Logo
FrontierNews.ai

Medical Device Makers Face a New Compliance Puzzle: How to Align the EU AI Act With Existing Regulations

The EU AI Act is stacking new obligations on top of rules that medical device makers already follow, forcing companies to rethink how they document, test, and govern AI systems. Unlike traditional regulations that focus narrowly on safety or data protection, the AI Act adds transparency and trustworthiness requirements that don't always align with existing frameworks. The result is a compliance puzzle that many organizations are still learning to solve.

Why Is Aligning the EU AI Act With Medical Device Rules So Difficult?

Medical device manufacturers already operate under strict European rules: the Medical Device Regulation (MDR) and In Vitro Diagnostic Regulation (IVDR). These frameworks emphasize safety and performance. The EU AI Act, by contrast, focuses on data governance, transparency, and fundamental rights. When a company uses AI in a medical device, it must now satisfy both sets of requirements simultaneously, and they don't always speak the same language.

The challenge is that each regulation asks different questions. MDR and IVDR ask: "Is this device safe and does it perform as intended?" The AI Act asks: "Is this system transparent, trustworthy, and does it respect fundamental rights?" A company might have excellent safety documentation but lack the data governance records the AI Act demands. Conversely, strong data practices don't automatically prove the device is safe.

What Are the Key Overlapping Obligations Between These Frameworks?

Rather than treating the AI Act and MDR/IVDR as separate compliance projects, experts recommend identifying where they overlap and building unified systems that satisfy both. Several critical areas demand attention across both regimes:

  • Quality Management Systems (QMS): Both frameworks require documented processes and controls. The AI Act adds specific obligations around data governance and model management that can be embedded into existing QMS documentation.
  • Data Governance and Access: The AI Act sets strict demands for how data is collected, stored, and accessed. Medical device regulations also require data controls, so integrating these requirements avoids duplication and creates a single source of truth.
  • Human Oversight and Risk Management: Both frameworks require clear accountability and risk assessment. The AI Act emphasizes human oversight of high-risk systems, while MDR/IVDR focus on clinical risk. Unified governance structures can address both.
  • Technical Documentation: Medical devices require detailed technical files. The AI Act requires documentation of training data, model behavior, and lifecycle controls. Combining these into unified technical documentation reduces redundancy.

The most effective approach is to integrate AI Act requirements into existing documentation and quality systems rather than building parallel compliance structures. This avoids duplication, reduces the burden on teams, and creates clearer audit trails for regulators.

How to Integrate AI Act Requirements Into Existing Medical Device Quality Systems

  • Embed AI Obligations Into QMS: Rather than creating a separate AI compliance program, add AI-specific controls to your existing quality management system. This includes documenting how AI models are developed, tested, and monitored throughout their lifecycle.
  • Unify Technical Documentation: Create a single technical file that addresses both MDR/IVDR safety requirements and AI Act transparency obligations. Include data sources, model architecture, performance metrics, and controls for managing both safety and fundamental-rights risks.
  • Establish Clear Data Governance: Define how training data is collected, labeled, stored, and accessed. Document consent mechanisms and ensure compliance with both GDPR (which the AI Act builds on) and medical device data requirements.
  • Define Roles and Governance Structures: Assign clear ownership for AI governance. This includes roles for model oversight, data stewardship, and compliance monitoring. Ensure these roles satisfy both device regulation and AI Act accountability requirements.
  • Create Audit-Ready Evidence: Design controls that can be evidenced and verified. Rather than simply switching on protections, document how they work and why they meet regulatory expectations. This preparation is essential because any AI handling regulated data will eventually be audited.

Organizations that treat this as a unified challenge rather than two separate compliance projects save time and reduce the risk of gaps. The key is recognizing that both frameworks are asking similar questions about control, transparency, and accountability, even if they use different language.

What New Roles and Governance Changes Do Companies Need?

Integrating AI into medical device workflows requires organizational changes. Companies need to define new roles and governance structures that bridge the gap between technical teams and compliance functions. Data scientists and software engineers must work closely with regulatory affairs and quality assurance professionals to ensure that AI systems are built with compliance in mind from the start, not retrofitted later.

This collaboration is particularly important because the people building AI models often don't fully understand regulatory requirements, and compliance teams may lack the technical knowledge to evaluate AI systems. Creating shared governance structures, clear documentation standards, and regular communication between these groups helps prevent costly misalignments later.

How Does the EU AI Act Compare to FDA Approaches in the United States?

The EU AI Act takes a risk-based approach, placing the strictest duties on high-risk uses and imposing penalties as high as 35 million euros or 7 percent of global turnover. The FDA's approach to regulating AI in medical devices, by contrast, is less prescriptive and focuses more on safety and performance than on data governance and transparency.

For companies operating in both markets, this means understanding two different regulatory philosophies. European regulators are asking detailed questions about how AI systems work, what data they use, and how they respect fundamental rights. U.S. regulators focus more on whether the device is safe and effective. Both approaches are valid, but they require different documentation and governance strategies.

The broader pattern is clear: AI-specific rules are arriving on top of existing regulations across multiple sectors and jurisdictions. Regulators are watching closely, particularly in high-stakes industries like healthcare where breaches carry enormous costs. The average healthcare data breach costs 7.42 million dollars, the highest of any industry for the fourteenth consecutive year, according to IBM's 2025 Cost of a Data Breach Report. That financial pressure, combined with regulatory fines, means compliance is not optional.

For medical device makers, the time to act is now. Building AI systems with compliance in mind from the start, integrating AI Act requirements into existing quality systems, and establishing clear governance structures will make the transition smoother and reduce the risk of costly compliance failures down the road.