p4mx health
← All impulses
Medical softwareAugust 24, 2026· 4 min read

The EU AI Act hits medical devices twice

Teams building software with a medical intended purpose know the MDR. For AI-enabled products, a second body of law has applied since 2024: the AI Act. Both operate in parallel, and for many medical devices the AI Act bites precisely where a notified body already assesses. This article shows when an AI medical device counts as high-risk, how the two conformity routes connect, and which deadlines apply.

Since 2024, a medical device with an AI component sits under two bodies of law at once. Alongside the Medical Device Regulation (MDR), which your teams know from the field, the European Union’s AI Act applies. Both require a conformity assessment, both have their own deadlines — and if you think only of one, you plan the other too late.

Two regulations, one product

The MDR (Regulation (EU) 2017/745) decides whether software is a medical device and which risk class it falls into. The AI Act (Regulation (EU) 2024/1689, in force since 1 August 2024) governs the requirements placed on an AI system — its risk management, its data, its traceability. For an AI medical device the two apply side by side: the AI Act does not replace the MDR, it layers on top.

Two terms carry the rest of this article. An AI system within the meaning of the Regulation is more than any piece of statistics or a fixed rule; whether a function falls under it is itself an assessment. A notified body is an independent, state-designated conformity assessment body that assesses conformity for many medical devices.

When an AI medical device counts as high-risk

Under Article 6(1) of the AI Act, an AI system is high-risk where two conditions meet: first, the AI system is itself a product — or a safety component of a product — covered by one of the Union harmonisation acts listed in Annex I of the AI Act; and second, that product must undergo a third-party conformity assessment before being placed on the market. The MDR is in that Annex I.

Because medical software rarely falls into class I under Rule 11 of Annex VIII of the MDR, but regularly sits at class IIa or above — and therefore engages a notified body — the second condition is met for most AI medical devices. In short: as soon as a notified body must assess your AI medical device, it is high-risk under the AI Act.

The Coordination Group (MDCG) and the AI Board (AIB) confirmed this in June 2025 in guidance MDCG 2025-6: an AI medical device is high-risk where it is a safety component, or is itself a medical device and is subject to conformity assessment by a notified body under the MDR or IVDR. Products without a notified body — in-house manufacture or self-certified class I, for example — do not meet the second condition and are not high-risk on that basis.

How the two conformity routes connect

Both frameworks require a conformity assessment, but they are not meant to be run twice. Under MDCG 2025-6, the AI Act’s additional requirements are embedded into the existing MDR assessment and handled through the same notified body, so as to avoid duplicate assessments. In practice, this order has proven itself:

  1. Clarify whether the product is an AI system within the meaning of the Regulation and whether it is high-risk under Article 6.
  2. Reconcile the requirements: risk management, data governance, technical documentation, record-keeping, human oversight and transparency overlap with MDR obligations but are not identical to them.
  3. Close only the gap to the MDR, rather than writing the existing MDR documentation a second time.
  4. Agree early with the notified body how the two assessments will be brought together.

Deadlines — and a moving target

The AI Act applies in stages. The rules for high-risk systems via the Annex I product route — the route through which medical devices are caught — apply under Article 113 from 2 August 2027.

This date is currently in motion. In 2025 the European Commission proposed a simplification package (the “Digital Omnibus”) that would postpone the high-risk obligations for embedded products such as medical devices; as the deliberations stood in spring 2026, a shift to 2 August 2028 was under discussion. The procedure was not concluded at the time of writing. Check the binding deadline against the current text of the Regulation, therefore, not against this assessment.

Where this does not apply

Not every AI medical device carries the full weight of the AI Act, and no MDR obligation disappears because the AI Act applies. Where a product does not meet the second condition — no assessment by a notified body — it is not high-risk under Article 6(1); individual obligations such as transparency requirements may still apply. Conversely, the AI Act replaces neither the clinical evaluation nor the market surveillance of the MDR. And classification as an AI system is itself an assessment: not every statistical function is AI within the meaning of the Regulation. Where the legal position — as with the deadlines — is not yet settled, restraint toward sweeping statements is warranted.

Conclusion

For AI-enabled medical devices, conformity is not a question of either the MDR or the AI Act, but of both in one procedure. Placing the AI requirements alongside the MDR documentation early, and agreeing a joint route with the notified body, avoids duplicated work and late surprises. Because the deadlines are still moving, keeping an eye on the current state of the Regulation is part of planning.

Sources: Regulation (EU) 2024/1689 (AI Act), Article 6(1), Annex I and Article 113. Regulation (EU) 2017/745 (Medical Device Regulation, MDR), Annex VIII Rule 11. Medical Device Coordination Group and Artificial Intelligence Board: MDCG 2025-6 / AIB 2025-1, FAQ on the interplay between the Medical Devices Regulation & In Vitro Diagnostic Medical Devices Regulation and the Artificial Intelligence Act, June 2025. European Commission: Digital Omnibus package (legislative proposal), 2025 — procedure not concluded at the time of writing.

Does this match your situation?

We begin with a process analysis and show, with evidence, what is possible.

Arrange a conversation