The AI Act Omnibus Explained: What the 2026 EU Rules Mean for Medical Device and IVD Manufacturers

Discover how the EU AI Act Omnibus affects AI medical devices and IVD manufacturers. Learn about the No Duplication principle, transparency rules, key 2026 and 2028 deadlines, and how MDR and IVDR compliance are converging with AI regulation.
The AI Act Omnibus Explained: What the 2026 EU Rules Mean for Medical Device and IVD Manufacturers

Published: 15th June 2026

Reviewed by: David Small BSc (Hons), MSc, MTOPRA (Founder and CEO)

The EU Has Finally Clarified How the AI Act Works Alongside MDR and IVDR

For the past two years, one of the biggest concerns facing AI medical device manufacturers has been regulatory overlap. Companies developing AI-powered Software as a Medical Device (SaMD), diagnostic algorithms, and machine learning systems have been asking the same question:

“Will we need two separate regulatory systems — one for MDR/IVDR and another for the EU AI Act?”

Following major political agreements reached in May 2026, the EU has finally provided much-needed clarity through the emerging “AI Act Omnibus” framework.

The new approach significantly reduces duplication between the EU AI Act and existing MDR/IVDR conformity assessment procedures, while also extending key deadlines for high-risk AI medical devices to August 2028.

However, while some obligations have been delayed, others begin much sooner. Transparency requirements for AI systems — including chatbot disclosures and AI-generated content labeling — are expected to apply from August 2026.

For medical device and IVD manufacturers, the message is clear: the compliance timeline may have shifted, but preparation cannot wait.

What Is the EU AI Act Omnibus Package?

The “AI Act Omnibus” refers to the latest political agreements and implementation clarifications designed to streamline how the EU AI Act interacts with existing sector-specific legislation, including:

  • EU MDR 2017/745
  • EU IVDR 2017/746
  • GDPR
  • Cybersecurity regulations
  • Product safety legislation

The primary goal is to avoid duplicate regulatory oversight while still ensuring:

  • AI safety
  • Transparency
  • Human oversight
  • Data governance
  • Cybersecurity
  • Ethical AI deployment

For healthcare manufacturers, this clarification is critical because most AI-enabled medical technologies already operate under strict MDR or IVDR controls.

Why the AI Act Matters to Medical Device Manufacturers

The EU AI Act introduces horizontal AI legislation that applies across industries.

However, medical devices are considered one of the highest-risk AI sectors because they directly impact:

  • Patient diagnosis
  • Treatment decisions
  • Clinical workflows
  • Healthcare outcomes
  • Patient safety

Examples of high-risk AI medical technologies include:

  • AI diagnostic imaging software
  • Clinical decision support systems
  • Oncology prediction tools
  • AI pathology systems
  • Remote patient monitoring algorithms
  • AI triage software
  • Predictive analytics platforms

Without regulatory alignment, manufacturers feared being subjected to:

  • Duplicate audits
  • Separate technical assessments
  • Parallel quality systems
  • Multiple notified body reviews

The 2026 agreements now provide a more practical framework.

High-Risk AI Medical Device Deadlines Extended to August 2028

The New Compliance Timeline

One of the biggest outcomes of the May 2026 political agreements is the extension of deadlines for high-risk AI medical devices.

Under the revised timeline:

  • High-risk AI systems regulated under MDR/IVDR now have until August 2028 before full AI Act obligations apply.

This gives manufacturers additional time to:

  • Update technical documentation
  • Strengthen AI governance systems
  • Improve transparency controls
  • Align PMS procedures
  • Enhance cybersecurity frameworks
  • Build lifecycle AI monitoring processes

Why the Extension Was Necessary

The extension reflects industry concerns around:

  • Limited Notified Body capacity
  • Unclear implementation guidance
  • Technical complexity of AI systems
  • Overlap between MDR/IVDR and AI Act requirements
  • Resource shortages within regulatory teams

Many healthcare AI companies argued that simultaneous compliance deadlines would have created:

  • Certification bottlenecks
  • Delayed innovation
  • Reduced market access
  • Increased costs
  • Regulatory confusion

The revised timeline gives manufacturers breathing room — but not a reason to delay preparation.

