In brief
In July 2026, the AI Omnibus postponed to August 2028 the main obligations for high-risk AI systems (Art. 6(1)), while EN 18286:2026 clarifies the QMS expected under Article 17 of the AI Act. Fold these requirements into the existing MDR/IVDR infrastructure, rather than building a parallel AI Act QMS.
In July 2026, the AI Act roadmap for MedTech changed
Two developments reshaped the picture for manufacturers of medical devices that integrate artificial intelligence.
The Digital Omnibus on AI (Regulation (EU) 2026/1744), applicable from 27 July 2026, postponed to 2 August 2028 the main obligations for high-risk AI systems under Article 6(1), which can cover certain medical devices and IVDs.
At the same time, EN 18286:2026 (Artificial intelligence – Quality management system for EU AI Act regulatory purposes) was published. It provides a concrete frame for the quality management system required by Article 17 of the AI Act.
Is your device really a high-risk AI system?
Not every medical device that uses AI is automatically high-risk under the AI Act. For the Article 6(1) route, the AI system must itself be a product covered by Annex I legislation or a safety component of that product, and the product must undergo third-party conformity assessment. The MDR and IVDR are listed in that annex.
The Omnibus also tightened the notion of a safety component. Merely embedding AI in a device is not enough. The safety function must be part of the system’s intended purpose and aim to prevent or reduce risks to health or safety. Functions limited to assistance, performance optimisation, efficiency or automation alone do not characterise that function.
Before any gap analysis, check the chain: AI system → role in the device → MDR/IVDR classification → conformity path → high-risk qualification.
AI Omnibus: what actually changes for manufacturers
For high-risk systems linked to Annex I products under Article 6(1), the deadline moves from 2 August 2027 to 2 August 2028. The extra year brings application closer to the real availability of supporting standards and EU implementation tools. But 2028 is not a new starting line: risk management, data, documentation, logging, human oversight, robustness, cybersecurity and the quality system remain at the core of the regime.
The Omnibus also introduces a useful mechanism for sectors that are already heavily regulated. For Article 6(1) systems, some AI Act obligations may be limited where Annex I sectoral law already ensures an equivalent or higher level of protection. The Commission must define those situations through delegated acts. For medical devices, the signal is clear: the legislator wants to reduce duplication between the AI Act and product rules. That does not mean MDR automatically covers the AI Act today. It means you need a precise map of overlaps and gaps, not a second compliance system.
EN 18286: the AI Act quality system becomes concrete
EN 18286:2026 sets requirements and guidance to establish, implement and maintain a quality management system for organisations providing AI systems. It mainly targets providers of high-risk systems and supports Article 17 of the AI Act.
For an organisation already built around ISO 13485, this does not mean replacing the medical QMS. Article 17 allows providers already subject to sectoral quality-system duties to integrate AI Act elements into that existing system. The logic becomes: ISO 13485 as the base → AI Act requirements identified → EN 18286 as the frame to organise the additions.
One regulatory nuance remains essential. EN 18286 is published (availability 22 July 2026), but its citation in the Official Journal of the EU is still indicated as pending. Presumption of conformity attaches to the OJEU reference of a harmonised standard. In other words: EN 18286 is usable now, but you should not yet claim presumption of conformity on that basis.
One QMS: where to embed AI Act requirements
Manufacturers already run risk management, design control, change control, validation, PMS, document control and CAPA. That is where AI-specific controls belong.
Risk and data
Connect model, data and bias risks to product risks. Trace provenance, selection, quality and limits of training, validation and test data, then link those decisions to claimed performance.
Human oversight
Define who can understand, contest, disregard or interrupt AI output, and turn those choices into design requirements aligned with the IFU, training and post-market activities.
Change control and PMS
Assess changes to the model, datasets or environment under both MDR/IVDR and AI Act lenses. Also monitor performance shifts, bias or new behaviours that may affect benefit-risk.
This is where an eQMS integrated with team tools helps: AI evidence must not stay scattered across tickets, code repos, data-science environments, test reports and the quality system.
What to do before 2028
The delay buys time to build compliance into the product, not to rebuild it later. Regulatory strategy should include AI Act qualification early enough, while the PULSE programme helps connect QMS, development and technical documentation on one compliance path. For evolving products also targeting the United States, see our article on the PCCP for AI medical software.
Action plan
- Re-validate AI Act qualification after the Omnibus changes.
- Update your roadmap with the 2 August 2028 deadline when Article 6(1) applies.
- Run a gap analysis across ISO 13485 / MDR-IVDR / AI Act / EN 18286.
- Map each requirement into an existing process before creating a new procedure.
- Prioritise hard-to-rebuild evidence: data, bias, performance, oversight and design decisions.
- Adapt change control and PMS to model and performance evolution.
- Watch EN 18286 OJEU citation and other supporting AI Act standards.
The useful test: for each AI Act requirement, can you name the QMS process that owns it and the evidence that proves it?
Conclusion
Use the next two years to fold AI Act requirements progressively into the existing ISO 13485 / MDR system, and take advantage of the Omnibus mechanism to reduce duplication once it is clarified. Neither wait until 2028, nor build a second QMS.
FAQ
When does the AI Act apply to high-risk medical devices?
For high-risk AI systems under Article 6(1) linked to Annex I regulated products, the Omnibus set the deadline at 2 August 2028.
Are all medical devices with AI high-risk?
No. You need to assess whether the AI is itself a covered product or a safety component, and whether the product requires third-party conformity assessment. The Omnibus also tightened the safety-component notion.
Does the Omnibus remove AI Act duties for medical devices?
Not automatically. It creates a mechanism to limit some obligations where Annex I sectoral law already provides equivalent or higher protection. The Commission must define the situations and the scope of those limitations.
What is EN 18286?
EN 18286:2026 is a European standard on the quality management system for AI Act regulatory purposes. It supports organisations providing AI systems, especially high-risk ones, and helps implement Article 17.
Is EN 18286 already harmonised?
It is published by CEN-CENELEC, but OJEU citation was still indicated as pending (checked 7 August 2026). It therefore does not yet carry the presumption of conformity of a cited harmonised standard.
Does EN 18286 replace ISO 13485?
No. For medical device manufacturers, ISO 13485 remains the QMS foundation. Article 17 of the AI Act allows AI Act quality requirements to be integrated into an existing sectoral system.
Should we wait until 2028 to start?
No. Data, risk analyses, design decisions, performance claims and changes are created during development. Capturing them now avoids rebuilding years of justification close to the deadline.
QARA PULSE analysis based on Regulation (EU) 2024/1689 (AI Act), Regulation (EU) 2026/1744 (Digital Omnibus on AI), EN 18286:2026, the MDR and the IVDR. Standardisation status checked on 7 August 2026. Not personalised legal advice. AI system qualification, high-risk status and applicable requirements must be assessed case by case.