In Brief
An artificial intelligence used in healthcare is not automatically a medical device. Its qualification depends in particular on its intended purpose. When a system falls under both the MDR/IVDR and the AI Act, obligations must be articulated from the design stage: risk management, human oversight, traceability, documentation, cybersecurity and surveillance.
Key Points
AI in healthcare ≠ automatically a medical device.
The intended purpose of the software is decisive for MDR/IVDR analysis.
Status under the AI Act must be analysed separately.
The same system may simultaneously fall under both the AI Act and the MDR/IVDR.
Human oversight must be real and effective, not reduced to an automatic validation step.
Compliance must be built by design, before deployment.
Artificial intelligence is progressively entering every dimension of the healthcare system: medical image interpretation, diagnostic support, risk prediction, clinical documentation, remote monitoring, care organisation, and assistance for healthcare professionals.
But using artificial intelligence in a medical context does not, by itself, determine its legal status. The same technology may fall under very different regulatory frameworks depending on its purpose, how it functions, its integration into the care pathway, and the role it plays in a medical decision.
In Europe, three questions must be distinguished:
Does the software constitute a medical device?
Does it constitute an artificial intelligence system within the meaning of the AI Act?
If both regulations apply, how are their obligations to be articulated?
1. AI Used in Medicine Is Not Automatically a Medical Device
One of the most common misconceptions is that software becomes a medical device simply because it is used by a doctor or in a healthcare institution. That is not the determining criterion.
Under European law, the analysis is based on the intended purpose of the software. Regulation (EU) 2017/745 — the MDR — defines the medical device based on the pursued medical purpose.
It depends essentially on what the software is intended to do.
Some Examples
Schedule management, appointments, billing: not a medical device
Consultation transcription: depends on the claimed functionalities
Radiological detection: clearly enters the scope of MDSW
Therapeutic recommendation: in-depth MDR analysis indispensable
2. SaMD and MDSW: A Useful Terminological Distinction
The term Software as a Medical Device — SaMD is widely used internationally (IMDRF).
Within the European regulatory framework, the terminology used is: Medical Device Software — MDSW.
The presence of artificial intelligence does not automatically transform software into a medical device.
3. The AI Act: A Separate Second Analysis
When software uses a system meeting the regulatory definition of artificial intelligence, a second analysis begins.
European Regulation 2024/1689 — the AI Act — organises obligations according to a risk-based logic. It does not replace the MDR or IVDR. The regulations may overlap.
AI used in healthcare is not automatically "high-risk" under the AI Act. Qualification must be carried out system by system.
4. The Real Challenge: MDR + AI Act
When artificial intelligence is incorporated into a medical device falling simultaneously under both frameworks, the manufacturer must articulate:
risk management
technical documentation
human oversight
transparency
cybersecurity
post-market surveillance
traceability
The Medical Device Coordination Group and the AI Board published in June 2025 a specific FAQ: MDCG 2025-6 on the interaction MDR/IVDR × AI Act.
5. Human Oversight Must Not Become a Fiction
It would be dangerous to consider that a human oversight obligation is satisfied simply because a "Validate" button appears at the end of an algorithmic recommendation.
Meaningful oversight requires that the user be able to understand the role of the system, know its limitations, correctly interpret its outputs, and retain the ability to override a recommendation.
The risk is that of automation bias: the tendency to place excessive trust in a recommendation produced by an automated system.
The real question is not: "Does a human validate the result?" But: "Does this human genuinely have the information and means necessary to exercise meaningful control?"
6. The Doctor Must Not Become the Software's Last Regulatory Barrier
Final validation by a doctor does not exempt other actors from their own obligations. Depending on the situation, different actors may be involved: manufacturer, provider, deployer, healthcare institution, healthcare professional, host, data controller, data processor.
Their responsibilities are neither necessarily identical nor necessarily exclusive of one another.
7. Before Deploying Medical AI: Ten Essential Questions
What exactly is the intended purpose of the system?
Is there a medical purpose?
Does the software fall under the MDR or IVDR?
What is its regulatory classification?
Does the system fall under the AI Act?
What is its risk category under that regulation?
Who is legally the manufacturer, provider or deployer?
What human oversight is realistically possible?
What records must be kept?
What happens when an incident is detected?
8. Governance Begins Before Development
The classic mistake is to build the product, then ask: "How do we make it compliant?"
In a mature MedTech architecture, the intended purpose determines regulatory qualification, which drives risk mapping, which shapes technical architecture, data governance, human oversight, validation, traceability and surveillance. Compliance thus becomes a property of the system's architecture.
9. AI Act Timeline: Not All Obligations Enter Into Force Simultaneously
Prohibited practices and AI literacy: applicable since February 2025
Governance and general-purpose AI models: applicable since August 2025
Transparency obligations (Article 50): applicable from 2 August 2026
High-risk systems integrated into regulated products: specific timetable
For a MedTech company, tracking this calendar itself becomes a governance function.
10. What a Healthcare Professional Should Remember
Artificial intelligence does not constitute a legal vacuum. But it does not fall under a single regulation. Depending on the system, several frameworks may simultaneously apply: AI Act, MDR/IVDR, data protection, cybersecurity, medical law, liability, national rules.
Before asking "Is our AI compliant?" one must first answer a more fundamental question: "Legally, what exactly is our system?"
Main Regulatory Sources
Regulation (EU) 2024/1689 — Artificial Intelligence Act
Regulation (EU) 2017/745 — MDR
Regulation (EU) 2017/746 — IVDR
MDCG 2019-11 rev.1, June 2025
MDCG 2025-6, June 2025
European Commission, Guidelines on transparency obligations, July 2026
*This article presents a general analysis of the regulatory framework. It does not constitute an individualised legal or regulatory opinion.*