The EU AI Act: What Medical Device Manufacturers Need to Know (Even in the U.S.)

Aug 11, 2026 | 2 min read

Clinician in a lab coat reviewing brain scan images on a tablet

U.S. medical device manufacturers who haven’t started thinking about the EU AI Act are operating on a dangerous assumption: that it doesn’t apply to them.

The entered into force on August 1, 2024. It establishes the world’s first comprehensive legal framework for artificial intelligence, and it classifies AI systems used in medical devices as high-risk. All AI medical devices qualify automatically, without further analysis. For manufacturers of AI-enabled software as a medical device (SaMD), diagnostic algorithms, imaging analysis tools, or any device with embedded machine learning, the compliance obligations are significant.

The extraterritorial reach of this regulation mirrors the GDPR: it applies to any organization placing an AI system on the EU market or whose AI outputs are used by EU healthcare providers or hospitals, regardless of where that organization is based. According to a 2024 analysis published in , the majority of international manufacturers of the 690+ AI/ML-enabled medical devices authorized by the U.S. FDA fall within the EU AI Act’s scope.

This article breaks down what the regulation requires, how it interacts with existing EU frameworks like the MDR and IVDR, and what U.S. manufacturers need to do and when.


Key Takeaways

  • The EU AI Act classifies all AI systems in medical devices regulated under MDR or IVDR as high-risk AI, triggering a full set of documentation, governance, oversight, and conformity requirements.
  • The Act has extraterritorial reach: U.S.-based manufacturers whose AI outputs are used by EU healthcare providers are in scope, even without an EU presence.
  • Key compliance deadlines: most high-risk AI obligations applied from August 2, 2026; for CE-marked MDR/IVDR SaMD subject to Notified Body review, the deadline is August 2, 2027.
  • The AI Act does not replace MDR or IVDR. Both frameworks apply simultaneously to AI-powered SaMD.
  • Notified Bodies are already incorporating AI Act expectations into MDR audits, ahead of the legal deadline.

What Is the EU AI Act?

The EU AI Act is the European Union’s comprehensive regulatory framework for artificial intelligence. It classifies AI systems by risk level: unacceptable risk (prohibited), high-risk, limited risk, and minimal risk, setting compliance obligations proportionate to those classifications.

For the medical device industry, the relevant tier is high-risk AI. Under Annex III of the AI Act, any AI system that is itself a medical device, or functions as a safety component within a medical device regulated under the EU MDR or IVDR, is automatically classified as high-risk AI. There is no separate AI risk classification process for CE-marked devices. The medical device status determines it.

What makes this different from existing device regulations is what it focuses on. MDR and IVDR govern whether a device is safe and performs as claimed. The AI Act governs how the AI system within that device was built, trained, and governed. It introduces requirements around training data, model validation, bias assessment, explainability, and human oversight that go significantly beyond what FDA clearance or MDR CE marking have historically required.


Which Devices Are Covered?

SaMD that uses any form of machine learning, deep learning, statistical inference, or probabilistic modeling to generate clinical outputs falls under the AI Act. Covered outputs include diagnostic classifications, treatment recommendations, patient risk scores, and image analysis. Specific examples include:

  • Convolutional neural networks used in medical imaging analysis
  • Natural language processing tools used in clinical documentation or decision support
  • Bayesian classifiers and other probabilistic inference systems
  • Reinforcement learning models embedded in device control software

The AI Act does not apply to traditional rule-based software with fixed logic and no learning or inference component. Software that executes a defined algorithm without adaptive behavior is not an AI system under the Act’s definition.


The “Brussels Effect”: Why U.S.-Only Manufacturers Can’t Ignore This

The EU AI Act applies to any organization that “places an AI system on the [EU] market or puts an AI system into service in the Union,” as well as any organization whose AI output is used within the EU, regardless of where that organization is established. This structure, sometimes called the “,” has a well-established precedent in how GDPR reached U.S. companies.

In practical terms:

  • A U.S. company whose diagnostic AI is licensed to European hospitals is subject to the Act.
  • A U.S. company whose imaging software generates outputs reviewed by EU clinicians is subject to the Act.
  • A U.S. company with no EU office, no EU staff, and no EU servers is still in scope when its AI system’s outputs reach EU healthcare providers.

For manufacturers with any EU distribution, even indirect, this is not a future problem. It is a current one.

The regulatory landscape in the U.S. is also evolving. The FDA has increased its scrutiny of AI/ML-enabled devices, and while the U.S. has generally pursued a more flexible regulatory model than the EU, building the documentation infrastructure to meet EU AI Act standards will also improve your posture for FDA engagement. That relationship does not work in reverse. FDA 510(k) clearance does not satisfy EU AI Act obligations, and technical documentation built to FDA standards alone will have significant gaps relative to what the AI Act requires.


What High-Risk AI Obligations Require

Medical device manufacturers whose AI systems are classified as high-risk must address the following requirements before placing the device on the EU market.

Risk management system. Manufacturers must implement and document an AI-specific risk management process. This is separate from the ISO 14971 risk management already required under MDR and IVDR, though both must be integrated. The AI Act’s risk framing extends beyond device safety to include impacts on fundamental rights.

Data governance. Training, validation, and testing datasets must be documented as relevant, representative, and free from errors and bias. Demographic and geographic representativeness must be explicitly addressed. This is one of the most significant compliance gaps for AI medical devices, as most existing technical files under MDR do not include this level of data documentation.

Technical documentation. AI-specific content must be incorporated into the MDR/IVDR technical file. This includes training methodology, model architecture, validation approach across relevant subgroups, performance characteristics, and known limitations. For CE-marked devices, the AI Act allows this content to be integrated into the existing technical file rather than maintained separately. The content requirements are additive either way.

