Published: 15th June 2026
Reviewed by: David Small BSc (Hons), MSc, MTOPRA (Founder and CEO)
The EU Has Finally Clarified How the AI Act Works Alongside MDR and IVDR
For the past two years, one of the biggest concerns facing AI medical device manufacturers has been regulatory overlap. Companies developing AI-powered Software as a Medical Device (SaMD), diagnostic algorithms, and machine learning systems have been asking the same question:
“Will we need two separate regulatory systems — one for MDR/IVDR and another for the EU AI Act?”
Following major political agreements reached in May 2026, the EU has finally provided much-needed clarity through the emerging “AI Act Omnibus” framework.
The new approach significantly reduces duplication between the EU AI Act and existing MDR/IVDR conformity assessment procedures, while also extending key deadlines for high-risk AI medical devices to August 2028.
However, while some obligations have been delayed, others begin much sooner. Transparency requirements for AI systems — including chatbot disclosures and AI-generated content labeling — are expected to apply from August 2026.
For medical device and IVD manufacturers, the message is clear: the compliance timeline may have shifted, but preparation cannot wait.
Building AI Medical Device Software?
While the AI Act introduces additional requirements for AI-enabled medical devices and IVDs, manufacturers must still comply with established software lifecycle requirements. For a complete guide to IEC 62304, including software development, verification, validation and maintenance requirements, read our IEC 62304 Explained: Medical Device Software Development Guide.
What Is the EU AI Act Omnibus Package?
The “AI Act Omnibus” refers to the latest political agreements and implementation clarifications designed to streamline how the EU AI Act interacts with existing sector-specific legislation, including:
- EU MDR 2017/745
- EU IVDR 2017/746
- GDPR
- Cybersecurity regulations
- Product safety legislation
The primary goal is to avoid duplicate regulatory oversight while still ensuring:
- AI safety
- Transparency
- Human oversight
- Data governance
- Cybersecurity
- Ethical AI deployment
For healthcare manufacturers, this clarification is critical because most AI-enabled medical technologies already operate under strict MDR or IVDR controls.
Why the AI Act Matters to Medical Device Manufacturers
The EU AI Act introduces horizontal AI legislation that applies across industries.
However, medical devices are considered one of the highest-risk AI sectors because they directly impact:
- Patient diagnosis
- Treatment decisions
- Clinical workflows
- Healthcare outcomes
- Patient safety
Examples of high-risk AI medical technologies include:
- AI diagnostic imaging software
- Clinical decision support systems
- Oncology prediction tools
- AI pathology systems
- Remote patient monitoring algorithms
- AI triage software
- Predictive analytics platforms
Without regulatory alignment, manufacturers feared being subjected to:
- Duplicate audits
- Separate technical assessments
- Parallel quality systems
- Multiple notified body reviews
The 2026 agreements now provide a more practical framework.
High-Risk AI Medical Device Deadlines Extended to August 2028
The New Compliance Timeline
One of the biggest outcomes of the May 2026 political agreements is the extension of deadlines for high-risk AI medical devices.
Under the revised timeline:
- High-risk AI systems regulated under MDR/IVDR now have until August 2028 before full AI Act obligations apply.
This gives manufacturers additional time to:
- Update technical documentation
- Strengthen AI governance systems
- Improve transparency controls
- Align PMS procedures
- Enhance cybersecurity frameworks
- Build lifecycle AI monitoring processes
Why the Extension Was Necessary
The extension reflects industry concerns around:
- Limited Notified Body capacity
- Unclear implementation guidance
- Technical complexity of AI systems
- Overlap between MDR/IVDR and AI Act requirements
- Resource shortages within regulatory teams
Many healthcare AI companies argued that simultaneous compliance deadlines would have created:
- Certification bottlenecks
- Delayed innovation
- Reduced market access
- Increased costs
- Regulatory confusion
The revised timeline gives manufacturers breathing room — but not a reason to delay preparation.
The “No Duplication” Rule: A Major Win for MedTech Companies
What Is the No Duplication Principle?
Perhaps the most important clarification for manufacturers is the introduction of the “No Duplication” rule.
Under this principle, AI medical devices already assessed under MDR or IVDR should not automatically require a completely separate AI-specific conformity assessment if equivalent requirements have already been evaluated.
