Under the EU AI Act, AI in a medical device is high-risk when the AI is the device, or a safety component of it, and the MDR or IVDR requires a notified body to assess it, which covers most diagnostic and monitoring software in class IIa and above. Those obligations apply from 2 August 2028 through the existing device conformity assessment, and hospitals using such systems take on deployer duties.
When medical AI becomes high-risk
Article 6(1) of the AI Act sets two conditions. The AI system must be a product, or a safety component of a product, covered by legislation listed in Annex I, and that product must need a third-party conformity assessment under that legislation. The Medical Devices Regulation (EU) 2017/745 and the In Vitro Diagnostic Medical Devices Regulation (EU) 2017/746 are points 11 and 12 of Annex I, Section A. So the device class decides the AI Act status, and the AI Act does not change the device class.
The joint guidance from the Medical Device Coordination Group and the AI Board, MDCG 2025-6 / AIB 2025-1 of June 2025, sets this out device by device.
| Device class | Notified body involved? | High-risk under Article 6(1)? |
|---|---|---|
| MDR class I (not sterile, no measuring function, not reusable surgical) | No | No |
| MDR class I sterile, measuring or reusable surgical | Yes | Yes |
| MDR class IIa, IIb and III | Yes | Yes |
| IVDR class A (not sterile) | No | No |
| IVDR class A sterile | Yes | Yes |
| IVDR class B, C and D | Yes | Yes |
| In-house device under Article 5(5) MDR or IVDR | No | No |
For software, MDR Rule 11 in Annex VIII does most of the sorting. Software that provides information used to take diagnostic or therapeutic decisions is class IIa; it is class IIb if those decisions could cause a serious deterioration of health or a surgical intervention, and class III if they could cause death or an irreversible deterioration. Software that monitors physiological processes is class IIa, or IIb for vital parameters where variations could put the patient in immediate danger. All other software is class I. An AI tool that flags suspected findings on scans for a radiologist therefore usually lands in class IIa or higher, needs a notified body and is high-risk.
The Digital Omnibus on AI, Regulation (EU) 2026/1744, narrowed what counts as a safety component. AI used solely for non-safety purposes such as user assistance, performance optimisation, service efficiency, automation, convenience or quality control is not a safety component, unless its failure would endanger health and safety. A third-party assessment needed only for non-health risks, such as radio spectrum or electromagnetic interference, does not satisfy the second condition. The Commission published draft guidelines on high-risk classification for consultation on 19 May 2026; check whether a final version has followed before relying on them.
Two parts of the Act apply whatever the device class: the prohibited practices in Article 5 and the transparency duties in Article 50, which cover, for example, a symptom-checker chatbot that talks to patients.
The dates after the Digital Omnibus
| Date | What applies to healthcare AI |
|---|---|
| 2 February 2025 | Prohibited practices; AI literacy measures for staff (Art. 4) |
| 2 August 2026 | Article 50: tell people they are dealing with AI; mark synthetic content |
| 2 December 2026 | New prohibitions on AI that generates non-consensual intimate imagery or child sexual abuse material; end of the marking grace period for generative systems already on the market |
| 1 August 2027 | Commission guidelines due on integrating AI Act duties into device risk and quality systems |
| 2 August 2027 | Commission delegated acts due on where device law already covers AI Act requirements |
| 2 December 2027 | High-risk obligations for Annex III systems, such as emergency triage |
| 28 January 2028 | MDR and IVDR notified bodies must apply for designation under the AI Act |
| 2 August 2028 | High-risk obligations for AI in Annex I products, including medical devices and IVDs |
MDCG 2025-6 was written before the Omnibus, so its references to August 2027 for Annex I systems are out of date. Our EU AI Act timeline covers the dates outside healthcare.
How conformity assessment works with notified bodies
There is one assessment, not two. Article 43(3), as rewritten by the Omnibus, tells the provider of a high-risk AI system covered by Annex I, Section A, to follow the conformity assessment procedure of the MDR or IVDR. The AI Act’s requirements for high-risk systems in Articles 8 to 15 are assessed as part of that procedure, together with the AI-specific parts of the quality management system. Where a system falls under both Annex I and Annex III, the device procedure applies, and MDCG 2025-6 gives an emergency triage system that qualifies as a medical device as its example.
