EU AI Act High-Risk Series, Part 4: Healthcare & MedTech
Healthcare AI has two EU AI Act deadlines eight months apart, and which applies depends on whether your product is legally a medical device. How to classify correctly, what goes in the technical file, and why health-system procurement is already asking.
Cameron Mukherjee, Director · · Updated
For: MedTech and healthcare AI vendors, and health providers deploying diagnostic, decision-support or triage AI
Key points
- Healthcare AI has two tracks: AI that is a medical device under MDR/IVDR requiring notified-body assessment is high-risk under Article 6(1) with a deadline of 2 August 2028; standalone Annex III uses such as emergency triage have a deadline of 2 December 2027.
- For device-track products the AI Act requirements are folded into the MDR conformity assessment (MDCG 2025-6), not run as a separate programme.
- The workplace emotion-recognition ban has an explicit medical and safety exemption, but it does not cover general wellbeing or burnout monitoring.
- Lower-class clinical decision support that does not require third-party assessment may not be automatically high-risk; classification should be done formally.
- Human oversight in healthcare means a clinician who can understand and override the output in a clinical context.
Part 4 of our five-part series on high-risk AI under the EU AI Act, written for the directors who have to decide what to build, buy and sign off. Part 1 covered recruitment and HR technology; Part 2 covered finance and insurance; Part 3 covered education and EdTech; Part 5 covers critical infrastructure.
Ask two healthcare AI businesses when they must comply with the EU AI Act and you can get two correct answers eight months apart. Which applies to you turns on one question: is your AI legally a medical device? Healthcare is the one sector in this series that splits into two tracks with two deadlines, and getting the classification wrong in either direction is expensive: over-classifying buys a conformity assessment you did not need, under-classifying risks a product off the market.
What has changed
The "Digital Omnibus on AI", Regulation (EU) 2026/1744, in force since 27 July 2026, postponed both healthcare-relevant deadlines. Standalone Annex III systems moved from 2 August 2026 to 2 December 2027. AI that is a safety component of a product already regulated under EU product-safety law (Annex I) moved from 2 August 2027 to 2 August 2028.
What the delay did not touch:
- Since 2 February 2025: prohibited practices and staff AI-literacy obligations. Article 5(1)(f)'s ban on inferring emotions from biometric data in workplaces and education specifically exempts medical and safety purposes; healthcare is the explicit carve-out. Commission guidance has clarified the exemption does not cover general workplace stress or "wellbeing" monitoring, and a proportionality test still applies.
- Since 2 August 2025: general-purpose model obligations and the governance and penalty framework.
- From 2 August 2026: transparency duties.
The two tracks: is your AI a medical device?
Track 1: your AI is a medical device, or a safety component of one. Under Article 6(1), software that meets the definition of a medical device or in vitro diagnostic under MDR or IVDR, broadly MDR class IIa and above or IVDR class B to D, and needs third-party conformity assessment from a notified body, is automatically high-risk. Certain Class I MDR devices with sterile, measuring or reusable-surgical sub-designations also require notified-body sign-off and can trigger Article 6(1). Diagnostic imaging AI, AI-assisted triage sold as a device, and most serious clinical decision support sit here. Deadline: 2 August 2028. Under MDCG 2025-6, the AI Act's requirements (data governance, logging, human oversight, post-market monitoring) are folded into the conformity assessment your notified body already runs, not a second process.
Track 2: your AI is not a device but is named in Annex III. Annex III point 5(a) covers AI used by public authorities to determine eligibility for essential public services, naming healthcare as an example. Point 5(d) names emergency healthcare patient triage systems. Neither needs to be a device. Deadline: 2 December 2027.
The difficult ground is between the tracks: software marketed as "clinical decision support" at a lower MDR class that does not trigger third-party assessment may not automatically be high-risk under Article 6(1). Getting that classification right and documented is one of the harder calls in the series, and worth doing formally rather than assuming.
