← Back to all articles
Insights

EU AI Act and Medical Devices: How the MDR/IVDR Interplay Actually Works After the Digital Omnibus

Abstract editorial image evoking AI-enabled medical device certification: a single integrated approval pathway where two regulatory streams merge into one, with subtle clinical and diagnostic-imaging motifs. Indigo (#3730A3) primary with amber (#E0A100) accents on a light background (#FAFAFD). Clean, modern, professional. No text, no logos, no CE marks, no stethoscopes or generic hospital stock imagery.

If you make AI-enabled medical devices, the Digital Omnibus handed you the longest runway of anyone under the EU AI Act. Annex I high-risk obligations now apply from 2 August 2028 - twelve months later than the original date, and eight months after the deadline for standalone Annex III systems.

That is the good news. The rest of the picture is less comfortable. The infrastructure your compliance route depends on - designated notified bodies, harmonised standards, access to independent test datasets - is not ready, and the industry's attempt to get medical devices carved out of the AI Act altogether failed in May 2026.

This guide covers what actually applies: when an AI-enabled device becomes high-risk, how the single integrated conformity assessment under Article 43(3) is supposed to work, what the healthcare uses are that are high-risk without being medical devices, and where the guidance you will find online is now out of date.

1. Two conditions, not one

The classification rule for product-embedded AI sits in Article 6(1) and works through Annex I, Section A. MDR (EU) 2017/745 is item 11 on that list; IVDR (EU) 2017/746 is item 12.

The joint MDCG/AI Board guidance - MDCG 2025-6, published June 2025 - sets out the test. An AI system used for a medical purpose is high-risk under Article 6(1) only if both conditions are met:

  1. it is a safety component of a medical device or IVD, or is itself such a device; and
  2. it is subject to third-party conformity assessment by a notified body under MDR or IVDR.

Both. Not either.

The second condition does the real work, and it means your AI Act status is decided by your device classification - which you already know.

Device class Notified body involved? High-risk under Art 6(1)?
MDR Class I (non-sterile, non-measuring, non-reusable surgical) No No
MDR Class I sterile / measuring / reusable surgical Yes Yes
MDR Class IIa, IIb, III Yes Yes
MDR Annex XVI products Yes Yes
IVDR Class A (non-sterile) No No
IVDR Class A sterile Yes Yes
IVDR Class B, C, D Yes Yes

Most clinical AI software lands in MDR Class IIa or above under Rule 11, so most of it is high-risk. But the exception at the bottom of the scale is real and worth checking before you build a compliance programme you do not need.

Two further points from MDCG 2025-6 that come up constantly:

In-house devices are outside Article 6(1). AI manufactured and used only within an EU health institution under MDR/IVDR Article 5(5) is not subject to third-party assessment, so it does not meet condition two. The prohibited-practice rules in Article 5 and other AI Act obligations still apply - this is not a blanket exemption - and the MDCG has signalled that further guidance on in-house AI is coming.

The AI Act does not reclassify your device. Being high-risk under Article 6(1) does not push a device into a higher MDR or IVDR class. Causation runs one way only: your MDR/IVDR class determines your AI Act status, never the reverse.

Terminology note: MDCG 2025-6 states that all MDR/IVDR references to "manufacturer" should be read as "provider" for AI Act purposes. Same entity, two vocabularies.

2. One conformity assessment, not two

This is the part most worth understanding, because it is the difference between a manageable programme and a duplicated one.

Article 43(3) of the AI Act reads:

"For high-risk AI systems covered by the Union harmonisation legislation listed in Section A of Annex I, the provider shall follow the relevant conformity assessment procedure as required under those legal acts. The requirements set out in Section 2 of this Chapter shall apply to those high-risk AI systems and shall be part of that assessment.[2]"

"Shall be part of that assessment." You do not run a second, parallel AI Act procedure. Articles 8 to 15 - risk management, data governance, technical documentation, logging, transparency, human oversight, accuracy and robustness - get folded into the MDR or IVDR assessment your notified body already performs. Annex VII points 4.3, 4.4, 4.5 and the fifth paragraph of point 4.6 also apply.

