How the EU AI Act Applies to Medical Devices
By Vaclav Vlcek, MD
A manufacturer that adds new functionality to a medical device may come within a second regulation on top of the MDR or IVDR, but only where that functionality qualifies as an AI system under Article 3(1). Where it does, the EU AI Act may add obligations, depending on how the system is classified and on the role the company holds. For systems that qualify as high-risk under Article 6(1), a notified body examines that work as part of the sectoral review the device already goes through, once the relevant provisions apply.
For most companies the practical question is a narrow one: what the Act adds to the MDR or IVDR, and when it starts to apply. This introduction answers both, and sets up the three parts that follow.
Summary
The EU AI Act (Regulation (EU) 2024/1689) is the EU's horizontal framework for artificial intelligence, and many AI-enabled medical devices qualify as high-risk under it. Article 6(1) sets a two-part test: the AI must be a safety component of, or itself be, a product covered by one of the laws listed in Annex I, which include the MDR and IVDR at Section A; and that product must require third-party conformity assessment. For systems classified solely under Article 6(1) and Annex I, Section A, Chapter III, Sections 1 to 3, except Article 6(5), apply from 2 August 2028, following the Digital Omnibus on AI (Regulation (EU) 2026/1744), subject to Article 111. Under Article 43, the applicable AI Act requirements form part of the relevant MDR or IVDR conformity assessment, carried out by a notified body empowered to do so under Article 43(3).
What the EU AI Act Is
The EU AI Act's reach comes from its legal form. It is a regulation, which means it applies directly in every member state with no national law to enact first. It also carries the same standing as the MDR, IVDR, and GDPR, which puts it in the same compliance conversation a manufacturer already has.
The Act reached that status quickly for a law of its scale. Formally titled Regulation (EU) 2024/1689, it was approved by the European Parliament on 13 March 2024, adopted by the Council on 21 May 2024, published in the Official Journal on 12 July 2024, and in force on 1 August 2024.
It has not stood still since. A first amendment arrived on 27 July 2026 through the Digital Omnibus on AI (Regulation (EU) 2026/1744), which pushed several of the high-risk deadlines back. That amendment is the reason the dates in this series differ from those in the Act as first published.
How the Act Sits Alongside the MDR and IVDR
For most manufacturers, the most important question is this: does the Act reach their device at all? Article 6(1), as amended by the Digital Omnibus, answers it with a two-part test, and both parts have to be met.
First, the AI must be intended as a safety component of a product, or be that product itself, where the product falls under one of the EU laws listed in Annex I, Section A, the MDR and IVDR among them. Second, that product must be required to undergo third-party conformity assessment under the same legislation, subject to Article 6(1c).
Taken together, the two conditions can capture AI in MDR classes IIa to III and IVDR classes B to D. Notified-body involvement also reaches some lower-class devices: under MDR Article 52 that includes Class I devices placed on the market sterile, having a measuring function, or constituting reusable surgical instruments (Is, Im and Ir), and under IVDR Article 48 it includes Class A sterile devices. Note what class alone does and does not settle: it can satisfy the third-party assessment limb, but the AI must still be the regulated product itself or a safety component of it.
Example: AI inside a Class IIb diagnostic imaging tool, an AI-based ECG interpretation feature, and an IVD algorithm in IVDR class C can sit in the high-risk tier where the product concerned undergoes third-party conformity assessment and the AI is itself the regulated product or a safety component of it. Merely forming part of the product is not enough. A Class I device carrying only a self-declaration fails the second condition and does not enter the tier this way. A Class Is, Im or Ir device does involve a notified body, for sterility, metrology or reuse, so it needs checking rather than assuming.
The Act operates as an added layer, and the MDR or IVDR regime stays fully in force underneath it. The existing MDR or IVDR duties remain; the applicable AI Act duties are added on top, attaching to the AI system and to the operators concerned. That is why manufacturers end up managing a second, overlapping set of obligations. We work through that overlap with manufacturers in our EU MDR compliance consulting and IVDR consultancy work.
For an Article 6(1) system covered by Annex I, Section A, the provider follows the applicable MDR or IVDR conformity-assessment procedure, and the AI Act's Section 2 requirements form part of that assessment. There is no separate AI Act procedure to run alongside it.
