode.

How to use it in Medical Affairs and MSL work. Three fits. First, pre-call evidence briefs: pull a cited synthesis of the latest data on a mechanism or indication before a KOL meeting, then verify the citations yourself. Second, medical-information triage: use it to orient quickly on an inbound question before drafting the formal, MLR-governed response. Third, literature grounding: a fast second opinion on what the current evidence base actually says, with the primary sources one click away.

What it is

Citation-grounded clinical evidence engine for healthcare professionals

Best for

Pre-call briefs, medical-information orientation, evidence grounding

Access

Free for verified clinicians. Create an account and verify your NPI or professional credentials at openevidence.com

Cost model

Free to the user, funded by advertising

Compliance note. OpenEvidence is a decision-support and orientation tool, not a source of MLR-approved or promotional content. Never paste proprietary, pre-approval, or pipeline information into it, and treat every output as a draft that requires medical review before it informs any external communication. Access is gated to verified clinicians, so it is not a fit for non-clinical staff. Because it is ad-funded, factor data-use and independence questions into your assessment. Under the EU AI Act's Article 50, a professional-use diagnostic-support tool may be exempt from end-user AI disclosure, but your internal governance and audit-trail obligations still apply.

That is Issue 01. If a colleague forwarded this to you, you can get it yourself every Monday at newsletter.ichealth-ai.com/subscribe.
One email a week. No sponsorship. See you next Monday.

iCHealth Pathway is a weekly research note by Dr. Issam Chebouti on AI transformation for Pharma, Medical Affairs, and Healthcare leaders.

Issue 01, Monday 3 August 2026. 5 minutes of signal. 0 minutes of hype.