MDCG 2025-6 confirms the mechanics: those AI Act requirements "must be assessed or taken into consideration as part of the conformity assessment procedure under MDR and IVDR," on the legal basis of Articles 16(f) and 43(3) of the AI Act read with Article 52 MDR and Article 48 IVDR.

Three practical consequences:

A single technical file. Article 11(2) requires one set of technical documentation for high-risk AI that is also a regulated product. MDCG 2025-6 also confirms that the existing MDR/IVDR sampling rules for technical documentation review continue to govern - there is no separate AI Act sampling regime.

Integrate, do not duplicate. Article 8(2) permits manufacturers to fold AI Act testing, reporting, information and documentation into existing MDR/IVDR documentation and procedures, and MDCG 2025-6 says manufacturers are "strongly encouraged to use this flexibility." The same steer applies to post-market monitoring: the AI Act monitoring plan may be integrated into the existing MDR/IVDR plan.

Change control mostly carries over. Substantial modification is an autonomous AI Act concept under Article 3(23), and Article 43(4) triggers re-assessment. But pre-determined change control plans recorded under Annex IV point 2(f) do not constitute substantial modification - and MDCG 2025-6 says such changes should correspondingly not be treated as a change to the certified device under MDR Annex IX 4.10 or IVDR Annex IX 4.11.

There is a condition attached to all of this, in the second half of Article 43(3). Your existing notified body may only assess AI Act conformity where "the compliance of those notified bodies with Article 31(4), (5), (10) and (11) has been assessed in the context of the notification procedure under those legal acts.[2]"

Which brings us to the problem.

3. The notified body gap

The integrated route only works if notified bodies are actually designated to run it. As of April 2026, no notified bodies were formally designated in the NANDO database for AI Act conformity assessments - a count of zero. We have not been able to verify a more recent figure directly against NANDO, so treat that as an April 2026 snapshot rather than today's number; but nothing published since suggests a large cohort has since been designated.

This was predicted. Team-NB, the European association of medical device notified bodies, warned in April 2025 that "delays are likely to cause a shortage of designated NBs, when the high-risk scope of the AI Act becomes applicable," flagging "the inherent risk of a major disruption of the medical device software (MDSW) market."

Team-NB's proposed fix is the Article 43(3) route itself: extend existing MDR software codes under Regulation (EU) 2017/2185 to cover AI Act requirements, rather than requiring full horizontal designation under Article 30. Its position paper records resistance to this: "we observe recent discussions, that designations according to this second option shall not be possible. This position is in contradiction to Article 43(3) and bears the imminent risk of notified bodies not being able to pursue their obligations in a timely manner.[4]" We have found no public resolution of that question.

The capacity problem sits on top of an existing MDR backlog. The Commission's 18th Notified Bodies Survey, published in March 2026 with data to 31 October 2025, records 33,175 medical device applications against 17,549 certificates issued, and 3,634 IVD applications against 2,194 certificates. Certificate volumes are rising - MDR up 18% and IVDR up 23% against the mid-2025 snapshot - but the gap between applications and certificates is the number to watch when you plan your submission window.

Standards are behind too. No AI Act harmonised standards had been cited in the Official Journal as of April 2026, and no Article 41 common specifications had been adopted. The main European AI standard in development failed its CEN-CENELEC enquiry vote in February 2026 with roughly 1,288 comments; its scope was amended in March 2026 and a re-vote was pending, with finalisation not expected before 2027.

The Commission has been reasonably direct about why the deadline moved: the Omnibus "ensures the rules apply when companies have the right support tools to facilitate implementation, such as standards."

