MedTech Companies Face a Dual Regulatory Maze: How to Navigate Both EU AI Act and Medical Device Rules
Medical device companies are caught between two regulatory regimes, and the overlap is creating confusion about how to stay compliant. The EU AI Act focuses on data governance and transparency, while the Medical Device Regulation (MDR) and In Vitro Diagnostic Regulation (IVDR) emphasize safety and performance. Rather than treating these as separate compliance burdens, industry experts now recommend integrating AI Act requirements directly into existing quality management systems to streamline the process.
Why Are Medical Device Makers Struggling With AI Regulation?
The challenge stems from the fact that each regulatory framework was designed with different priorities. The EU AI Act, which took effect in phases starting in 2024, requires companies to document how AI systems handle data, ensure human oversight, and manage risks related to fundamental rights like privacy and fairness. Meanwhile, MDR and IVDR, which govern how medical devices are approved and monitored in Europe, focus on clinical safety, performance, and post-market surveillance.
For a company developing an AI-powered diagnostic tool or a machine learning algorithm that supports clinical decision-making, this means navigating overlapping documentation requirements, risk assessment frameworks, and governance structures. Without a unified approach, organizations end up duplicating effort, creating redundant documentation, and potentially missing critical compliance gaps.
How to Integrate AI Act and Medical Device Regulations Into One System
- Unified Quality Management System: Embed AI Act obligations directly into your existing quality management system (QMS) rather than building a separate AI compliance track. This means documenting AI-specific risks alongside traditional device safety risks, managing both data governance and clinical performance in one integrated framework.
- Consolidated Technical Documentation: Create unified technical documentation that satisfies both AI Act and MDR/IVDR expectations. This includes documenting data sources, model training processes, lifecycle controls, and how the system handles edge cases or unexpected inputs, all within a single technical file.
- Overlapping Risk Management: Identify and address the intersection of safety risks and fundamental-rights risks in one risk management process. For example, if your AI system could produce biased diagnostic recommendations, that's both a safety issue (incorrect diagnosis) and a fairness issue (potential discrimination), requiring coordinated mitigation strategies.
- Data Governance and Access Controls: Establish data governance practices that meet both frameworks' requirements for data quality, traceability, and access. The AI Act demands transparency about training data; MDR/IVDR requires documentation of how data supports clinical claims. A unified data governance approach addresses both.
- Human Oversight and Governance Roles: Define clear roles for human oversight of AI systems, including who reviews model outputs, who approves changes, and how the organization monitors for performance drift or safety issues over time.
The most effective solution is to recognize that these regulations are complementary, not contradictory. Both require rigorous documentation, risk management, and human oversight. By aligning them from the start, companies can avoid the trap of building parallel compliance systems and instead create a single, comprehensive framework that satisfies both regulators.
What Do Regulators Actually Expect From AI-Powered Medical Devices?
The FDA, which regulates medical devices in the United States, takes a different approach than the EU. While the FDA focuses primarily on clinical safety and performance, the EU AI Act adds a layer of requirements around data transparency, model explainability, and protection of fundamental rights. Understanding these differences is critical for companies that sell devices in multiple markets.
In Europe, manufacturers must now demonstrate not only that their AI system works safely and effectively, but also that they have controls in place to prevent misuse, that they can explain how the system makes decisions, and that they have processes to monitor and report on the system's performance after it reaches the market. This includes maintaining detailed logs of how the AI system processes data and making those logs available to regulators upon request.
For regulatory affairs and quality assurance professionals, this means developing new competencies around AI literacy. Understanding how machine learning models work, what data governance means in practice, and how to document AI-specific risks is no longer optional. Similarly, data scientists and software engineers working on medical devices need to understand the regulatory landscape and how their technical decisions affect compliance.
"Dr. Bassil Akra, CEO of AKRA TEAM, has been instrumental in shaping the Medical Device Regulation and In Vitro Diagnostic Regulation, and he continues to advise organizations on navigating the intersection of AI governance and device regulation," noted his extensive background in bridging the language between legislators, notified bodies, and industry stakeholders.
Dr. Bassil Akra, CEO, AKRA TEAM
Dr. Akra's work with the Medical Device Coordination Group and his involvement in evaluating the impact of proposed regulatory changes on the healthcare system underscore how dynamic this landscape has become. Companies that wait for final guidance risk falling behind; those that begin integrating AI Act requirements into their quality systems now will have a competitive advantage when regulators begin enforcement.
Why This Matters for Your Organization
If your company develops, manufactures, or distributes medical devices that incorporate AI or machine learning, the time to act is now. Waiting until regulators issue enforcement guidance could mean costly rework, delayed product launches, or even market withdrawal. The organizations that succeed will be those that view AI regulation not as a compliance burden, but as an opportunity to build trust with regulators, healthcare providers, and patients.
The key takeaway is simple: don't build two separate compliance systems. Instead, unify your approach by embedding AI Act requirements into your existing MDR/IVDR quality systems. This reduces duplication, strengthens your overall compliance posture, and positions your organization to adapt quickly as regulations evolve.