Skip to content

FAQ · AI Act deadlines, high-risk status, Article 4 & 10, GDPR overlap.

EU AI Act and data

What the EU AI Act adds on top of MDR for AI-enabled devices, when the obligations bite, and how it interacts with GDPR.

7 questions · P1 first

Does the EU AI Act apply to my medical device?

P1

If your device contains an AI system and requires Notified Body conformity assessment under MDR or IVDR — in practice Class IIa and above — it is automatically high-risk under the AI Act via Article 6(1), and the Act's requirements apply on top of MDR. Non-AI devices and most Class I software sit outside this particular route — though stand-alone AI can still be caught by Annex III. > > *Status (updated 25 July 2026): the Digital Omnibus package postponing the high-risk deadlines was published in the Official Journal on 24 July 2026 and enters into force on 27 July 2026 — the deferred deadlines are now the legally binding ones; see [When do the AI Act deadlines hit medical devices?](/resources/faq/ai-act-deadlines) for the current dates.*

When do the AI Act deadlines hit medical devices?

P1

Under the Digital Omnibus package — published in the Official Journal on 24 July 2026 and in force from 27 July 2026 — Annex III general high-risk obligations move to 2 December 2027 and Article 6(1) medical-device obligations to 2 August 2028, roughly 16 months and a full year later than the Act's original dates. From entry into force, the deferred dates are the legally binding ones; the original dates (2 August 2026 and 2 August 2027) are superseded. Article 4 AI literacy has applied since 2 February 2025 already, regardless of the Omnibus, with no grace period. > > *Status (updated 25 July 2026): Official Journal publication is confirmed — the deferred dates are the legally binding ones from 27 July 2026. Next scheduled review: 1 October 2026.*

Is my healthcare AI "high-risk" under the AI Act?

P1

Two routes make healthcare AI high-risk: Article 6(1), automatically capturing AI that is a Notified-Body-assessed medical device, or an Annex III listed use case (such as emergency triage). Most clinical AI is caught by the first route. Wellness and purely administrative AI generally is not high-risk.

Do I need a separate conformity assessment for the AI Act?

P1

No — not a second procedure. For AI that is a medical device, AI Act Article 43(3) builds the AI Act conformity check into your existing MDR Notified Body assessment: the single-procedure design is settled in law. What isn't yet settled is which overlapping requirements get formally exempted — the Commission has authority to adopt delegated acts to do that, and none has been adopted so far. Expect one procedure, but a fuller file.

What is the AI literacy obligation (Article 4)?

P2

Article 4 requires providers and deployers of AI systems to ensure staff have sufficient AI literacy for their role — understanding the systems they build or operate, their limits, and their risks. It has applied since 2 February 2025, with no grace period and no exemption tied to the Digital Omnibus reform, and it applies well beyond high-risk systems.

What does AI Act Article 10 (data governance) require?

P2

Article 10 requires high-risk AI training, validation, and test data to be governed: relevant, sufficiently representative, examined for bias, and managed under documented practices covering provenance and preparation. For medical AI, this formalises what good ML development and MDR clinical evidence expectations already push toward.

Does GDPR apply to my medical device data?

P2

Almost certainly yes: health data is special-category data under GDPR Article 9, so processing needs an explicit legal basis, strong security, and usually a data protection impact assessment. GDPR runs alongside MDR and the AI Act as a third parallel obligation — same evidence, three regulators.

See where you stand, in about ten minutes.

Free, AI-powered, and every gap comes with a next step.

Start the MedTech Compass