Skip to content
Amended. Regulation (EU) 2026/1744 entered into force 27 July 2026. See what moved →
EU AI Act ChecklistIndependent reference
Industry guide · MedTech

EU AI Act for MedTech

MedTech is the one sector where most published AI Act guidance gives you the wrong date. Medical device AI is high-risk through Annex I, not Annex III, which means 2 August 2028, and you already have a notified body, a QMS and a technical file, which changes what the work actually is.

Art. 6(1)Annex Iapplies 2 Aug 2028
Classification route. Article 6(1): the product route. AI that is a safety component of, or is itself, a product covered by the Annex I harmonisation legislation (including the MDR and IVDR) and required to undergo third-party conformity assessment. Applies from 2 August 2028.

What is in scope, and what is not

 Detail
Annex I routeAI as a safety component of, or itself, a medical device or IVD under the MDR or IVDR requiring third-party conformity assessment — 2 August 2028
Annex III route, separatelyPoint 5(a) if used by or on behalf of public authorities to evaluate eligibility for healthcare services; point 5(d) emergency triage; point 1 for biometric or emotion-recognition components — 2 December 2027
Not the AI Act's product routeHospital back-office AI, scheduling, coding and billing — assess separately

Expert analysis. Classification turns on the intended purpose of each system. This is our reading of common deployments, not an authoritative classification.

Where this usually goes next

Three situations account for most people reading this page. Each has a different answer.

A deal is blocked on an AI questionnaire

Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.

How this works for AI companies →

You need ISO/IEC 42001 documentation

23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.

Free gap assessment →
See the three tiers →

You are not sure what reaches you

Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.

Book a free 20-minute call →

This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →

Two dates, and most summaries give you one

A diagnostic support tool regulated as a medical device is Annex I: 2 August 2028. An emergency triage system under Annex III point 5(d), or a healthcare eligibility system used by a public authority under point 5(a), is 2 December 2027.

A MedTech company can therefore hold both dates simultaneously across its portfolio. Any guide quoting a single high-risk date has not distinguished the two routes, and that is a fast way to test whether an adviser has read the Regulation or a summary of it.

Where the genuine new work sits. You already have a QMS, a technical file, post-market surveillance and vigilance reporting. Those satisfy a great deal. What MDR does not give you: Article 10 data governance in AI Act terms including the bias examination duty, Article 14 human oversight framed around automation bias and override authority, Article 15’s five named AI attack classes, and the Article 12 logging specification. Those are the gap. Expert analysis.

Layering onto MDR and IVDR

  • One conformity assessment, extended scope. Where the AI is part of a device already undergoing third-party assessment, the AI Act requirements are assessed within that procedure rather than through a parallel one. Your notified body needs the relevant designation.
  • Your MDR QMS is the foundation for Article 17, but the two are not identical — map rather than assume.
  • Vigilance reporting is not Article 73. Different definitions of a reportable event, different deadlines, potentially different authorities.
  • Clinical evaluation does not discharge Article 10. Bias examination across the persons and groups on whom the device is intended to be used is an AI Act requirement with no direct MDR analogue.

What applies before December 2027

Article 50 applies now to any patient- or clinician-facing conversational or generative feature. Article 4 literacy applies to clinical deployers.

The deferral in Regulation (EU) 2026/1744 covers Chapter III Sections 1 to 3. It does not cover Article 5, Article 4, Chapter V general-purpose AI, Article 49 registration or Article 50 transparency. Full timeline →

Status labels on this page

Verified fact: The Annex III points, article references and dates cited above, checked against the consolidated Regulation and the Commission's AI Act Service Desk.

Expert analysis: The in-scope/out-of-scope allocation, the sector edge case, and the parallel-regulation reading.

Unsettled: Harmonised standards remain in development and the Commission's Annex III guidelines are in draft. Sector supervisory practice has not yet formed.

Next step

Map MDR evidence to Chapter III before 2028

The efficient path is a gap analysis from your existing technical file to the AI Act requirements, not a second programme. Most of the file transfers; four areas do not.

Classify before you build

Twelve questions mapping your system against Articles 5, 6, 50 and Annex III. No email required.

Run the classifier →

Frequently asked

When does the EU AI Act apply to medical devices?

AI that is a safety component of, or is itself, a product covered by the Annex I harmonisation legislation including the MDR and IVDR, and required to undergo third-party conformity assessment, follows the Article 6(1) route and applies from 2 August 2028 following Regulation (EU) 2026/1744. That is a different date from the 2 December 2027 date for stand-alone Annex III systems.

Does MDR compliance satisfy the EU AI Act?

No, though it covers a substantial part. An MDR quality management system, technical documentation, post-market surveillance and vigilance reporting provide much of the foundation. Article 10 data governance including bias examination, Article 14 human oversight framed around automation bias and override authority, the AI-specific attack classes named in Article 15, and the Article 12 logging specification have no direct MDR analogue.

Do we need a separate conformity assessment for the AI Act?

Generally not a separate procedure. Where the AI is part of a product already subject to third-party conformity assessment under Annex I legislation, the AI Act requirements are assessed within that existing procedure. The notified body must hold the relevant designation.