The EU AI Act for Healthcare: Medical AI Compliance Explained
Artificial intelligence is moving into clinics faster than the rules that govern it, until now. The EU AI Act is the world's first comprehensive law on artificial intelligence, and for anyone building or buying medical AI in Europe, it changes what compliant means.
This article explains the AI Act specifically for healthcare and medical software: what it is, who it applies to, the risk levels, the timeline, and the question everyone actually asks, whether a clinical AI counts as high-risk.
This article is general information, not legal advice. For decisions about a specific product, consult a qualified regulatory or legal advisor.
What is the EU AI Act?
The EU AI Act is Regulation (EU) 2024/1689, a binding EU-wide law that regulates artificial intelligence based on the risk it poses to health, safety, and fundamental rights. It was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024, with obligations phasing in over the following years.
Its core idea is simple: the higher the risk an AI system poses, the stricter the rules. Instead of regulating the technology itself, it regulates how and where AI is used.
Who does the EU AI Act apply to?
It applies across the AI supply chain, not just developers:
- Providers: those who develop an AI system (or have it developed) and put it on the EU market under their own name.
- Deployers: organisations that use an AI system in a professional capacity, for example a hospital using a clinical AI tool.
- Importers and distributors: those bringing non-EU AI systems into the EU market.
Crucially, it has extraterritorial reach: if your AI's output is used in the EU, the Act can apply even if your company is based outside the EU. For healthcare, that means a clinic in Germany using a US-built AI tool brings both parties into scope.
The four risk levels (the heart of the Act)
Every AI system falls into one of four tiers:
| Risk level | What it means | Examples | Rules |
|---|---|---|---|
| Unacceptable | Banned outright | Social scoring, manipulative or exploitative AI, certain biometric practices | Prohibited |
| High-risk | Allowed, but heavily regulated | Medical device AI, critical infrastructure, employment, credit scoring | Full compliance regime |
| Limited | Transparency duties only | Chatbots, AI-generated content and deepfakes | Must disclose AI use |
| Minimal | No specific obligations | Spam filters, AI in video games | Voluntary codes |
Most everyday software sits in minimal or limited risk. Healthcare is where things get serious, because a lot of medical AI can land in high-risk.
When does the EU AI Act apply? (The timeline)
The Act applies in stages, not all at once:
- 1 August 2024: entered into force.
- 2 February 2025: bans on prohibited AI practices apply; AI-literacy obligations begin.
- 2 August 2025: rules for general-purpose AI (GPAI) models, governance bodies, and penalties apply.
- 2 August 2026: most obligations for high-risk AI (Annex III use cases) and transparency duties apply.
- 2 August 2027: obligations for high-risk AI that are products or safety components of products already regulated under EU law, including medical devices, apply.
So for most medical device AI, the key date is 2 August 2027, but preparation needs to start long before that, because the underlying technical work (risk management, data governance, documentation) takes time.
Is my healthcare AI high-risk? (The question that matters)
This is where the AI Act and medical device law meet. Under Article 6(1) of the AI Act, an AI system is high-risk when both of these are true: it is a product, or a safety component of a product, covered by EU harmonisation legislation listed in Annex I, which includes the Medical Device Regulation (MDR 2017/745); and that product is required to undergo a third-party conformity assessment, meaning a Notified Body must be involved.
In plain terms, for medical device software:
- Class IIa, IIb or III medical device AI needs a Notified Body, so it is high-risk under the AI Act.
- Class I medical device AI (self-certified, no Notified Body) is generally not high-risk under Article 6.
There is also a nuance in Article 6(3): even some AI in listed categories may not be high-risk if it performs a narrow, procedural task and does not pose a significant risk of harm, but this must be documented and justified.
The practical takeaway for medical AI: your MDR classification usually drives your AI Act risk level. If a new feature pushes your software from Class I into Class IIa, for example by adding patient-specific clinical decision-support, it can simultaneously make you high-risk under the AI Act. The two regimes move together.
What obligations come with high-risk?
