Published: 15th June 2026
Reviewed by: David Small BSc (Hons), MSc, MTOPRA (Founder and CEO)
The EU Has Finally Clarified How the AI Act Works Alongside MDR and IVDR
For the past two years, one of the biggest concerns facing AI medical device manufacturers has been regulatory overlap. Companies developing AI-powered Software as a Medical Device (SaMD), diagnostic algorithms, and machine learning systems have been asking the same question:
“Will we need two separate regulatory systems — one for MDR/IVDR and another for the EU AI Act?”
Following major political agreements reached in May 2026, the EU has finally provided much-needed clarity through the emerging “AI Act Omnibus” framework.
The new approach significantly reduces duplication between the EU AI Act and existing MDR/IVDR conformity assessment procedures, while also extending key deadlines for high-risk AI medical devices to August 2028.
However, while some obligations have been delayed, others begin much sooner. Transparency requirements for AI systems — including chatbot disclosures and AI-generated content labeling — are expected to apply from August 2026.
For medical device and IVD manufacturers, the message is clear: the compliance timeline may have shifted, but preparation cannot wait.
Building AI Medical Device Software?
While the AI Act introduces additional requirements for AI-enabled medical devices and IVDs, manufacturers must still comply with established software lifecycle requirements. For a complete guide to IEC 62304, including software development, verification, validation and maintenance requirements, read our IEC 62304 Explained: Medical Device Software Development Guide.
What Is the EU AI Act Omnibus Package?
The “AI Act Omnibus” refers to the latest political agreements and implementation clarifications designed to streamline how the EU AI Act interacts with existing sector-specific legislation, including:
- EU MDR 2017/745
- EU IVDR 2017/746
- GDPR
- Cybersecurity regulations
- Product safety legislation
The primary goal is to avoid duplicate regulatory oversight while still ensuring:
- AI safety
- Transparency
- Human oversight
- Data governance
- Cybersecurity
- Ethical AI deployment
For healthcare manufacturers, this clarification is critical because most AI-enabled medical technologies already operate under strict MDR or IVDR controls.
Why the AI Act Matters to Medical Device Manufacturers
The EU AI Act introduces horizontal AI legislation that applies across industries.
However, medical devices are considered one of the highest-risk AI sectors because they directly impact:
- Patient diagnosis
- Treatment decisions
- Clinical workflows
- Healthcare outcomes
- Patient safety
Examples of high-risk AI medical technologies include:
- AI diagnostic imaging software
- Clinical decision support systems
- Oncology prediction tools
- AI pathology systems
- Remote patient monitoring algorithms
- AI triage software
- Predictive analytics platforms
Without regulatory alignment, manufacturers feared being subjected to:
- Duplicate audits
- Separate technical assessments
- Parallel quality systems
- Multiple notified body reviews
The 2026 agreements now provide a more practical framework.
High-Risk AI Medical Device Deadlines Extended to August 2028
The New Compliance Timeline
One of the biggest outcomes of the May 2026 political agreements is the extension of deadlines for high-risk AI medical devices.
Under the revised timeline:
- High-risk AI systems regulated under MDR/IVDR now have until August 2028 before full AI Act obligations apply.
This gives manufacturers additional time to:
- Update technical documentation
- Strengthen AI governance systems
- Improve transparency controls
- Align PMS procedures
- Enhance cybersecurity frameworks
- Build lifecycle AI monitoring processes
Why the Extension Was Necessary
The extension reflects industry concerns around:
- Limited Notified Body capacity
- Unclear implementation guidance
- Technical complexity of AI systems
- Overlap between MDR/IVDR and AI Act requirements
- Resource shortages within regulatory teams
Many healthcare AI companies argued that simultaneous compliance deadlines would have created:
- Certification bottlenecks
- Delayed innovation
- Reduced market access
- Increased costs
- Regulatory confusion
The revised timeline gives manufacturers breathing room — but not a reason to delay preparation.
The “No Duplication” Rule: A Major Win for MedTech Companies
What Is the No Duplication Principle?
