We use a few strictly-necessary cookies, no marketing trackers, and cookieless analytics. Read our cookie policy, or pick a preference.
The regimes that decide whether medical AI reaches a patient. Software with a medical purpose is a medical device, so a diagnostic or clinical-decision model must clear a conformity assessment on clinical evidence, and from 2028 the AI Act's high-risk duties run inside that same assessment.
If software is intended for diagnosis, prevention, monitoring, prediction, or treatment, it is a medical device under the MDR, or an in-vitro diagnostic device under the IVDR, and it must be classified by risk, backed by clinical or performance evidence, and CE-marked before it goes to market. Most clinical AI lands in a class that requires a notified body to review it.
The two regimes are separate: a device is one or the other. But for AI, they now converge with the AI Act. A medical AI device that is high-risk under the Act carries the Act's requirements through the existing MDR or IVDR conformity assessment, from 2 August 2028, so the goal is one assessment that satisfies both, not two parallel files.
Largely self-certified. Few AI devices qualify once they inform a clinical decision.
Notified-body review begins. Much diagnostic and monitoring AI sits here.
Heavier scrutiny of clinical evidence and the quality system.
Most demanding route: full clinical evaluation and continuous oversight.
Every manufacturer must designate a person responsible for regulatory compliance, with defined qualifications, who answers for conformity, technical documentation, post-market surveillance, and vigilance reporting. It is a named accountability inside the organisation, so regulatory responsibility for a medical AI device rests with an identified competent person, not diffused across a team.
Both regulations apply now. Extended transition periods let compliant legacy devices continue while they move across, and the AI Act layer lands in 2028.
MDR applies, replacing the Medical Devices Directive.
IVDR applies, replacing the IVD Directive.
Extended deadlines for legacy MDR devices, staggered by risk class.
AI Act high-risk duties apply to devices under Union product law (Annex I).
Source: Official Journal of the EU · MDR/IVDR as amended (incl. Reg. 2023/607 transition extensions) · confirm class-specific deadlines against the consolidated text
Duties attach along the chain, with a notified body as the independent check for all but the lowest-risk devices.
The primary duties: classification, clinical or performance evidence, technical documentation, a quality system, and post-market surveillance.
The EU point of contact, holding documentation and cooperating with authorities on the manufacturer's behalf.
Reviews the evidence and quality system for medium and higher-risk devices before a CE mark can be applied.
Verify the CE marking, documentation, and registration are in place, and keep traceability through the chain.
The regulations leave fines to member states, but the operational exposure, losing the market and facing liability, is uniform.
| Exposure | What it means |
|---|---|
| Nationalset by each state | Member states set penalties for MDR and IVDR breaches (MDR Art. 113, IVDR Art. 106); they must be effective, proportionate, and dissuasive. |
| Withdrawal+ civil liability | Non-conforming devices can be withdrawn or recalled, and a defect exposes the manufacturer to strict liability under the Product Liability Directive. |
Confirm national penalty regimes and current notified-body capacity in each market of supply
"Our model is decision support, so it isn't a medical device."
Intended purpose is what counts. If the software is meant to inform a diagnosis or treatment decision, it is very likely a device and needs a conformity assessment.
"Once we have the CE mark, the regulatory work is done."
Post-market surveillance, clinical follow-up, and vigilance reporting continue for the device's life, and updates to a learning model can require re-assessment.
"An MDR approval already covers the AI Act."
From 2028 the AI Act's high-risk requirements are additional, though satisfied through the same conformity assessment. The assessment gets deeper, not duplicated.
A clinical AI device meets the MDR or IVDR, the AI Act as a high-risk system, the GDPR for patient data, and the Product Liability Directive if it fails. We map at the level of the obligation across all of them.