🌐 Toward Integrated Regulation of Artificial Intelligence in Healthcare
MDCG Guide 2025-6 was published in June 2025 by the Medical Device Coordination Group (MDCG) and the Artificial Intelligence Board (AIB). It provides practical guidance on the joint application of the European MDR/IVDR regulations and the Artificial Intelligence Act (AIA) for medical devices incorporating artificial intelligence systems, known as MDAI (Medical Device AI). It is intended for manufacturers, notified bodies, and competent authorities.
Effective date of the requirements of Regulation 2024/1689:
- Prior to August 2, 2027, the AIA requirements for MDAIs already on the market do not apply, unless there is a significant change on or after that date
- After August 2, 2027, all AIA requirements will apply in full to MDAIs placed on the market or modified
🔍 Key Points of the Regulatory Framework
- Mandatory dual compliance
Any medical device that incorporates a high-risk AI system must comply with the requirements of both regulations:
- MDR/IVDR for Clinical Safety and Performance
- AIA for risks specific to AI (fundamental rights, bias, cybersecurity, etc.)
- Classification of MDAIs
An MDAI is considered high-risk if:
- is itself a medical device or a safety component,
- and is subject to a conformity assessment by a notified body under the MDR or the IVDR.
- Single Technical Document
Manufacturers are encouraged to include all elements required by the MDR/IVDR and the AIA—including software architecture, training/validation data, and risk and performance assessments—in a single set of documentation.
🔐 Stricter Requirements for MDAs
Quality and Lifecycle Management
MDAIs must be accompanied by an integrated quality management system covering:
- the design,
- post-marketing surveillance,
- updates,
- and the predefined changes.
Data Governance
The data used to train, validate, and test an MDAI must be:
- representative, comprehensive, and unbiased,
- in accordance with the GDPR,
- and documented within a robust governance framework.
Transparency and Human Oversight
MDAs must:
- provide human oversight mechanisms tailored to their level of autonomy,
- to enable healthcare professionals to understand the decisions,
- and clearly inform users when they interact with AI.
Cybersecurity
AI-specific security measures must be built in from the design stage to:
- prevent unauthorized access and malicious tampering,
- ensure the system’s robustness and resilience throughout its lifecycle.
📈 Monitoring and Regulatory Developments
The text also states:
- the procedures for clinical and performance evaluation of MDAIs,
- the combined MDR/IVDR+AIA compliance procedures,
- the rules governing substantial post-market changes,
- and the need to train end users in how to interpret and properly use AI systems.
Additional guidelines are expected, particularly regarding substantial modifications, predetermined change plans, and AI literacy training.
📌 Conclusion
This document marks an important milestone in the European harmonization of requirements for medical devices incorporating artificial intelligence. It confirms that the AIA does not replace the MDR or the IVDR, but rather supplements them with requirements specific to AI. Manufacturers must now navigate an integrated regulatory framework that ensures both patient safety and respect for fundamental rights.