EU AI Act (EU 2024/1689)
The EU AI Act establishes risk-based obligations for AI systems placed on the EU market. Medical device AI is automatically classified as high-risk, requiring conformity assessment, risk management, data governance, and human oversight obligations alongside EU MDR.
EU 2024/1689 — EUR-Lex ↗EU AI Act Classifier & Conformity Assessment
Classify your AI system in 6 questions and run a full 26-requirement gap assessment against Art. 9–15 obligations.
Risk Classes & Obligations
The AI Act establishes four risk tiers with proportionate obligations for each.
AI systems that pose an unacceptable risk to health, safety, or fundamental rights — including real-time remote biometric identification in public spaces, social scoring by public authorities, and subliminal manipulation — are strictly prohibited.
Conformity assessment: Prohibited
AI systems that are safety components of regulated products (incl. medical devices under EU MDR/IVDR) or that fall under Annex III sectors (employment, law enforcement, education, critical infrastructure) are subject to the full set of Art. 9–15 obligations.
Conformity assessment: Notified Body or Internal QMS
AI systems that interact with natural persons (chatbots, emotion recognition, AI-generated content) must meet transparency obligations — users must be informed they are interacting with an AI system.
Conformity assessment: Self-declaration (transparency only)
All other AI systems (e.g. spam filters, AI in video games, basic recommendation systems) fall into the minimal risk category. No mandatory requirements apply, though voluntary codes of conduct are encouraged.
Conformity assessment: None required
| Art. | Obligation |
|---|---|
| 9 | Risk Management System Establish and maintain a risk management system specific to the AI system lifecycle, iteratively identifying and mitigating AI-specific risks including concept drift and bias. |
| 10 | Data Governance Implement data governance practices covering training data quality, bias examination, provenance documentation, and special category data handling. |
| 11 | Technical Documentation Maintain Annex IV technical documentation covering AI system description, training methodology, validation results, and post-market monitoring plan. |
| 12 | Automatic Logging High-risk AI systems must automatically log events to enable post-market monitoring, incident investigation, and regulatory audit. |
| 13 | Transparency & Information Provide clear information to deployers on AI capabilities, limitations, performance metrics, and conditions of reliable use through the instructions for use. |
| 14 | Human Oversight Design AI systems with built-in mechanisms enabling competent persons to effectively monitor, intervene, and override AI outputs during operation. |
| 15 | Accuracy, Robustness & Security Achieve declared accuracy levels; ensure robustness against errors, distributional shift, and adversarial attacks; implement cybersecurity measures. |
Compliance Timeline
Key dates for the phased entry into force of EU AI Act obligations.
Regulation entered into force — 20 days after publication in the Official Journal of the EU.
Prohibited practices (Art. 5) became enforceable — biometric surveillance, social scoring, subliminal manipulation.
GPAI model obligations (Art. 51–56) apply — technical documentation, transparency, copyright compliance policies.
Full obligations for high-risk AI systems (Art. 6+, Annex III) — including medical device AI as safety components.
High-risk AI in safety-critical regulated sectors listed in Annex I (machinery, medical devices under specific directives).
High-risk AI Act obligations apply from 2 August 2026 — less than 18 months from now. Medical device AI systems must be compliant before that date.
Key Concepts Explained
Plain-language explanations of the most important AI Act concepts for medical device teams.
What is an AI System under the AI Act?
The EU AI Act defines an AI system as a machine-based system designed to operate with varying levels of autonomy that may exhibit adaptiveness, and that, for explicit or implicit objectives, infers from inputs how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. A medical device using a trained machine learning model to generate diagnostic suggestions or treatment recommendations qualifies as an AI system.
Medical Device AI as High-Risk
AI systems that are safety components of products regulated under EU MDR (2017/745) or IVDR (2017/746) are automatically classified as high-risk under Annex III §5 of the EU AI Act, regardless of the device's MDR risk class. This means virtually all AI-enabled medical devices — from Class I software-only devices providing diagnostic suggestions to Class III implantable systems — are subject to the full suite of AI Act obligations. The key question is whether the AI system is a "safety component": any AI that influences a clinical decision, treatment selection, or patient monitoring qualifies.
MDR and AI Act: Cumulative Obligations
The EU AI Act and EU MDR apply cumulatively. Manufacturers must satisfy both regulatory frameworks. However, the regulations share significant structural overlap that reduces the total compliance burden:
- MDR Annex II/III technical documentation ↔ AI Act Annex IV technical documentation (significant overlap in content requirements)
- ISO 14971 risk management ↔ AI Act Art. 9 risk management (AI Act adds AI-specific risk dimensions)
- IEC 62304 software lifecycle ↔ AI Act development methodology documentation
- MDR post-market surveillance ↔ AI Act Art. 12 logging and post-market monitoring
- MDR Art. 10(9) QMS ↔ AI Act Art. 17 quality management system (can be unified)
- MDR notified body conformity assessment ↔ AI Act Art. 43(3) allows reliance on MDR assessment for AI Act conformity
CRA and AI Act: Cybersecurity Alignment
If your AI-enabled medical device has digital connectivity, the EU Cyber Resilience Act (CRA, EU 2024/2847) also applies alongside the AI Act. CRA Annex I cybersecurity requirements (vulnerability management, security-by-design, SBOM) complement AI Act Art. 15(5) adversarial robustness requirements. A unified cybersecurity risk assessment can address both regulations, though AI-specific adversarial attack testing goes beyond standard CRA requirements.
