MDCG 2025-6: MDR/IVDR and the AI Act interplay - FAQ, explained
How the EU AI Act applies alongside MDR or IVDR to medical device AI, from high-risk status and data governance to conformity assessment and PMS.
MDCG 2025-6 is the first joint FAQ on medical device AI under the MDR/IVDR and EU AI Act. Most AI devices requiring a notified body are high-risk AI systems under Article 6(1), but the AI Act does not change their MDR/IVDR class. Manufacturers can integrate AI Act controls into the existing QMS, technical documentation, conformity assessment and PMS system — provided both sets of requirements remain fully covered.
Who this applies to
This FAQ applies when medical device software contains an AI system as defined by the AI Act, or when the AI system is itself a medical device or IVD. The guidance calls this medical device artificial intelligence (MDAI) and includes accessories and MDR Annex XVI products.
It is primarily for manufacturers, notified bodies and competent authorities, but deployers — such as healthcare organisations using an AI system under their authority — also have obligations. Be careful with terminology: an MDR/IVDR “user” is not automatically the same legal actor as an AI Act “deployer”.
When is medical device AI “high-risk”?
Under AI Act Article 6(1), both conditions must be met:
- the AI system is itself a medical device, or is a safety component of one; and
- the device is subject to third-party conformity assessment under the MDR or IVDR.
That produces the following practical result:
MDR/IVDR route |
High-risk AI under Article 6(1)? |
|---|---|
MDR class I, with no sterile, measuring or reusable-surgical aspect |
No — no notified body is involved |
MDR class I sterile, measuring or reusable surgical |
Yes |
MDR class IIa, IIb or III |
Yes |
MDR Annex XVI product requiring notified-body assessment |
Yes |
IVDR class A non-sterile |
No |
IVDR class A sterile, or class B, C or D |
Yes |
In-house device meeting MDR/IVDR Article 5(5) |
No under Article 6(1), because there is no third-party conformity assessment |
This logic runs in one direction: the MDR/IVDR class and conformity-assessment route help determine AI Act high-risk status. The AI Act does not move a device into a higher MDR or IVDR class.
An AI system that is not high-risk under Article 6(1) is not outside the AI Act altogether. Prohibited-practice rules, transparency obligations for certain systems, and AI-literacy duties can still apply. The same is true for qualifying in-house MDAI.
One integrated system, two sets of requirements
The guidance strongly encourages manufacturers to use the AI Act's integration flexibility. You do not need parallel quality systems and duplicate technical files. AI Act processes, testing, reports and documentation can sit inside the MDR/IVDR QMS and technical documentation.
Integration is not equivalence, though. The existing system must be expanded where the AI Act adds a new dimension:
Existing MDR/IVDR process |
AI-specific coverage to add |
|---|---|
Risk management |
Risks to health, safety and fundamental rights; foreseeable deployment conditions; ongoing review throughout the lifecycle |
Data governance |
Relevance, representativeness and quality of training, validation and test data; error and bias controls; provenance and monitoring |
Technical documentation |
Model design and development, data, validation, declared performance metrics, logging and predetermined changes |
Information supplied |
Transparency about capabilities, limitations, intended and precluded uses, accuracy and human-oversight measures |
Usability and training |
Appropriate oversight competence, authority to intervene or override, protection against automation bias and sufficient AI literacy |
Cybersecurity |
AI-specific vulnerabilities, robustness and resilience alongside MDR/IVDR security controls |
PMS |
Continuous AI performance, interactions with other AI systems, logs, deployer feedback and continued compliance with AI Act Articles 8–15 |
Clinical evaluation or performance evaluation remains central. The evidence must support the device's safety, performance and clinical benefit under MDR/IVDR and the AI system's accuracy, robustness, transparency and oversight claims under the AI Act. For continuously learning systems, validation and post-market controls must address how performance can evolve.
Conformity assessment and changes
For high-risk MDAI under Article 6(1), the conformity-assessment procedure follows the MDR or IVDR. The notified-body assessment incorporates the relevant AI Act requirements rather than sending the same medical device through a separate AI Act procedure.
Change control still needs two explicit tests. “Substantial modification” is an autonomous AI Act concept; it is not automatically aligned with a significant or substantial change under MDR/IVDR. A high-risk system needs a new conformity assessment after a substantial AI modification. Predetermined changes to a learning system are not substantial under the AI Act when they were clearly specified in the original technical documentation and assessed during the initial conformity assessment.
The FAQ also explains the transition for Article 6(1) medical device AI. The high-risk obligations apply from 2 August 2027. Devices placed on the market or put into service before that date come within those obligations when the AI system undergoes a significant design change on or after 2 August 2027; devices first placed on the market from that date must comply at placement.
What this means for you, practically
- Document the two gateway tests. Establish whether the software meets the AI-system definition and whether the device's conformity assessment involves a notified body.
- Extend your QMS gap analysis beyond safety. Add fundamental-rights risks, data governance, bias, logging, transparency, human oversight, AI literacy and deployer feedback to the relevant procedures.
- Define measurable performance. Predefine accuracy, robustness and cybersecurity metrics and probabilistic thresholds; connect them to validation, the IFU and post-market triggers.
- Design oversight around the use case. Name who can understand, monitor, ignore, override or stop the output, what training they need, and how you control automation bias. A stop button alone is not a human-oversight strategy.
- Put both legal tests into change control. Assess every model, data, architecture and intended-purpose change under the MDR/IVDR and AI Act separately, and document any predetermined change plan before conformity assessment.
Turn templates into working QMS documents.
Start from OpenRegulatory templates, fill them out with AI assistance, and keep them connected to your QMS in Formwork.