The AI Act Omnibus Explained: What the 2026 EU Rules Mean for Medical Device and IVD Manufacturers

Discover how the EU AI Act Omnibus affects AI medical devices and IVD manufacturers. Learn about the No Duplication principle, transparency rules, key 2026 and 2028 deadlines, and how MDR and IVDR compliance are converging with AI regulation.
The AI Act Omnibus Explained: What the 2026 EU Rules Mean for Medical Device and IVD Manufacturers

Published: 15th June 2026

Reviewed by: David Small BSc (Hons), MSc, MTOPRA (Founder and CEO)

The EU Has Finally Clarified How the AI Act Works Alongside MDR and IVDR

For the past two years, one of the biggest concerns facing AI medical device manufacturers has been regulatory overlap. Companies developing AI-powered Software as a Medical Device (SaMD), diagnostic algorithms, and machine learning systems have been asking the same question:

“Will we need two separate regulatory systems — one for MDR/IVDR and another for the EU AI Act?”

Following major political agreements reached in May 2026, the EU has finally provided much-needed clarity through the emerging “AI Act Omnibus” framework.

The new approach significantly reduces duplication between the EU AI Act and existing MDR/IVDR conformity assessment procedures, while also extending key deadlines for high-risk AI medical devices to August 2028.

However, while some obligations have been delayed, others begin much sooner. Transparency requirements for AI systems — including chatbot disclosures and AI-generated content labeling — are expected to apply from August 2026.

For medical device and IVD manufacturers, the message is clear: the compliance timeline may have shifted, but preparation cannot wait.

What Is the EU AI Act Omnibus Package?

The “AI Act Omnibus” refers to the latest political agreements and implementation clarifications designed to streamline how the EU AI Act interacts with existing sector-specific legislation, including:

  • EU MDR 2017/745
  • EU IVDR 2017/746
  • GDPR
  • Cybersecurity regulations
  • Product safety legislation

The primary goal is to avoid duplicate regulatory oversight while still ensuring:

  • AI safety
  • Transparency
  • Human oversight
  • Data governance
  • Cybersecurity
  • Ethical AI deployment

For healthcare manufacturers, this clarification is critical because most AI-enabled medical technologies already operate under strict MDR or IVDR controls.

Why the AI Act Matters to Medical Device Manufacturers

The EU AI Act introduces horizontal AI legislation that applies across industries.

However, medical devices are considered one of the highest-risk AI sectors because they directly impact:

  • Patient diagnosis
  • Treatment decisions
  • Clinical workflows
  • Healthcare outcomes
  • Patient safety

Examples of high-risk AI medical technologies include:

  • AI diagnostic imaging software
  • Clinical decision support systems
  • Oncology prediction tools
  • AI pathology systems
  • Remote patient monitoring algorithms
  • AI triage software
  • Predictive analytics platforms

Without regulatory alignment, manufacturers feared being subjected to:

  • Duplicate audits
  • Separate technical assessments
  • Parallel quality systems
  • Multiple notified body reviews

The 2026 agreements now provide a more practical framework.

High-Risk AI Medical Device Deadlines Extended to August 2028

The New Compliance Timeline

One of the biggest outcomes of the May 2026 political agreements is the extension of deadlines for high-risk AI medical devices.

Under the revised timeline:

  • High-risk AI systems regulated under MDR/IVDR now have until August 2028 before full AI Act obligations apply.

This gives manufacturers additional time to:

  • Update technical documentation
  • Strengthen AI governance systems
  • Improve transparency controls
  • Align PMS procedures
  • Enhance cybersecurity frameworks
  • Build lifecycle AI monitoring processes

Why the Extension Was Necessary

The extension reflects industry concerns around:

  • Limited Notified Body capacity
  • Unclear implementation guidance
  • Technical complexity of AI systems
  • Overlap between MDR/IVDR and AI Act requirements
  • Resource shortages within regulatory teams

Many healthcare AI companies argued that simultaneous compliance deadlines would have created:

  • Certification bottlenecks
  • Delayed innovation
  • Reduced market access
  • Increased costs
  • Regulatory confusion

The revised timeline gives manufacturers breathing room — but not a reason to delay preparation.

The “No Duplication” Rule: A Major Win for MedTech Companies

What Is the No Duplication Principle?

Perhaps the most important clarification for manufacturers is the introduction of the “No Duplication” rule.

Under this principle, AI medical devices already assessed under MDR or IVDR should not automatically require a completely separate AI-specific conformity assessment if equivalent requirements have already been evaluated.

This is a major shift toward regulatory harmonisation.