Notified bodies already designated under the MDR or IVDR can assess the AI Act requirements, provided their notification covered the AI-specific criteria in Article 31(4), (5), (10) and (11), and they must apply for designation under the AI Act by 28 January 2028. The Omnibus also confirmed that a device does not need a notified body just because it contains a high-risk AI system: the route stays the one the device regulation prescribes.
The Act lets manufacturers fold its requirements into what they already run:
- Documentation. Article 11(2) asks for a single set of technical documentation covering both laws, and Article 8(2) lets testing and reporting be integrated into existing device procedures.
- Quality management. Article 17(3) lets the AI Act’s quality management aspects sit inside the device quality management system.
- Post-market monitoring. Article 72(4) lets the AI Act elements go into the existing device post-market surveillance plan, provided protection is equivalent.
- Serious incidents. Article 73(10) limits AI Act notifications for devices to infringements of fundamental-rights law; other incidents go through device vigilance.
- Clinical evidence. MDCG 2025-6 treats a clinical investigation or performance study of high-risk device AI as testing in real-world conditions under Article 60.
New Article 2(13) may cut duplication further: by delegated act, the Commission can limit specific requirements where device law already gives equivalent protection.
The proposal to move devices out of Section A
On 16 December 2025 the Commission proposed a targeted revision of the MDR and IVDR, COM(2025) 1023, that would move both regulations from Section A to Section B of Annex I. The AI Act would then apply to devices only through the limited provisions for Section B products, and the Commission could set AI-specific requirements through the device regulations. The European Parliament’s Legislative Observatory lists the file as awaiting a committee decision in the public health committee, with a plenary vote indicated for December 2026 (verified October 2026). Until it is adopted and in force, plan for the rules above.
Health uses listed in Annex III
Some health-related AI is high-risk without being a medical device. Annex III point 5 covers:
- Public benefits and services: AI used by or on behalf of public authorities to evaluate eligibility for essential public assistance benefits and services, including healthcare services, or to grant, reduce, revoke or reclaim them (point 5(a)).
- Insurance: AI for risk assessment and pricing of natural persons in life and health insurance (point 5(c)).
- Emergencies: AI that evaluates and classifies emergency calls, dispatches or prioritises emergency first response, including medical aid, and emergency healthcare patient triage systems (point 5(d)).
These obligations apply from 2 December 2027. Article 6(3) lets a provider show that an Annex III system is not high-risk when it only performs a narrow procedural or preparatory task, but a system that profiles people always stays high-risk. Before using an Annex III system, deployers that are bodies governed by public law or private entities providing public services, which includes many hospitals, must complete a fundamental rights impact assessment under Article 27. That assessment does not apply to device AI that is high-risk only through Annex I.
What hospitals must do as deployers
A hospital that uses a high-risk AI system under its own authority is a deployer. The duties in Article 26 translate into concrete work on the ward and in IT:
| Duty | Article | In a hospital |
|---|---|---|
| Use as instructed | 26(1) | Configure and use the system within the provider’s instructions for use and intended purpose |
| Human oversight | 26(2) | Name the clinicians who oversee it; give them training and the authority to override or stop it |
| Input data | 26(4) | Check that the data you feed it is relevant and representative for your patients |
| Monitoring and incidents | 26(5) | Watch performance; suspend use and tell the provider and authority about risks; report serious incidents to the provider first |
| Logs | 26(6) | Keep the logs the system generates, where you control them, for at least six months |
| Staff information | 26(7) | Tell workers and their representatives before using it at work |
| Registration | 26(8), 49(3) | Public-authority deployers register their use of Annex III systems in the EU database |
| Telling patients | 26(11) | Inform people when an Annex III system makes or assists decisions about them |
| DPIA | 26(9) | Use the provider’s Article 13 information in your GDPR data protection impact assessment |
Two duties already apply: AI literacy measures for staff (Article 4) and disclosure by patient-facing chatbots that they are AI (Article 50). Our guide to human oversight under Article 14 covers how to design the review step.
