← Back to list

AI in Medical Devices: What MDR & IVDR Cover and What the EU AI Act Adds

A manufacturer submitting an AI-based medical device for CE marking today faces a critical challenge: understanding which regulations…

Nisha Patil (medical device Expert ) · 2026-04-22 06:11 · 3 claps · 6.3 min read
#ai-in-medical-diagnosis #ai-in-medical #ai-in-medical-research
Open on Medium ↗
Wiki topics: AI · AI · General CLI · Clinical Medicine

AI in Medical Devices: What MDR & IVDR Cover and What the EU AI Act Adds

A manufacturer submitting an AI-based medical device for CE marking today faces a critical challenge: understanding which regulations apply, how the Medical Device Regulation (MDR), In Vitro Diagnostic Regulation (IVDR), and the EU AI Act interact, and where compliance gaps could delay or derail approval. Understanding where each framework begins and where it stops is critical if you want faster approvals and fewer regulatory objections.

Where MDR and IVDR Already Apply to AI ?

The Medical Device Regulation (MDR) and In Vitro Diagnostic Regulation (IVDR) were never written specifically for AI. Yet, they already regulate most AI-based medical technologies because they focus on intended use, risk, and clinical impact not technology type.

1. AI as Software (SaMD) is Already Regulated

If your AI performs a medical function diagnosis, prediction, or monitoring it is classified as Software as a Medical Device (SaMD) under the Medical Device Regulation (MDR) or the In Vitro Diagnostic Regulation (IVDR).

However, classification is not generic it is specifically governed by Rule 11 under MDR, which is the most important rule for AI-based software.

How Rule 11 Applies to AI

Under Rule 11:

  • Software providing information used for diagnostic or therapeutic decisions is typically classified as Class IIa or higher
  • If decisions may cause serious deterioration or surgical intervention, it can be Class IIb
  • If decisions may result in death or irreversible deterioration, it is Class III

In practice, this means most AI-based medical software is not Class I, even if manufacturers initially assume low risk.

Role of MDCG 2019–11

The MDCG 2019–11 provides detailed guidance on:

  • Qualification of software as a medical device
  • Interpretation of Rule 11
  • Classification examples for different software types

Notified Bodies heavily rely on this guidance when reviewing AI-based devices.

2. Clinical Evidence is Still Mandatory

AI tools often rely on retrospective datasets, but under the Medical Device Regulation (MDR) and In Vitro Diagnostic Regulation (IVDR), that alone is not sufficient.

You must show:

  • Clinical validity in real-world or clinically representative populations
  • Performance consistency across independent and diverse datasets
  • Clear justification of training, validation, and test data

What Datasets Are Acceptable?

Regulators expect datasets that are:

  • Clinically relevant → reflect actual intended use (target population, setting)
  • Representative → include variability (age, gender, disease stage, geography where applicable)
  • Independent → separate training and validation datasets to avoid bias
  • High-quality and traceable → well-documented source, labeling, and preprocessing

In many cases, prospective clinical data or real-world performance data is required to support claims.

3. Lifecycle Control is Strict (and Difficult for AI)

Traditional devices are static. AI systems are not. Under the Medical Device Regulation (MDR) and In Vitro Diagnostic Regulation (IVDR), regulators expect controlled, predictable software behavior throughout the lifecycle.

What Are the Regulatory Expectations?

Manufacturers are expected to:

  • Lock the algorithm version at the time of CE marking (no uncontrolled changes)
  • Manage updates through a formal change control process within the QMS
  • Assess whether changes are significant and require re-certification
  • Define intended performance and operating limits clearly
  • Implement post-market surveillance (PMS) to monitor real-world performance
  • Maintain traceability and documentation of all changes

Guidance such as MDCG 2020–3 is commonly used to determine whether a software update triggers regulatory impact.

4. Transparency and Documentation

Manufacturers must provide:

  • Clear intended use
  • Algorithm description (to a reasonable level)
  • Risk management (ISO 14971 alignment)
  • Usability and human factors validation

However, MDR does not deeply define algorithm transparency requirements this is where gaps begin.

The Regulatory Gap: What MDR and IVDR Do NOT Fully Cover

Even though the Medical Device Regulation (MDR) and In Vitro Diagnostic Regulation (IVDR) regulate AI-based devices, they do not fully address several AI-specific risks that directly impact regulatory submissions.

Bias in Training Datasets

MDR/IVDR require clinical performance, but they do not explicitly define how to assess or mitigate bias in training data. In practice, this means a model may perform well overall but fail in specific sub-populations leading to regulatory objections during clinical evaluation.

Continuous Learning Systems

The frameworks assume a static, version-controlled device, not one that evolves over time. As a result, continuously learning AI systems are difficult to justify, because any performance change must be validated and documented before approval.

Explainability of AI Decisions

MDR requires safety and performance, but it does not clearly define how transparent or explainable an algorithm must be. This creates challenges when manufacturers must justify clinical decisions, especially for black-box models, during Notified Body review.

Data Governance and Quality Standards

While clinical evidence is required, MDR/IVDR do not provide detailed expectations for dataset quality, representativeness, and lifecycle management. This often leads to inconsistent data documentation, which is a common reason for regulatory queries.

AI-Specific Cybersecurity Considerations

Cybersecurity is already addressed under MDCG 2019–16, including requirements for risk management, secure design, and incident response.