The “No Duplication” Rule: A Major Win for MedTech Companies

What Is the No Duplication Principle?

Perhaps the most important clarification for manufacturers is the introduction of the “No Duplication” rule.

Under this principle, AI medical devices already assessed under MDR or IVDR should not automatically require a completely separate AI-specific conformity assessment if equivalent requirements have already been evaluated.

This is a major shift toward regulatory harmonisation.

How the No Duplication Rule Works

If your MDR or IVDR conformity assessment already covers areas such as:

  • Risk management
  • Cybersecurity
  • Clinical performance
  • Human oversight
  • PMS
  • Data governance
  • Software lifecycle controls
  • Usability engineering

then portions of the AI Act requirements may be considered satisfied through the existing process.

This could significantly reduce:

  • Administrative burden
  • Audit duplication
  • Certification delays
  • Regulatory costs

What Manufacturers Still Need to Demonstrate

The No Duplication rule does not eliminate AI Act compliance.

Manufacturers must still demonstrate that their systems adequately address:

  • AI transparency
  • Bias mitigation
  • Data quality
  • Human oversight
  • Algorithm accountability
  • Model monitoring
  • Explainability where appropriate
  • Continuous performance management

In practice, this means manufacturers should begin integrating AI governance directly into their existing MDR/IVDR systems rather than creating parallel frameworks.

Immediate AI Transparency Rules Begin in August 2026

Not All AI Act Requirements Are Delayed

While high-risk medical device obligations have been extended, certain AI transparency requirements begin much earlier.

From August 2026, organisations using AI systems — including healthcare companies — may face immediate obligations relating to:

  • AI chatbot disclosures
  • Synthetic content labeling
  • AI-generated communication transparency
  • User awareness obligations

This means some compliance activities must begin now.

AI Chatbot Disclosure Requirements

Organisations deploying AI chatbots must ensure users are clearly informed they are interacting with AI unless it is obvious from context.

This applies to:

  • Customer support chatbots
  • Patient triage assistants
  • AI scheduling tools
  • Healthcare information assistants
  • AI-powered web chat systems

Manufacturers and healthcare providers should review:

  • Website chatbot disclosures
  • Terms of use
  • Privacy notices
  • Patient-facing communications

Failure to provide adequate transparency may create compliance risk.

Labeling Requirements for AI-Generated Content

The AI Act also introduces obligations relating to AI-generated or manipulated content.

Companies may need to label:

  • Synthetic media
  • AI-generated patient communications
  • Automated reports
  • AI-created educational content
  • Deepfake-style media outputs

For MedTech companies increasingly using generative AI tools internally and externally, governance controls are becoming essential.

💻
The Engineering Prerequisite

You cannot pass an EU AI Act conformity assessment if your underlying software lifecycle is flawed. Review our technical blueprint, IEC 62304 Explained: Medical Device Software Development, to align your core coding standards with global regulations.

How MDR, IVDR, and the AI Act Are Converging

The Rise of Integrated AI Compliance

The latest EU agreements signal a broader regulatory trend:
AI compliance is no longer separate from medical device compliance.

Instead, regulators expect manufacturers to integrate AI governance into:

  • ISO 13485 QMS systems
  • Risk management processes
  • PMS frameworks
  • Clinical evaluation activities
  • Cybersecurity management
  • Software lifecycle controls

Manufacturers that treat AI compliance as an isolated project may struggle in future audits.

Key Areas Manufacturers Should Focus on Now

1. Conduct an AI Gap Assessment

Manufacturers should evaluate whether existing MDR/IVDR systems adequately address:

  • AI lifecycle monitoring
  • Bias management
  • Transparency controls
  • Human oversight
  • Data governance
  • Explainability

2. Review Software Classification

Many AI-enabled systems fall under:

  • MDR Rule 11
  • IVDR software classification requirements

This may increase regulatory scrutiny and require Notified Body involvement.