Example: A manufacturer placing a new Class IIb AI diagnostic tool on the market after the applicable date has the notified body examine the AI Act requirements within the MDR procedure, keeping it to one assessment covering the device and its AI. The same applies to a legacy system undergoing a significant change in its design after that date.
When the Rules Apply
Timing is where the Act causes the most confusion, and for two reasons: it phases in over several years, and the Digital Omnibus moved the later dates back after the fact. For a medical-device manufacturer, three points on that timeline carry the weight.
Article 113 assigns 2 December 2027 to the Article 6(2) and Annex III route and 2 August 2028 to the Article 6(1) and Annex I route. Where only one route applies, the date is clear. The Regulation does not expressly resolve the date where both routes independently apply. Medical-device AI will commonly follow the Annex I route, but an Annex III assessment remains necessary.
The third point is a caution that sits under the other two. A set of duties runs on the original schedule regardless of the deferral. The Article 50 transparency obligations have applied since 2 August 2026, and from that date the AI Office and national authorities began enforcing the applicable rules. A manufacturer whose systems fall within Article 50 therefore has an earlier date to track alongside 2028. Article 50(2), covering machine-readable marking of synthetic content, applies generally from that date too, with a transitional compliance deadline of 2 December 2026 for systems already placed on the market before it.
Example: One company can face all three dates. If the AI in its Class IIa cardiac monitor meets both Article 6(1) conditions and does not independently fall under Article 6(2) as well, it falls due on 2 August 2028. The recruitment screening tool its HR team uses is an Annex III system and, if it remains high-risk after applying Article 6(3), is due on 2 December 2027. And if the company provides the chatbot on its support site, the Article 50(1) disclosure-design duty has applied to it since 2 August 2026, unless the AI interaction is obvious from the perspective of a reasonably well-informed, observant and circumspect natural person. Where the chatbot is a third-party product the company merely deploys, that design duty sits with its provider.
One further rule concerns high-risk systems already placed on the market or put into service before their applicable date. Under Article 111(2), the high-risk regime applies to the operators of such systems only where, from that date, the systems undergo significant changes in their designs. For a system classified solely through Article 6(1), that date is 2 August 2028. Recital 39 makes clear that the transition operates at the level of type and model: where at least one unit was lawfully placed on the market or put into service before the cut-off, further units of the same type and model fall within it for as long as the design remains unchanged.
Two cautions on that rule. "Significant changes in their designs" is the statutory test here, and it is a different test from the "substantial modification" that triggers a fresh conformity assessment under Article 43(4), the two should not be treated as interchangeable. And providers and deployers of high-risk systems intended for use by public authorities face a separate backstop date of 2 August 2030.
How a Manufacturer Can Prepare
Companies do not have to wait for 2028. The preparation work can start now, and it is the same whatever the deadline. Most of it maps onto processes an ISO 13485 manufacturer already runs. Seven steps cover the ground:
Confirm whether the Act applies, and in what role
Determine whether the product meets the definition of an AI system, whether it is high-risk, and whether the company acts as a provider, deployer, importer, or distributor. The role sets the obligations.
Run a gap assessment against the MDR or IVDR
Some duties already exist under those regulations, such as a quality management system, risk management, and technical documentation. Others are new for the sector, such as data governance and human oversight. A clause-level comparison shows where the gaps are.
Update the quality system and documentation
Revise the quality management system and technical documentation to cover the AI-specific requirements, and integrate the Act's post-market monitoring arrangements into the MDR or IVDR post-market surveillance system.
Confirm the right people are in place
AI, data, and regulatory expertise may need recruitment or training.
Govern the training, validation, and test data
Where relevant and limited to what is necessary for its tasks, the notified body must be granted full access to those datasets as part of the technical documentation assessment, subject where appropriate to security safeguards. Data governance should therefore be in place from the start of development.
Track official guidance
Follow the European Commission and the EU AI Office for guidance on aligning the MDR/IVDR and AI Act conformity routes. The joint MDCG and AI Board guidance (MDCG 2025-6) is still the latest sectoral guidance on that interplay, but it is non-binding, dated 19 June 2025, and predates the Digital Omnibus, so it must be read subject to the consolidated Act and Regulation (EU) 2026/1744.
Check assessment capacity early
Under Article 43(3), the Annex I Section A notified bodies to which that provision refers must apply for designation by 28 January 2028. A body already notified under the MDR or IVDR may perform that assessment only where its compliance with Article 31(4), (5), (10) and (11) has been assessed and evidenced through the existing sectoral notification. Applying is not the same as being designated, so a manufacturer planning a 2028 assessment should confirm its notified body's position and capacity well before then.