This is a major shift toward regulatory harmonisation.
How the No Duplication Rule Works
If your MDR or IVDR conformity assessment already covers areas such as:
- Risk management
- Cybersecurity
- Clinical performance
- Human oversight
- PMS
- Data governance
- Software lifecycle controls
- Usability engineering
then portions of the AI Act requirements may be considered satisfied through the existing process.
This could significantly reduce:
- Administrative burden
- Audit duplication
- Certification delays
- Regulatory costs
What Manufacturers Still Need to Demonstrate
The No Duplication rule does not eliminate AI Act compliance.
Manufacturers must still demonstrate that their systems adequately address:
- AI transparency
- Bias mitigation
- Data quality
- Human oversight
- Algorithm accountability
- Model monitoring
- Explainability where appropriate
- Continuous performance management
In practice, this means manufacturers should begin integrating AI governance directly into their existing MDR/IVDR systems rather than creating parallel frameworks.
Immediate AI Transparency Rules Begin in August 2026
Not All AI Act Requirements Are Delayed
While high-risk medical device obligations have been extended, certain AI transparency requirements begin much earlier.
From August 2026, organisations using AI systems — including healthcare companies — may face immediate obligations relating to:
- AI chatbot disclosures
- Synthetic content labeling
- AI-generated communication transparency
- User awareness obligations
This means some compliance activities must begin now.
AI Chatbot Disclosure Requirements
Organisations deploying AI chatbots must ensure users are clearly informed they are interacting with AI unless it is obvious from context.
This applies to:
- Customer support chatbots
- Patient triage assistants
- AI scheduling tools
- Healthcare information assistants
- AI-powered web chat systems
Manufacturers and healthcare providers should review:
- Website chatbot disclosures
- Terms of use
- Privacy notices
- Patient-facing communications
Failure to provide adequate transparency may create compliance risk.
Labeling Requirements for AI-Generated Content
The AI Act also introduces obligations relating to AI-generated or manipulated content.
Companies may need to label:
- Synthetic media
- AI-generated patient communications
- Automated reports
- AI-created educational content
- Deepfake-style media outputs
For MedTech companies increasingly using generative AI tools internally and externally, governance controls are becoming essential.
The Engineering Prerequisite
You cannot pass an EU AI Act conformity assessment if your underlying software lifecycle is flawed. Review our technical blueprint, IEC 62304 Explained: Medical Device Software Development, to align your core coding standards with global regulations.
How MDR, IVDR, and the AI Act Are Converging
The Rise of Integrated AI Compliance
The latest EU agreements signal a broader regulatory trend:
AI compliance is no longer separate from medical device compliance.
Instead, regulators expect manufacturers to integrate AI governance into:
- ISO 13485 QMS systems
- Risk management processes
- PMS frameworks
- Clinical evaluation activities
- Cybersecurity management
- Software lifecycle controls
Manufacturers that treat AI compliance as an isolated project may struggle in future audits.
Key Areas Manufacturers Should Focus on Now
1. Conduct an AI Gap Assessment
Manufacturers should evaluate whether existing MDR/IVDR systems adequately address:
- AI lifecycle monitoring
- Bias management
- Transparency controls
- Human oversight
- Data governance
- Explainability
2. Review Software Classification
Many AI-enabled systems fall under:
- MDR Rule 11
- IVDR software classification requirements
This may increase regulatory scrutiny and require Notified Body involvement.
3. Strengthen Post-Market Surveillance for AI
AI systems require continuous lifecycle oversight.
Manufacturers should strengthen:
- Real-world performance monitoring
- Algorithm drift detection
- Complaint trending
- Cybersecurity monitoring
- Clinical feedback analysis
4. Improve Technical Documentation Structure
Regulators increasingly expect structured documentation demonstrating:
- AI model governance
- Validation processes
- Training data quality
- Human oversight mechanisms
- Change management controls
5. Prepare Transparency Disclosures Before August 2026
Organisations using AI chatbots or generative AI systems should review transparency obligations immediately.
This includes:
- User notifications
- AI interaction disclosures
- Content labelling policies
- Governance procedures
Frequently Asked Questions About the AI Act and Medical Devices
Are AI medical devices considered high-risk under the AI Act?
