AI in Medical Devices: What MDR & IVDR Cover and What the EU AI Act Adds
A manufacturer submitting an AI-based medical device for CE marking today faces a critical challenge: understanding which regulations…
AI in Medical Devices: What MDR & IVDR Cover and What the EU AI Act Adds

A manufacturer submitting an AI-based medical device for CE marking today faces a critical challenge: understanding which regulations apply, how the Medical Device Regulation (MDR), In Vitro Diagnostic Regulation (IVDR), and the EU AI Act interact, and where compliance gaps could delay or derail approval. Understanding where each framework begins and where it stops is critical if you want faster approvals and fewer regulatory objections.
Where MDR and IVDR Already Apply to AI ?
The Medical Device Regulation (MDR) and In Vitro Diagnostic Regulation (IVDR) were never written specifically for AI. Yet, they already regulate most AI-based medical technologies because they focus on intended use, risk, and clinical impact not technology type.
1. AI as Software (SaMD) is Already Regulated
If your AI performs a medical function diagnosis, prediction, or monitoring it is classified as Software as a Medical Device (SaMD) under the Medical Device Regulation (MDR) or the In Vitro Diagnostic Regulation (IVDR).
However, classification is not generic it is specifically governed by Rule 11 under MDR, which is the most important rule for AI-based software.
How Rule 11 Applies to AI
Under Rule 11:
- Software providing information used for diagnostic or therapeutic decisions is typically classified as Class IIa or higher
- If decisions may cause serious deterioration or surgical intervention, it can be Class IIb
- If decisions may result in death or irreversible deterioration, it is Class III
In practice, this means most AI-based medical software is not Class I, even if manufacturers initially assume low risk.
Role of MDCG 2019–11
The MDCG 2019–11 provides detailed guidance on:
- Qualification of software as a medical device
- Interpretation of Rule 11
- Classification examples for different software types
Notified Bodies heavily rely on this guidance when reviewing AI-based devices.
2. Clinical Evidence is Still Mandatory
AI tools often rely on retrospective datasets, but under the Medical Device Regulation (MDR) and In Vitro Diagnostic Regulation (IVDR), that alone is not sufficient.
You must show:
- Clinical validity in real-world or clinically representative populations
- Performance consistency across independent and diverse datasets
- Clear justification of training, validation, and test data
What Datasets Are Acceptable?
Regulators expect datasets that are:
- Clinically relevant → reflect actual intended use (target population, setting)
- Representative → include variability (age, gender, disease stage, geography where applicable)
- Independent → separate training and validation datasets to avoid bias
- High-quality and traceable → well-documented source, labeling, and preprocessing
In many cases, prospective clinical data or real-world performance data is required to support claims.
3. Lifecycle Control is Strict (and Difficult for AI)
Traditional devices are static. AI systems are not. Under the Medical Device Regulation (MDR) and In Vitro Diagnostic Regulation (IVDR), regulators expect controlled, predictable software behavior throughout the lifecycle.
What Are the Regulatory Expectations?
Manufacturers are expected to:
- Lock the algorithm version at the time of CE marking (no uncontrolled changes)
- Manage updates through a formal change control process within the QMS
- Assess whether changes are significant and require re-certification
- Define intended performance and operating limits clearly
- Implement post-market surveillance (PMS) to monitor real-world performance
- Maintain traceability and documentation of all changes
Guidance such as MDCG 2020–3 is commonly used to determine whether a software update triggers regulatory impact.
4. Transparency and Documentation
Manufacturers must provide:
- Clear intended use
- Algorithm description (to a reasonable level)
- Risk management (ISO 14971 alignment)
- Usability and human factors validation
However, MDR does not deeply define algorithm transparency requirements this is where gaps begin.
The Regulatory Gap: What MDR and IVDR Do NOT Fully Cover
Even though the Medical Device Regulation (MDR) and In Vitro Diagnostic Regulation (IVDR) regulate AI-based devices, they do not fully address several AI-specific risks that directly impact regulatory submissions.
Bias in Training Datasets
MDR/IVDR require clinical performance, but they do not explicitly define how to assess or mitigate bias in training data. In practice, this means a model may perform well overall but fail in specific sub-populations leading to regulatory objections during clinical evaluation.
Continuous Learning Systems
The frameworks assume a static, version-controlled device, not one that evolves over time. As a result, continuously learning AI systems are difficult to justify, because any performance change must be validated and documented before approval.
Explainability of AI Decisions
MDR requires safety and performance, but it does not clearly define how transparent or explainable an algorithm must be. This creates challenges when manufacturers must justify clinical decisions, especially for black-box models, during Notified Body review.
Data Governance and Quality Standards
While clinical evidence is required, MDR/IVDR do not provide detailed expectations for dataset quality, representativeness, and lifecycle management. This often leads to inconsistent data documentation, which is a common reason for regulatory queries.
AI-Specific Cybersecurity Considerations
Cybersecurity is already addressed under MDCG 2019–16, including requirements for risk management, secure design, and incident response.
However, the gap lies in AI-specific cybersecurity risks, such as:
- Vulnerability to data poisoning or adversarial attacks
- Risks from model manipulation or drift over time
- Lack of clear guidance on securing training and validation pipelines
These AI-specific threats are not explicitly covered under MDR/IVDR, creating uncertainty during risk assessment.