3. Strengthen Post-Market Surveillance for AI

AI systems require continuous lifecycle oversight.

Manufacturers should strengthen:

  • Real-world performance monitoring
  • Algorithm drift detection
  • Complaint trending
  • Cybersecurity monitoring
  • Clinical feedback analysis

 4. Improve Technical Documentation Structure

Regulators increasingly expect structured documentation demonstrating:

  • AI model governance
  • Validation processes
  • Training data quality
  • Human oversight mechanisms
  • Change management controls

 5. Prepare Transparency Disclosures Before August 2026

Organisations using AI chatbots or generative AI systems should review transparency obligations immediately.

This includes:

  • User notifications
  • AI interaction disclosures
  • Content labelling policies
  • Governance procedures

Frequently Asked Questions About the AI Act and Medical Devices

Yes. Most AI-enabled medical devices regulated under MDR or IVDR are classified as high-risk AI systems.

 

Not necessarily. Under the new No Duplication principle, existing MDR/IVDR conformity assessments may satisfy parts of the AI Act requirements.

Many high-risk obligations are now delayed until August 2028 for MDR/IVDR-regulated AI devices.

However, transparency obligations begin earlier in August 2026.

 

The main challenges include:

  • AI governance integration
  • Transparency obligations
  • Cybersecurity controls
  • Lifecycle monitoring
  • Data quality management
  • Regulatory documentation

Final Thoughts: The Regulatory Picture Is Finally Becoming Clearer

For AI medical device and IVD manufacturers, the May 2026 political agreements provide long-awaited clarity.

The extension to August 2028 reduces immediate pressure, while the No Duplication rule helps avoid unnecessary regulatory overlap between MDR/IVDR and the AI Act.

However, this is not a pause button for compliance.

The organisations best positioned for long-term success will be those that begin integrating AI governance into their existing quality and regulatory systems today.

AI regulation in healthcare is no longer theoretical — it is becoming operational.

 

Need Help Preparing for the EU AI Act?

At Patient Guard Ltd, we help medical device and IVD manufacturers navigate the evolving intersection between:

  • MDR
  • IVDR
  • AI Act compliance
  • Software regulation
  • Cybersecurity
  • PMS and vigilance
  • AI governance systems

Our team supports:

  • AI regulatory gap analyses
  • SaMD classification reviews
  • Technical documentation remediation
  • PMS integration
  • AI transparency compliance
  • Cybersecurity strategy
  • ISO 13485 alignment
  • Regulatory roadmap planning

If your organisation is developing AI-powered healthcare technologies, now is the time to prepare for the next generation of EU regulatory oversight.

Contact Patient Guard Ltd Today to Discuss Your AI Compliance Strategy

References

This guide is based on the following legislation, official guidance and regulatory publications relating to the EU Artificial Intelligence Act, medical devices, in vitro diagnostic medical devices and AI-enabled healthcare technologies.

Organisation Reference Why it's relevant
European Union Regulation (EU) 2024/1689 – Artificial Intelligence Act (AI Act) Establishes the European Union's legal framework for artificial intelligence, including requirements for high-risk AI systems and AI-enabled medical devices.
European Union Regulation (EU) 2017/745 on Medical Devices (MDR) Provides the legal framework governing medical devices in the European Union and explains how AI-enabled medical devices are regulated alongside the AI Act.
European Union Regulation (EU) 2017/746 on In Vitro Diagnostic Medical Devices (IVDR) Provides the legal framework for AI-enabled in vitro diagnostic medical devices and their interaction with the AI Act.
European Commission AI Act Single Information Platform Provides the European Commission's official implementation portal for the AI Act, including practical guidance, compliance tools, legal obligations, timelines and supporting resources to help organisations understand and apply the Regulation.
Medicines and Healthcare products Regulatory Agency (MHRA) Software and Artificial Intelligence (AI) as a Medical Device Provides UK regulatory guidance on AI-enabled medical devices and Software as a Medical Device, supporting comparison with the evolving EU framework.
International Medical Device Regulators Forum (IMDRF) Software as a Medical Device (SaMD): Key Definitions Provides internationally recognised terminology for Software as a Medical Device, supporting the article's discussion of AI-enabled software products.

