Artificial Intelligence is reshaping healthcare, enabling unprecedented advances in diagnosis, treatment and personalised care. However, these benefits come with complex regulatory challenges, especially when AI is integrated into medical devices. In the European Union, manufacturers must navigate a dual regulatory framework: the Medical Device Regulation (MDR) and the In Vitro Diagnostic Medical Devices Regulation (IVDR), alongside the more recent Artificial Intelligence Act (AIA). Devices that incorporate high-risk AI systems—referred to as Medical Device Artificial Intelligence (MDAI)—must comply with the combined requirements of all applicable legislation. 

 

The AIA introduces novel provisions designed to address risks to health, safety and fundamental rights that arise from AI-specific characteristics, such as autonomy, opacity and adaptiveness. Meanwhile, the MDR and IVDR continue to ensure the clinical safety and performance of medical and diagnostic technologies. The interplay between these regulations demands a coherent approach from manufacturers, notified bodies and competent authorities. A harmonised strategy is essential to ensure compliance, avoid duplication and maintain public confidence in medical innovation. 

 

Defining High-Risk MDAI and Its Regulatory Implications 

A central concept introduced by the AIA is that of high-risk AI systems. An MDAI qualifies as high-risk under Article 6(1) of the AIA if it is either a safety component or constitutes the medical device itself, and if it is subject to third-party conformity assessment under MDR or IVDR. This dual condition links the classification of medical devices with the obligations under AI legislation, establishing a clear but stringent threshold. Not all MDAIs are automatically considered high-risk under the AIA; only those that fall within certain risk classes and require external conformity assessment are subject to its full scope. 

 

Must Read: Reforming EU Medical Device Rules for Better Care 

 

Importantly, the classification of a device under MDR or IVDR determines whether the AIA’s high-risk provisions apply, but the reverse is not true. A device deemed high-risk under AIA does not necessarily move to a higher risk class under MDR or IVDR. This regulatory principle ensures that AI-specific requirements enhance but do not replace the existing safety and performance criteria. Furthermore, MDR Annex XVI products, accessories and in-house manufactured devices used only within health institutions are subject to different levels of scrutiny, with some excluded from high-risk categorisation under the AIA, provided they meet specific conditions. 

 

Manufacturers must recognise that different definitions apply under each framework. While MDR and IVDR refer to ‘users’ (typically healthcare professionals or patients), the AIA introduces the term ‘deployer’, which refers to legal or natural persons using an AI system professionally. These terminological distinctions affect compliance obligations and clarify the roles of those involved in the development, deployment and supervision of MDAI. 

 

Integrated Systems for Quality and Risk Management 

Quality and risk management systems are fundamental to both the MDR/IVDR and AIA. The MDR and IVDR already require that manufacturers establish, document, implement and continuously update quality management systems that are proportionate to the device’s classification. The AIA builds on this by requiring quality systems specifically targeted to AI. These must include policies on data management, risk mitigation, transparency, human oversight and cybersecurity. Manufacturers are encouraged to integrate these obligations within their existing frameworks rather than build parallel systems. 

 

Lifecycle management plays a crucial role. High-risk MDAI must be designed for safe use throughout their operational life, with provisions for post-market monitoring, feedback loops and updates. The AIA stresses that risk management must be a continuous process, with attention to real-world data, evolving risks and system behaviour over time. For AI systems that learn after deployment, post-market monitoring becomes essential to ensure ongoing compliance, particularly where models update or adapt in response to new inputs. 

 

The AIA’s requirement for a risk management system focuses on preventing harm to fundamental rights and ensuring that AI outputs remain trustworthy. This includes identifying and mitigating foreseeable risks such as algorithmic bias or dataset drift. These considerations go beyond traditional clinical safety and touch on ethical dimensions of AI use in healthcare. Both the MDR/IVDR and AIA require that these risks are systematically documented, reviewed and addressed, with detailed record-keeping to demonstrate conformity. 

 

Data Governance, Transparency and Human Oversight 

AI systems are only as reliable as the data on which they are built. Accordingly, the AIA introduces stringent data governance requirements for high-risk MDAI. These include obligations to ensure that training, validation and testing datasets are of high quality, representative of the intended population and sufficiently free of bias and errors. The MDR and IVDR reinforce these expectations through requirements for clinical and performance evaluation based on robust, well-designed studies. The use of inappropriate or biased datasets not only compromises performance but may also infringe upon legal protections against discrimination. 

 

Transparency is another shared priority. The AIA requires that high-risk MDAI be designed so that outputs are interpretable and appropriately documented. Deployers must understand how to use the system, what its limitations are and under what conditions it is safe and effective. Similarly, the MDR and IVDR require that users receive clear instructions and adequate information to support clinical decision-making. Transparency is not a feature to be added later—it is a core component of system design and risk management, verified as part of the conformity assessment. 

 

Human oversight is legally mandated by both frameworks. High-risk MDAIs must be designed to allow human intervention and supervision. The AIA specifies that oversight measures must be built into the system architecture and tailored to the level of autonomy. This may include emergency stop functions, alerts or constraints on system decision-making. The MDR and IVDR further require that medical devices be usable by their intended users, with particular attention to reducing use errors. Usability engineering and training requirements must also be aligned, particularly when MDAI is deployed in sensitive or high-stakes environments. 

 

The convergence of the Artificial Intelligence Act with the MDR and IVDR represents a major shift in the regulation of medical technologies in the European Union. Manufacturers of high-risk MDAI face a multi-layered regulatory landscape, but one that is increasingly harmonised and transparent. Compliance with both frameworks is not only feasible but essential for ensuring that AI-driven devices are safe, effective and trustworthy. 

 

By integrating AI-specific requirements into existing quality and risk management systems, manufacturers can create a coherent approach that avoids redundancy while meeting the highest standards of safety, ethics and performance. Careful attention to data governance, transparency and human oversight will not only support regulatory compliance but also promote patient trust and professional accountability. As AI becomes an integral part of modern medicine, the regulatory frameworks that govern it must continue to evolve—but always with patient safety and fundamental rights at the forefront. 

 

Source: IDERHA 

Image Credit: iStock




Latest Articles

medical AI, EU compliance, MDR, IVDR, AI Act, MDAI, AI in healthcare, medical device regulation, high-risk AI Explore how EU law governs high-risk AI in healthcare, balancing safety, innovation, ethics, and compliance.