1. Does the EU AI Act apply to your software?

The EU AI Act (Regulation EU 2024/1689) defines an AI system as software developed with machine learning, logic- or knowledge-based approaches, or statistical methods that generates outputs — predictions, recommendations, decisions — influencing real or virtual environments. If your SaMD uses any form of ML inference to produce clinical outputs, it almost certainly qualifies.

The risk class question resolves quickly for most medical software companies. Under Annex III of the AI Act, AI systems that are medical devices under MDR, or that are safety components of a medical device, are automatically classified as high-risk AI. There is no separate AI risk classification exercise. Your MDR device class determines your AI Act status.

The practical rule

Class IIa, IIb, or III under EU MDR + Notified Body conformity assessment = high-risk AI under the AI Act. Class I MDR devices without NB assessment are generally outside high-risk AI scope, unless they function as a safety component within a higher-class system.

If your software is not yet classified under EU MDR, that classification question comes first. See our guide on EU MDR Rule 11 and SaMD classification before proceeding.

2. The deadlines — original, revised, and which applies to you

This is the section that has changed most since this guide was first published. On 7 May 2026, EU institutions reached a provisional political agreement on the Digital Omnibus on AI, which postpones high-risk AI obligations across the board. Medical devices — AI systems that are themselves a medical device, or a safety component of one — fall under Annex I as product-embedded high-risk AI, not Annex III. Here is where things stand:

2 August 2027
(original date)
Superseded, pending formal adoption. This was the original Annex I deadline for AI systems that are medical devices or safety components. The Digital Omnibus agreement postpones this by one year.
2 August 2028
(revised date)
New deadline for AI SaMD under Annex I, following the Digital Omnibus agreement. This applies whether your product is already on the market or still in development — Annex I does not carry the same "new placement vs. already marketed" split that Annex III does. Formal adoption and Official Journal publication are expected before 2 August 2026.
2 December 2027 Annex III use-based high-risk AI (recruitment, credit scoring, law enforcement, education, etc.) — not the relevant category for most SaMD, since medical devices sit under Annex I. Mentioned here because compliance summaries frequently conflate the two Annexes.
What "pending formal adoption" means in practice

The political agreement is not yet law. Formal adoption by the Parliament and Council, followed by publication in the Official Journal, is expected before 2 August 2026 — the current legally binding deadline. Until publication, the original dates remain technically in force. In practice, reversal of a confirmed provisional agreement at this stage would be unusual, so we recommend planning against 2 August 2028 while monitoring for the formal publication. We will update this guide the moment it is confirmed.

3. What your existing MDR work already covers

The good news: substantial portions of the AI Act's high-risk requirements map directly onto EU MDR and ISO 13485 obligations you are likely already meeting. MDCG guidance document MDCG 2025-6 explicitly acknowledges this overlap and encourages using existing MDR documentation to demonstrate AI Act compliance where the requirements are equivalent.

Requirement area MDR / ISO 13485 coverage AI Act status
Quality Management System ISO 13485 fully covers Article 17 QMS structure Partial — extend for AI processes
Risk management ISO 14971 covers most AI Act risk obligations Partial — add AI-specific risks
Technical documentation MDR Annex II technical file overlaps with AI Act Annex IV Partial — add data governance sections
Conformity assessment Notified Body MDR assessment Largely covered
Post-market surveillance MDR PMS plan and PMCF Partial — add AI monitoring metrics
Data governance documentation Not required under MDR New — Article 10 requirement
Transparency / IFU for AI outputs IFU requirements exist but less specific New — Articles 13–14
Human oversight by design Not explicitly required under MDR New — Article 14 design requirement
EU AI database registration No MDR equivalent New — before market placement

4. What is genuinely new — the four gaps

Despite the overlaps, the AI Act introduces four requirement areas with no direct MDR equivalent. These are where companies with solid MDR files still have meaningful work to do.

Gap 1 — Data governance (Article 10)

The AI Act requires documented data governance practices covering the entire ML pipeline: data collection, labelling, cleaning, augmentation, and — critically — the representativeness of training, validation, and test datasets. You must demonstrate that your datasets adequately represent the intended patient population by age, sex, ethnicity, clinical setting, and relevant comorbidities, and document how bias was identified and mitigated.

In practice, this means retroactively documenting decisions made during model development. For many teams, this is the most time-consuming AI Act compliance task — dataset provenance records rarely exist in the form the AI Act requires.

Gap 2 — Transparency and instructions for use (Articles 13–14)

High-risk AI systems must be transparent enough to enable clinical users to interpret outputs and exercise meaningful human oversight. Your IFU must explain the model's limitations, conditions under which outputs may be unreliable, and how users should verify AI recommendations before acting on them. A "for physician review only" disclaimer does not satisfy this requirement. The level of explainability required is substantially more prescriptive than current IFU standards under MDR.

Gap 3 — Human oversight by design (Article 14)

This is a design requirement, not a documentation requirement. Your product architecture must allow clinical users to stop, override, or disregard AI outputs at appropriate decision points. If your current system makes it difficult in practice to override an AI recommendation — whether by UX design or workflow integration — redesign may be necessary before the 2 August 2028 deadline.