However, the gap lies in AI-specific cybersecurity risks, such as:

  • Vulnerability to data poisoning or adversarial attacks
  • Risks from model manipulation or drift over time
  • Lack of clear guidance on securing training and validation pipelines

These AI-specific threats are not explicitly covered under MDR/IVDR, creating uncertainty during risk assessment.

What the EU AI Act Adds on Top ?

The EU AI Act does not replace MDR or IVDR it sits on top of them and introduces horizontal AI-specific requirements.

1. Risk-Based Classification for AI Systems

Under the EU AI Act, AI systems are classified into four categories:

  • Unacceptable risk (prohibited)
  • High-risk
  • Limited risk
  • Minimal risk

When Is AI in Medical Devices Considered High-Risk?

According to Annex III, AI systems are classified as high-risk if they are:

  • Intended to be used as a safety component of a medical device, or
  • Themselves qualify as a medical device under MDR/IVDR and require third-party conformity assessment

This means many AI-based medical devices fall into the high-risk category but not all AI used in healthcare does.

2. Data Governance Requirements

This is one of the biggest changes.

Manufacturers must ensure:

  • Training datasets are relevant, representative, and free from bias
  • Data quality is documented and controlled
  • Data gaps and limitations are clearly addressed

This goes far beyond MDR expectations.

3. Transparency and Explainability

Unlike MDR, the AI Act requires:

  • Clear information on how the AI system works
  • Instructions for use explaining system limitations
  • Human-understandable outputs where possible

This is especially important for clinical decision support tools.

4. Human Oversight

AI cannot operate in a completely autonomous way in high-risk scenarios.

You must define:

  • Human control mechanisms
  • Override capabilities
  • Responsibilities of healthcare professionals

5. Continuous Monitoring and Logging

The AI Act introduces stricter expectations for:

  • Automatic logging of system behavior
  • Traceability of outputs
  • Monitoring for performance drift

This directly addresses the dynamic nature of AI, which MDR struggles with.

How MDR, IVDR and the AI Act Work Together ?

Think of it as a layered system:

  • MDR / IVDR → Safety, performance, clinical evidence, CE marking
  • EU AI Act → Data quality, transparency, algorithm accountability

You do not choose one over the other you must comply with both simultaneously.

Key Compliance Challenges for Manufacturers

From practical regulatory experience, most companies struggle with:

1. Aligning Clinical Evidence with AI Performance

Traditional clinical studies do not always reflect how AI behaves in real-world environments.

2. Managing Algorithm Updates

Even small changes in models may trigger regulatory impact under MDR.

3. Data Quality Documentation

Many companies underestimate how deeply regulators now assess datasets.

4. Dual Compliance Burden

Meeting MDR/IVDR and AI Act requirements together increases:

  • Documentation workload
  • Audit complexity
  • Time to market

What This Means for Your Regulatory Strategy ?

If you are developing AI-based medical devices, your approach must shift:

  • Treat data as a regulated component, not just input
  • Build regulatory strategy during development, not after
  • Plan for controlled updates, not continuous learning without oversight
  • Integrate AI governance into your quality management system (QMS)

How Can Operon Strategist Help?

End-to-End Regulatory Support for AI Medical Devices. ***Operon Strategist*** helps manufacturers navigate MDR, IVDR, and EU AI Act compliance in an integrated way, reducing delays and regulatory risks.

  • AI-based device classification and regulatory pathway strategy
  • Clinical evaluation & performance study planning for AI systems
  • Technical documentation aligned with MDR/IVDR + AI Act requirements
  • Data governance and risk management framework setup
  • Support for CE marking and Notified Body interactions

With a combined regulatory and technical approach, Operon Strategist ensures your AI medical device is not just compliant but approval-ready.

FAQs

1. Does MDR already cover AI in medical devices? Yes. Under the Medical Device Regulation (MDR), AI-based software is regulated as a medical device if it has a clinical purpose. However, MDR focuses on safety and performance not AI-specific risks like bias or transparency.

2. What is the role of IVDR in AI-based diagnostics? The In Vitro Diagnostic Regulation (IVDR) applies to AI tools used in laboratory diagnostics, such as predictive algorithms or data interpretation software. It requires performance evaluation and scientific validity.

3. Why was the EU AI Act introduced if MDR and IVDR already exist? The EU AI Act was introduced to address gaps not covered by MDR/IVDR, such as data quality, algorithm transparency, bias, and continuous monitoring of AI systems.

4. Are all AI medical devices considered high-risk under the AI Act? Most AI medical devices fall under the high-risk category because they directly impact patient care and clinical decisions. This means stricter compliance requirements.

5. Do manufacturers need to comply with both MDR/IVDR and the AI Act? Yes. These frameworks work together. MDR/IVDR focus on device safety and clinical performance, while the AI Act focuses on trustworthy AI and data governance.


메타데이터
post_id
81279e89227f
slug
ai-in-medical-devices-what-mdr-ivdr-cover-and-what-the-eu-ai-act-adds-81279e89227f
url
https://medium.com/@nish21958/ai-in-medical-devices-what-mdr-ivdr-cover-and-what-the-eu-ai-act-adds-81279e89227f
canonical_url
https://medium.com/@nish21958/ai-in-medical-devices-what-mdr-ivdr-cover-and-what-the-eu-ai-act-adds-81279e89227f
author_url
https://medium.com/@nish21958
status
ok
fetched_at
2026-08-06 20:41:47