Transparency and instructions for use. Users must be explicitly informed about the AI system’s capabilities, performance metrics across relevant patient subgroups, limitations, and the circumstances under which human review or override is required. Most current SaMD instructions for use do not meet this standard.

Human oversight. The system must be designed so that clinicians can override, disregard, or reverse AI outputs at all times. The system must not undermine the user’s ability to intervene. For most clinical SaMD, AI operates in decision-support mode, and the IFU and system design must make clear that clinical judgment is the final authority.

Accuracy, robustness, and cybersecurity. Performance must be declared and validated. The system must be resilient to errors, faults, and adversarial inputs. Cybersecurity obligations under the AI Act overlap with existing MDR cybersecurity requirements but are not identical to them.

Conformity assessment. High-risk AI systems must undergo a conformity assessment before being placed on the market. For CE-marked MDR/IVDR devices, this will be conducted through the existing Notified Body pathway, with the AI Act assessment layered into the MDR/IVDR review process rather than administered separately.


The Dual Compliance Challenge

The AI Act does not replace the MDR or IVDR. Both frameworks apply simultaneously to AI-powered SaMD, and compliance with one does not fulfill obligations under the other.

The practical distinction:

  • EU MDR / IVDR — Safety, clinical performance, and quality of the device
  • EU AI Act — How the AI system was built, trained, validated, and governed

In areas where the frameworks overlap, including risk management, technical documentation, and post-market surveillance, the AI Act adds AI-specific content requirements on top of what MDR already requires. In areas without overlap, particularly training data governance, bias assessment, and fundamental rights impact assessment, the AI Act introduces obligations that are entirely new to the medical device compliance landscape.

The EU has built in a streamlined integration pathway: AI Act technical documentation requirements can be incorporated into the existing MDR/IVDR technical file, and Notified Bodies designated under MDR/IVDR can conduct AI Act conformity assessments within the same review. This reduces duplication but does not reduce the substance of what’s required.


Compliance Timeline

Understanding which deadline applies to your device matters. The dates are often misquoted.

August 2024: EU AI Act entered into force.

February 2025: Prohibitions on unacceptable-risk AI and AI literacy requirements applied.

August 2025: General-Purpose AI (GPAI) model obligations applied. SaMD built on a foundation model or fine-tuned LLM triggers obligations for both the foundation model provider and the SaMD developer under this provision.

August 2, 2026: High-risk AI obligations apply to Annex III AI systems not subject to third-party conformity assessment, such as hospital workflow tools or patient triage algorithms that are not CE-marked as medical devices.

August 2, 2027: Article 6(1) applies. This is the key deadline for CE-marked MDR/IVDR SaMD subject to Notified Body review. Most Class IIb/III medical devices and Class C/D IVDs with embedded AI fall under this date.

August 2, 2028: Extended deadline for AI systems embedded in Annex I product-regulated categories, following a postponement adopted in the EU AI Act Omnibus. This is the applicable deadline for certain product-embedded AI under harmonised legislation.

One important caveat from practitioners already in this process: Notified Bodies are already incorporating AI Act-style questions into MDR and IVDR audits, ahead of the legal deadlines. Waiting for the statutory deadline to begin documentation work means reworking technical files under time pressure, at exactly the moment Notified Bodies are becoming more rigorous.

For the full official implementation timeline, see the .


Practical Steps to Begin Now

Inventory your AI systems. Identify every AI component across your SaMD portfolio and confirm whether each meets the EU AI Act’s definition of an AI system: machine learning, statistical inference, adaptive behavior. Document the risk classification and rationale for each.

Audit your technical documentation for AI-specific gaps. Review your existing MDR/IVDR technical files against the Annex IV requirements of the AI Act. The most common gaps are training data governance documentation, bias assessment, subgroup performance validation, explainability approach, and human oversight design.

Assess your data governance practices. The AI Act’s requirements for training data representativeness and demographic documentation are more explicit than anything MDR alone requires. Undocumented training data governance is a priority gap to close before any Notified Body engagement.

Update your IFU and labeling. Transparency obligations require explicit disclosure of AI limitations, performance metrics across relevant subgroups, and the conditions under which human override is required or expected. Most existing SaMD IFUs do not meet this standard.

Build AI performance monitoring into your post-market surveillance plan. PMS for AI-powered SaMD must now include tracking for model drift, accuracy degradation over time, and distribution shift in real-world data. A PMS plan without AI-specific monitoring metrics needs to be updated before your next compliance review.

Engage your Notified Body early. Different NBs are at different stages of AI Act readiness. Ask directly how they are approaching AI Act integration into MDR/IVDR assessments, and what documentation they will expect to see. Early clarity prevents gaps at audit.


Where 91³Ô¹ÏÍø Can Help

Integrating EU AI Act requirements into an existing medical device development program, or into the technical documentation of an already-CE-marked device, requires cross-functional expertise in regulatory affairs, software development, risk management, and quality systems. It is not a documentation exercise that sits apart from engineering. It requires changes to how AI systems are built, validated, and monitored.

At 91³Ô¹ÏÍø, we work with medical device manufacturers across device classes and regulatory pathways. Whether you are assessing your EU AI Act exposure for the first time, working to close documentation gaps in an existing technical file, or building a new AI-enabled device with dual MDR and AI Act compliance in mind from the start, we can help you navigate the requirements and build the record that will hold up under review.

Start the conversation here.


Sources

Written By:

91³Ô¹ÏÍø

91³Ô¹ÏÍø

Communications Team

91³Ô¹ÏÍø Newsletter

Sign up to receive articles and insights, delivered monthly.

Schedule a no-committment project call

Reach out to discuss your project to find out if 91³Ô¹ÏÍø could be a good fit for you.