← Back to list

SaMD and the EU AI Act: Two Regulatory Systems, One Product

AI-enabled medical devices are now subject to both EU MDR/IVDR and the EU AI Act. The interaction between the two frameworks creates…

Ashish Yadav · 2026-04-08 23:05 · 2 claps · 7.0 min read
#eu-ai-act #amd #eu-mdr #eu-ivdr #digital-health
Open on Medium ↗
Wiki topics: DH · Digital Health & Health Tech

SaMD and the EU AI Act: Two Regulatory Systems, One Product

AI-enabled medical devices are now subject to both EU MDR/IVDR and the EU AI Act. The interaction between the two frameworks creates classification and conformity assessment complexity that most digital health teams have not yet mapped.

There is a regulatory reality facing AI-enabled medical device developers in Europe that is more complex than either framework’s documentation individually suggests, and that has not yet been fully absorbed by most digital health regulatory teams.

EU MDR and IVDR created a substantially more demanding conformity assessment pathway for medical devices and in vitro diagnostics than the directives they replaced. The EU AI Act, which entered into force in August 2024 and is now in phased application, created an additional overlay for AI systems across all sectors — including medical devices. For a product that is an AI-enabled medical device or diagnostic — Software as a Medical Device under MDR, or an AI-enabled IVD under IVDR — both regulatory frameworks apply simultaneously. The product must satisfy MDR or IVDR. It must also satisfy the EU AI Act. And the interaction between them creates complexity that is not resolved simply by reading both frameworks side by side.

The Classification Problem

The EU AI Act classifies AI systems by risk level: unacceptable risk (prohibited), high risk, limited risk, and minimal risk. Medical devices are addressed explicitly in Annex III of the Act, which defines a set of AI system categories that are automatically classified as high risk. AI systems intended to be used as safety components of medical devices, or AI systems that are themselves medical devices, fall within the high-risk category if they are required to undergo third-party conformity assessment under the applicable medical device regulation.

This means that for most Class IIb and Class III medical devices under MDR, and for most Class C and Class D IVDs under IVDR — which require notified body involvement in conformity assessment — the AI systems embedded in those products are automatically high-risk under the EU AI Act. The MDR/IVDR classification effectively determines the AI Act classification. That linkage is not always visible in how digital health teams are approaching EU AI Act compliance, because the MDR/IVDR and AI Act workstreams are often running separately within the same organization.

The practical consequence of high-risk classification under the EU AI Act is a specific set of requirements: technical documentation, risk management, data governance, transparency measures, accuracy standards, human oversight provisions, and post-market monitoring. These requirements overlap substantially with what MDR and IVDR already require — but they are not identical, and the overlap does not mean they are equivalent. An organization that has satisfied MDR technical documentation requirements has not automatically satisfied EU AI Act technical documentation requirements, even though both cover aspects of the same product.

Where the Frameworks Align and Where They Do Not

There are areas of genuine alignment between MDR/IVDR and the EU AI Act that can be exploited in compliance strategy. Both require risk management systems. Both require technical documentation that is maintained and updated throughout the product lifecycle. Both require post-market surveillance and, for the highest-risk products, real-world performance data. Both impose transparency obligations, though the specific form differs. For organizations that are already running mature MDR or IVDR compliance programs, these aligned requirements are not new obligations — they are existing obligations that need to be documented to satisfy an additional regulatory audience.

The areas of divergence are more operationally demanding. The EU AI Act introduces requirements around training data governance that MDR and IVDR do not address with the same specificity. High-risk AI systems must be developed using training, validation, and testing datasets that meet specific quality standards, are relevant, representative, sufficiently complete, and free from errors and biases. That is a data governance standard that applies to the AI development process itself — which means it applies retrospectively to training data decisions that may have been made years before the AI Act entered into force. Organizations whose AI systems are already on the market under MDR or IVDR need to assess whether their historical data governance practices would satisfy the AI Act standard, and whether the documentation of those practices is sufficient for the conformity assessment that the Act requires.

The human oversight requirements under the EU AI Act are also more specific than what MDR and IVDR require in the abstract. High-risk AI systems must be designed so that natural persons can understand the system’s output, monitor its functioning, and intervene or override it. The oversight requirement is a design requirement, not just a process requirement — which means it has implications for how the AI system presents its outputs, what information it provides to users, and whether the user interface allows meaningful human intervention. These are product design decisions that need to be resolved before the conformity assessment, not after it.

The Conformity Assessment Interaction

One of the most practically significant questions for AI-enabled medical device developers is whether the EU AI Act conformity assessment can be coordinated with the MDR or IVDR conformity assessment, and if so, how.

The EU AI Act establishes a specific coordination mechanism for medical devices: where an AI system is also a medical device and is already subject to conformity assessment by a notified body under MDR or IVDR, the notified body conducting the medical device conformity assessment can also conduct the AI Act conformity assessment. This is not automatic — the notified body must be designated under the AI Act as well as under MDR or IVDR — but it creates the possibility of a coordinated process that avoids duplication.

