AI as a Medical Device: What the EU AI Act Means for Digital Health Manufacturers
Many AI-powered medical devices are automatically classified as high-risk systems under the EU AI Act — adding a second compliance layer alongside the MDR. What matters now is not another silo, but an integrated architecture. We map the legal landscape and show how two regulatory frameworks become one process.
Anyone placing AI-based software as a medical device on the EU market faces a dual regulatory challenge. In addition to the Medical Device Regulation (MDR) or the In Vitro Diagnostic Regulation (IVDR), the AI Act applies as a horizontal framework regulating the use of AI across all product categories in the EU. For digital health manufacturers, this is not a footnote — it is a strategic turning point.
Why Almost Every AI Medical Device Qualifies as High-Risk
The classification mechanism is far-reaching. Under Article 6 of the AI Act, any AI system that falls under the harmonisation legislation listed in Annex I (which includes MDR and IVDR) and requires a third-party conformity assessment is automatically classified as a high-risk AI system. In practice: as soon as a Notified Body is involved in the conformity assessment, the medical device is simultaneously a high-risk AI system. An AI-powered image analysis system, a sepsis prediction algorithm, or an intelligent insulin pump is therefore both a medical device and high-risk AI.
What the High-Risk Classification Requires in Practice
The obligations for providers are extensive: risk management system (Art. 9), data governance (Art. 10), technical documentation (Art. 11, Annex IV), logging (Art. 12), transparency (Art. 13), human oversight (Art. 14), accuracy, robustness and cybersecurity (Art. 15), quality management system (Art. 17), as well as post-market monitoring and incident reporting. Much of this will be familiar to an MDR-experienced organisation — but the overlap is not exact.
MDR and AI Act Do Not Duplicate Each Other
The central lever lies in integration rather than parallel operation. The greatest synergies are found in risk management (ISO 14971 / Art. 9 AI Act), technical documentation (Annex II MDR / Annex IV AI Act), and post-market surveillance. A QMS based on ISO 13485, extended by an AI module (aligned with ISO 42001), can serve both frameworks. AI-specific risks such as bias, model drift, and robustness can be embedded as additional categories in an existing ISO 14971 framework, rather than building a second system from scratch.
The Deadlines Are Shifting
The AI Act entered into force on 1 August 2024. Originally, 2 August 2026 was set as the deadline for high-risk obligations, and 2 August 2027 for AI in regulated products (Annex I, including MDR/IVDR). The EU Commission has since adjusted course via the Digital Omnibus: the central high-risk obligations are to be tied to the availability of harmonised standards and guidelines, meaning the rules are expected to become binding up to 16 months later than originally planned. For manufacturers: the direction is clear, the exact deadline is shifting. This is a window of opportunity, not a pause.
It Is a Leadership Issue, Not Just a Regulatory Affairs Issue
The AI Act affects development, data science, usability engineering, regulatory affairs, and vigilance simultaneously. This is a cross-functional transformation that must be set up and led as a change project. This is precisely where the thread of our work runs: Advisory for regulatory strategy and gap analysis, Delivery for the integrated implementation of QMS, documentation and risk management, Interim Leadership for guiding an organisation through a transition that demands multiple functions at once.
Conclusion
For AI medical devices: MDR and AI Act are cumulative, but not redundant. The competitive advantage does not come from a second compliance silo, but from a shared architecture — planned early and led consistently. The shifted deadlines are the right moment to set this up now.
| Dimension | MDR / IVDR | EU AI Act (High-Risk) | Integration Potential |
|---|---|---|---|
| Status | Fully in force | Staggered, high-risk deadlines shifting | – |
| High-risk trigger | – | Third-party conformity assessment under Annex I (Art. 6) | Classification to be considered jointly |
| Risk management | ISO 14971 | Art. 9 (iterative) | One framework, AI risks added |
| Technical documentation | Annex II | Annex IV | Shared structure |
| QMS | ISO 13485 | Art. 17 (+ ISO 42001) | Extension module, not parallel QMS |
| Post-market | Vigilance / PMS | Monitoring + Incident Reporting | Shared process |
| Responsibility | RA / QM | Cross-functional | Change project with clear leadership |
Do you have a concrete project?
Talk to us about your project, no obligation, at eye level.
Schedule a conversationMore Insights

SaMD and Rule 11: Why the Reform Proposal Does Not Restore Class I

Digital Business Ecosystems: The Evolution of Patient Care in 2027