If your medical AI is high-risk, you must, among other things:
- Operate a risk management system across the AI's lifecycle.
- Meet data governance standards for training, validation, and testing data.
- Maintain technical documentation and automatic logging of events.
- Ensure transparency and clear information for deployers.
- Build in human oversight.
- Achieve appropriate accuracy, robustness, and cybersecurity.
- Register the system in the EU database and complete a conformity assessment.
Encouragingly, the AI Act is designed to align with the MDR. Where a medical device already meets MDR requirements (technical documentation, risk management, post-market surveillance), much of that work can be reused to satisfy the AI Act, rather than duplicated.
EU AI Act and MDR: how the two stack up
For medical AI, you are almost never dealing with the AI Act alone:
| MDR (2017/745) | EU AI Act (2024/1689) | |
|---|---|---|
| Governs | Safety and performance of the medical device | AI-specific risks (data, transparency, oversight) |
| Classification | Class I / IIa / IIb / III | Minimal / limited / high / unacceptable |
| Link | Class of device | Drives whether the AI is high-risk |
| Assessment | Notified Body (Class IIa and above) | Conformity assessment, often via the MDR route |
The two are complementary: the MDR asks is the device safe and effective; the AI Act asks is the AI governed, transparent, and overseen. A compliant medical-AI programme addresses both together.
What are the penalties?
Non-compliance is expensive:
- Prohibited AI practices: up to 35 million euros or 7% of total worldwide annual turnover, whichever is higher.
- Most other breaches, for example high-risk obligations: up to 15 million euros or 3%.
- Supplying incorrect or misleading information to authorities: up to 7.5 million euros or 1%.
How to approach EU AI Act compliance, a practical path
You don't need to solve everything at once. A sensible sequence:
- Inventory your AI. List every AI system or feature you provide or use.
- Classify each one. Which risk tier? For medical software, start from your MDR class, it usually decides your AI Act risk level.
- Map the overlap with MDR. Identify what your existing MDR technical file already covers, so you don't duplicate work.
- Close the AI-specific gaps. Data governance, logging, transparency, human oversight, robustness.
- Document and justify. Especially any not high-risk determination, write down why, with the Article 6 reasoning.
- Watch feature changes. Any new feature that adds clinical decision-support can change your MDR class and your AI Act risk level. Re-assess before you ship.
- Track the timeline. Align your roadmap to the 2026 and 2027 dates.
- Is the EU AI Act in force now?
- Yes. It entered into force on 1 August 2024, but its obligations apply in stages between February 2025 and August 2027.
- Does the EU AI Act apply to companies outside the EU?
- Yes. If your AI system is placed on the EU market or its output is used in the EU, the Act can apply regardless of where your company is based.
- Is all medical AI high-risk under the AI Act?
- No. Medical AI is high-risk when it is a medical device that requires a Notified Body conformity assessment (Class IIa and above). Class I self-certified software is generally not high-risk.
- When do medical device AI obligations apply?
- The obligations for high-risk AI that are regulated products, including medical devices, apply from 2 August 2027.
- How is the EU AI Act different from the MDR?
- The MDR governs the safety and performance of the medical device; the AI Act governs AI-specific risks such as data governance, transparency, and human oversight. They apply together, and your MDR class usually determines your AI Act risk level.
- What happens if we don't comply?
- Fines range up to 35 million euros or 7% of global turnover for the most serious breaches, down to 7.5 million euros or 1% for providing incorrect information.
- Does a chatbot or medical information tool count as high-risk?
- Not automatically. A purely informational tool that isn't a Notified-Body-assessed medical device typically falls under limited-risk (transparency) or minimal-risk, but the specific facts matter, and any AI that talks to users must disclose that it is AI.
- Where can I read the official law?
- The full text is Regulation (EU) 2024/1689, available free on EUR-Lex.
Referências
This article provides general information about the EU AI Act and is not legal or regulatory advice. AI and medical device regulation is complex and fact-specific; for decisions about a particular product or organisation, seek advice from a qualified professional.