In practice, the notified body landscape for AI Act designation is still developing. As of mid-2025, the designation process for notified bodies under the EU AI Act was underway but not complete, and the practical availability of notified bodies who can conduct coordinated conformity assessment under both frameworks was limited. Organizations planning conformity assessment timelines need to account for the availability of appropriately designated notified bodies and the fact that coordinated assessment, where available, still requires demonstrating compliance with both frameworks’ distinct requirements.

What I have seen in practice is that digital health teams are often planning their EU AI Act compliance as if it is a self-assessment exercise — on the assumption that the coordinated pathway with the notified body is not available or is too early to plan around. That assumption may be reasonable in the short term, but it risks creating a compliance posture that was designed for self-assessment and needs to be rebuilt for notified body review when coordinated assessment becomes more broadly available. Building for notified body review from the beginning — even if self-assessment is the current pathway — produces a more defensible technical file and a shorter transition when coordinated assessment becomes available.

The Post-Market Surveillance Gap

Both MDR/IVDR and the EU AI Act require post-market surveillance for AI-enabled medical devices, but the specific requirements differ in ways that create a practical design challenge.

MDR and IVDR post-market surveillance requirements focus on clinical performance data, vigilance reporting, periodic safety update reports, and trend reporting. The PMPF (Post-Market Performance Follow-up) requirements under IVDR, in particular, require ongoing collection of post-market clinical performance data that demonstrates sustained compliance with the general safety and performance requirements.

The EU AI Act adds post-market monitoring requirements that are specifically oriented toward AI system performance: monitoring for bias, accuracy drift, unexpected behavior, and the performance of the AI system in real-world conditions that may differ from the training and validation environment. These monitoring requirements are about the AI model’s behavior over time, not just the device’s clinical performance — which means they require different monitoring infrastructure, different data sources, and different analytical approaches than PMPF typically encompasses.

Organizations that are designing their post-market surveillance programs now need to build surveillance that satisfies both frameworks simultaneously. That means clinical performance data collection for MDR/IVDR, and AI performance monitoring for the EU AI Act, integrated into a single post-market program with clear ownership, defined monitoring parameters, and documented escalation criteria for each category of surveillance data.

The programs I have seen that are furthest ahead on this challenge are the ones that designed the post-market surveillance architecture before the product was deployed — not as a documentation exercise, but as an operational design choice. The monitoring infrastructure, the data collection mechanisms, the alert thresholds, and the review processes were designed as part of the product program. The organizations that are designing these elements after deployment are facing a harder problem because the data architecture that post-market monitoring requires was not built into the product from the beginning.

What Regulatory Teams Need to Do Now

The practical implication of the dual-framework reality for digital health regulatory teams is a set of specific near-term decisions that cannot be deferred without accumulating compliance risk.

The first is to conduct the classification analysis under both frameworks, explicitly. If you have an AI-enabled SaMD or AI-enabled IVD, the EU AI Act classification needs to be determined — and documented — based on the MDR or IVDR classification and the conformity assessment requirements that apply. That analysis needs to be part of the regulatory strategy document, not assumed.

The second is to map the technical documentation requirements under both frameworks and identify where they overlap and where they diverge. The gaps between MDR/IVDR technical file requirements and EU AI Act technical documentation requirements are where the additional compliance work is concentrated. Knowing where those gaps are before the conformity assessment preparation begins is substantially more efficient than discovering them during it.

The third is to include data governance as a regulatory strategy item. The EU AI Act’s training data requirements are not a technical afterthought — they are a conformity assessment requirement. If the AI system’s training data governance was not designed to satisfy a regulatory standard, that gap needs to be assessed and addressed. This is particularly important for AI systems that were developed before the EU AI Act entered into force and are now being assessed for compliance.

The fourth is to design the post-market surveillance program to satisfy both frameworks simultaneously, from the beginning. The cost of designing integrated surveillance before deployment is substantially lower than the cost of redesigning surveillance infrastructure after the product is on the market.

The dual-framework reality is not going away. For AI-enabled medical devices in Europe, MDR or IVDR and the EU AI Act are both part of the regulatory environment — not sequentially but simultaneously. The organizations that are navigating this well are the ones that have mapped the interaction explicitly and built their compliance strategy around both frameworks from the beginning. The organizations that are managing each framework separately will find that the complexity is not additive. It is multiplicative.

Ashish Yadav is the founder of PrecisionPulse Consulting, advising life sciences organizations on AI governance, regulatory strategy, and AI-enabled clinical program design.


메타데이터
post_id
97d2ad91a0e5
slug
samd-and-the-eu-ai-act-two-regulatory-systems-one-product-97d2ad91a0e5
url
https://medium.com/@yadav_ashish/samd-and-the-eu-ai-act-two-regulatory-systems-one-product-97d2ad91a0e5
canonical_url
https://medium.com/@yadav_ashish/samd-and-the-eu-ai-act-two-regulatory-systems-one-product-97d2ad91a0e5
author_url
https://medium.com/@yadav_ashish
status
ok
fetched_at
2026-06-09 15:37:30