Analysis

AI Act and medical devices: what SaMD manufacturers should prepare now

Illustration: AI Act and medical software (SaMD) under MDR/IVDR.

Manufacturers of software as a medical device (SaMD) and devices with an AI component now read two layers of EU law side by side: Regulation (EU) 2017/745 (MDR) or Regulation (EU) 2017/746 (IVDR), and Regulation (EU) 2024/1689 (AI Act). The AI Act does not replace the MDR/IVDR technical file. It adds obligations for AI systems, especially when they are classified as high-risk.

This analysis is for product, quality and regulatory teams that need to decide what to embed in the QMS now, without inventing a second quality system. The goal is to connect the AI Act and MDR/IVDR around data governance, monitoring and human oversight, with evidence reusable for the notified body.

Who is in scope and why act now

Article 6(1) of the AI Act treats as high-risk an AI system intended to be used as a safety component of a product, or that is itself a product, covered by Union harmonisation legislation listed in Annex I, where that product must undergo third-party conformity assessment. Annex I, Section A, expressly lists the MDR and the IVDR.

In practice, many SaMD / MDSW devices in class IIa and above (or IVD class B and above) can fall into this pattern when the system meets the AI Act definition of an AI system, acts as a safety component or product, and requires notified-body assessment. Classification remains case-by-case.

Under Article 113, the AI Act generally applies from 2 August 2026, while Article 6(1) and the corresponding obligations apply from 2 August 2027. That window is best used to extend the existing QMS, not to bolt on an AI Act binder outside design control.

What the AI Act adds (without duplicating MDR)

For high-risk systems, Chapter III requires among other things a risk management system, data and data governance, technical documentation, record-keeping / logging, transparency and information to deployers, human oversight, and accuracy, robustness and cybersecurity. Several of these themes already intersect ISO 13485, ISO 14971, IEC 62304 and the MDR/IVDR general safety and performance requirements.

The useful move is a mapping exercise: which AI Act requirement is already covered by a QMS procedure or design-control record, and where a specific proof is missing (training/validation data policy, human-oversight criteria, drift monitoring).

Data and governance

Document provenance, relevance, potential bias and quality criteria for datasets used to train, validate and test the model, tied to intended use. Link those decisions to the risk file and software requirements, not to a marketing annex.

Human oversight and transparency

Clarify who can monitor, interrupt or override system output, under which use conditions, and what information is provided to the deployer / professional user. Keep IFU, training and post-market surveillance aligned with that narrative.

Monitoring, logging and post-market

Extend PMS / PMCF (or PMPF for IVD) to detect performance shifts, AI-related events and drift signals. Logging that supports investigation must be defined, retained and accessible under the QMS, not only in engineering log piles.

Operational QMS action plan

  • Map the product: AI system under the AI Act? safety component? MDR/IVDR class and notified-body path?
  • Extend existing SOPs (risk management, design control, change control, PMS, cyber) instead of creating an isolated “AI Act manual”.
  • Update the technical documentation with an AI Act ↔ MDR/IVDR evidence traceability table.
  • Align the notified-body story with your CE marking narrative; avoid a parallel opaque file.
  • Industrialise continuous traceability (requirements, tests, releases, monitoring) through your eQMS and, where useful, Qapsule.

For market and dossier framing, see QARA PULSE regulatory strategy and CE marking.

FAQ

Does the AI Act replace the MDR for SaMD?

No. The AI Act adds to MDR/IVDR duties. For Annex I products that require third-party assessment, high-risk AI Act requirements must be connected to the same technical file and QMS already expected under MDR/IVDR.

When do Article 6(1) high-risk obligations apply?

Under Article 113 of the AI Act, Article 6(1) and the corresponding obligations apply from 2 August 2027. The broader application date is 2 August 2026, with earlier dates for some chapters. Always confirm the consolidated text on EUR-Lex.

Do we need a second “AI Act” quality system?

Usually not. The robust approach is to extend ISO 13485 / the existing QMS (data, human oversight, monitoring, cyber) and trace evidence in the technical documentation. A parallel binder outside process creates audit gaps.

Where should we start if the model changes often?

First stabilise intended use, data governance and change control. If you also target the United States, connect this work to a coherent PCCP (see our PCCP analysis) and an operational post-market monitoring loop.

How can QARA PULSE help?

By mapping AI Act ↔ MDR/IVDR into your QMS, preparing notified-body evidence, and industrialising traceability with eQMS deployment and Qapsule. Contact us for a focused scoping call.

QARA PULSE analysis (July 2026) based on texts published on EUR-Lex. Not personalised legal advice. Always check the consolidated regulation and your product classification with an expert.

Related: Regulatory strategy · CE marking · Qapsule · PCCP and AI software · Contact

← All resources