4 Things You Should Know about the AI Act as a Medical Device Manufacturer

Many of us remember the early-2000’s comedy Not Another Teen Movie. When medical device manufacturers first hear about the EU AI Act, a similar thought often comes to mind: Not yet another regulation.
The reaction is understandable. Medical devices are already among the most highly regulated products on the market. Manufacturers must comply with the Medical Device Regulation (MDR) or In Vitro Diagnostic Regulation (IVDR), numerous harmonised standards, guidance documents, and country-specific requirements. Although regulatory frameworks across global markets share many similarities, each comes with its own nuances that require careful attention.
Introducing another regulation can feel like yet another compliance burden: analysing new requirements, updating procedures, creating additional documentation, expanding risk management activities, potentially involving Notified Bodies in new ways, and extending the scope of internal and external audits.
Before dismissing the AI Act as “just another regulation,” however, it is worth taking a closer look. Many of its requirements will already be familiar to medical device manufacturers. In many cases, the AI Act builds on existing principles rather than introducing entirely new ones.
That does not mean there is nothing new to learn. The AI Act introduces additional expectations, particularly around data governance, transparency, algorithm performance, bias management, and ongoing monitoring of AI systems. Understanding where these new requirements complement existing MDR obligations – and where they go beyond them – is key to achieving efficient compliance.
This blog explores four things medical device manufacturer should know about the EU AI Act, highlighting the familiar concepts.
The great advantage that medical device manufacturers already have is that they are used to work with regulations. Many requirements are already partially fulfilled with the documentation and process required by MDR and IVDR. Most manufacturers have a working quality management system in place and have established processes. Every decision with a medical devices is risk-based following a risk management process and documented in a risk management file. The technical documentation required by MDR and IVDR provides a solid basis to integrate the additional documentation requirements of the AI act.
IEC 62304 gives a practical framework on how to develop medical device software. This framework can be adopted to AI when it comes to design controls and traceability. Guidance on how to apply the risk management process can be found in the ISO/TS 24971-2 and AAMI TIR 34971. There is already guidance available and there is no need to reinvent the wheel.
ISO/IEC 42001:2023 Information technology — Artificial intelligence — Management system provides a framework for establishing a QMS for AI systems manufacturer.The requirements are similar to the requirements of ISO 13485.
So instead of dealing with a completely new topic medical device manufacturers have to perform a gap assessment rather than introducing new processes and deliverables. Quality managers could use the AI act gap analysis as an opportunity to conduct a review of the existing process with the respective process owners. In the process, not only are gaps identified, but potentially also the occasional imprecise or outdated process descriptions eliminated. The primary frustration among medical device manufacturers regarding the AI Act stems largely from the fact that there is yet another new regulation that must be considered and evaluated, and then integrated into the Quality Management System and technical documentation.
Another topic that medical device manufacturers are already familiar with is classification. There are various classifications like EU, US, Canadian, Australian classification, software safety classification, documentation level classification that medical device manufacturers already know, so another classification is nothing to worry about. The AI Act defines two classes of devices: low risk and high risk devices. The classification rules are defined in article 6 of the AI act.
From a medical device point of view the AI act defines that medical devices and in-vitro medical devices that may impact patient safety are considered high risk AI systems. An additional criteria defines that devices that require a conformity assessment by a notified body are also considered high risk. The decision tree is quite clear and medical device manufacturers need to focus on the intended use of their AI and its relevance for safety. Annex III of the AI act defines some exceptions of AI systems that are also considered high risk, but medical devices are not mentioned there. Therefore, medical device manufacturers can ignore Annex III for now.
Even relatively simple AI functionality embedded in a medical device can trigger the full set of High-Risk AI requirements. This feels a bit off in medical device sector, to treat devices with great impact on safety the same as devices with low impact. Especially when the issue with rule 11 of the MDR classification is considered. As rule 11 makes it very hard for standalone software medical devices to be classified as class I as the rule basically requires a software that fulfills the medical device definition to be classified as clas IIa or higher.
Annex II and Annex III of MDR and Annex VI of the AI act describe the required contents of the technical documentation for the respective regulation. The AI act has less requirements on the technical file and mostly requires the same contents and documents/ records as the EU MDR does.
Going through the requirements on the technical documentation of the AI, the first required documentation is about general description of the AI system, including its intended purpose, provider, version, deployment format, hardware and software requirements, interfaces with other systems, product integration where applicable, and the information necessary for users to install, operate, and interact with the system safely and as intended.
The technical documentation should describe the development and design of the AI system, including the methods used, system architecture, algorithms, design choices, optimization objectives, and any third-party components or pre-trained models involved. It should provide information on training, validation, and testing data, including data sources, selection, preparation, and quality measures, as well as details on human oversight, system changes, performance monitoring, validation procedures, accuracy, robustness, potential bias, and cybersecurity measures implemented to ensure compliance and safe operation.
Additionally a description of the risk management process, the appropriateness of performance metrics for the AI system, a description of relevant changes made by the provider to the AI system through its lifetime and a post-market surveillance process is required. Last but not least, a declaration of conformity to the AI act needs to be added in the technical documentation.

