📡 Regulatory news

MDR and AI Act: regulating medical devices that embed artificial intelligence

Medical devices that embed artificial intelligence now fall under two European regulatory frameworks at once: the MDR (EU) 2017/745 and the AI Act (EU) 2024/1689. Since the MDCG 2025-6 guidance was published in June 2025, the interplay between the two regulations has become clearer: classification under Article 6(1) of the AI Act, integrated conformity assessment through MDR notified bodies, and additional requirements for data governance, transparency and human oversight. With obligations postponed to 2 August 2028 (Digital Omnibus agreement, May 2026), manufacturers gain extra time, not an exemption.

9 min read

Medical devices that embed artificial intelligence, whether machine learning algorithms for diagnostic imaging, predictive models for patient monitoring or clinical decision support systems, now sit at the intersection of two European regulations: the MDR (Regulation (EU) 2017/745) and the AI Act (Regulation (EU) 2024/1689).

The publication of the MDCG 2025-6 guidance in June 2025, co-signed by the MDCG and the Artificial Intelligence Board, has clarified the essentials of this interplay. Manufacturers who have not yet integrated this document into their regulatory monitoring are falling behind in a way that is becoming risky to maintain.

What the MDR already covers for devices embedding AI

The MDR does not mention artificial intelligence as such. Its requirements nonetheless apply fully to any medical device that embeds software, whether AI or not.

For AI software qualifying as a medical device (SaMD), the relevant MDR requirements include: classification under Rule 11 of Annex VIII, which classifies software providing information for therapeutic or diagnostic purposes as IIa, IIb or III depending on the severity of the possible consequences; the requirements of Annex I, section 17 on programmable electronic systems, which impose repeatability, reliability and development in line with the state of the art; the software life cycle under IEC 62304; the clinical evaluation of algorithmic performance; and risk management incorporating the specificities of AI (model drift, algorithmic bias, out-of-distribution robustness).

On the MDCG guidance side, three documents frame the topic: MDCG 2019-11 on the qualification and classification of software as a medical device, MDCG 2020-1 on the clinical data of medical device software, and MDCG 2019-16 rev. 1 on the cybersecurity software life cycle. These texts do not deal specifically with AI, but they lay the regulatory foundation onto which the AI Act is grafted.

The AI Act and its interplay with the MDR: what MDCG 2025-6 says

The AI Act, which entered into force on 1 August 2024, creates a horizontal regulatory framework for AI systems in the European Union. It adopts a risk-tiered classification: unacceptable, high risk, limited risk, minimal risk.

Medical devices embedding an AI system do not fall under Annex III of the AI Act (contrary to what is often read). They are classified as high-risk systems under Article 6, paragraph 1, combined with Annex I: as safety components integrated into products covered by EU harmonisation legislation (here, the MDR). This distinction is not academic. It determines the application deadline and the conformity assessment procedure.

MDCG 2025-6 introduces the concept of MDAI (Medical Device Artificial Intelligence) to designate AI systems used for medical purposes and falling under the MDR or the IVDR. This document, structured as a FAQ, clarifies several critical points.

Classification. An MDAI is considered a high-risk AI system if two conditions are met: it constitutes a safety component or is itself a medical device, and it is subject to a conformity assessment by a notified body under the MDR. High-risk classification under the AI Act does not change the MDR class of the device. It is the MDR class that determines whether the AI system is high-risk in the sense of the AI Act, not the other way around.

Conformity assessment. Conformity assessment for MDAIs goes through the existing MDR procedure, via the notified body. There is no separate AI Act procedure. However, the AI Act-specific requirements that are not covered by the MDR must be integrated into the technical documentation and the quality management system. These include, in particular, the governance of training data, algorithmic transparency, effective human oversight and post-market monitoring of AI performance.

Manufacturer = provider. MDCG 2025-6 specifies that the term “manufacturer” in the MDR sense corresponds to the term “provider” in the AI Act sense. One single operator, one single responsibility, two sets of requirements to document.