How the No Duplication Rule Works

If your MDR or IVDR conformity assessment already covers areas such as:

  • Risk management
  • Cybersecurity
  • Clinical performance
  • Human oversight
  • PMS
  • Data governance
  • Software lifecycle controls
  • Usability engineering

then portions of the AI Act requirements may be considered satisfied through the existing process.

This could significantly reduce:

  • Administrative burden
  • Audit duplication
  • Certification delays
  • Regulatory costs

What Manufacturers Still Need to Demonstrate

The No Duplication rule does not eliminate AI Act compliance.

Manufacturers must still demonstrate that their systems adequately address:

  • AI transparency
  • Bias mitigation
  • Data quality
  • Human oversight
  • Algorithm accountability
  • Model monitoring
  • Explainability where appropriate
  • Continuous performance management

In practice, this means manufacturers should begin integrating AI governance directly into their existing MDR/IVDR systems rather than creating parallel frameworks.

Immediate AI Transparency Rules Begin in August 2026

Not All AI Act Requirements Are Delayed

While high-risk medical device obligations have been extended, certain AI transparency requirements begin much earlier.

From August 2026, organisations using AI systems — including healthcare companies — may face immediate obligations relating to:

  • AI chatbot disclosures
  • Synthetic content labeling
  • AI-generated communication transparency
  • User awareness obligations

This means some compliance activities must begin now.

AI Chatbot Disclosure Requirements

Organisations deploying AI chatbots must ensure users are clearly informed they are interacting with AI unless it is obvious from context.

This applies to:

  • Customer support chatbots
  • Patient triage assistants
  • AI scheduling tools
  • Healthcare information assistants
  • AI-powered web chat systems

Manufacturers and healthcare providers should review:

  • Website chatbot disclosures
  • Terms of use
  • Privacy notices
  • Patient-facing communications

Failure to provide adequate transparency may create compliance risk.

Labeling Requirements for AI-Generated Content

The AI Act also introduces obligations relating to AI-generated or manipulated content.

Companies may need to label:

  • Synthetic media
  • AI-generated patient communications
  • Automated reports
  • AI-created educational content
  • Deepfake-style media outputs

For MedTech companies increasingly using generative AI tools internally and externally, governance controls are becoming essential.

💻
The Engineering Prerequisite

You cannot pass an EU AI Act conformity assessment if your underlying software lifecycle is flawed. Review our technical blueprint, IEC 62304 Explained: Medical Device Software Development, to align your core coding standards with global regulations.

How MDR, IVDR, and the AI Act Are Converging

The Rise of Integrated AI Compliance

The latest EU agreements signal a broader regulatory trend:
AI compliance is no longer separate from medical device compliance.

Instead, regulators expect manufacturers to integrate AI governance into:

  • ISO 13485 QMS systems
  • Risk management processes
  • PMS frameworks
  • Clinical evaluation activities
  • Cybersecurity management
  • Software lifecycle controls

Manufacturers that treat AI compliance as an isolated project may struggle in future audits.

Key Areas Manufacturers Should Focus on Now

1. Conduct an AI Gap Assessment

Manufacturers should evaluate whether existing MDR/IVDR systems adequately address:

  • AI lifecycle monitoring
  • Bias management
  • Transparency controls
  • Human oversight
  • Data governance
  • Explainability

2. Review Software Classification

Many AI-enabled systems fall under:

  • MDR Rule 11
  • IVDR software classification requirements

This may increase regulatory scrutiny and require Notified Body involvement.

3. Strengthen Post-Market Surveillance for AI

AI systems require continuous lifecycle oversight.

Manufacturers should strengthen:

  • Real-world performance monitoring
  • Algorithm drift detection
  • Complaint trending
  • Cybersecurity monitoring
  • Clinical feedback analysis

 4. Improve Technical Documentation Structure

Regulators increasingly expect structured documentation demonstrating:

  • AI model governance
  • Validation processes
  • Training data quality
  • Human oversight mechanisms
  • Change management controls

 5. Prepare Transparency Disclosures Before August 2026

Organisations using AI chatbots or generative AI systems should review transparency obligations immediately.

This includes:

  • User notifications
  • AI interaction disclosures
  • Content labelling policies
  • Governance procedures

Frequently Asked Questions About the AI Act and Medical Devices

Yes. Most AI-enabled medical devices regulated under MDR or IVDR are classified as high-risk AI systems.

 

Not necessarily. Under the new No Duplication principle, existing MDR/IVDR conformity assessments may satisfy parts of the AI Act requirements.

Many high-risk obligations are now delayed until August 2028 for MDR/IVDR-regulated AI devices.

