Do I need a separate conformity assessment for the AI Act?
In short: No — not a second procedure. For AI that is a medical device, AI Act Article 43(3) builds the AI Act conformity check into your existing MDR Notified Body assessment: the single-procedure design is settled in law. What isn't yet settled is which overlapping requirements get formally exempted — the Commission has authority to adopt delegated acts to do that, and none has been adopted so far. Expect one procedure, but a fuller file.
One assessment, extended scope — settled by Article 43(3)
Where your AI system falls into high-risk status via Article 6(1) — meaning it's part of a device already going through MDR Notified Body conformity assessment — AI Act Article 43(3) is the mechanism: the AI Act conformity check is carried out as part of your existing MDR procedure, by the same notified body, as one combined submission rather than a parallel AI Act review by a second body. That single-procedure design is settled law, not just direction of travel. One practical bottleneck: your notified body must be designated under the AI Act as well as the MDR for the combined route to work — many are not yet dual-designated. What is genuinely unresolved is the elimination of duplicate requirements: the Digital Omnibus gives the European Commission authority to adopt delegated acts exempting specific AI Act high-risk requirements where MDR or IVDR already mandates equivalent standards, but no such delegated act has been adopted yet, and medical devices did not secure an automatic exemption in the Omnibus itself. (On timing: the Omnibus — published in the Official Journal on 24 July 2026, in force from 27 July 2026 — also moves the Article 6(1) medical-device application date from 2 August 2027 to 2 August 2028; the deferred date is now the legally binding one to plan against.)
What actually changes in your submission package
The practical effect is that the content of your existing technical file grows, not the number of review processes you go through. Your documentation will need to demonstrate data governance practices for training, validation, and test data (Article 10), a logging and traceability capability for the AI system's operation, human oversight measures built into the device's design, and risk management extended to cover AI-specific failure modes alongside your existing ISO 14971 risk file. Build these into your existing structure — a risk management section, a data-governance section — now, rather than waiting for the delegated-act mechanism to be finalised before starting; the underlying documentation work doesn't change regardless of how the procedural question resolves.
The exception worth knowing
Where your AI system is high-risk via the Annex III route rather than Article 6(1) — meaning it isn't itself part of an MDR device — no MDR Notified Body assessment exists to integrate into, and the AI Act's own standalone conformity assessment requirements apply on their own terms. This is a smaller subset of healthcare AI, but worth checking explicitly rather than assuming Route 1 integration applies by default.
Where next: One Notified Body for MDR and the AI Act · What does AI Act Article 10 (data governance) require?
Talk to us about your combined submission package. Book an expert conversation →
The full guide to the EU AI Act founder's handbook covers this question in context.