Yes. Most AI-enabled medical devices regulated under MDR or IVDR are classified as high-risk AI systems.
Do manufacturers need a second AI-specific audit?
Not necessarily. Under the new No Duplication principle, existing MDR/IVDR conformity assessments may satisfy parts of the AI Act requirements.
When do AI Act obligations apply to medical devices?
Many high-risk obligations are now delayed until August 2028 for MDR/IVDR-regulated AI devices.
However, transparency obligations begin earlier in August 2026.
What are the biggest AI Act risks for MedTech companies?
The main challenges include:
- AI governance integration
- Transparency obligations
- Cybersecurity controls
- Lifecycle monitoring
- Data quality management
- Regulatory documentation
Final Thoughts: The Regulatory Picture Is Finally Becoming Clearer
For AI medical device and IVD manufacturers, the May 2026 political agreements provide long-awaited clarity.
The extension to August 2028 reduces immediate pressure, while the No Duplication rule helps avoid unnecessary regulatory overlap between MDR/IVDR and the AI Act.
However, this is not a pause button for compliance.
The organisations best positioned for long-term success will be those that begin integrating AI governance into their existing quality and regulatory systems today.
AI regulation in healthcare is no longer theoretical — it is becoming operational.
Need Help Preparing for the EU AI Act?
At Patient Guard Ltd, we help medical device and IVD manufacturers navigate the evolving intersection between:
- MDR
- IVDR
- AI Act compliance
- Software regulation
- Cybersecurity
- PMS and vigilance
- AI governance systems
Our team supports:
- AI regulatory gap analyses
- SaMD classification reviews
- Technical documentation remediation
- PMS integration
- AI transparency compliance
- Cybersecurity strategy
- ISO 13485 alignment
- Regulatory roadmap planning
If your organisation is developing AI-powered healthcare technologies, now is the time to prepare for the next generation of EU regulatory oversight.
Contact Patient Guard Ltd Today to Discuss Your AI Compliance Strategy
References
This guide is based on the following legislation, official guidance and regulatory publications relating to the EU Artificial Intelligence Act, medical devices, in vitro diagnostic medical devices and AI-enabled healthcare technologies.
| Organisation | Reference | Why it's relevant |
|---|---|---|
| European Union | Regulation (EU) 2024/1689 – Artificial Intelligence Act (AI Act) | Establishes the European Union's legal framework for artificial intelligence, including requirements for high-risk AI systems and AI-enabled medical devices. |
| European Union | Regulation (EU) 2017/745 on Medical Devices (MDR) | Provides the legal framework governing medical devices in the European Union and explains how AI-enabled medical devices are regulated alongside the AI Act. |
| European Union | Regulation (EU) 2017/746 on In Vitro Diagnostic Medical Devices (IVDR) | Provides the legal framework for AI-enabled in vitro diagnostic medical devices and their interaction with the AI Act. |
| European Commission | AI Act Single Information Platform | Provides the European Commission's official implementation portal for the AI Act, including practical guidance, compliance tools, legal obligations, timelines and supporting resources to help organisations understand and apply the Regulation. |
| Medicines and Healthcare products Regulatory Agency (MHRA) | Software and Artificial Intelligence (AI) as a Medical Device | Provides UK regulatory guidance on AI-enabled medical devices and Software as a Medical Device, supporting comparison with the evolving EU framework. |
| International Medical Device Regulators Forum (IMDRF) | Software as a Medical Device (SaMD): Key Definitions | Provides internationally recognised terminology for Software as a Medical Device, supporting the article's discussion of AI-enabled software products. |
The regulatory framework for artificial intelligence continues to evolve. Manufacturers should always consult the latest published legislation, official guidance and regulatory updates when developing, placing or maintaining AI-enabled medical devices and IVDs on the European market.
David Small BSc (Hons), MSc, MTOPRA
Reviewed by
David Small, BSc (Hons), MSc, MTOPRA
Founder & CEO |
20+ years in medical device regulatory affairs, MDR/IVDR compliance and quality systems.