Gap 4 — EU AI database registration

High-risk AI systems must be registered in the EU database for high-risk AI systems before first market placement. This is a procedural requirement with no MDR equivalent. The database is expected to be publicly accessible well ahead of the (now revised) 2 August 2028 deadline. Build registration into your pre-launch checklist.

Your Notified Body and the AI Act

Your technical file will effectively need to satisfy both MDR Annex II/III and AI Act Annex IV requirements. Some Notified Bodies are beginning to integrate these assessments. Ask your NB directly how they are approaching AI Act compliance in their MDR audits — the answer varies significantly between bodies and affects how you structure your documentation.

Not sure what your AI Act gap looks like? We review your MDR technical file and identify exactly what needs to be added ahead of the August 2028 deadline.
Book free gap review →

5. The Digital Omnibus — what has been agreed

Earlier versions of this guide described the Digital Omnibus as an open question. It largely no longer is. After a first round of trilogue negotiations broke down on 28 April 2026, EU institutions reached a provisional political agreement on 6–7 May 2026, subsequently confirmed by Member State representatives in the Council on 13 May.

The key outcomes relevant to medical AI:

Where this stands as of writing

The agreement is provisional and still requires formal adoption by the European Parliament and Council, followed by publication in the Official Journal — expected before the current 2 August 2026 deadline (final approval anticipated around June, publication around July 2026). Once published, the amendments enter into force on the third day following publication and apply directly across all Member States. We recommend planning against the revised dates while treating formal publication as the trigger to fully de-risk your timeline.

The practical shift for most medical AI developers: the same underlying work — data governance documentation, transparency and IFU updates, human oversight by design, QMS extension, EU AI database registration — still needs to happen, but the runway has meaningfully lengthened. Rather than compressing a 3–6 month compliance programme into a matter of weeks before August 2026, most companies now have until August 2028 to plan and execute it properly, in step with their ongoing MDR technical file work.

That said, "more time" is not "no urgency." Harmonised standards supporting AI Act compliance are still being finalised by CEN-CENELEC, and companies seeking initial CE certification in the near term should build AI Act-aligned documentation into their technical file from the outset — retrofitting data governance documentation after the fact remains the most time-consuming part of this work regardless of which deadline applies.

6. Six-step action plan for 2028

If your SaMD uses ML and is Class IIa or above under MDR, these are the concrete steps to complete before the 2 August 2028 deadline. The total effort for a company with an existing MDR technical file is typically three to six months when done systematically — with the extended timeline, there is no need to compress this, but there is also no reason to defer it entirely. Building it into your next MDR technical file revision cycle is the most efficient path.

  1. 1
    Inventory every AI component in your product Document each ML model: its purpose, training data source, version history, and the clinical outputs it generates. This is the foundation for AI Act Annex IV technical documentation and your ongoing monitoring plan. If you cannot articulate this clearly, your AI Act compliance work cannot begin.
  2. 2
    Gap-assess your technical file against AI Act Annex IV Compare your current MDR technical file section by section against the nine Annex IV requirements. Data governance documentation (training data provenance, bias assessment methodology) and explainability approach are the most common gaps in files we review. A structured technical documentation audit surfaces these gaps systematically — worth doing now even with the extended deadline, since it folds naturally into your next MDR technical file update.
  3. 3
    Document your training datasets retroactively Reconstruct and document data collection methodology, labelling process, dataset composition by relevant demographic subgroups, and the bias identification and mitigation steps taken during development. This is typically the most time-consuming step for teams that did not document as they built.
  4. 4
    Update your PMS plan for continuous AI monitoring Add AI-specific performance metrics to your existing post-market surveillance plan: model accuracy drift by patient subgroup, out-of-distribution detection rates, and defined thresholds for triggering model review or withdrawal. This overlaps with MDR PMCF requirements and can be integrated into your existing PMS framework.
  5. 5
    Extend your ISO 13485 QMS to cover AI-specific processes Add at minimum: a procedure for managing training data versions, a bias assessment process, and a model change management procedure that determines when a post-deployment model change constitutes a significant change requiring a new conformity assessment under MDR. Extending an existing QMS for these AI processes typically takes four to eight weeks.
  6. 6
    Contact your Notified Body and monitor formal adoption of the Digital Omnibus Ask your NB directly how they are integrating AI Act requirements into their MDR audits — some have published guidance, many have not, and their approach affects your documentation strategy. In parallel, track formal adoption and Official Journal publication of the Digital Omnibus agreement (expected before 2 August 2026) to confirm the 2 August 2028 date is locked in, and prepare for EU AI database registration ahead of that deadline.

Companies with solid MDR technical files and ISO 13485 QMS in place are significantly better positioned than those starting from scratch. The gap between "MDR compliant" and "AI Act compliant" is real — but it is bridgeable in three to six months when approached systematically. With the deadline now extended to 2 August 2028, the sensible move is to fold this work into your regular MDR documentation cycle rather than treat it as a separate fire drill.