What has to change
The obligations resemble the rest of the series: risk management, data governance and bias testing, technical documentation, logging, human oversight, transparency and post-market monitoring. What differs is where the work happens.
- On the device track, this is additional evidence in the technical file your notified body already reviews. The practical work is ensuring existing MDR documentation covers the AI-specific points: training data provenance, bias testing, and a real oversight process for the clinician using the tool.
- On the Annex III track, the process looks like the rest of the series: conformity assessment and registration by December 2027.
- Either way, human oversight in healthcare means a clinician who can understand and override the output in a clinical context, not a technically retained veto that is never used.
What is at stake commercially
Fines under Article 99 are tiered and unchanged: up to €35M or 7% for breaching a prohibition; up to €15M or 3% for high-risk non-compliance, which is where most healthcare failures fall; up to €7.5M or 1% for misleading a regulator or notified body; for SMEs, the lower figure.
In healthcare an AI Act failure rarely stays contained. On the device track it lands on MDR enforcement, in the worst case a suspended CE mark and a product off the market. Patient-safety incidents involving AI draw scrutiny from regulators, clinicians and the press faster than any formal timeline. Health-system procurement is already asking for the classification and the evidence.
The return on classifying correctly and early is a single technical file that satisfies the notified body and the Act together, and a product that can be sold into EU health systems without a compliance caveat.
What to do now
- Classify each product formally against MDR/IVDR and the AI Act, and record the reasoning. Treat this as its own exercise.
- On the device track, audit the technical file for the AI-specific evidence and plan its inclusion in the next conformity assessment.
- On the Annex III track, schedule conformity assessment and registration against December 2027.
- Design clinician oversight that works in practice, and log every output and override.
- Prepare the answers for health-system procurement now.
How Hexploits helps
We do the engineering side of EU AI Act readiness and data protection engineering for the systems that hold patient data, working alongside your regulatory affairs team and notified body rather than in place of them. We are the core team behind swarmd.ai, an EU AI Act readiness platform for governing AI agents in regulated industries, and the audit and oversight patterns built there are the ones we apply to clinical systems.
Request a proposal or talk to an engineer. You will have a written scope and an indicative price within two working days.
This is our view of the operational and technical side of compliance, not legal advice. Pair it with your legal counsel and regulatory affairs team for formal sign-off. Next in the series: Part 5, critical infrastructure.
Questions this raises
When does the EU AI Act apply to medical device AI?
Is emergency triage AI high-risk?
Do we run two compliance programmes?
How Hexploits helps
- EU AI Act readiness for UK businesses
EU AI Act readiness is the work of classifying each AI system against the Act’s risk tiers, and building the risk management, technical documentation, logging, human oversight and post-market monitoring that high-risk systems must have before their deadline.
- Data protection engineering
Data protection engineering builds GDPR obligations into systems so they run automatically: encryption, retention and deletion, subject access, consent, and records of processing.
More insights
EU AI Act High-Risk Series, Part 5: Critical Infrastructure
11 September 2026
AI managing power grids, water supply or road traffic is high-risk under the EU AI Act only where it is a genuine safety component, and part of the scope test is still draft guidance. How utilities, operators and their vendors should classify, and what to build if they are in scope.
EU AI Act High-Risk Series, Part 3: Education & EdTech
28 August 2026
Admissions, grading and exam-monitoring tools are high-risk under the EU AI Act, and emotion recognition in proctoring is banned outright. What universities, exam boards and EdTech vendors have to build by December 2027, and why institutional buyers are already asking.
EU AI Act High-Risk Series, Part 2: Finance & Insurance
21 August 2026
Credit scoring and life or health insurance pricing are high-risk under the EU AI Act, with a mandatory impact assessment for every deployer. What a lender, insurer or payments business has to build by December 2027, and how to do it once for every regulator.
Next step
Have a question this raised?
Tell us about the system and the sector. A named engineer replies within one working day. A written scope and an indicative price within two working days of a short scoping call.