EU AI Act and Medical Devices: What MedTech Manufacturers Need to Get Right
A practical regulatory perspective for manufacturers developing AI-enabled medical devices and medical software for the European market.

Artificial intelligence is becoming part of everyday medical technology. AI is now being used in diagnostic imaging, clinical decision support, patient monitoring, digital therapeutics, laboratory applications and a growing range of software-based medical devices.
For manufacturers, however, adding AI to a medical product does more than introduce a new technology. It can change the regulatory questions that need to be addressed across the entire product lifecycle.
For products placed on the European market, the EU Artificial Intelligence Act (EU AI Act) needs to be considered alongside the EU Medical Device Regulation (EU MDR 2017/745) or, where applicable, the EU In Vitro Diagnostic Medical Device Regulation (EU IVDR 2017/746).
The important point is that these regulations should not be treated as two completely separate compliance projects.
For an AI-enabled medical device, the manufacturer's regulatory strategy needs to establish how the device is classified, which AI Act obligations apply, how AI-specific risks are controlled, how data and model changes are governed, and how the evidence remains consistent throughout the product lifecycle.
That is where many manufacturers are now having to rethink their existing regulatory approach.
The First Question: Does the EU AI Act Apply to Your Medical Device?
Not every product that uses artificial intelligence will be regulated in exactly the same way under the AI Act. The analysis depends on the nature of the AI system, its intended purpose, how it is used, and its relationship to the applicable European product legislation.
For medical devices, one of the key considerations is whether the AI system is itself a medical device or safety component of a product covered by the EU MDR or IVDR and whether the relevant conformity-assessment route involves a third party (such as a Notified Body).
This is important because the regulatory consequences can be substantially different depending on the classification and conformity-assessment pathway. Manufacturers should therefore avoid a simple assumption that:
“If our product uses AI, it is automatically subject to every high-risk AI requirement.”
The correct approach is to determine the applicable AI Act classification and obligations based on the actual product and regulatory pathway.
Where AI-Enabled Medical Devices Create Additional Regulatory Challenges
1. Establish a Clear AI and Product Inventory
Before assessing compliance, manufacturers need to understand exactly where AI is being used across the product portfolio. This sounds straightforward, but many organizations have AI functionality distributed across different products, software versions, modules and development environments.
The assessment should identify:
- AI-enabled medical devices
- Standalone medical software (SaMD)
- AI-based diagnostic functions
- Clinical decision-support functions
- Machine-learning components embedded in hardware
- AI features added through software updates
- Third-party AI models or algorithms
- Cloud-based AI services connected to medical devices
For each product, the manufacturer should establish the intended purpose, medical-device status, applicable classification, AI functionality and relevant regulatory pathway. Without this baseline, it is difficult to build an effective compliance programme.
2. Align the AI Act Strategy With the MDR or IVDR Strategy
The EU AI Act does not replace the MDR or IVDR. For manufacturers of AI-enabled medical devices, the regulatory challenge is therefore one of alignment. The manufacturer needs to understand where requirements overlap and where additional AI-specific obligations need to be addressed.
For example, information relating to intended purpose, risk management, technical documentation, data, software lifecycle, human oversight, performance, post-market monitoring, and changes to the product may appear across multiple regulatory frameworks. The objective should be to maintain one coherent regulatory evidence structure rather than creating disconnected MDR, IVDR and AI Act documentation.
3. Revisit the Quality Management System (QMS)
An AI-enabled product requires controls that may be more dynamic than those traditionally used for conventional medical devices. The manufacturer's QMS should provide appropriate control over areas such as:
- AI system development & verification
- Data management, sourcing and labelling
- Training, testing, and validation
- Model performance tracking
- Software and algorithm updates
- Cybersecurity and vulnerability remediation
- Supplier and third-party AI component controls
- Post-market monitoring and feedback loops
Manufacturers should consider how AI-specific controls fit into their existing ISO 13485 framework. The objective is not necessarily to create a completely separate “AI QMS.” In most cases, the more practical approach is to determine where AI governance needs to be incorporated into the existing quality system and where additional controls are required.
4. Treat Data Governance as a Product-Safety Issue
For AI-based medical technology, data quality is not simply a technical concern. It can directly affect clinical performance and patient safety. Manufacturers should establish appropriate controls around training, validation and testing datasets, including their:
- Source, provenance, and relevance
- Quality and representativeness
- Selection criteria and labelling methodologies
- Known limitations and blind spots
- Bias and potential sources of error
A model can perform well in development and still perform poorly when used with a different patient population, clinical environment, imaging system or data distribution. That is why dataset characteristics and limitations should be considered as part of the overall risk and performance assessment. Where personal health data is involved, manufacturers must also reconcile applicable GDPR and data-protection requirements.