The practical reading for 2026: AI-enabled medical devices continue to be certified exclusively under MDR/IVDR. No separate AI Act conformity assessment is required today, and none will be until 2 August 2028.

4. Healthcare AI that is high-risk without being a device

Not every high-risk healthcare system is a medical device, and the ones that are not follow a materially lighter route.

Three Annex III entries matter:

  • Point 5(d) - "AI systems intended to evaluate and classify emergency calls by natural persons or to be used to dispatch, or to establish priority in the dispatching of, emergency first response services, including by police, firefighters and medical aid, as well as of emergency healthcare patient triage systems."
  • Point 5(a) - AI used by or on behalf of public authorities to evaluate eligibility for essential public assistance benefits and services, "including healthcare services," and to grant, reduce, revoke or reclaim them.
  • Point 5(c) - risk assessment and pricing for natural persons in life and health insurance.

None of these is necessarily a medical device. All are high-risk.

The route is the important difference. Under Article 43(2), Annex III points 2 to 8 follow Annex VI internal control - self-assessment, no notified body. Only Annex III point 1 (biometrics) can require the Annex VII third-party route. So a hospital-deployed triage tool that is not a device faces a far lighter pre-market path than one that is.

And where both could apply? MDCG 2025-6 is clear: "where both AIA Annexes I and III apply, Annex I alone should prevail for that MDAI." Its worked example is exactly the awkward case - an emergency triage AI that also qualifies as a medical device follows the Article 6(1) and 43(3) route, not Annex VI self-assessment.

Note also the different deadlines. An Annex III triage tool that is not a device faces 2 December 2027. The same functionality inside a regulated device faces 2 August 2028.

5. What the Digital Omnibus changed

Regulation (EU) 2026/1744, the Digital Omnibus on AI, was adopted on 8 July 2026, published in the Official Journal on 24 July 2026, and entered into force on 27 July 2026. It amends Article 113 to postpone Chapter III, Sections 1 to 3.

Original date New date Shift
Annex III / Art 6(2) standalone high-risk 2 August 2026 2 December 2027 +16 months
Annex I / Art 6(1) product-embedded high-risk 2 August 2027 2 August 2028 +12 months

In the Commission's own words: "the rules for high-risk AI systems embedded into regulated products (Annex I) have an extended transition period until 2 August 2028 and the rules for high-risk use cases in certain sensitive areas (Annex III) have been extended to 2 December 2027."

The deferral is unconditional. The Commission's original proposal would have tied the high-risk deadline to harmonised standards being ready; that mechanism was dropped. The dates are fixed regardless of whether the standards arrive.

What did not move: the AI Act became generally applicable on 2 August 2026, and the Commission began enforcing it on that date. Article 50 transparency obligations apply now, with Article 50(2) marking deferred only to 2 December 2026 for systems already on the market. The new Article 5 prohibitions on non-consensual intimate imagery and AI-generated CSAM apply from 2 December 2026. Amendments to Article 4 (AI literacy) and the new Article 4a legal basis for processing special-category data for bias detection applied from entry into force on 27 July 2026 - that last one is quietly useful if you need protected-attribute data to test a clinical model for bias.

Also worth diarising: the Commission's final high-risk classification guidelines are now due by 1 August 2027, with post-market monitoring plan guidance due by 2 September 2027.

6. A warning about MDCG 2025-6

MDCG 2025-6 remains the single most useful document on the AI Act and MDR/IVDR interplay. It is also now partly out of date, and we have found no revision.

Its transition analysis - including the Article 111(2) discussion - is built entirely around 2 August 2027 as the Annex I application date. That date is now 2 August 2028. Anyone reading the FAQ today and taking its timing at face value will plan against a deadline that no longer exists.

Use it for the substantive analysis: the two-condition test, the Article 43(3) integration, the Annex I over Annex III precedence rule, the in-house exemption, change control. Do not use it for dates. And note it is explicitly non-binding and "not a European Commission document."

