Does the EU AI Act apply to my medical device?
In short: If your device contains an AI system and requires Notified Body conformity assessment under MDR or IVDR — in practice Class IIa and above — it is automatically high-risk under the AI Act via Article 6(1), and the Act's requirements apply on top of MDR. Non-AI devices and most Class I software sit outside this particular route — though stand-alone AI can still be caught by Annex III.
Status (updated 25 July 2026): the Digital Omnibus package postponing the high-risk deadlines was published in the Official Journal on 24 July 2026 and enters into force on 27 July 2026 — the deferred deadlines are now the legally binding ones; see When do the AI Act deadlines hit medical devices? for the current dates.
The mechanism, in plain terms
Article 6(1) of the AI Act creates an automatic route into "high-risk" status: if your product is, or contains, an AI system, and that product is itself an Annex I item — MDR or IVDR medical devices among them — requiring third-party conformity assessment by a Notified Body, the AI system is automatically classified high-risk. In practice, this covers Class IIa, IIb, and III MDR software with any genuine AI component. Class I self-certified devices, and any non-AI software regardless of class, sit outside this specific route into high-risk status — though note this is route-specific: AI used in areas listed in Annex III (emergency triage, for example) can still be high-risk even without Notified Body involvement.
Why "on top of," not "instead of"
The AI Act is deliberately designed to integrate with your existing MDR conformity assessment rather than create a second, parallel procedure. Your Notified Body extends its existing technical documentation and QMS review to cover AI Act-specific requirements — data governance, logging, human oversight, and risk management for the AI system specifically — rather than a second body running a separate AI Act assessment. This is real, additive work, but it's structured as an extension of a process you're already running, not a duplicate one.
What actually changes because of the recent timeline shift
The Digital Omnibus package that postpones the AI Act's high-risk deadlines was published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744 and enters into force on 27 July 2026. From entry into force, the postponed dates are the legally binding ones: 2 December 2027 for Annex III stand-alone high-risk systems, and 2 August 2028 for high-risk AI in regulated products — including medical devices under Article 6(1). The original 2 August 2026 and 2 August 2027 deadlines are superseded. Plan against the postponed dates. One thing the Omnibus does not move: Article 4's AI-literacy obligation has applied since 2 February 2025, for providers and deployers alike.
Where next: When Medical Device AI Becomes High-Risk · Is my healthcare AI "high-risk" under the AI Act?
Find out in minutes where your product likely sits. Start the MedTech Compass → — AI-generated first read, not a validated determination.
The full guide to the EU AI Act for medical devices covers this question in context.