Skip to content
AI in Healthcare

Article

EU AI Act high-risk obligations for medical devices: a practical compliance guide

The EU AI Act's high-risk obligations are now in force for medical devices. What the requirements mean in practice and how they layer on EU MDR.

By AI in Healthcare Editorial Updated
  • EU AI Act
  • regulation
  • medical devices
  • compliance
  • EU MDR
  • international

August 2026 is not a soft deadline. The EU AI Act’s high-risk AI obligations are now binding for AI systems used as, or embedded in, medical devices — and the compliance posture of most U.S.-based medical AI companies ranges from incomplete to aspirational. Understanding precisely what is required, how the AI Act layers onto the existing EU Medical Device Regulation, and what practical steps companies must take is no longer a future problem. It is this quarter’s problem.

What the August 2026 obligations actually require

The EU AI Act classifies most AI-enabled medical devices and in vitro diagnostic devices as high-risk AI systems under Annex III. This classification triggers a substantial set of obligations that go beyond what the EU MDR requires for device safety and performance.

The core obligations for high-risk AI systems include: a conformity assessment demonstrating the AI system meets the Act’s requirements; a risk management system specifically for AI risk (distinct from but interoperable with the MDR’s risk management requirements); technical documentation covering the training data, model architecture, performance metrics, and intended purpose; an automatic logging function that enables post-deployment traceability of system operations; transparency obligations that ensure operators and users receive adequate information about the system’s capabilities and limitations; human oversight measures that allow qualified individuals to override, halt, or intervene in the system’s operation; and robustness and accuracy requirements throughout the system’s lifecycle.

These obligations do not replace EU MDR compliance — they stack on top of it. A Class IIb device with AI functionality now faces two parallel regulatory frameworks with partially overlapping and partially distinct requirements. The European Commission has acknowledged the overlap and issued guidance on harmonization, but the practical reality is that compliance teams must navigate both.

The notified body question

Here is where many U.S. companies hit their first concrete problem. High-risk AI system conformity assessments under the AI Act must, for most medical devices, involve a notified body — the same bodies that handle EU MDR technical documentation review. Notified body capacity in Europe has been severely strained since the EU MDR transition, with backlogs measured in months to years for some device categories.

Companies that have not already established a notified body relationship for EU MDR purposes face the prospect of entering a congested market for conformity assessment services at exactly the moment when AI Act demand is adding to the backlog. Companies that have an existing notified body relationship are in a meaningfully better position, but should not assume that their MDR notified body will automatically handle AI Act conformity assessment — in many cases, this requires a separate engagement and, potentially, a supplemental audit.

The practical implication: if you have not already had the AI Act conformity assessment conversation with your EU MDR notified body, that conversation is overdue.

How the frameworks interact

The EU MDR and EU AI Act share conceptual territory in several areas — risk management, post-market surveillance, clinical evaluation — but operationalize those concepts differently enough to create compliance complexity.

Risk management under EU MDR ISO 14971 focuses on device safety risks to patients and users. AI Act risk management adds an AI-specific layer concerned with accuracy degradation, dataset bias, distributional shift, and cybersecurity risks specific to AI/ML systems. Companies that have mature ISO 14971 programs will find some of this familiar, but the AI Act’s emphasis on training data governance and ongoing monitoring of model performance in deployment is genuinely new territory for most medical device quality systems.

Post-market surveillance under EU MDR requires monitoring device performance against defined safety and performance specifications. The AI Act adds an obligation for continuous monitoring of AI system performance and logging that enables retrospective audit. Integrating these into a coherent post-market surveillance program — rather than running two parallel systems — requires deliberate architecture of the quality management system.

Transparency and human oversight in practice

Two requirements deserve particular attention because they are both substantively important and commonly misunderstood.

The transparency obligation does not mean simply disclosing that an AI system is being used. It means providing operators and users with meaningful information about the system’s intended purpose, the conditions under which it performs as specified, the nature and likelihood of errors or limitations, and the appropriate level of reliance. For clinical AI tools, this translates into clinical labeling requirements that are considerably more detailed than what U.S. FDA clearance typically demands.

The human oversight requirement is not satisfied by putting a radiologist or clinician in the loop as a rubber stamp. The AI Act requires that the human oversight mechanism be technically implemented and practically effective — meaning that the system must be designed so that a qualified person can meaningfully understand, monitor, and override the system’s outputs. AI tools designed to accelerate clinical decisions by making the human review technically optional or practically difficult will face scrutiny here.

What U.S. companies with EU ambitions must do now

For companies that do not yet have EU market authorization: the AI Act compliance posture must be designed in, not retrofitted. This means engaging a notified body early, building EU AI Act requirements into the technical documentation architecture from the start, and ensuring that training data governance practices are documented in a way that will survive audit.

For companies that already have EU MDR certification and are marketing in the EU: the immediate tasks are a gap analysis against AI Act high-risk obligations, an assessment of whether existing technical documentation and quality system elements can be extended to cover AI Act requirements or require new documentation, and a conversation with your notified body about the path to an AI Act conformity assessment.

The EU AI Act represents the most comprehensive regulatory framework for clinical AI anywhere in the world. For companies with EU market ambitions, it is not optional — and August 2026 means the clock has already started.