However, transparency obligations begin earlier in August 2026.

 

The main challenges include:

  • AI governance integration
  • Transparency obligations
  • Cybersecurity controls
  • Lifecycle monitoring
  • Data quality management
  • Regulatory documentation

Final Thoughts: The Regulatory Picture Is Finally Becoming Clearer

For AI medical device and IVD manufacturers, the May 2026 political agreements provide long-awaited clarity.

The extension to August 2028 reduces immediate pressure, while the No Duplication rule helps avoid unnecessary regulatory overlap between MDR/IVDR and the AI Act.

However, this is not a pause button for compliance.

The organisations best positioned for long-term success will be those that begin integrating AI governance into their existing quality and regulatory systems today.

AI regulation in healthcare is no longer theoretical — it is becoming operational.

 

Need Help Preparing for the EU AI Act?

At Patient Guard Ltd, we help medical device and IVD manufacturers navigate the evolving intersection between:

  • MDR
  • IVDR
  • AI Act compliance
  • Software regulation
  • Cybersecurity
  • PMS and vigilance
  • AI governance systems

Our team supports:

  • AI regulatory gap analyses
  • SaMD classification reviews
  • Technical documentation remediation
  • PMS integration
  • AI transparency compliance
  • Cybersecurity strategy
  • ISO 13485 alignment
  • Regulatory roadmap planning

If your organisation is developing AI-powered healthcare technologies, now is the time to prepare for the next generation of EU regulatory oversight.

Contact Patient Guard Ltd Today to Discuss Your AI Compliance Strategy

David Small BSc (Hons), MSc, MTOPRA

David Small BSc (Hons), MSc, MTOPRA

Reviewed by
David Small, BSc (Hons), MSc, MTOPRA
Founder & CEO |
20+ years in medical device regulatory affairs,  MDR/IVDR compliance and quality systems.

Patient Guards Recent Posts

10 Common Technical Documentation Deficiencies Found During EU MDR and IVDR Notified Body Reviews

10 Common Technical Documentation Deficiencies Found During EU MDR and IVDR Notified Body Reviews

Preparing technical documentation for EU MDR or IVDR certification is only half the challenge. Successfully passing a Notified Body review depends on demonstrating consistency across your Quality Management System, Clinical Evaluation, Risk Management, Biological Evaluation, Performance Evaluation and Post-Market Surveillance activities. Discover ten of the most common technical documentation deficiencies identified during MDR and IVDR conformity assessments—and learn how to reduce the likelihood of costly review cycles and certification delays.

Read More »
Patient Guard EU Authorised Representative Services

EU Authorised Representative Services for Medical Device & IVD Manufacturers

Selling medical devices or IVDs in Europe? If your company is based outside the EU, appointing an EU Authorised Representative (EC Rep) is a legal requirement under EU MDR 2017/745 and IVDR 2017/746. Patient Guard provides expert EU Authorised Representative services, EUDAMED support, regulatory guidance, and ongoing compliance management to help manufacturers access and maintain the European market with confidence.

Read More »

Need Training?

Do you need training on Quality Management Systems or EU MDR/ EU IVDR? then check out our training courses.

Share this guide:

Most Popular

10 Common Technical Documentation Deficiencies Found During EU MDR and IVDR Notified Body Reviews

Preparing technical documentation for EU MDR or IVDR certification is only half the challenge. Successfully passing a Notified Body review depends on demonstrating consistency across your Quality Management System, Clinical Evaluation, Risk Management, Biological Evaluation, Performance Evaluation and Post-Market Surveillance activities. Discover ten of the most common technical documentation deficiencies identified during MDR and IVDR conformity assessments—and learn how to reduce the likelihood of costly review cycles and certification delays.

Read More »

EU Authorised Representative Services for Medical Device & IVD Manufacturers

Selling medical devices or IVDs in Europe? If your company is based outside the EU, appointing an EU Authorised Representative (EC Rep) is a legal requirement under EU MDR 2017/745 and IVDR 2017/746. Patient Guard provides expert EU Authorised Representative services, EUDAMED support, regulatory guidance, and ongoing compliance management to help manufacturers access and maintain the European market with confidence.

Read More »
patient guard
Patient Guard

Sign up to our newsletter

Be the first to hear industry news and how Patient Guard can help you.

Get the latest updates on medical device regulation

Sign up to our newsletter and we’ll deliver news and insights straight to your inbox.
Patient Guard Regulatory Affairs and Quality Assurance

Get the Medical Device Technical Checklist

Thank you! The checklist is now ready to download.

checklist-tablet