Where the EU MDR and the AI Act Overlap for Medical Device Software
10 min read · updated August 11, 2026
A piece of AI-based medical device software in the European Union is regulated twice: once as a medical device, once as a high-risk AI system. That is not an oversight. Article 6(1) of the AI Act is drafted to pull it in deliberately, and several later articles exist to stop the result being two parallel compliance programmes.
The route into high-risk
Article 6(1) of Regulation (EU) 2024/1689 classifies an AI system as high-risk when two conditions hold together: the system is intended to be used as a safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in Annex I; and that product is required to undergo a third-party conformity assessment under that legislation before being placed on the market. EUR-Lex publishes the consolidated AI Act.
Annex I Section A lists Regulation (EU) 2017/745 on medical devices and Regulation (EU) 2017/746 on in vitro diagnostic medical devices. EUR-Lex publishes the MDR. So the classification question reduces to the second condition: does the device require notified body involvement? Under the MDR, software is classified largely through Rule 11 in Annex VIII, which pushes most software intended to provide information used for diagnostic or therapeutic decisions to class IIa or above, and anything above class I requires a notified body. The practical effect is that most AI-based medical device software is high-risk under the AI Act automatically, without anyone assessing its risk under the AI Act at all.
Why this is not the Annex III route
Readers who have met the AI Act through its list of high-risk use cases — biometrics, employment, essential services, and the rest of Annex III — often look for medical devices there and do not find them. They are in a different limb. That distinction has consequences beyond taxonomy.
- The Article 6(3) filter does not apply. Article 6(3) lets a provider of an Annex III system argue that it does not pose a significant risk and is therefore not high-risk. That derogation is written for Annex III. A device caught by Article 6(1) has no equivalent escape.
- Registration works differently. Annex III systems go into the EU database under Article 49; Article 6(1) products are registered under their own sectoral rules, with the AI Act’s registration obligations adapted accordingly. See the EU database registration rules.
- The conformity assessment procedure is the sectoral one. This is the largest difference and it is the subject of the next section.
- The application date is later. The obligations for Article 6(1) products run on a longer clock than those for Annex III systems.
The integration provisions
The AI Act contains a set of articles whose only purpose is to prevent duplication with Annex I legislation. They are easy to miss and they are what makes dual regulation manageable.
Article 8(2) allows a provider whose product is covered by Annex I legislation to integrate the testing, reporting and documentation processes required by the AI Act into the documentation and procedures that already exist under that legislation, to ensure consistency and avoid duplication. In practice this is the licence to run one quality management system rather than two: your MDR quality management system under Article 10 of the MDR absorbs the AI Act’s Article 17 quality management requirements rather than sitting beside them.
Article 43(3) provides that for high-risk systems caught by Article 6(1) and listed in Annex I Section A, the provider follows the conformity assessment procedure required under the relevant Annex I legislation — the MDR’s Annex IX, X or XI routes — and the notified body designated under that legislation checks compliance with the AI Act’s Chapter III Section 2 requirements as part of that assessment. One notified body, one assessment, an expanded scope. See Article 43 conformity assessment.
Article 11(2) permits the technical documentation required by Annex IV of the AI Act to be provided as a single set of documentation together with the MDR technical documentation, rather than as a separate file. Article 47 allows a single EU declaration of conformity covering both instruments, and Article 48 means one CE marking, not two.
The result is that a well-run MDR programme is most of an AI Act programme. The mistake in the other direction is just as common: a team that treats the AI Act as fully absorbed and never maps the delta.
What the MDR file does not already cover
The MDR has risk management, clinical evaluation, post-market surveillance and vigilance. The AI Act adds requirements that a conventional MDR file does not necessarily answer:
- Data governance, Article 10. Training, validation and testing data sets must meet quality criteria — relevance, representativeness, examination for bias, and consideration of the specific geographical, contextual, behavioural or functional setting of use. The MDR asks whether the clinical evidence supports the claim; Article 10 asks about the composition of the training set itself. See Article 10 data governance.
- Logging, Article 12. Automatic recording of events over the lifetime of the system, with retention. MDR device software is not generally required to keep an event log of its own inferences. See Article 12 logging.
- Human oversight, Article 14. The system must be designed so that it can be effectively overseen, with the oversight measures built into the system or implementable by the deployer. This overlaps with MDR human factors work but is not the same test.
- Transparency to deployers, Article 13. Instructions for use must state accuracy metrics, known limitations, and the circumstances that may lead to risks — a more specific obligation than MDR labelling requirements.
- Deployer-side obligations. The hospital operating the device becomes a deployer under Article 26, and in many cases a public body deployer will owe a fundamental rights impact assessment under Article 27. That obligation does not exist under the MDR at all.
Timing, and what is still a proposal
The AI Act entered into force on 1 August 2024 and applies in stages under Article 113. The obligations attaching to high-risk systems caught by Article 6(1) — the medical device route — run on the longest of those, applying from 2 August 2027 rather than the August 2026 date that governs most of the Act. Devices already on the market are addressed by the transitional provisions in Article 111, which treat legacy systems differently from new placements; read Article 111 directly, because the treatment turns on whether the design changes significantly after the applicable date.
For the timeline of the Act as a whole, see the EU AI Act timeline; for the definition question that decides which obligations you owe at all, see provider versus deployer.