AI Act · Healthtech

AI Act for Healthtech: Medical Devices, Health Data and Compliance

Most AI-enabled medical devices are high-risk under the AI Act (Art. 6(1) + Annex I, MDR/IVDR). Learn the conformity assessment obligations, Art. 9 GDPR health data and the mandatory DPIA.

Is your medical AI high-risk under the AI Act?

The AI Act (Regulation (EU) 2024/1689) classifies most AI-enabled health systems as high-risk. The classification is based on two main routes:

Route 1: Regulated products (Art. 6(1) + Annex I): AI that is itself a product or safety component covered by EU harmonised legislation (MDR 2017/745, IVDR 2017/746) and requires conformity assessment by a notified body is high-risk. This includes most medical software with AI (SaMD), in vitro diagnostic devices with AI and implantable devices with AI.

Route 2: Annex III specific use cases:

  • Point 5(c): AI for risk assessment and pricing of life and health insurance
  • Point 5(d): AI for emergency healthcare patient triage and dispatch of emergency services
  • Point 1(c): Emotion recognition (high-risk where not prohibited)

Emotion recognition in health: Art. 5(1)(f) prohibits emotion recognition in the workplace and educational institutions, with medical or safety exceptions. In healthcare contexts it may be permitted if it meets the requirements.

Health data (GDPR Art. 9): Health data are special categories of data. Processing requires explicit consent or one of the exceptions of Art. 9(2)(h) (healthcare) or (i) (public health). The DPIA (Art. 35) is normally mandatory.

  • MDR/IVDR classification — We determine whether your AI is a high-risk medical device under Annex I
  • Conformity assessment — We coordinate the process with notified bodies and the AI Act documentation
  • Healthcare DPIA — We carry out the Art. 35 GDPR Impact Assessment for health data
  • Art. 9 GDPR analysis — We identify the appropriate legal basis for health data
  • AESIA and AEMPS coordination — We act before the Spanish and European competent authorities

AI Act obligations for high-risk Healthtech

If your medical AI is high-risk (Art. 6(1) + Annex I or Annex III), the AI Act obligations are:

For providers (developers):

  • Risk management system (Art. 9)
  • Training data quality (Art. 10), especially critical for health data
  • Technical documentation and record-keeping (Art. 11)
  • Transparency and information for deployers (Art. 13)
  • Human oversight (Art. 14), with appropriate design for healthcare professionals
  • Accuracy, robustness and cybersecurity (Art. 15)
  • Conformity assessment before market placement (Art. 6 + Annex I/III)
  • Registration in the EU database (Art. 49)

MDR/IVDR + AI Act coordination: The European Commission has published MDCG 2025-6 guidance on the interplay between MDR/IVDR and the AI Act. The conformity assessment can be integrated to avoid duplication.

For deployers (healthcare facilities, professionals):

  • Designate staff with competence for human oversight (Art. 26(2))
  • Carry out FRIA (Art. 27) if the system is under Annex III point 5(c) or 5(d)
  • Notify serious incidents (Art. 73)
  • Follow the provider's instructions

Timeline: High-risk systems under Annex I (regulated products) must comply before 2 August 2028. Those under Annex III before 2 December 2027. Prohibited practices under Art. 5 have been in force since 2 February 2025.

AI use cases in Healthtech and their classification

Use caseAI Act classificationApplicable rule
Medical software with AI (SaMD)High riskArt. 6(1) + Annex I (MDR)
In vitro diagnostics with AIHigh riskArt. 6(1) + Annex I (IVDR)
AI for emergency triageHigh riskAnnex III, point 5(d)
AI for life/health insuranceHigh riskAnnex III, point 5(c)
AI for emotion recognitionHigh-risk or prohibitedAnnex III 1(c) + Art. 5(1)(f)
Symptom checker chatbot (non-diagnostic)Limited riskArt. 50(1) transparency
General wellness appMinimal (generally)GDPR Art. 9

Real enforcement cases in the healthcare sector

  • Marina Salud, S.A., €500,000 (2025) — Unlawful sub-processor engagement under Art. 28 GDPR. Source: Enforcement Tracker
  • AEPD — Guide for healthcare professionals: AEPD
  • AEPD — Guide for patients and healthcare users: AEPD
  • AEPD — Technical note on mobile health apps: AEPD
  • MDCG 2025-6 — MDR/IVDR and AI Act interplay: European Commission