What the EU AI Act Adds on Top ?
The EU AI Act does not replace MDR or IVDR it sits on top of them and introduces horizontal AI-specific requirements.
1. Risk-Based Classification for AI Systems
Under the EU AI Act, AI systems are classified into four categories:
- Unacceptable risk (prohibited)
- High-risk
- Limited risk
- Minimal risk
When Is AI in Medical Devices Considered High-Risk?
According to Annex III, AI systems are classified as high-risk if they are:
- Intended to be used as a safety component of a medical device, or
- Themselves qualify as a medical device under MDR/IVDR and require third-party conformity assessment
This means many AI-based medical devices fall into the high-risk category but not all AI used in healthcare does.
2. Data Governance Requirements
This is one of the biggest changes.
Manufacturers must ensure:
- Training datasets are relevant, representative, and free from bias
- Data quality is documented and controlled
- Data gaps and limitations are clearly addressed
This goes far beyond MDR expectations.
3. Transparency and Explainability
Unlike MDR, the AI Act requires:
- Clear information on how the AI system works
- Instructions for use explaining system limitations
- Human-understandable outputs where possible
This is especially important for clinical decision support tools.
4. Human Oversight
AI cannot operate in a completely autonomous way in high-risk scenarios.
You must define:
- Human control mechanisms
- Override capabilities
- Responsibilities of healthcare professionals
5. Continuous Monitoring and Logging
The AI Act introduces stricter expectations for:
- Automatic logging of system behavior
- Traceability of outputs
- Monitoring for performance drift
This directly addresses the dynamic nature of AI, which MDR struggles with.
How MDR, IVDR and the AI Act Work Together ?
Think of it as a layered system:
- MDR / IVDR → Safety, performance, clinical evidence, CE marking
- EU AI Act → Data quality, transparency, algorithm accountability
You do not choose one over the other you must comply with both simultaneously.
Key Compliance Challenges for Manufacturers
From practical regulatory experience, most companies struggle with:
1. Aligning Clinical Evidence with AI Performance
Traditional clinical studies do not always reflect how AI behaves in real-world environments.
2. Managing Algorithm Updates
Even small changes in models may trigger regulatory impact under MDR.
3. Data Quality Documentation
Many companies underestimate how deeply regulators now assess datasets.
4. Dual Compliance Burden
Meeting MDR/IVDR and AI Act requirements together increases:
- Documentation workload
- Audit complexity
- Time to market
What This Means for Your Regulatory Strategy ?
If you are developing AI-based medical devices, your approach must shift:
- Treat data as a regulated component, not just input
- Build regulatory strategy during development, not after
- Plan for controlled updates, not continuous learning without oversight
- Integrate AI governance into your quality management system (QMS)
How Can Operon Strategist Help?
End-to-End Regulatory Support for AI Medical Devices. ***Operon Strategist*** helps manufacturers navigate MDR, IVDR, and EU AI Act compliance in an integrated way, reducing delays and regulatory risks.
- AI-based device classification and regulatory pathway strategy
- Clinical evaluation & performance study planning for AI systems
- Technical documentation aligned with MDR/IVDR + AI Act requirements
- Data governance and risk management framework setup
- Support for CE marking and Notified Body interactions
With a combined regulatory and technical approach, Operon Strategist ensures your AI medical device is not just compliant but approval-ready.
FAQs
1. Does MDR already cover AI in medical devices? Yes. Under the Medical Device Regulation (MDR), AI-based software is regulated as a medical device if it has a clinical purpose. However, MDR focuses on safety and performance not AI-specific risks like bias or transparency.
2. What is the role of IVDR in AI-based diagnostics? The In Vitro Diagnostic Regulation (IVDR) applies to AI tools used in laboratory diagnostics, such as predictive algorithms or data interpretation software. It requires performance evaluation and scientific validity.
3. Why was the EU AI Act introduced if MDR and IVDR already exist? The EU AI Act was introduced to address gaps not covered by MDR/IVDR, such as data quality, algorithm transparency, bias, and continuous monitoring of AI systems.
4. Are all AI medical devices considered high-risk under the AI Act? Most AI medical devices fall under the high-risk category because they directly impact patient care and clinical decisions. This means stricter compliance requirements.
5. Do manufacturers need to comply with both MDR/IVDR and the AI Act? Yes. These frameworks work together. MDR/IVDR focus on device safety and clinical performance, while the AI Act focuses on trustworthy AI and data governance.
메타데이터
- post_id
- 81279e89227f
- slug
- ai-in-medical-devices-what-mdr-ivdr-cover-and-what-the-eu-ai-act-adds-81279e89227f
- url
- https://medium.com/@nish21958/ai-in-medical-devices-what-mdr-ivdr-cover-and-what-the-eu-ai-act-adds-81279e89227f
- canonical_url
- https://medium.com/@nish21958/ai-in-medical-devices-what-mdr-ivdr-cover-and-what-the-eu-ai-act-adds-81279e89227f
- author_url
- https://medium.com/@nish21958
- status
- ok
- fetched_at
- 2026-08-06 20:41:47