General-Purpose AI (GPAI) Models
General-purpose AI models — large foundation models trained on broad data that can serve multiple purposes — are subject to a separate set of obligations under Art. 51–56 of the EU AI Act, applicable from 2 August 2025. Medical device manufacturers integrating third-party GPAI models (such as large language models for clinical note summarisation) must ensure the model provider fulfils GPAI obligations and obtain the necessary technical documentation. If your own product incorporates a GPAI model, provider obligations may also apply.
Conformity Assessment for High-Risk AI
High-risk AI systems must undergo a conformity assessment before being placed on the EU market. For AI systems that are safety components of EU MDR-regulated medical devices, Art. 43(3) of the AI Act allows the notified body conducting the MDR conformity assessment to also assess AI Act compliance — reducing the audit burden. For other high-risk AI systems, either a third-party audit by an accredited conformity assessment body (Art. 43(1)) or an internal quality management system assessment (Art. 43(2)) is required, depending on the system's risk level and applicable annexes.
EU AI Database Registration
High-risk AI systems under Annex III must be registered in the EU AI database before being placed on the market or put into service. For high-risk AI systems that are safety components of regulated products (including medical devices), registration is carried out by the notified body responsible for the conformity assessment. Deployers of high-risk AI systems in certain sensitive contexts (law enforcement, migration, judicial) must also register in a non-public section of the database.
Synergies with Existing Standards
How your existing MDR, IEC 62304, ISO 14971, and CRA compliance work reduces the AI Act gap.
| AI Act Requirement |
|---|
AI Risk Management ISO 14971 |
Data Governance IEC 62304 + GDPR |
Technical Documentation IEC 62304 |
Logging / Audit Trail IEC 62304 §8 |
Human Oversight EU MDR Art. 15 |
Cybersecurity CRA Annex I + ISO 14971 |
Frequently Asked Questions
Answers to the most common questions from medical device manufacturers.
Does the EU AI Act apply to my medical device?
If your medical device incorporates an AI system — a trained machine learning model, neural network, or similar technology — that influences diagnostic or therapeutic decisions, it almost certainly qualifies as a high-risk AI system under Annex III §5. This applies even to Class I MDR devices if they use AI for decision support.
When do I need to be compliant?
The deadline for full compliance for high-risk AI systems (including medical device AI) is 2 August 2026. GPAI model obligations applied from 2 August 2025. Prohibited practices under Art. 5 have applied since 2 February 2025.
Do I need a separate notified body for the AI Act?
Not necessarily. Art. 43(3) of the EU AI Act allows the notified body conducting your MDR conformity assessment to also assess AI Act compliance. Check with your current notified body whether they are accredited for AI Act assessments.
What is the difference between the AI Act and CRA for medical devices?
The AI Act governs AI-specific obligations (risk management, data governance, transparency, human oversight). The CRA governs cybersecurity requirements for all products with digital elements. Both may apply to your device simultaneously. A unified compliance programme addressing both is recommended.
Does ISO 14971 cover AI Act risk management requirements?
ISO 14971 provides approximately 80% coverage for AI Act Art. 9 risk management requirements. The main gap is AI-specific risks not addressed in traditional risk management: concept drift, training data bias, distributional shift, and adversarial inputs. An AI-specific risk management annex to your existing risk management file is typically sufficient.
What is a Model Card and do I need one?
A Model Card is a structured document describing an AI model's purpose, architecture, training data, performance metrics, known limitations, and ethical considerations. While not explicitly named in the AI Act, the Annex IV technical documentation requirements effectively require equivalent information. Creating a Model Card is an efficient way to satisfy these requirements.
What are the GPAI obligations for medical device manufacturers?
If you integrate a third-party GPAI model (e.g. a large language model), you are a deployer and the model provider must give you technical documentation and copyright compliance information. If you develop and place a GPAI model on the market as part of your product, provider obligations under Art. 53 apply, including technical documentation, copyright policy, and transparency summaries.
What is the EU AI database and when do I need to register?
The EU AI database is a public registry of high-risk AI systems. Registration is required before placing a high-risk AI system on the EU market. For medical device AI, the notified body typically handles registration as part of the conformity assessment process.
Can I use the same QMS for MDR and AI Act compliance?
Yes. Art. 17 of the EU AI Act requires a quality management system for providers of high-risk AI systems. The regulation explicitly allows this QMS to be integrated with an existing QMS established under MDR Art. 10(9). A unified ISO 13485 QMS with AI-specific extensions is the recommended approach.
What penalties apply for non-compliance?
Violations of the prohibited practices (Art. 5) can result in fines of up to €35 million or 7% of global annual turnover. Non-compliance with other obligations for high-risk AI systems can result in fines of up to €15 million or 3% of global annual turnover. Market surveillance authorities in each EU member state are responsible for enforcement.
Is post-market surveillance required specifically for AI?
Yes. Art. 12 requires automatic logging for post-market monitoring, and Art. 72 requires a post-market monitoring plan for high-risk AI systems. For medical device AI, this can be integrated with the existing MDR post-market surveillance system, but must additionally cover AI-specific KPIs such as model performance stability, drift detection, and anomaly rates.
EU AI Act Classifier & Conformity Assessment
Classify your AI system in 6 questions and run a full 26-requirement gap assessment against Art. 9–15 obligations.
Start free assessment →