The EU AI Act makes most medical AI 'high-risk.' The hard part starts in 2027
Under Article 6, AI that is or sits inside a device already needing an independent safety check counts as high-risk. A 70-study review finds the trouble is overlap with existing device law.
The European Union's Artificial Intelligence Act sorts AI systems by risk and puts the heaviest obligations on a tier it calls "high-risk," and for healthcare the practical effect is sweeping: most AI built into a medical device lands in that tier automatically. Article 6(1) classifies as high-risk any AI system that is itself, or is a safety component of, a product already covered by EU product-safety law requiring a third-party conformity assessment — a category that expressly includes medical devices and in vitro diagnostic medical devices [s1]. The obligations that follow do not take effect until 2 August 2027, and a scoping review of the field argues the central difficulty is less the Act's own rules than how they overlap with the device regulation already in force [s2].
What the Act actually says
The AI Act is Regulation (EU) 2024/1689, and it phases in over years rather than arriving at once [s1]. Its outright prohibitions — on a short list of unacceptable uses — applied from 2 February 2025; the bulk of the Regulation applies from 2 August 2026; and the high-risk obligations attached to Article 6(1) products, the route that captures medical devices, apply from 2 August 2027 [s1]. That staggered calendar is why, in late 2026, most of the compliance work for clinical AI is still ahead of the sector rather than behind it.
The mechanism is worth stating precisely, because it is often garbled. The Act does not name "medical AI" and declare it high-risk. Instead, recital 50 and Article 6(1) reach any AI that is a product, or a safety component of one, "falling within the scope of" listed Union harmonisation legislation, where that product must undergo a third-party conformity assessment [s1]. The Medical Devices Regulation (EU) 2017/745 and the In Vitro Diagnostic Medical Devices Regulation (EU) 2017/746 are on that list [s1]. Since software that is a medical device above the lowest risk class already needs a notified body — an independent assessor — to sign it off, that same software is now high-risk under the AI Act as well. One peer-reviewed analysis of the Act's healthcare implications concludes bluntly that most clinical AI tools are classified high-risk [s3].
The double-regulation problem
Being high-risk brings a long list of duties — risk management, data governance, technical documentation, logging, transparency, human oversight and post-market monitoring — layered on top of the MDR's existing requirements. A scoping review published in September 2026 tried to map how heavy that overlap is. Screening the literature to February 2026, it included 70 studies from 2018 to 2025 and extracted 261 distinct challenges and 113 recommendations, grouped into five domains: regulatory framework, data issues, accountability and ethics, development and deployment, and certification [s2]. The regulatory-framework domain was the most frequently raised, reflecting the overlap between the MDR, the AI Act and other legislation and, the authors note, the absence of harmonised standards to comply against [s2]. Transparency was the only theme where the literature offered more recommendations than it catalogued problems [s2].
That gap — obligations that exist on paper but lack the technical standards that tell a manufacturer how to meet them — is the practical bottleneck. It also falls on a party the device world is less used to regulating: the "deployer," the hospital or clinic running the AI. A compliance analysis aimed at healthcare facilities maps deployer duties under Articles 26, 27 and 50, including site-specific validation, structured human oversight to guard against automation bias, and, for some systems, a Fundamental Rights Impact Assessment before use [s3]. In other words, buying a CE-marked, AI Act-compliant tool does not end an institution's obligations; it starts a new set of them.
How it compares
The EU's approach is horizontal — one AI law across every sector, bolted onto sector rules — where the United States has so far worked device-by-device through the FDA, including its predetermined change-control plans for models that update after clearance and its discussion of generative AI. Other systems have moved faster on volume: China has cleared AI medical devices at a pace that raises its own questions. None of these regimes yet closes the gap this site returns to repeatedly — that clearance or conformity certifies a process, not that a tool improves patient outcomes — and the jurisdictional patchwork means the same tool can be governed very differently depending on where it is deployed.
What to watch
The harmonised standards. The Act's 2027 deadline is fixed, but the technical standards that would make its obligations concrete are still being drafted, and the scoping review identifies their absence as the most-cited problem in the literature [s2]. Whether those land in time — and whether they align with the MDR rather than duplicating it — will decide if the AI Act raises the floor on clinical AI safety or mainly adds paperwork to devices already assessed. Manufacturers and hospitals watching this space should track the standards bodies, not just the statute.
This article is informational and is not medical or legal advice.
Sources
- [s1] "Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)." Official Journal of the European Union, in force 1 August 2024; Article 6(1) obligations apply from 2 August 2027. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689
- [s2] "Challenges and Recommendations in Regulating AI Medical Devices in the European Union: A Scoping Review." Healthcare (Basel), published online 5 September 2026. https://doi.org/10.3390/healthcare14172865
- [s3] "The EU AI Act: implications and compliance guidance for healthcare facilities." Frontiers in Digital Health, published online 10 June 2026. https://doi.org/10.3389/fdgth.2026.1808373
Sources
- Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) — Official Journal of the European Union (EUR-Lex) , July 12, 2024
- Challenges and Recommendations in Regulating AI Medical Devices in the European Union: A Scoping Review — Healthcare (Basel) , September 5, 2026
- The EU AI Act: implications and compliance guidance for healthcare facilities — Frontiers in Digital Health , June 10, 2026
How the FDA lets an AI device update itself without a new clearance
A predetermined change control plan is the FDA's answer to a model that keeps learning: pre-approve a bounded set of future changes, and the manufacturer can ship them without returning for a fresh review.
The FDA's blueprint for AI medical devices: what a maker must show, cradle to grave
A January 2025 draft guidance lays out the documentation the agency expects across an AI device's whole life, including bias checks across demographic groups and postmarket monitoring. It is not yet binding.
New US rules make certified health records reveal how their AI was built
A federal rule now requires certified electronic health records to publish a standard set of facts about each predictive algorithm they ship, including how it was validated and whether it was tested for fairness.
Remote patient monitoring is booming in Medicare. The evidence lags the billing
Medicare paid over $500 million for remote monitoring in 2024, but a watchdog found 43% of patients didn't get the full service — and rigorous evidence that it improves outcomes remains limited.