The regulatory framework for artificial intelligence continues to evolve. Manufacturers should always consult the latest published legislation, official guidance and regulatory updates when developing, placing or maintaining AI-enabled medical devices and IVDs on the European market.

David Small BSc (Hons), MSc, MTOPRA

David Small BSc (Hons), MSc, MTOPRA

Reviewed by
David Small, BSc (Hons), MSc, MTOPRA
Founder & CEO |
20+ years in medical device regulatory affairs,  MDR/IVDR compliance and quality systems.

Patient Guards Recent Posts

Cosmetic Product Safety Report (CPSR): A Complete Guide to UK Cosmetic Compliance

Before a cosmetic product can legally be placed on the UK market, manufacturers and Responsible Persons must demonstrate that it is safe for human use under normal or reasonably foreseeable conditions. The Cosmetic Product Safety Report (CPSR) is one of the most important regulatory documents required under the UK Cosmetics Regulation. This guide explains what a CPSR is, who can prepare one, what information it must contain, how it relates to the Product Information File (PIF) and how it supports legal cosmetic compliance.

Read More »

IVDR PMPF Explained: A Complete Guide to Post-Market Performance Follow-up

Post-Market Performance Follow-up (PMPF) is a fundamental requirement under the EU In Vitro Diagnostic Regulation (IVDR), ensuring that manufacturers continually monitor the scientific validity, analytical performance and clinical performance of their in vitro diagnostic medical devices after CE marking. This guide explains IVDR PMPF requirements, PMPF Plans, PMPF Reports, Annex XIII expectations and how ongoing performance monitoring supports continued regulatory compliance throughout the device lifecycle.

Read More »

IVDR Scientific Validity Explained: A Complete Guide for Manufacturers

Scientific Validity is the first pillar of IVDR Performance Evaluation and provides the scientific foundation demonstrating that an analyte or biomarker is associated with a specific clinical condition or physiological state. This guide explains Scientific Validity under Regulation (EU) 2017/746, including literature reviews, Scientific Validity Reports, Annex XIII requirements, evidence appraisal and how Scientific Validity supports successful CE marking.

Read More »

Need Training?

Do you need training on Quality Management Systems or EU MDR/ EU IVDR? then check out our training courses.

