How the EU AI Act Applies to Medical Devices
By Vaclav Vlcek, MD
A manufacturer that adds AI to a medical device now answers to a second regulation on top of the MDR or IVDR. That regulation is the EU AI Act, and it governs how the AI is built, documented, and overseen. For higher-risk devices, a Notified Body checks that work as part of the review the device already goes through.
For most companies the practical question is a narrow one: what the Act adds to the MDR or IVDR, and when it starts to apply. This introduction answers both, and sets up the three parts that follow.
Summary
The EU AI Act (Regulation (EU) 2024/1689) is the first broad AI law in the EU, and it treats most AI-enabled medical devices as high-risk. A device that already undergoes third-party conformity assessment under the MDR or IVDR is high-risk under Article 6(1) and Annex I of the Act, so it must meet the Act's requirements on top of its existing ones. After the Digital Omnibus on AI (Regulation (EU) 2026/1744), these obligations apply from 2 August 2028 for medical devices, and conformity is assessed by a Notified Body, in most cases through the existing MDR or IVDR procedure. The Act adds a layer on top of the MDR and IVDR rather than replacing them.
What the EU AI Act Is
The EU AI Act's reach comes from its legal form. It is a regulation, which means it applies directly in every member state with no national law to enact first. It also carries the same standing as the MDR, IVDR, and GDPR, which puts it in the same compliance conversation a manufacturer already has.
The Act reached that status quickly for a law of its scale. Formally titled Regulation (EU) 2024/1689, it was approved by the European Parliament on 13 March 2024, adopted by the Council on 21 May 2024, published in the Official Journal on 12 July 2024, and in force on 1 August 2024.
It has not stood still since. A first amendment arrived on 27 July 2026 through the Digital Omnibus on AI (Regulation (EU) 2026/1744), which pushed several of the high-risk deadlines back. That amendment is the reason the dates in this series differ from those in the Act as first published.
How the Act Sits Alongside the MDR and IVDR
For most manufacturers, the most important question is this: does the Act reach their device at all? The answer is a single test. A device that already undergoes third-party conformity assessment under the MDR or IVDR is high-risk under the Act, through Article 6(1) and Annex I, which name those regulations among the product laws that pull a device into the tier. In practice that captures AI in MDR classes IIa to III and IVDR classes B to D.
The Act operates as an added layer, and the MDR or IVDR regime stays fully in force underneath it. A device keeps every duty it already carried and takes on the Act's in addition, which is why manufacturers end up managing a second, overlapping set of obligations.
The assessment stays with a Notified Body, and in most cases it can run inside the existing MDR or IVDR procedure. That usually means a single combined assessment covering the device and its AI together.
When the Rules Apply
Timing is where the Act causes the most confusion, and for two reasons: it phases in over several years, and the Digital Omnibus moved the later dates back after the fact. For a medical-device manufacturer, three points on that timeline carry the weight.
The first is the earliest, and it belongs to other people's systems. Stand-alone high-risk systems under Annex III, such as recruitment or credit-scoring tools, apply from 2 December 2027. The date that matters for medical devices comes later. AI embedded in regulated products under Annex I, medical devices among them, applies from 2 August 2028, and that is the date most manufacturers plan to.
The third point is a caution that sits under the other two. A set of duties runs on the original schedule regardless of the deferral. The Article 50 transparency obligations and the enforcement of the general-purpose AI rules still begin on 2 August 2026, which gives a manufacturer an earlier date to track alongside 2028.
How a Manufacturer Can Prepare
Companies do not have to wait for 2028. The preparation work can start now, and it is the same whatever the deadline. Most of it maps onto processes an ISO 13485 manufacturer already runs. There are six steps to cover this:
Confirm whether the Act applies, and in what role
Determine whether the product meets the definition of an AI system, whether it is high-risk, and whether the company acts as a provider, deployer, importer, or distributor. The role sets the obligations.
Run a gap assessment against the MDR or IVDR
Some duties already exist under those regulations, such as a quality management system, risk management, and technical documentation. Others are new for the sector, such as data governance and human oversight. A clause-level comparison shows where the gaps are.
Update the quality system and documentation
Revise the quality management system, technical documentation, and post-market surveillance procedures to cover the AI-specific requirements.
Confirm the right people are in place
AI, data, and regulatory expertise may need recruitment or training.
Govern the training, validation, and test data
A Notified Body may request access to these datasets during conformity assessment, so data governance should be in place from the start of development.
Track official guidance
Follow the European Commission and the EU AI Office for guidance on aligning the MDR/IVDR and AI Act conformity routes.
What This Series Covers
The rest of the series follows the order a manufacturer would work in, each part building on the one before.
Part 1 - Regulatory Foundations and Scope
Covers the definitions, the roles of provider and deployer, the risk tiers, and the implementation timeline. [Internal link: descriptive anchor to Part 1]
Part 2 - Core Requirements for Medical Device AI Systems
Covers the article-by-article obligations and how they layer onto the MDR, ISO 13485, and IEC 62304. [Internal link: descriptive anchor to Part 2]
Part 3 - Cross-Regulatory Intersections and Practical Compliance
Covers how the Act meets the MDR, the GDPR, and the U.S. FDA, with a practical compliance path. [Internal link: descriptive anchor to Part 3]
Frequently Asked Questions
When do the EU AI Act's rules for medical devices apply?
The core obligations for AI embedded in medical devices apply from 2 August 2028, following the deferral introduced by the Digital Omnibus on AI. Stand-alone high-risk systems under Annex III apply earlier, from 2 December 2027.
Does the EU AI Act replace the MDR or IVDR?
No. The Act adds a layer on top of the MDR and IVDR. A device that is high-risk under those regulations is also high-risk under the Act and must meet both sets of requirements.
Is every AI-enabled medical device high-risk under the Act?
Not automatically. A device is high-risk under Article 6(1) and Annex I when it undergoes third-party conformity assessment under the MDR or IVDR. The Digital Omnibus also narrowed the safety-component definition, so an AI feature that only assists the user or optimises performance without creating a health or safety risk may fall outside the high-risk category.
Who is responsible under the Act, the manufacturer or the hospital?
Both, in different roles. The manufacturer is usually the provider and holds the pre-market obligations. A hospital that uses the system is usually the deployer and holds the in-use obligations, such as human oversight and monitoring.