Timeline: what changed with the Digital Omnibus

The Digital Omnibus political agreement of 7 May 2026 (formal adoption expected before 2 August 2026) amended the application deadlines for AI Act obligations for high-risk systems.

For AI systems embedded in regulated products (Annex I of the AI Act, including medical devices): the application deadline moves from 2 August 2027 to 2 August 2028. For high-risk systems under Annex III (recruitment, credit scoring, education), the deadline is postponed to 2 December 2027.

Concretely, a manufacturer of AI-embedding devices gains an additional twelve-month reprieve to reach AI Act compliance. This is no reason to procrastinate: the AI Act technical documentation (Annex IV) requires three to six months of work, and the CEN-CENELEC harmonised standards (JTC 21) will not be finalised before the end of 2026 at the earliest.

What AI medical device manufacturers must anticipate now

The postponement to 2 August 2028 suspends no MDR obligation. Manufacturers who submit a technical file to a notified body in 2026 or 2027 must already integrate the AI specificities into their MDR documentation, independently of the AI Act.

Five work streams are required from now on.

First, extended risk management. ISO 14971 risk management plans must integrate the risks specific to AI: training data bias, post-deployment model drift, out-of-distribution behaviour, adversarial attacks. This is not a future AI Act option, it is a current MDR requirement under Annex I, section 3.

Second, the documentation of training data. The AI Act will require full traceability of datasets: provenance, representativeness, identified biases, corrective measures. Waiting until 2028 to structure this documentation means discovering at that point that the data used three years earlier was not documented to the required standards.

Third, clinical validation on representative cohorts. The clinical evaluation of an AI device is not limited to demonstrating algorithmic performance on a test set. It must prove that this performance holds on populations representative of the intended use, including on subpopulations at risk of bias.

Fourth, augmented post-market surveillance. AI algorithms evolve, whether or not the model is updated. Drift of the input data in real-world conditions can degrade performance without any modification of the model itself. The PMS plan must integrate continuous monitoring of algorithmic performance, not only the conventional vigilance channels.

Fifth, documented human oversight. The AI Act requires that high-risk AI systems be designed to allow effective human oversight. For diagnostic support software, this means documenting how the practitioner can understand, interpret and, where appropriate, override the algorithmic output.

The ISOFAC perspective

At ISOFAC, we observe that most SME manufacturers embedding AI in their devices still treat the AI Act as a future problem. This is a sequencing error. The requirements that the AI Act will formalise in 2028 are, for the most part, already enforceable under the MDR: AI risk management falls under Annex I, section 3; software validation falls under section 17; clinical evaluation of algorithmic performance falls under Article 61. What changes with the AI Act is the level of formalism expected on data governance, transparency and human oversight.

The real risk for an SME manufacturer is not missing the 2028 deadline. It is submitting a technical file to a notified body in 2026 or 2027 with insufficient AI risk management, and being met with a major non-conformity on MDR requirements that already apply.

If you are developing a medical device embedding AI and have not yet structured your combined MDR/AI Act regulatory approach, the right time to do so is before your next submission, not after the harmonised standards are published.

Sources

  • Regulation (EU) 2024/1689, AI Act (EUR-Lex)
  • Regulation (EU) 2017/745, MDR (EUR-Lex, consolidated version 10.01.2025)
  • MDCG 2025-6 / AIB 2025-1, FAQ on interplay between MDR/IVDR and the AI Act (health.ec.europa.eu, June 2025)
  • MDCG 2019-11, Guidance on qualification and classification of software (health.ec.europa.eu)
  • MDCG 2020-1, Guidance on clinical evaluation of SaMD (health.ec.europa.eu)
  • Digital Omnibus on AI political agreement (Council of the EU, 7 May 2026)

Topics covered:

artificial intelligence medical device MDR AI Act MDCG 2025-6 MDR Rule 11 software AI Act medical device compliance AI medical device manufacturer regulation Digital Omnibus 2028 ISO 14971