MedTech Companies Face a Regulatory Puzzle: How to Navigate Both EU AI Rules and Device Safety Laws
Medical device companies are caught between two regulatory regimes, and many don't know how to align them. The EU AI Act focuses on data governance and transparency, while Medical Device Regulation (MDR) and In Vitro Diagnostic Regulation (IVDR) emphasize safety and performance. For companies building AI-powered medical devices, this creates a compliance maze with overlapping obligations that can lead to duplicated effort and documentation.
Why Are Medical Device Makers Struggling With AI Governance?
The challenge stems from the fact that each regulatory framework was designed with different priorities in mind. The EU AI Act, which took effect in phases starting in 2024, requires companies to manage data carefully and be transparent about how their AI systems work. Meanwhile, MDR and IVDR, which govern how medical devices are approved and monitored in Europe, focus on ensuring devices are safe and perform as intended. When a company develops an AI-powered diagnostic tool or treatment device, it must satisfy both sets of rules, but the frameworks don't naturally align.
Many organizations struggle because they treat these regulations as separate compliance projects rather than integrated systems. This approach leads to redundant documentation, conflicting governance structures, and wasted resources. The most effective solution, according to regulatory experts, is to embed AI Act requirements directly into existing quality management systems rather than building parallel compliance processes.
How to Integrate AI Governance Into Medical Device Compliance
- Unified Documentation: Create technical documentation that satisfies both AI Act and MDR/IVDR expectations simultaneously, including data governance, model lifecycle controls, and risk management records that serve both frameworks.
- Quality Management System Integration: Embed AI obligations into your existing quality management system (QMS) instead of creating separate AI compliance tracks, ensuring data governance, human oversight, and risk management are handled once for both regulations.
- Role and Governance Adaptation: Define new organizational roles and governance structures specifically for AI oversight, clarifying responsibilities for both the device manufacturer and end users, who also carry regulatory obligations under the AI Act.
- Data Governance Framework: Establish how you'll manage access to datasets, logs, and model artifacts to meet the AI Act's strict data requirements while maintaining the safety and performance documentation MDR/IVDR demand.
- Risk Management Alignment: Develop a unified risk management approach that addresses both safety and performance risks (MDR/IVDR focus) and fundamental rights risks (AI Act focus) in a single process.
A workshop being offered by the Regulatory Affairs Professionals Society (RAPS) Western Canada Chapter is designed to help companies navigate this exact challenge. The program, titled "AI Literacy for MedTech: Regulatory Augmented Intelligence," focuses on practical strategies for integrating the EU AI Act into MDR and IVDR compliance workflows.
What Does the FDA Approach Look Like in Comparison?
The regulatory landscape differs significantly depending on geography. While European companies must juggle the EU AI Act alongside MDR/IVDR, the FDA in the United States takes a different approach to regulating AI in medical devices. Understanding these differences is critical for companies operating across multiple markets. The RAPS workshop specifically addresses how the EU AI Act aligns with MDR and IVDR requirements and how it differs from the FDA's regulatory strategy, helping professionals understand the nuances of each system.
For regulatory affairs professionals, quality assurance teams, data scientists, and MedTech leaders involved in AI integration, the stakes are high. Non-compliance can result in delayed product approvals, market access restrictions, or enforcement actions. The good news is that companies that proactively integrate these frameworks can streamline their compliance efforts and reduce the risk of costly mistakes.
Dr. Bassil Akra, CEO of AKRA TEAM and a recognized authority in European medical device regulation, is among the experts leading this educational effort. His firm specializes in helping stakeholders develop compliant regulatory, clinical, and quality strategies in the EU, and he has been instrumental in shaping both the MDR and IVDR frameworks themselves.
"The most effective solution is to integrate AI Act requirements into existing documentation and quality systems to avoid duplication," noted Dr. Akra's work in regulatory strategy development.
Dr. Bassil Akra, CEO, AKRA TEAM
As AI becomes increasingly central to medical device innovation, companies that master this dual-framework approach will gain a competitive advantage. Those that treat AI governance as an afterthought risk falling behind in a market where regulatory compliance is not optional. The convergence of AI Act and device regulations represents a new frontier in MedTech governance, and early movers who get it right will set the standard for their industry.
" }