Is your medical AI high-risk under the AI Act?
The AI Act (Regulation (EU) 2024/1689) classifies most AI-enabled health systems as high-risk. The classification is based on two main routes:
Route 1: Regulated products (Art. 6(1) + Annex I): AI that is itself a product or safety component covered by EU harmonised legislation (MDR 2017/745, IVDR 2017/746) and requires conformity assessment by a notified body is high-risk. This includes most medical software with AI (SaMD), in vitro diagnostic devices with AI and implantable devices with AI.
Route 2: Annex III specific use cases:
- Point 5(c): AI for risk assessment and pricing of life and health insurance
- Point 5(d): AI for emergency healthcare patient triage and dispatch of emergency services
- Point 1(c): Emotion recognition (high-risk where not prohibited)
Emotion recognition in health: Art. 5(1)(f) prohibits emotion recognition in the workplace and educational institutions, with medical or safety exceptions. In healthcare contexts it may be permitted if it meets the requirements.
Health data (GDPR Art. 9): Health data are special categories of data. Processing requires explicit consent or one of the exceptions of Art. 9(2)(h) (healthcare) or (i) (public health). The DPIA (Art. 35) is normally mandatory.
- MDR/IVDR classification — We determine whether your AI is a high-risk medical device under Annex I
- Conformity assessment — We coordinate the process with notified bodies and the AI Act documentation
- Healthcare DPIA — We carry out the Art. 35 GDPR Impact Assessment for health data
- Art. 9 GDPR analysis — We identify the appropriate legal basis for health data
- AESIA and AEMPS coordination — We act before the Spanish and European competent authorities
AI Act obligations for high-risk Healthtech
If your medical AI is high-risk (Art. 6(1) + Annex I or Annex III), the AI Act obligations are:
For providers (developers):
- Risk management system (Art. 9)
- Training data quality (Art. 10), especially critical for health data
- Technical documentation and record-keeping (Art. 11)
- Transparency and information for deployers (Art. 13)
- Human oversight (Art. 14), with appropriate design for healthcare professionals
- Accuracy, robustness and cybersecurity (Art. 15)
- Conformity assessment before market placement (Art. 6 + Annex I/III)
- Registration in the EU database (Art. 49)
MDR/IVDR + AI Act coordination: The European Commission has published MDCG 2025-6 guidance on the interplay between MDR/IVDR and the AI Act. The conformity assessment can be integrated to avoid duplication.
For deployers (healthcare facilities, professionals):
- Designate staff with competence for human oversight (Art. 26(2))
- Carry out FRIA (Art. 27) if the system is under Annex III point 5(c) or 5(d)
- Notify serious incidents (Art. 73)
- Follow the provider's instructions
Timeline: High-risk systems under Annex I (regulated products) must comply before 2 August 2028. Those under Annex III before 2 December 2027. Prohibited practices under Art. 5 have been in force since 2 February 2025.
AI use cases in Healthtech and their classification
| Use case | AI Act classification | Applicable rule |
|---|---|---|
| Medical software with AI (SaMD) | High risk | Art. 6(1) + Annex I (MDR) |
| In vitro diagnostics with AI | High risk | Art. 6(1) + Annex I (IVDR) |
| AI for emergency triage | High risk | Annex III, point 5(d) |
| AI for life/health insurance | High risk | Annex III, point 5(c) |
| AI for emotion recognition | High-risk or prohibited | Annex III 1(c) + Art. 5(1)(f) |
| Symptom checker chatbot (non-diagnostic) | Limited risk | Art. 50(1) transparency |
| General wellness app | Minimal (generally) | GDPR Art. 9 |
Real enforcement cases in the healthcare sector
- Marina Salud, S.A., €500,000 (2025) — Unlawful sub-processor engagement under Art. 28 GDPR. Source: Enforcement Tracker
- AEPD — Guide for healthcare professionals: AEPD
- AEPD — Guide for patients and healthcare users: AEPD
- AEPD — Technical note on mobile health apps: AEPD
- MDCG 2025-6 — MDR/IVDR and AI Act interplay: European Commission
AI Act compliance checklist for Healthtech
- Determine whether the AI is a medical device (MDR/IVDR)
- Classify under Annex I (regulated products) or Annex III
- Verify no prohibited practices under Art. 5
- Implement risk management system (Art. 9)
- Document training data quality (Art. 10)
- Prepare integrated AI Act + MDR technical documentation (Art. 11)
- Establish human oversight appropriate for healthcare professionals (Art. 14)
- Ensure accuracy, robustness and cybersecurity (Art. 15)
- Carry out conformity assessment with notified body
- Register in EU database (Art. 49)
- Carry out Art. 35 GDPR DPIA for health data
- Identify Art. 9 GDPR legal basis (explicit consent or 9(2)(h)/(i))
- Carry out Art. 27 FRIA if triage (5d) or insurance (5c)
- Coordinate with AEMPS, AESIA and AEPD
Official sources
- Regulation (EU) 2024/1689 (AI Act): EUR-Lex
- MDR 2017/745 (Medical devices): EUR-Lex
- IVDR 2017/746 (In vitro diagnostics): EUR-Lex
- MDCG 2025-6 (MDR/IVDR + AI Act interplay): European Commission
- EDPB — Guidelines 1/2026 on scientific research: EDPB
Related resources
- AI Act Hub — Resource centre on the European AI Regulation
- AI Act Glossary — 45+ key terms with article references
- GDPR Glossary — 45+ key terms of the GDPR and LOPDGDD
- AI Act vs GDPR — Comparative table of both regulations
- AI Act Compliance Checker — Self-assess your AI system
- AI & Data Regulation Service — Integrated advisory
- GDPR for Healthtech — Sectoral GDPR guide for healthtech
This page is general information, not legal or medical advice. Each AI system must be analysed individually. Fines and deadlines cited are based on Regulation (EU) 2024/1689 in force at the date of publication.