MDCG 2025-6 is the first joint FAQ on medical device AI under the MDR/IVDR and EU AI Act. Most AI devices requiring a notified body are high-risk AI systems under Article 6(1), but the AI Act does not change their MDR/IVDR class. Manufacturers can integrate AI Act controls into the existing QMS, technical documentation, conformity assessment and PMS system — provided both sets of requirements remain fully covered.
Who this applies to
This FAQ applies when medical device software contains an AI system as defined by the AI Act, or when the AI system is itself a medical device or IVD. The guidance calls this medical device artificial intelligence (MDAI) and includes accessories and MDR Annex XVI products.
It is primarily for manufacturers, notified bodies and competent authorities, but deployers — such as healthcare organisations using an AI system under their authority — also have obligations. Be careful with terminology: an MDR/IVDR “user” is not automatically the same legal actor as an AI Act “deployer”.
When is medical device AI “high-risk”?
Under AI Act Article 6(1), both conditions must be met:
the AI system is itself a medical device, or is a safety component of one; and
the device is subject to third-party conformity assessment under the MDR or IVDR.
That produces the following practical result:
MDR/IVDR route
High-risk AI under Article 6(1)?
MDR class I, with no sterile, measuring or reusable-surgical aspect
No — no notified body is involved
MDR class I sterile, measuring or reusable surgical
Yes
MDR class IIa, IIb or III
Yes
MDR Annex XVI product requiring notified-body assessment
Yes
IVDR class A non-sterile
No
IVDR class A sterile, or class B, C or D
Yes
In-house device meeting MDR/IVDR Article 5(5)
No under Article 6(1), because there is no third-party conformity assessment
This logic runs in one direction: the MDR/IVDR class and conformity-assessment route help determine AI Act high-risk status. The AI Act does not move a device into a higher MDR or IVDR class.
An AI system that is not high-risk under Article 6(1) is not outside the AI Act altogether. Prohibited-practice rules, transparency obligations for certain systems, and AI-literacy duties can still apply. The same is true for qualifying in-house MDAI.
One integrated system, two sets of requirements
The guidance strongly encourages manufacturers to use the AI Act's integration flexibility. You do not need parallel quality systems and duplicate technical files. AI Act processes, testing, reports and documentation can sit inside the MDR/IVDR QMS and technical documentation.
Integration is not equivalence, though. The existing system must be expanded where the AI Act adds a new dimension:
Existing MDR/IVDR process
AI-specific coverage to add
Risk management
Risks to health, safety and fundamental rights; foreseeable deployment conditions; ongoing review throughout the lifecycle
Data governance
Relevance, representativeness and quality of training, validation and test data; error and bias controls; provenance and monitoring
Technical documentation
Model design and development, data, validation, declared performance metrics, logging and predetermined changes
Information supplied
Transparency about capabilities, limitations, intended and precluded uses, accuracy and human-oversight measures
Usability and training
Appropriate oversight competence, authority to intervene or override, protection against automation bias and sufficient AI literacy
Cybersecurity
AI-specific vulnerabilities, robustness and resilience alongside MDR/IVDR security controls
PMS
Continuous AI performance, interactions with other AI systems, logs, deployer feedback and continued compliance with AI Act Articles 8–15
Clinical evaluation or performance evaluation remains central. The evidence must support the device's safety, performance and clinical benefit under MDR/IVDR and the AI system's accuracy, robustness, transparency and oversight claims under the AI Act. For continuously learning systems, validation and post-market controls must address how performance can evolve.
Conformity assessment and changes
For high-risk MDAI under Article 6(1), the conformity-assessment procedure follows the MDR or IVDR. The notified-body assessment incorporates the relevant AI Act requirements rather than sending the same medical device through a separate AI Act procedure.
Change control still needs two explicit tests. “Substantial modification” is an autonomous AI Act concept; it is not automatically aligned with a significant or substantial change under MDR/IVDR. A high-risk system needs a new conformity assessment after a substantial AI modification. Predetermined changes to a learning system are not substantial under the AI Act when they were clearly specified in the original technical documentation and assessed during the initial conformity assessment.
Timeline update: MDCG 2025-6 was published under the original AI Act timetable and therefore explains a 2 August 2027 application date for Article 6(1) medical device AI. That statement accurately describes the source document, but it is no longer the operative deadline. The later AI Omnibus, which entered into force in July 2026, moved the application of the high-risk rules for AI embedded in Annex I products to 2 August 2028. Medical-device manufacturers should use the current legal deadline while retaining the guidance for its substantive interpretation of MDR/IVDR and AI Act interplay.
What this means for you, practically
Document the two gateway tests. Establish whether the software meets the AI-system definition and whether the device's conformity assessment involves a notified body.
Extend your QMS gap analysis beyond safety. Add fundamental-rights risks, data governance, bias, logging, transparency, human oversight, AI literacy and deployer feedback to the relevant procedures.
Define measurable performance. Predefine accuracy, robustness and cybersecurity metrics and probabilistic thresholds; connect them to validation, the IFU and post-market triggers.
Design oversight around the use case. Name who can understand, monitor, ignore, override or stop the output, what training they need, and how you control automation bias. A stop button alone is not a human-oversight strategy.
Put both legal tests into change control. Assess every model, data, architecture and intended-purpose change under the MDR/IVDR and AI Act separately, and document any predetermined change plan before conformity assessment.