Perhaps the most important clarification for manufacturers is the introduction of the “No Duplication” rule.
Under this principle, AI medical devices already assessed under MDR or IVDR should not automatically require a completely separate AI-specific conformity assessment if equivalent requirements have already been evaluated.
This is a major shift toward regulatory harmonisation.
How the No Duplication Rule Works
If your MDR or IVDR conformity assessment already covers areas such as:
- Risk management
- Cybersecurity
- Clinical performance
- Human oversight
- PMS
- Data governance
- Software lifecycle controls
- Usability engineering
then portions of the AI Act requirements may be considered satisfied through the existing process.
This could significantly reduce:
- Administrative burden
- Audit duplication
- Certification delays
- Regulatory costs
What Manufacturers Still Need to Demonstrate
The No Duplication rule does not eliminate AI Act compliance.
Manufacturers must still demonstrate that their systems adequately address:
- AI transparency
- Bias mitigation
- Data quality
- Human oversight
- Algorithm accountability
- Model monitoring
- Explainability where appropriate
- Continuous performance management
In practice, this means manufacturers should begin integrating AI governance directly into their existing MDR/IVDR systems rather than creating parallel frameworks.
Immediate AI Transparency Rules Begin in August 2026
Not All AI Act Requirements Are Delayed
While high-risk medical device obligations have been extended, certain AI transparency requirements begin much earlier.
From August 2026, organisations using AI systems — including healthcare companies — may face immediate obligations relating to:
- AI chatbot disclosures
- Synthetic content labeling
- AI-generated communication transparency
- User awareness obligations
This means some compliance activities must begin now.
AI Chatbot Disclosure Requirements
Organisations deploying AI chatbots must ensure users are clearly informed they are interacting with AI unless it is obvious from context.
This applies to:
- Customer support chatbots
- Patient triage assistants
- AI scheduling tools
- Healthcare information assistants
- AI-powered web chat systems
Manufacturers and healthcare providers should review:
- Website chatbot disclosures
- Terms of use
- Privacy notices
- Patient-facing communications
Failure to provide adequate transparency may create compliance risk.
Labeling Requirements for AI-Generated Content
The AI Act also introduces obligations relating to AI-generated or manipulated content.
Companies may need to label:
- Synthetic media
- AI-generated patient communications
- Automated reports
- AI-created educational content
- Deepfake-style media outputs
For MedTech companies increasingly using generative AI tools internally and externally, governance controls are becoming essential.
The Engineering Prerequisite
You cannot pass an EU AI Act conformity assessment if your underlying software lifecycle is flawed. Review our technical blueprint, IEC 62304 Explained: Medical Device Software Development, to align your core coding standards with global regulations.
How MDR, IVDR, and the AI Act Are Converging
The Rise of Integrated AI Compliance
The latest EU agreements signal a broader regulatory trend:
AI compliance is no longer separate from medical device compliance.
Instead, regulators expect manufacturers to integrate AI governance into:
- ISO 13485 QMS systems
- Risk management processes
- PMS frameworks
- Clinical evaluation activities
- Cybersecurity management
- Software lifecycle controls
Manufacturers that treat AI compliance as an isolated project may struggle in future audits.
Key Areas Manufacturers Should Focus on Now
1. Conduct an AI Gap Assessment
Manufacturers should evaluate whether existing MDR/IVDR systems adequately address:
- AI lifecycle monitoring
- Bias management
- Transparency controls
- Human oversight
- Data governance
- Explainability
2. Review Software Classification
Many AI-enabled systems fall under:
- MDR Rule 11
- IVDR software classification requirements
This may increase regulatory scrutiny and require Notified Body involvement.
3. Strengthen Post-Market Surveillance for AI
AI systems require continuous lifecycle oversight.
Manufacturers should strengthen:
- Real-world performance monitoring
- Algorithm drift detection
- Complaint trending
- Cybersecurity monitoring
- Clinical feedback analysis
4. Improve Technical Documentation Structure
Regulators increasingly expect structured documentation demonstrating:
- AI model governance
- Validation processes
- Training data quality
- Human oversight mechanisms
- Change management controls
5. Prepare Transparency Disclosures Before August 2026
Organisations using AI chatbots or generative AI systems should review transparency obligations immediately.
