Skip to content

EU AI Act High-Risk Series, Part 4: Healthcare & MedTech

Healthcare AI has two EU AI Act deadlines eight months apart, and which applies depends on whether your product is legally a medical device. How to classify correctly, what goes in the technical file, and why health-system procurement is already asking.

Cameron Mukherjee, Director · · Updated

For: MedTech and healthcare AI vendors, and health providers deploying diagnostic, decision-support or triage AI

Key points

  • Healthcare AI has two tracks: AI that is a medical device under MDR/IVDR requiring notified-body assessment is high-risk under Article 6(1) with a deadline of 2 August 2028; standalone Annex III uses such as emergency triage have a deadline of 2 December 2027.
  • For device-track products the AI Act requirements are folded into the MDR conformity assessment (MDCG 2025-6), not run as a separate programme.
  • The workplace emotion-recognition ban has an explicit medical and safety exemption, but it does not cover general wellbeing or burnout monitoring.
  • Lower-class clinical decision support that does not require third-party assessment may not be automatically high-risk; classification should be done formally.
  • Human oversight in healthcare means a clinician who can understand and override the output in a clinical context.

Part 4 of our five-part series on high-risk AI under the EU AI Act, written for the directors who have to decide what to build, buy and sign off. Part 1 covered recruitment and HR technology; Part 2 covered finance and insurance; Part 3 covered education and EdTech; Part 5 covers critical infrastructure.


Ask two healthcare AI businesses when they must comply with the EU AI Act and you can get two correct answers eight months apart. Which applies to you turns on one question: is your AI legally a medical device? Healthcare is the one sector in this series that splits into two tracks with two deadlines, and getting the classification wrong in either direction is expensive: over-classifying buys a conformity assessment you did not need, under-classifying risks a product off the market.


What has changed

The "Digital Omnibus on AI", Regulation (EU) 2026/1744, in force since 27 July 2026, postponed both healthcare-relevant deadlines. Standalone Annex III systems moved from 2 August 2026 to 2 December 2027. AI that is a safety component of a product already regulated under EU product-safety law (Annex I) moved from 2 August 2027 to 2 August 2028.

What the delay did not touch:

  • Since 2 February 2025: prohibited practices and staff AI-literacy obligations. Article 5(1)(f)'s ban on inferring emotions from biometric data in workplaces and education specifically exempts medical and safety purposes; healthcare is the explicit carve-out. Commission guidance has clarified the exemption does not cover general workplace stress or "wellbeing" monitoring, and a proportionality test still applies.
  • Since 2 August 2025: general-purpose model obligations and the governance and penalty framework.
  • From 2 August 2026: transparency duties.

The two tracks: is your AI a medical device?

Track 1: your AI is a medical device, or a safety component of one. Under Article 6(1), software that meets the definition of a medical device or in vitro diagnostic under MDR or IVDR, broadly MDR class IIa and above or IVDR class B to D, and needs third-party conformity assessment from a notified body, is automatically high-risk. Certain Class I MDR devices with sterile, measuring or reusable-surgical sub-designations also require notified-body sign-off and can trigger Article 6(1). Diagnostic imaging AI, AI-assisted triage sold as a device, and most serious clinical decision support sit here. Deadline: 2 August 2028. Under MDCG 2025-6, the AI Act's requirements (data governance, logging, human oversight, post-market monitoring) are folded into the conformity assessment your notified body already runs, not a second process.

Track 2: your AI is not a device but is named in Annex III. Annex III point 5(a) covers AI used by public authorities to determine eligibility for essential public services, naming healthcare as an example. Point 5(d) names emergency healthcare patient triage systems. Neither needs to be a device. Deadline: 2 December 2027.

The difficult ground is between the tracks: software marketed as "clinical decision support" at a lower MDR class that does not trigger third-party assessment may not automatically be high-risk under Article 6(1). Getting that classification right and documented is one of the harder calls in the series, and worth doing formally rather than assuming.


What has to change

The obligations resemble the rest of the series: risk management, data governance and bias testing, technical documentation, logging, human oversight, transparency and post-market monitoring. What differs is where the work happens.

  • On the device track, this is additional evidence in the technical file your notified body already reviews. The practical work is ensuring existing MDR documentation covers the AI-specific points: training data provenance, bias testing, and a real oversight process for the clinician using the tool.
  • On the Annex III track, the process looks like the rest of the series: conformity assessment and registration by December 2027.
  • Either way, human oversight in healthcare means a clinician who can understand and override the output in a clinical context, not a technically retained veto that is never used.

What is at stake commercially

Fines under Article 99 are tiered and unchanged: up to €35M or 7% for breaching a prohibition; up to €15M or 3% for high-risk non-compliance, which is where most healthcare failures fall; up to €7.5M or 1% for misleading a regulator or notified body; for SMEs, the lower figure.

In healthcare an AI Act failure rarely stays contained. On the device track it lands on MDR enforcement, in the worst case a suspended CE mark and a product off the market. Patient-safety incidents involving AI draw scrutiny from regulators, clinicians and the press faster than any formal timeline. Health-system procurement is already asking for the classification and the evidence.

The return on classifying correctly and early is a single technical file that satisfies the notified body and the Act together, and a product that can be sold into EU health systems without a compliance caveat.


What to do now

  1. Classify each product formally against MDR/IVDR and the AI Act, and record the reasoning. Treat this as its own exercise.
  2. On the device track, audit the technical file for the AI-specific evidence and plan its inclusion in the next conformity assessment.
  3. On the Annex III track, schedule conformity assessment and registration against December 2027.
  4. Design clinician oversight that works in practice, and log every output and override.
  5. Prepare the answers for health-system procurement now.

How Hexploits helps

We do the engineering side of EU AI Act readiness and data protection engineering for the systems that hold patient data, working alongside your regulatory affairs team and notified body rather than in place of them. We are the core team behind swarmd.ai, an EU AI Act readiness platform for governing AI agents in regulated industries, and the audit and oversight patterns built there are the ones we apply to clinical systems.

Request a proposal or talk to an engineer. You will have a written scope and an indicative price within two working days.

This is our view of the operational and technical side of compliance, not legal advice. Pair it with your legal counsel and regulatory affairs team for formal sign-off. Next in the series: Part 5, critical infrastructure.

Questions this raises

When does the EU AI Act apply to medical device AI?
From 2 August 2028 for AI that is a medical device or safety component requiring notified-body assessment under MDR or IVDR.
Is emergency triage AI high-risk?
Yes. Emergency healthcare patient triage systems are named in Annex III point 5(d), with a deadline of 2 December 2027, whether or not they are medical devices.
Do we run two compliance programmes?
No. For device-track products the AI Act evidence is added to the technical file the notified body already reviews.

How Hexploits helps

  • EU AI Act readiness for UK businesses

    EU AI Act readiness is the work of classifying each AI system against the Act’s risk tiers, and building the risk management, technical documentation, logging, human oversight and post-market monitoring that high-risk systems must have before their deadline.

  • Data protection engineering

    Data protection engineering builds GDPR obligations into systems so they run automatically: encryption, retention and deletion, subject access, consent, and records of processing.

Have a question this raised?

Tell us about the system and the sector. A named engineer replies within one working day. A written scope and an indicative price within two working days of a short scoping call.