MedTech Terms
    The authoritative reference
    All terms

    EU AI Act

    EU regulation establishing risk-based requirements for AI systems, including most medical AI.

    Reviewed by Christian Espinosa, Founder, Blue Goat CyberLast reviewed May 5, 2026

    Definition

    Regulation (EU) 2024/1689 classifies AI systems by risk. Medical-device AI is generally treated as 'high-risk' and must meet AI Act requirements (data governance, transparency, human oversight, robustness, post-market monitoring) in addition to MDR/IVDR.
    What the regulation says
    The EU AI Act, specifically Regulation (EU) 2024/1689, categorizes AI systems based on their risk level, with AI in medical devices generally falling under the "high-risk" classification. This necessitates adherence to the Act's stringent requirements, covering aspects like data governance, transparency, human oversight, robustness, and post-market monitoring, in addition to existing EU Medical Device Regulation (MDR) or In Vitro Diagnostic Regulation (IVDR) obligations. The Act explicitly aims to ensure that AI systems placed on the Union market and used in the Union are safe and respect existing fundamental rights and Union values.

    What this means in practice

    Conformity assessment for medical AI is integrated with the existing Notified Body process. Phased application runs through 2027; manufacturers should align technical documentation now.

    Examples

    • A manufacturer developing an AI-powered diagnostic imaging system must demonstrate robust data governance practices for the AI model's training data, as per AI Act requirements.
    • An AI-enabled surgical robot requires clear human oversight mechanisms, allowing medical professionals to intervene or override AI decisions, in line with the EU AI Act.
    • A company marketing an AI algorithm for disease prediction must establish a comprehensive post-market monitoring system to track the AI's performance and address any emerging risks or biases.
    Common pitfalls
    • Failing to integrate AI Act requirements into technical documentation early will lead to significant delays in market access.
    • Assuming that MDR/IVDR compliance alone is sufficient for AI-powered medical devices is a critical error.
    • Neglecting to establish robust post-market monitoring for AI systems will result in non-compliance and potential regulatory action.
    • Misinterpreting the "high-risk" classification criteria for AI in medical devices can lead to inadequate conformity assessment.
    • Overlooking the need for human oversight mechanisms in AI-driven medical devices will result in non-adherence to the Act.

    Frequently asked questions

    The phased application of the EU AI Act runs through 2027. Manufacturers should proactively align their technical documentation now to meet the upcoming requirements, integrating them with existing MDR/IVDR processes.

    Cross-references

    Governs

    Things this term applies rules or requirements to.

    Grouped by theme

    Primary references

    3 sources
    Link health: 3 verified· last checked 2026-06-20
    EUR-Lex·1IMDRF·1MDCG·1
    1. 1
      EU AI Act (Reg. 2024/1689)
      Verified
      EUR-Lexeur-lex.europa.eu
    2. 2
      IMDRF - Software as a Medical Device
      Verified
      IMDRFimdrf.org
    3. 3
      MDCG Software Guidance
      Verified
      MDCGhealth.ec.europa.eu

    Inline markers like [1] jump to the matching reference above.