This includes:
- User notifications
- AI interaction disclosures
- Content labelling policies
- Governance procedures
Frequently Asked Questions About the AI Act and Medical Devices
Are AI medical devices considered high-risk under the AI Act?
Yes. Most AI-enabled medical devices regulated under MDR or IVDR are classified as high-risk AI systems.
Do manufacturers need a second AI-specific audit?
Not necessarily. Under the new No Duplication principle, existing MDR/IVDR conformity assessments may satisfy parts of the AI Act requirements.
When do AI Act obligations apply to medical devices?
Many high-risk obligations are now delayed until August 2028 for MDR/IVDR-regulated AI devices.
However, transparency obligations begin earlier in August 2026.
What are the biggest AI Act risks for MedTech companies?
The main challenges include:
- AI governance integration
- Transparency obligations
- Cybersecurity controls
- Lifecycle monitoring
- Data quality management
- Regulatory documentation
Final Thoughts: The Regulatory Picture Is Finally Becoming Clearer
For AI medical device and IVD manufacturers, the May 2026 political agreements provide long-awaited clarity.
The extension to August 2028 reduces immediate pressure, while the No Duplication rule helps avoid unnecessary regulatory overlap between MDR/IVDR and the AI Act.
However, this is not a pause button for compliance.
The organisations best positioned for long-term success will be those that begin integrating AI governance into their existing quality and regulatory systems today.
AI regulation in healthcare is no longer theoretical — it is becoming operational.
Need Help Preparing for the EU AI Act?
At Patient Guard Ltd, we help medical device and IVD manufacturers navigate the evolving intersection between:
- MDR
- IVDR
- AI Act compliance
- Software regulation
- Cybersecurity
- PMS and vigilance
- AI governance systems
Our team supports:
- AI regulatory gap analyses
- SaMD classification reviews
- Technical documentation remediation
- PMS integration
- AI transparency compliance
- Cybersecurity strategy
- ISO 13485 alignment
- Regulatory roadmap planning
If your organisation is developing AI-powered healthcare technologies, now is the time to prepare for the next generation of EU regulatory oversight.
Contact Patient Guard Ltd Today to Discuss Your AI Compliance Strategy
David Small BSc (Hons), MSc, MTOPRA
Reviewed by
David Small, BSc (Hons), MSc, MTOPRA
Founder & CEO |
20+ years in medical device regulatory affairs, MDR/IVDR compliance and quality systems.
Patient Guards Recent Posts

10 Common Technical Documentation Deficiencies Found During EU MDR and IVDR Notified Body Reviews
Preparing technical documentation for EU MDR or IVDR certification is only half the challenge. Successfully passing a Notified Body review depends on demonstrating consistency across your Quality Management System, Clinical Evaluation, Risk Management, Biological Evaluation, Performance Evaluation and Post-Market Surveillance activities. Discover ten of the most common technical documentation deficiencies identified during MDR and IVDR conformity assessments—and learn how to reduce the likelihood of costly review cycles and certification delays.

EU Authorised Representative Services for Medical Device & IVD Manufacturers
Selling medical devices or IVDs in Europe? If your company is based outside the EU, appointing an EU Authorised Representative (EC Rep) is a legal requirement under EU MDR 2017/745 and IVDR 2017/746. Patient Guard provides expert EU Authorised Representative services, EUDAMED support, regulatory guidance, and ongoing compliance management to help manufacturers access and maintain the European market with confidence.

Predetermined Change Control Plans (PCCPs): The Future of Agile Compliance for Medical Device Software
Learn how PCCPs help medical device software manufacturers manage updates, support AI systems, and enable agile compliance under evolving MDR and UKCA frameworks.
Need Training?
Do you need training on Quality Management Systems or EU MDR/ EU IVDR? then check out our training courses.