Patient Guards Recent Posts

Cosmetic Product Safety Report (CPSR): A Complete Guide to UK Cosmetic Compliance
Before a cosmetic product can legally be placed on the UK market, manufacturers and Responsible Persons must demonstrate that it is safe for human use under normal or reasonably foreseeable conditions. The Cosmetic Product Safety Report (CPSR) is one of the most important regulatory documents required under the UK Cosmetics Regulation. This guide explains what a CPSR is, who can prepare one, what information it must contain, how it relates to the Product Information File (PIF) and how it supports legal cosmetic compliance.

IVDR PMPF Explained: A Complete Guide to Post-Market Performance Follow-up
Post-Market Performance Follow-up (PMPF) is a fundamental requirement under the EU In Vitro Diagnostic Regulation (IVDR), ensuring that manufacturers continually monitor the scientific validity, analytical performance and clinical performance of their in vitro diagnostic medical devices after CE marking. This guide explains IVDR PMPF requirements, PMPF Plans, PMPF Reports, Annex XIII expectations and how ongoing performance monitoring supports continued regulatory compliance throughout the device lifecycle.

IVDR Scientific Validity Explained: A Complete Guide for Manufacturers
Scientific Validity is the first pillar of IVDR Performance Evaluation and provides the scientific foundation demonstrating that an analyte or biomarker is associated with a specific clinical condition or physiological state. This guide explains Scientific Validity under Regulation (EU) 2017/746, including literature reviews, Scientific Validity Reports, Annex XIII requirements, evidence appraisal and how Scientific Validity supports successful CE marking.
Need Training?
Do you need training on Quality Management Systems or EU MDR/ EU IVDR? then check out our training courses.
Posted on Google![]()
Munna P52 days agoTrustindex verifies that the original source of the review is Google.
Working with the Patient Guard team has been a great experience throughout our MHRA and ISO 13485 documentation journey. Their expertise, structured approach, and practical guidance helped our team build a robust quality management system while keeping us aligned with regulatory expectations. The collaboration was professional, responsive, and focused on finding solutions rather than simply identifying issues. A special thank you to Alex and Steve for their outstanding coordination, responsiveness, and continuous support throughout the project. They were always approachable, provided valuable feedback, and worked closely with our team to resolve challenges efficiently. Their commitment made a significant difference in keeping our documentation effort on track. I highly recommend Patient Guard to any healthcare or MedTech organization looking for experienced regulatory and quality system partners for MHRA, ISO 13485, and broader medical device compliance initiatives. Thank you again to the entire Patient Guard team for being such reliable partners.Posted on Google![]()
Peter Reeve79 days agoTrustindex verifies that the original source of the review is Google.
STEPPER design, manufacture & distribute eyewear across the globe. With the increasingly complex landscape concerning the placing of Mecial Devices onto the market, we realised we needed professional guidance. We found Patient Guard via a simple internet search and are delighted we did! They provide a pragmatic solution to our needs, are totally reliable & always available to answer our (often simplistic) questions. They are highly efficient & responsive to what is a changing picture in our world and nothing is too much trouble. We have a much better understanding of regulatory affairs and our responsibilities as manufacturers & distributors and they support us in navigating the requirements in different territories. Updating our Declaration of Conformity, ensuring our labelling is compliant and acting as our PRRC are the key areas of their service for us.Posted on Google![]()
Derek Timm79 days agoTrustindex verifies that the original source of the review is Google.
For those companıes lookıng to comply to ISO standards and ın partıcular ISO13485 whıch to be honest ıs a nıghtmare I would strongly suggest goıng to the professıonals as ındeed we dıd by joınıng forces wıth Patıent Guard Ltd The staff are fantastıc nothıng ıs too much trouble and as a medıcal supply company we sımply cannot lıve wıthout them Thanks ın partıcular to Alex and Steve for all the hard work and our best regards from Dan Medıca South LımıtedPosted on Google![]()
BMSCriticalCare116 days agoTrustindex verifies that the original source of the review is Google.
Great service, very helpful and always willing to answer any questions we have,Posted on Google![]()
Thomson Software787 days agoTrustindex verifies that the original source of the review is Google.
Alex Lewis of PatientGuard guided us through the ISO13485 process in a thorough, systematic and efficient manner. He was friendly, patient and willing to go the extra mile. Excellent service.Verified by TrustindexTrustindex verified badge is the Universal Symbol of Trust. Only the greatest companies can get the verified badge who has a review score above 4.5, based on customer reviews over the past 12 months. Read more