Back to blog
August 11, 20266 min readMarina Bernhard
⚖️ AI Governance & Law

AI Governance in Healthcare: Understanding the AI Act, SaMD and MDR

In Brief

An artificial intelligence used in healthcare is not automatically a medical device. Its qualification depends in particular on its intended purpose. When a system falls under both the MDR/IVDR and the AI Act, obligations must be articulated from the design stage: risk management, human oversight, traceability, documentation, cybersecurity and surveillance.

Key Points

AI in healthcare ≠ automatically a medical device.

The intended purpose of the software is decisive for MDR/IVDR analysis.

Status under the AI Act must be analysed separately.

The same system may simultaneously fall under both the AI Act and the MDR/IVDR.

Human oversight must be real and effective, not reduced to an automatic validation step.

Compliance must be built by design, before deployment.


Artificial intelligence is progressively entering every dimension of the healthcare system: medical image interpretation, diagnostic support, risk prediction, clinical documentation, remote monitoring, care organisation, and assistance for healthcare professionals.

But using artificial intelligence in a medical context does not, by itself, determine its legal status. The same technology may fall under very different regulatory frameworks depending on its purpose, how it functions, its integration into the care pathway, and the role it plays in a medical decision.

In Europe, three questions must be distinguished:

Does the software constitute a medical device?

Does it constitute an artificial intelligence system within the meaning of the AI Act?

If both regulations apply, how are their obligations to be articulated?


1. AI Used in Medicine Is Not Automatically a Medical Device

One of the most common misconceptions is that software becomes a medical device simply because it is used by a doctor or in a healthcare institution. That is not the determining criterion.

Under European law, the analysis is based on the intended purpose of the software. Regulation (EU) 2017/745 — the MDR — defines the medical device based on the pursued medical purpose.

It depends essentially on what the software is intended to do.

Some Examples

Schedule management, appointments, billing: not a medical device

Consultation transcription: depends on the claimed functionalities

Radiological detection: clearly enters the scope of MDSW

Therapeutic recommendation: in-depth MDR analysis indispensable


2. SaMD and MDSW: A Useful Terminological Distinction

The term Software as a Medical Device — SaMD is widely used internationally (IMDRF).

Within the European regulatory framework, the terminology used is: Medical Device Software — MDSW.

The presence of artificial intelligence does not automatically transform software into a medical device.


3. The AI Act: A Separate Second Analysis

When software uses a system meeting the regulatory definition of artificial intelligence, a second analysis begins.

European Regulation 2024/1689 — the AI Act — organises obligations according to a risk-based logic. It does not replace the MDR or IVDR. The regulations may overlap.

AI used in healthcare is not automatically "high-risk" under the AI Act. Qualification must be carried out system by system.


4. The Real Challenge: MDR + AI Act

When artificial intelligence is incorporated into a medical device falling simultaneously under both frameworks, the manufacturer must articulate:

risk management

technical documentation

human oversight

transparency

cybersecurity

post-market surveillance

traceability

The Medical Device Coordination Group and the AI Board published in June 2025 a specific FAQ: MDCG 2025-6 on the interaction MDR/IVDR × AI Act.


5. Human Oversight Must Not Become a Fiction

It would be dangerous to consider that a human oversight obligation is satisfied simply because a "Validate" button appears at the end of an algorithmic recommendation.

Meaningful oversight requires that the user be able to understand the role of the system, know its limitations, correctly interpret its outputs, and retain the ability to override a recommendation.

The risk is that of automation bias: the tendency to place excessive trust in a recommendation produced by an automated system.

The real question is not: "Does a human validate the result?" But: "Does this human genuinely have the information and means necessary to exercise meaningful control?"


6. The Doctor Must Not Become the Software's Last Regulatory Barrier

Final validation by a doctor does not exempt other actors from their own obligations. Depending on the situation, different actors may be involved: manufacturer, provider, deployer, healthcare institution, healthcare professional, host, data controller, data processor.

Their responsibilities are neither necessarily identical nor necessarily exclusive of one another.


7. Before Deploying Medical AI: Ten Essential Questions

What exactly is the intended purpose of the system?

Is there a medical purpose?

Does the software fall under the MDR or IVDR?

What is its regulatory classification?

Does the system fall under the AI Act?

What is its risk category under that regulation?

Who is legally the manufacturer, provider or deployer?

What human oversight is realistically possible?

What records must be kept?

What happens when an incident is detected?


8. Governance Begins Before Development

The classic mistake is to build the product, then ask: "How do we make it compliant?"

In a mature MedTech architecture, the intended purpose determines regulatory qualification, which drives risk mapping, which shapes technical architecture, data governance, human oversight, validation, traceability and surveillance. Compliance thus becomes a property of the system's architecture.


9. AI Act Timeline: Not All Obligations Enter Into Force Simultaneously

Prohibited practices and AI literacy: applicable since February 2025

Governance and general-purpose AI models: applicable since August 2025

Transparency obligations (Article 50): applicable from 2 August 2026

High-risk systems integrated into regulated products: specific timetable

For a MedTech company, tracking this calendar itself becomes a governance function.


10. What a Healthcare Professional Should Remember

Artificial intelligence does not constitute a legal vacuum. But it does not fall under a single regulation. Depending on the system, several frameworks may simultaneously apply: AI Act, MDR/IVDR, data protection, cybersecurity, medical law, liability, national rules.

Before asking "Is our AI compliant?" one must first answer a more fundamental question: "Legally, what exactly is our system?"


Main Regulatory Sources

Regulation (EU) 2024/1689 — Artificial Intelligence Act

Regulation (EU) 2017/745 — MDR

Regulation (EU) 2017/746 — IVDR

MDCG 2019-11 rev.1, June 2025

MDCG 2025-6, June 2025

European Commission, Guidelines on transparency obligations, July 2026


*This article presents a general analysis of the regulatory framework. It does not constitute an individualised legal or regulatory opinion.*

Ready to take back control of your schedule?

Request Your Free Digital Audit →