MDCG 2025-6: MDR/IVDR and the AI Act interplay - FAQ, explained

How the EU AI Act applies alongside MDR or IVDR to medical device AI, from high-risk status and data governance to conformity assessment and PMS.

Current Published August 12, 2026 Reviewed by Dr. Oliver Eidel

MDCG 2025-6 is the first joint FAQ on medical device AI under the MDR/IVDR and EU AI Act. Most AI devices requiring a notified body are high-risk AI systems under Article 6(1), but the AI Act does not change their MDR/IVDR class. Manufacturers can integrate AI Act controls into the existing QMS, technical documentation, conformity assessment and PMS system — provided both sets of requirements remain fully covered.

Who this applies to

This FAQ applies when medical device software contains an AI system as defined by the AI Act, or when the AI system is itself a medical device or IVD. The guidance calls this medical device artificial intelligence (MDAI) and includes accessories and MDR Annex XVI products.

It is primarily for manufacturers, notified bodies and competent authorities, but deployers — such as healthcare organisations using an AI system under their authority — also have obligations. Be careful with terminology: an MDR/IVDR “user” is not automatically the same legal actor as an AI Act “deployer”.

When is medical device AI “high-risk”?

Under AI Act Article 6(1), both conditions must be met:

  1. the AI system is itself a medical device, or is a safety component of one; and
  2. the device is subject to third-party conformity assessment under the MDR or IVDR.

That produces the following practical result:

MDR/IVDR route

High-risk AI under Article 6(1)?

MDR class I, with no sterile, measuring or reusable-surgical aspect

No — no notified body is involved

MDR class I sterile, measuring or reusable surgical

Yes

MDR class IIa, IIb or III

Yes

MDR Annex XVI product requiring notified-body assessment

Yes

IVDR class A non-sterile

No

IVDR class A sterile, or class B, C or D

Yes

In-house device meeting MDR/IVDR Article 5(5)

No under Article 6(1), because there is no third-party conformity assessment

This logic runs in one direction: the MDR/IVDR class and conformity-assessment route help determine AI Act high-risk status. The AI Act does not move a device into a higher MDR or IVDR class.

An AI system that is not high-risk under Article 6(1) is not outside the AI Act altogether. Prohibited-practice rules, transparency obligations for certain systems, and AI-literacy duties can still apply. The same is true for qualifying in-house MDAI.

One integrated system, two sets of requirements

The guidance strongly encourages manufacturers to use the AI Act's integration flexibility. You do not need parallel quality systems and duplicate technical files. AI Act processes, testing, reports and documentation can sit inside the MDR/IVDR QMS and technical documentation.

Integration is not equivalence, though. The existing system must be expanded where the AI Act adds a new dimension:

Existing MDR/IVDR process

AI-specific coverage to add

Risk management

Risks to health, safety and fundamental rights; foreseeable deployment conditions; ongoing review throughout the lifecycle

Data governance

Relevance, representativeness and quality of training, validation and test data; error and bias controls; provenance and monitoring

Technical documentation

Model design and development, data, validation, declared performance metrics, logging and predetermined changes

Information supplied

Transparency about capabilities, limitations, intended and precluded uses, accuracy and human-oversight measures

Usability and training

Appropriate oversight competence, authority to intervene or override, protection against automation bias and sufficient AI literacy

Cybersecurity

AI-specific vulnerabilities, robustness and resilience alongside MDR/IVDR security controls

PMS

Continuous AI performance, interactions with other AI systems, logs, deployer feedback and continued compliance with AI Act Articles 8–15

Clinical evaluation or performance evaluation remains central. The evidence must support the device's safety, performance and clinical benefit under MDR/IVDR and the AI system's accuracy, robustness, transparency and oversight claims under the AI Act. For continuously learning systems, validation and post-market controls must address how performance can evolve.

Conformity assessment and changes

For high-risk MDAI under Article 6(1), the conformity-assessment procedure follows the MDR or IVDR. The notified-body assessment incorporates the relevant AI Act requirements rather than sending the same medical device through a separate AI Act procedure.

Change control still needs two explicit tests. “Substantial modification” is an autonomous AI Act concept; it is not automatically aligned with a significant or substantial change under MDR/IVDR. A high-risk system needs a new conformity assessment after a substantial AI modification. Predetermined changes to a learning system are not substantial under the AI Act when they were clearly specified in the original technical documentation and assessed during the initial conformity assessment.

The FAQ also explains the transition for Article 6(1) medical device AI. The high-risk obligations apply from 2 August 2027. Devices placed on the market or put into service before that date come within those obligations when the AI system undergoes a significant design change on or after 2 August 2027; devices first placed on the market from that date must comply at placement.

What this means for you, practically

  1. Document the two gateway tests. Establish whether the software meets the AI-system definition and whether the device's conformity assessment involves a notified body.
  2. Extend your QMS gap analysis beyond safety. Add fundamental-rights risks, data governance, bias, logging, transparency, human oversight, AI literacy and deployer feedback to the relevant procedures.
  3. Define measurable performance. Predefine accuracy, robustness and cybersecurity metrics and probabilistic thresholds; connect them to validation, the IFU and post-market triggers.
  4. Design oversight around the use case. Name who can understand, monitor, ignore, override or stop the output, what training they need, and how you control automation bias. A stop button alone is not a human-oversight strategy.
  5. Put both legal tests into change control. Assess every model, data, architecture and intended-purpose change under the MDR/IVDR and AI Act separately, and document any predetermined change plan before conformity assessment.

Turn templates into working QMS documents.

Start from OpenRegulatory templates, fill them out with AI assistance, and keep them connected to your QMS in Formwork.

app.openregulatory.com / cardio-monitor / audit
Cardio Monitor · v2.4

Audit readiness

100%
32 SOPs signed QMS
47 requirements traced Techdoc
18 risks mitigated Risk
21 CFR Part 11 ready Compliance
Ready for ISO 13485 audit