EuroComply
Free assessment

EU AI Act · use case

EU AI Act for Medical Diagnosis and Clinical Decision Support AI

Diagnostic and clinical decision support AI is high-risk under the EU AI Act, usually via the Medical Devices Regulation. Which route applies, deadlines, and the documents needed.

Classify my system in 3 minutes

Free, no account. Pre-filled for this use case.

Risk tier

High-risk

High-risk (Art. 6(1) via the MDR/IVDR, or Annex III(5)(d) and health-related points)

When it applies

Systems that are medical devices: 2 August 2028. Annex III health systems that are not devices: 2 December 2027.

Regulation (EU) 2024/1689, Art. 6(1) and Annex I (MDR 2017/745, IVDR 2017/746); Annex III(5)(a) and 5(d); Art. 5

AI that helps diagnose, predicts patient deterioration, reads medical images, or recommends treatment is high-risk under the EU AI Act. The route into the high-risk regime is different from most other use cases: if the software is a medical device under the Medical Devices Regulation (MDR) or the In Vitro Diagnostic Regulation (IVDR) and needs a notified-body conformity assessment, it is high-risk under Article 6(1) and Annex I, not Annex III.

That distinction matters for the timeline and the paperwork. Device-based systems get until 2 August 2028 and go through the notified body that already certifies the device, with the AI Act requirements folded into the MDR technical documentation. Health AI that is not a device, for example a system that triages emergency calls or decides eligibility for public healthcare services, falls under Annex III and the 2 December 2027 deadline.

Classification

Why this classification applies

Article 6(1) makes an AI system high-risk when it is a product, or a safety component of a product, covered by the Union harmonisation legislation in Annex I and subject to third-party conformity assessment under that legislation. Diagnostic software is typically class IIa or higher under MDR Rule 11, which requires a notified body, so the condition is met.

Annex III adds health-related entries that do not depend on device status: AI evaluating eligibility for essential public services including healthcare (point 5(a)), and AI used to evaluate and classify emergency calls or to triage patients in emergency healthcare (point 5(d)).

Wellness apps that do not have a medical purpose (general fitness, sleep tracking without diagnosis) are usually neither devices nor Annex III systems, and are minimal-risk under the AI Act. The moment an app claims to detect a condition, the medical purpose brings it into MDR and the AI Act.

Obligations

What you have to do

  • Integrate the AI Act requirements (risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness) into the MDR technical documentation and quality management system (Art. 8, Art. 11(2)).
  • Data governance with clinical representativeness: patient populations, imaging equipment, sites; bias examination on age, sex and ethnicity (Art. 10).
  • Human oversight designed for clinicians: confidence indicators, ability to override, and safeguards against automation bias (Art. 14).
  • Post-market monitoring and serious-incident reporting coordinated with MDR vigilance (Arts. 72, 73).
  • Registration in the EU database; for device-based systems the registration is done under the sectoral legislation (Art. 49).
  • Deployers such as hospitals must ensure trained oversight, keep logs, and inform patients where the AI contributes to decisions about them (Art. 26).

Paperwork

Documents to have on file

MDR/IVDR technical documentation extended with Annex IV AI Act items
Risk management file aligned with ISO 14971
Data governance records for training, validation and testing datasets
Clinical evaluation and performance validation reports
Human oversight and instructions for use for clinicians
Post-market monitoring plan and serious-incident procedure
EU declaration of conformity (combined) and registration entries

Get these documents drafted for your system

Run the free assessment, then unlock the Compliance Pack: a PDF report plus editable first drafts of every required document and a 90-day plan. €49 one-time, no subscription.

Start free assessment

Common mistakes

Where companies get this wrong

  • Treating a symptom-checker chatbot as “just a chatbot”. If it suggests diagnoses, it has a medical purpose and is likely a device.
  • Validating only on the development site. Representativeness across populations and equipment is a data-governance requirement, not a nice-to-have.
  • Assuming CE marking under MDR already covers the AI Act. The requirements overlap but the AI-specific items (data governance, logging, human oversight design) must be demonstrably addressed.
  • Hospitals deploying research prototypes in care pathways. Putting a system into service for a medical purpose triggers the same obligations as selling it.

FAQ

Frequently asked questions

Our software is class I under MDR (self-certified). Is it high-risk under the AI Act?

Article 6(1) requires third-party conformity assessment under the sectoral law. Class I devices without a notified body do not meet that condition, so they are not high-risk via Annex I. Check whether an Annex III entry applies instead; for most class I software it does not.

Does the AI Act apply to research and clinical trials?

AI systems developed and used solely for scientific research are excluded (Art. 2(6)), and testing in real-world conditions has its own rules. Once the system is placed on the market or put into service for patient care, the exclusion ends.

Which authority enforces this?

For device-based systems, the notified bodies and the market surveillance authorities under MDR/IVDR act as the AI Act authorities as well. Member States designate them; the European Commission’s AI Office coordinates.

This page is general information about Regulation (EU) 2024/1689, updated 2026-09-17. It is not legal advice; classifications depend on the exact intended purpose of a system. Deadlines reflect the Digital Omnibus adopted in June 2026.

Related use cases

Depends on use

Insurance risk assessment & pricing

Read →

Depends on use

Biometric identification & categorisation

Read →

Limited risk

Customer service chatbots

Read →

Guide

EU AI Act compliance guide

Read →