AI Act compliance checklist for Healthtech

  • Determine whether the AI is a medical device (MDR/IVDR)
  • Classify under Annex I (regulated products) or Annex III
  • Verify no prohibited practices under Art. 5
  • Implement risk management system (Art. 9)
  • Document training data quality (Art. 10)
  • Prepare integrated AI Act + MDR technical documentation (Art. 11)
  • Establish human oversight appropriate for healthcare professionals (Art. 14)
  • Ensure accuracy, robustness and cybersecurity (Art. 15)
  • Carry out conformity assessment with notified body
  • Register in EU database (Art. 49)
  • Carry out Art. 35 GDPR DPIA for health data
  • Identify Art. 9 GDPR legal basis (explicit consent or 9(2)(h)/(i))
  • Carry out Art. 27 FRIA if triage (5d) or insurance (5c)
  • Coordinate with AEMPS, AESIA and AEPD

Official sources

  • Regulation (EU) 2024/1689 (AI Act): EUR-Lex
  • MDR 2017/745 (Medical devices): EUR-Lex
  • IVDR 2017/746 (In vitro diagnostics): EUR-Lex
  • MDCG 2025-6 (MDR/IVDR + AI Act interplay): European Commission
  • EDPB — Guidelines 1/2026 on scientific research: EDPB

This page is general information, not legal or medical advice. Each AI system must be analysed individually. Fines and deadlines cited are based on Regulation (EU) 2024/1689 in force at the date of publication.

Featured Services

Frequently Asked Questions

Is all medical AI high-risk under the AI Act?

Most is, but not all. AI that is itself a product or safety component covered by MDR 2017/745 or IVDR 2017/746 and requires conformity assessment by a notified body is high-risk (Art. 6(1) + Annex I). AI under Annex III point 5(c) (life and health insurance) and 5(d) (emergency triage) is also high-risk. General wellness AI or non-diagnostic health apps may not be high-risk.

What is the MDCG 2025-6 guidance?

MDCG 2025-6 is a European Commission document on the interplay between the Medical Devices Regulation (MDR 2017/745), the In Vitro Diagnostics Regulation (IVDR 2017/746) and the AI Act. It sets out how to integrate conformity assessment obligations to avoid duplication when a medical device with AI must comply with both MDR/IVDR and the AI Act.

Which GDPR legal basis applies to health data with AI?

Health data are special categories (Art. 9(1) GDPR). Common legal bases are: explicit consent (Art. 9(2)(a)), processing necessary for healthcare purposes (Art. 9(2)(h)), or reasons of public interest in the area of public health (Art. 9(2)(i)). The choice depends on the context: direct healthcare, research, public health. The Spanish LOPDGDD additionally regulates health data in its arts. 7-11.

When is the DPIA mandatory in healthtech?

The DPIA (Art. 35 GDPR) is mandatory for high-risk processing, including large-scale processing of special categories of data (health, biometrics). In healthtech, almost any health data processing with AI requires a DPIA. It must document the risk analysis, mitigation measures and residual assessment. It is a prerequisite before starting the processing.

Is emotion recognition prohibited in health?

Art. 5(1)(f) of the AI Act prohibits AI systems inferring emotions in the workplace and educational institutions, with medical or safety exceptions. In healthcare contexts it may be permitted if it meets the requirements of the AI Act and the GDPR. Emotion recognition as a high-risk category is regulated under Annex III point 1(c) where not prohibited.

What fines does the AI Act provide for healthtech?

Maximum fines are: up to €35 million or 7% of global turnover for prohibited practices; up to €15 million or 3% for breach of high-risk obligations. For SMEs and startups, the lower absolute amount applies. In addition, breach of MDR/IVDR may generate additional fines under medical devices legislation.

What enforcement cases exist in healthtech?

The AEPD fined Marina Salud, S.A. €500,000 (2025) for unlawful sub-processor engagement under Art. 28 GDPR. Although not specifically an AI case, it illustrates the AEPD's active supervision in the healthcare sector. The AEPD has also published guides for healthcare professionals and for patients and users.

Which authorities supervise the AI Act in healthtech in Spain?

The AESIA supervises the AI Act. The AEMPS (Spanish Agency for Medicines and Medical Devices) supervises medical devices under MDR/IVDR. The AEPD supervises health data processing under the GDPR. In medical AI cases, all three authorities may intervene simultaneously. At European level, the European AI Office coordinates AI Act enforcement.

Contact

If you want to talk about intellectual property protection, AI and data regulation, startup formation or international expansion, write us a few lines and schedule a conversation with the team.

A2 Estudio Legal
María de Molina, 41
28006 Madrid · Spain

Tel: +34 913 451 406
Email: info@a2estudiolegal.com

Tell us briefly about your project, development stage and target countries. We will respond with the next steps to start working together.

Let's talk
Contact us