Verena Wieser, Medical device consultant
Need help identifying your gaps?
Lorit Consultancy supports medical device manufacturers with:
There is not a single document or record required by the AI act that medical device manufacturers are not used to. Let’s be honest, if a manufacturer has no description and detailed specification of its AI system just because it is not written in the EU MDR / IVDR, the manufacturer has not understood medical devices. As every decision in medical devices is risk based (or at least should be), there will be no serious medical device manufacturer bypassing a thorough risk analysis of their AI system.
The task of the team will be to ensure that the existing documentation, that is already essential for MDR and IVDR and other regulations, is sufficient enough to understand the AI system and the associated risk, while a newly added requirement of a respective declaration of conformity to the EU AI act is equally met when it comes to the technical documentation.
The quality of an AI system depends not only on its algorithm but also on whether it has been developed for the people who will actually use it. In the FDA’S DRAFT guidance “Artificial Intelligence-Enabled Device Software Functions: Lifecycle Management and Marketing Submission Recommendations” FDA describes the importance of human factors. To create your AI/ ML model you need to understand your user needs to define the correct intended use & foreseeable misuse and to derive appropriate system and and software requirements. When choosing the training and test data, it is of most importance to represent the actual user/ patient groups and their characteristics.
A similar requirement can be found in the AI act. While knowing your users characteristics, the AI act has some additional requirements to avoid disadvantages for minorities and ensures gender equality and requires no discrimination, equality, and fundamental rights. Unlike AI systems used for decision-making about individuals (e.g., recruitment or credit scoring), medical AI systems generally evaluate physiological or pathological characteristics rather than social or demographic attributes. Consequently, many protected characteristics are not decision variables and have no direct influence on the intended medical purpose. Medical devices must distinguish between legitimate biological variation and unlawful discrimination, for example:

Accounting for the above mentioned differences is often necessary to achieve safe and effective clinical performance. Ignoring clinically relevant differences could itself introduce bias and reduce safety. The objective is therefore not identical performance across all groups, but appropriate clinical performance for the intended population and transparent communication of any known limitations. There is objective evidence in literature that pulse oximeters may overestimate oxygen saturation in patients with darker skin pigmentation because light absorption differs with melanin concentration. If oximeter manufacturers plan to use AI assistance in the signal interpretation they should consider this in the risk assessments and demonstrate if their AI system is reliable for all potential patient groups enough.
If a subgroup is insufficiently represented during development, manufacturers should determine whether this creates an unacceptable performance risk. The main counter measure is to expand the dataset to adequately represent all subgroups but that is not always possible. Thinking of skin cancer, it is more common in lighter skin types than in darker. If sufficient data is not available, the medical device manufacturers cannot create it and train their models. The restriction of the intended population in the intended use might than be the only reasonable option, as well as alternatively informing the users about the known performance limitations.
Another topic to keep in mind is the automation bias. Humans tend to trust machine automat. For healthcare professionals and lay users it must be clear how the output of the AI system was derived and it needs to be ensured that the human user understands the output and uses the output to draw the correct conclusions. To achieve this, usability testing in form of formative and summative evaluations is a must. Misinterpreting the AI systems output may lead to unacceptable risks and wrong decisions. Providing the user with information how the output was derived and showing trust intervals helps the human user to safely handle the output. It is better to provide no result and a clear error message in case that the AI system is not within trust limits for the calculations/ decisions. This alerts the human user to use traditional methods or reevaluate the input’s quality.
An important step in the risk management of AI system is the understanding of information necessary to use or interpret. This includes the misunderstanding, misuse and unavailability of data. FDA defines the following example in the above mentioned guidance:”For example, for devices that utilize complex algorithms, including AI-enabled devices, the performance in different disease subtypes may not be apparent to users, or the logic underlying the output information may not be easily understandable, which can negatively affect user understanding and use of the device”.
To sum it up, the AI act is another regulation to observe but with familiar concepts. The main task will be to analyse and understand the requirements of the AI act and identify which requirements are not completely covered in the QMS or technical documentation yet. The second step is to close the gaps. The AI act does not require rethinking your whole concept of developing a medical device and existing processes can be reused. The gap analysis can also highlight existing gaps to EU MDR and IVDR and contribute to the continuous improvement required by ISO 13485. If you are unsure how to take this first step, consider engaging with a consultant who has the experience to perform the gap analysis and provide solutions on how to fill the gaps. The AI act has not changed the existing medical device regulation and standards are available to help.
By Verena Wieser, Medical Device Consultant
From risk management to regulatory compliance, we help medical device teams navigate standards like IEC 60601, 62304, 61010, and ISO 13485. Our team supports you with practical, tailored guidance and training.