7. Industry lost the argument, and is regrouping

MedTech Europe, COCIR and DIGITALEUROPE lobbied hard for a single sector-specific pathway through MDR/IVDR only, arguing that layering AI Act obligations on top "does not raise the bar; it just adds complexity." They took it as far as the Commission President and Member State Permanent Representatives.

They lost. Medical technologies stayed inside the AI Act's high-risk regime while certain industrial AI applications secured an exemption. MedTech Europe's response to the 7 May 2026 political agreement was that "this is not the outcome MedTech Europe sought." The sector is now pushing for the MDR/IVDR revision to close the coherence gap instead.

One open issue that revision may need to address: independent test data. Notified bodies may need access to training, validation and test datasets under Annex VII point 4.3, and to independent datasets for additional testing under point 4.4. Team-NB has pointed out that "currently no easy pathway is established to guarantee access to independent test datasets[4]," and that the European Health Data Space "will not be readily available for the applicability of the high-risk scope of the AI Act." The EHDS Regulation entered into force in March 2025, but its secondary-use provisions phase in well after the AI Act's device deadline.

Duplication in post-market surveillance is the other live concern. Team-NB has flagged that AI Act registration under Article 71 and serious-incident reporting under Article 73 risk duplicating MDR/IVDR vigilance and fragmenting information across separate systems, and has asked for full integration or at least database interoperability.

What to do in the next twelve months

  1. Confirm the two conditions for each product. If a notified body is not involved under MDR or IVDR, you are not high-risk under Article 6(1) - document that conclusion rather than assuming it.
  2. Separate your Annex I and Annex III inventories. They have different deadlines (2 August 2028 versus 2 December 2027) and different conformity routes (integrated notified body versus self-assessment).
  3. Ask your notified body about AI Act designation now. Whether and when it will be designated determines your submission window. Given the designation gap, this is a scheduling question, not a formality.
  4. Map Articles 8 to 15 onto your existing MDR/IVDR documentation rather than building parallel artefacts. Article 8(2) exists precisely to let you do this, and the MDCG has said to use it.
  5. Extend your existing QMS and post-market monitoring plan rather than creating AI Act-specific versions.
  6. Solve independent test data access early. There is no established pathway and the EHDS will not arrive in time.
  7. Re-date your compliance file. Anything citing 2 August 2027 for Annex I - including MDCG 2025-6 - needs a correction note.
  8. Watch the MDR/IVDR revision. That, rather than the AI Act, is now where the coherence problem is most likely to be addressed.

The 2028 date is a genuine reprieve. It is also roughly the length of one MDR certification cycle in a system that is already running behind - which makes it less of a pause than it looks.

  1. MDCG 2025-6 / AIB 2025-1: Interplay between the MDR & IVDR and the AI Act (June 2025)
  2. Article 43: Conformity Assessment - EU AI Act
  3. EU AI Act conformity assessment: what to do when the infrastructure isn't ready (Reg Intel, April 2026)
  4. Team-NB Position Paper on the EU AI Act, v2 (9 April 2025)
  5. Notified Bodies Survey on certifications and applications (European Commission, 26 March 2026)
  6. Annex III: High-Risk AI Systems Referred to in Article 6(2) - EU AI Act
  7. Regulatory framework for AI - European Commission (last updated 3 August 2026)
  8. Regulation (EU) 2026/1744 (Digital Omnibus on AI), OJ 24 July 2026
  9. Commission starts enforcing AI Act rules and new transparency requirements (31 July 2026)
  10. The AI Act implementation timeline: what changes under the AI Omnibus (Future of Privacy Forum, 28 July 2026)
  11. MedTech Europe disappointed with EC conclusion on AI Act (Donawa, 25 May 2026)
  12. Joint industry voice calls for one coherent framework for AI-enabled medical technologies (MedTech Europe, 7 May 2026)
  13. AI Act and AI-enabled medical devices (DQS, 12 March 2026)