Share this guide:
Posted on Google Google
Munna P profile picture
Munna P
52 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Working with the Patient Guard team has been a great experience throughout our MHRA and ISO 13485 documentation journey. Their expertise, structured approach, and practical guidance helped our team build a robust quality management system while keeping us aligned with regulatory expectations. The collaboration was professional, responsive, and focused on finding solutions rather than simply identifying issues. A special thank you to Alex and Steve for their outstanding coordination, responsiveness, and continuous support throughout the project. They were always approachable, provided valuable feedback, and worked closely with our team to resolve challenges efficiently. Their commitment made a significant difference in keeping our documentation effort on track. I highly recommend Patient Guard to any healthcare or MedTech organization looking for experienced regulatory and quality system partners for MHRA, ISO 13485, and broader medical device compliance initiatives. Thank you again to the entire Patient Guard team for being such reliable partners.
Posted on Google Google
Peter Reeve profile picture
Peter Reeve
79 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
STEPPER design, manufacture & distribute eyewear across the globe. With the increasingly complex landscape concerning the placing of Mecial Devices onto the market, we realised we needed professional guidance. We found Patient Guard via a simple internet search and are delighted we did! They provide a pragmatic solution to our needs, are totally reliable & always available to answer our (often simplistic) questions. They are highly efficient & responsive to what is a changing picture in our world and nothing is too much trouble. We have a much better understanding of regulatory affairs and our responsibilities as manufacturers & distributors and they support us in navigating the requirements in different territories. Updating our Declaration of Conformity, ensuring our labelling is compliant and acting as our PRRC are the key areas of their service for us.
Posted on Google Google
Derek Timm profile picture
Derek Timm
79 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
For those companıes lookıng to comply to ISO standards and ın partıcular ISO13485 whıch to be honest ıs a nıghtmare I would strongly suggest goıng to the professıonals as ındeed we dıd by joınıng forces wıth Patıent Guard Ltd The staff are fantastıc nothıng ıs too much trouble and as a medıcal supply company we sımply cannot lıve wıthout them Thanks ın partıcular to Alex and Steve for all the hard work and our best regards from Dan Medıca South Lımıted
Posted on Google Google
BMSCriticalCare profile picture
BMSCriticalCare
116 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Great service, very helpful and always willing to answer any questions we have,
Posted on Google Google
Thomson Software profile picture
Thomson Software
787 days ago
Google star 1Google star 2Google star 3Google star 4Google star 5Trustindex verifies that the original source of the review is Google.
Alex Lewis of PatientGuard guided us through the ISO13485 process in a thorough, systematic and efficient manner. He was friendly, patient and willing to go the extra mile. Excellent service.
Verified by Trustindex
Trustindex verified badge is the Universal Symbol of Trust. Only the greatest companies can get the verified badge who has a review score above 4.5, based on customer reviews over the past 12 months. Read more

Most Popular

Cosmetic Product Safety Report (CPSR): A Complete Guide to UK Cosmetic Compliance

Before a cosmetic product can legally be placed on the UK market, manufacturers and Responsible Persons must demonstrate that it is safe for human use under normal or reasonably foreseeable conditions. The Cosmetic Product Safety Report (CPSR) is one of the most important regulatory documents required under the UK Cosmetics Regulation. This guide explains what a CPSR is, who can prepare one, what information it must contain, how it relates to the Product Information File (PIF) and how it supports legal cosmetic compliance.

Read More »

IVDR PMPF Explained: A Complete Guide to Post-Market Performance Follow-up

Post-Market Performance Follow-up (PMPF) is a fundamental requirement under the EU In Vitro Diagnostic Regulation (IVDR), ensuring that manufacturers continually monitor the scientific validity, analytical performance and clinical performance of their in vitro diagnostic medical devices after CE marking. This guide explains IVDR PMPF requirements, PMPF Plans, PMPF Reports, Annex XIII expectations and how ongoing performance monitoring supports continued regulatory compliance throughout the device lifecycle.

Read More »

IVDR Scientific Validity Explained: A Complete Guide for Manufacturers

Scientific Validity is the first pillar of IVDR Performance Evaluation and provides the scientific foundation demonstrating that an analyte or biomarker is associated with a specific clinical condition or physiological state. This guide explains Scientific Validity under Regulation (EU) 2017/746, including literature reviews, Scientific Validity Reports, Annex XIII requirements, evidence appraisal and how Scientific Validity supports successful CE marking.

Read More »

IVDR Performance Evaluation Explained: A Complete Guide for Manufacturers

Performance Evaluation is one of the most important requirements under the EU In Vitro Diagnostic Regulation (IVDR). Every manufacturer must demonstrate that their in vitro diagnostic medical device achieves its intended purpose through robust scientific validity, analytical performance and clinical performance evidence. This guide explains every stage of IVDR Performance Evaluation, including Performance Evaluation Plans (PEPs), Performance Evaluation Reports (PERs), Post-Market Performance Follow-up (PMPF) and how Performance Evaluation supports successful CE marking under Regulation (EU) 2017/746.

Read More »
patient guard
Patient Guard

Sign up to our newsletter

Be the first to hear industry news and how Patient Guard can help you.

Get the latest updates on medical device regulation

Sign up to our newsletter and we’ll deliver news and insights straight to your inbox.

Get the Medical Device Technical Checklist

Thank you! The checklist is now ready to download.