Hospitals that build their own tools need one more check. An AI tool developed and used only inside the hospital under MDR or IVDR Article 5(5), meeting all its conditions, does not go to a notified body and so is not high-risk under Article 6(1), according to MDCG 2025-6. Article 5(5) still requires the general safety and performance requirements, a quality management system, a public declaration and documentation, and the AI Act’s prohibitions still apply. The AI Board and the MDCG have said further guidance on in-house AI will follow. A hospital that puts a system into service under its own name is its provider under the AI Act.
GDPR: health data is special-category data
Data concerning health is a special category under Article 9 of the GDPR, and processing it needs one of the conditions in Article 9(2). For care itself, point (h) covers diagnosis, treatment and the management of health systems, on the basis of law or a contract with a health professional bound by professional secrecy; point (i) covers public health. Training models on patient records is a different purpose from treatment and needs its own assessment.
Article 35(3)(b) makes a DPIA mandatory for large-scale processing of special-category data, and the WP248 guidelines endorsed by the EDPB use a hospital processing patients’ genetic and health data as an example of processing that likely requires one. Build the DPIA and the AI Act paperwork together: the provider’s instructions for use feed the DPIA, and the DPIA’s risks belong in the hospital’s AI risk assessment template for that system.
Pharma and life sciences
Much pharmaceutical AI sits outside the high-risk rules. Article 2(6) excludes AI developed and put into service solely for scientific research and development, and Article 2(8) excludes research, testing and development before a system is placed on the market or put into service, though testing in real-world conditions is not excluded. Medicinal products legislation is not listed in Annex I, so drug-discovery and manufacturing AI is not high-risk by that route; check Annex III for uses such as hiring, and Article 50 for chatbots.
Companion diagnostics are the main exception. Rule 3 of IVDR Annex VIII places them in class C, which requires a notified body, so AI that is part of a companion diagnostic can be high-risk under Article 6(1).
Sector guidance fills the gap. The European Medicines Agency adopted a reflection paper on AI across the medicinal product lifecycle in September 2024, and on 14 January 2026 EMA and the US FDA published ten joint principles of good AI practice in drug development. For manufacturing, a draft Annex 22 on artificial intelligence was added to the EU GMP consultation that ran from 7 July to 7 October 2025, and after an EMA workshop on 30 June and 1 July 2026 it is still being finalised (verified October 2026).
Pharmaceutical manufacturers, research and development of medicinal products, and healthcare providers are also listed as high-criticality sectors under NIS2, and medical device manufacturing is in its second annex, so the NIS2 duties for AI systems apply to many of the same organisations.
How VDF AI fits
VDF AI is general-purpose software, not a medical device, and it holds no MDR, IVDR or other certification. Hospitals and life-sciences firms use it for administrative and knowledge work, such as drafting documents, answering questions from policies and procedures, and preparing files for a person to review. If a workflow would supply information used for diagnosis or treatment, the qualification questions in this guide apply to that workflow, and the answer belongs to your regulatory and clinical safety teams.
The platform runs inside your own environment, on-premises, in a private cloud or air-gapped, so patient data stays within your boundary. Role-based access control is included on every plan, consequential steps can wait for a person’s approval, and every prompt, retrieval, tool call, response and approval is logged with the actor and time and can stream to your SIEM, which gives the DPIA and the AI literacy programme concrete records. See on-premise AI for healthcare and the healthcare and life sciences brief; for the infrastructure side, our private AI guide for healthcare CIOs and CISOs goes further.
Sources
- AI Act, Regulation (EU) 2024/1689, on EUR-Lex
- Digital Omnibus on AI, Regulation (EU) 2026/1744
- MDCG 2025-6 / AIB 2025-1, interplay between the MDR, IVDR and AI Act
- Medical Devices Regulation (EU) 2017/745
- In Vitro Diagnostic Medical Devices Regulation (EU) 2017/746
- Commission proposal COM(2025) 1023 revising the MDR and IVDR
- Legislative Observatory, procedure 2025/0404(COD)
- Draft Commission guidelines on high-risk classification
- GDPR, Regulation (EU) 2016/679
- WP248 rev.01 DPIA guidelines, endorsed by the EDPB
- EMA, reflection paper on AI in the medicinal product lifecycle
- EMA, EMA and FDA principles for AI in medicine development
- European Commission, GMP consultation including Annex 22
- EMA, Annex 22 multistakeholder workshop