Example: A manufacturer running the gap assessment typically finds that risk management and technical documentation already have a solid basis in its MDR file, while the Act's data-governance duties under Article 10 and automatic logging under Article 12 call for more explicit and prescriptive AI-specific controls than the MDR asks for.
QMLogic supports this work directly through EU AI Act consulting for health software.
One further development is worth watching rather than relying on. Article 2(13), inserted by the Digital Omnibus, empowers the Commission to limit specific requirements in Articles 9 to 15 and 17 to 25 for Article 6(1) systems, where Annex I Section A legislation such as the MDR provides equivalent or higher protection and the limitation does not reduce overall protection. The Commission must adopt the delegated acts specifying this by 2 August 2027. Article 2(13) provides no self-executing limitation: subject to the Article 113 application dates, the requirements remain applicable unless and until a delegated act limits specified requirements for specified systems. None was in force as at 10 August 2026.
What This Series Covers
The rest of the series follows the order a manufacturer would work in, each part building on the one before.
Part 1: Regulatory Foundations and Scope covers the definitions, the roles of provider and deployer, the risk tiers, and the implementation timeline.
Part 2: Core Requirements for Medical Device AI Systems covers the article-by-article obligations and how they layer onto the MDR, ISO 13485, and IEC 62304.
Part 3: Cross-Regulatory Intersections and Practical Compliance covers how the Act meets the MDR, the GDPR, and the U.S. FDA, with a practical compliance path.
Frequently Asked Questions
When do the EU AI Act's rules for medical devices apply?
Article 113 assigns 2 December 2027 to the Article 6(2) and Annex III route and 2 August 2028 to the Article 6(1) and Annex I route. Where only one route applies, the date is clear. The Regulation does not expressly resolve the date where both routes independently apply. The two dates follow the deferral introduced by the Digital Omnibus on AI (Regulation (EU) 2026/1744).
Does the EU AI Act replace the MDR or IVDR?
No, and MDR or IVDR classification does not decide AI Act classification either. The two serve different purposes. Under Article 6(1) an AI system is high-risk only where it is itself an Annex I product or a safety component of one, and that product must undergo third-party conformity assessment. MDR or IVDR classification can satisfy the second condition, but it does not by itself make the AI system high-risk. Where both conditions do hold, the device carries the Act's requirements alongside its existing MDR or IVDR duties.
Is every AI-enabled medical device high-risk under the Act?
Not automatically. Article 6(1) requires two conditions together: the AI must be a safety component of, or itself be, a product covered by a law listed in Annex I such as the MDR or IVDR, and that product must require third-party conformity assessment.
Two limitations can apply, each with its own reach. The first concerns the safety-component route, which is framed by two complementary rules: under Article 6(1a), AI used solely for non-safety purposes such as user assistance, performance optimisation, service efficiency, automation, convenience or quality control is not a safety component; Article 6(1b) nevertheless overrides that exclusion where failure or malfunction of the AI would endanger health and safety. Note carefully that this only qualifies the safety-component route. An AI system that is itself an MDR or IVDR regulated product, such as standalone Software as a Medical Device, satisfies Article 6(1)(a) through the other limb without needing safety-component status, but it is high-risk through Article 6(1) only if Article 6(1)(b) is also satisfied, subject to Article 6(1c). Standalone SaMD is therefore not automatically high-risk.
The second concerns in-house manufacture: a device manufactured and used only within health institutions established in the Union, not transferred to another legal entity, and satisfying all the other conditions of MDR or IVDR Article 5(5), is not third-party assessed and so is not high-risk through Article 6(1). That is not the end of the analysis: Article 6(2) classifies Annex III systems as high-risk independently, and emergency healthcare triage is a listed Annex III use case, so an in-house system still has to be assessed against Annex III and the Act's generally applicable provisions.
Who is responsible under the Act, the manufacturer or the hospital?
Both, in different roles. The manufacturer is usually the provider and holds the pre-market obligations. A hospital that uses the system is usually the deployer and holds the in-use obligations, such as human oversight and monitoring. The two are not mutually exclusive: a health institution that develops a system, or has one developed, and puts it into service under its own name can be the provider and the deployer at once.