5. Expand Risk Management Beyond Traditional Software Risks
AI can introduce risk patterns that are not always adequately captured by a conventional software risk assessment. Depending on the application, manufacturers may need to consider:
- Incorrect or unstable model outputs
- Dataset limitations and distribution shifts
- Performance variability across patient subpopulations
- Model drift over time
- Unexpected interactions and edge cases
- Automation bias and inappropriate clinical over-reliance
- Cybersecurity threats and adversarial data poisoning
- Data integrity and degradation after deployment
These considerations should be incorporated into the manufacturer's established risk-management process under ISO 14971 rather than maintained as an isolated AI risk document. The goal is to demonstrate that AI-related hazards have been systematically identified, evaluated, controlled and monitored throughout the device lifecycle.
6. Human Oversight Needs to Be Designed, Not Added to the Documentation
For clinical AI, human oversight is more than a boilerplate statement that “a healthcare professional remains responsible.” The manufacturer needs to consider how the system will actually be used:
- Who reviews the AI output?
- When is mandatory human intervention required?
- Can the user easily override or modify the output?
- What happens when the system expresses low confidence or uncertainty?
- How are warnings and actionable explanations presented?
- Can the clinician readily understand the limitations of the output?
- What happens if the AI service becomes temporarily unavailable?
These considerations should be tangibly reflected in product design, user interface (UI/UX), usability engineering (IEC 62366-1), risk management, and the Instructions for Use (IFU).
7. Technical Documentation Needs to Reflect the AI Lifecycle
AI-enabled medical devices require documentation that explains not only what the software does, but also how the AI component was developed, validated and controlled. The regulatory documentation must address system architecture, model development, training and validation methodology, performance testing, limitations, cybersecurity, and risk controls.
The most important principle is consistency. The AI description in the technical documentation should match the actual product. The performance claims must be supported by clinical validation. The risk file must reflect known limitations, and the clinical evaluation must be fully aligned with the AI's intended use.
8. AI Changes Need Strong Change-Control Processes
Traditional software development already requires configuration and change control. AI systems can make this considerably more complicated. A change to training data, model architecture, model parameters, algorithm logic, performance thresholds, input data formats, or clinical indications may affect the regulatory status or performance of the device.
Manufacturers need a disciplined process for determining which changes can be made within the existing regulatory framework and which changes require additional verification, validation or formal regulatory notification. For AI-enabled medical devices, change control is an active part of the regulatory strategy—not simply a software-development procedure.
9. Post-Market Surveillance Needs to Monitor AI Performance
An AI medical device does not stop changing from a risk perspective once it has received CE marking. Manufacturers must establish mechanisms within PMS, vigilance, and Post-Market Clinical Follow-up (PMCF) to detect unexpected performance, user complaints, incorrect outputs, population-specific discrepancies, cybersecurity vulnerabilities, and model degradation in real-world clinical environments.
10. Do Not Treat the AI Act as a Standalone Certification Exercise
One of the most common strategic mistakes is to approach the AI Act as another isolated certification checklist. For medical device manufacturers, the better approach is to integrate AI governance into the existing product lifecycle:
When these processes are disconnected, compliance gaps become much more difficult to identify and manage during Notified Body audits.
What Manufacturers Should Do Before Entering the EU Market
For an AI-enabled medical device preparing for European market entry, a regulatory readiness assessment should address five broad areas:
Product & Regulatory Scope
Establish what the AI system does, its intended purpose, its relationship to the medical device, and the applicable MDR/IVDR and AI Act obligations.
Evidence & Performance
Review whether the available clinical, technical and performance evidence adequately supports the intended claims and identified risks.
AI Governance
Assess data governance, model development, validation, real-world monitoring, human oversight and change-control protocols.
Quality System & PMS
Ensure the ISO 13485 QMS adequately incorporates controls for AI development, while PMS monitors AI performance and emerging risks post-market.
How NKB Regovanta Supports AI-Enabled Medical Devices
At NKB Regovanta, we help medical device and IVD manufacturers address the regulatory challenges created by increasingly software-driven and AI-enabled products. Our approach combines medical device regulatory expertise, quality-system requirements, clinical evidence, software considerations and market-access strategy rather than treating AI compliance as a standalone exercise.
- EU AI Act Applicability & Regulatory Assessment: Assessment of the AI system, medical-device status, intended purpose and applicable regulatory obligations.
- EU MDR / IVDR Regulatory Strategy: Alignment of AI-related requirements with the applicable medical device or IVD regulatory pathway.
- AI Regulatory Gap Assessment: Identification of gaps across governance, technical documentation, risk management, data, performance and lifecycle controls.
- AI-Enabled Medical Device Technical Documentation: Review and development of documentation covering the AI system, software, data, performance, risk controls and applicable regulatory evidence.
- AI Risk Management & ISO 14971: Integration of AI-related risks into the manufacturer's medical device risk-management framework.
- QMS & ISO 13485 Integration: Development or enhancement of QMS processes covering AI development, validation, data governance, change control and post-market activities.
