Skip to content
Entourage
Article6 min read

The EU AI Act for Life Sciences: When AI Counts as High-Risk

Whether AI in a medical device or IVD counts as high-risk AI is decided not by the technology but by the conformity assessment route under the MDR or IVDR. How Art. 6 of the EU AI Act triggers the classification and which application dates matter.

EE

Entourage Editorial Team

The most common misconception about the EU AI Act is this: whether an AI system counts as high-risk supposedly depends on how complex the model is or how autonomously it makes decisions. In life sciences, that is wrong. For AI in medical devices and in-vitro diagnostics, the classification is decided not by the technology but by the regulatory route the product already follows anyway. Anyone who overlooks this mechanism classifies their system by gut feeling, and often ends up on the wrong side of the strictest regulatory tier.

What Triggers High-Risk Status

The EU AI Act (Regulation (EU) 2024/1689) provides two routes into the high-risk category, and for life sciences the first one is the most relevant.

Under Art. 6 (1), an AI system counts as high-risk AI when two conditions come together: the AI system is a safety component of a product, or is itself a product, that falls under one of the listed harmonisation acts, which include the MDR (EU 2017/745) and the IVDR (EU 2017/746), and this product must undergo a conformity assessment by a notified body. This is exactly where the MDR/IVDR classification becomes the trigger: software that, as a medical device under the MDR, is typically classified from Class IIa upwards undergoes a conformity assessment by a notified body. For IVDs, the same mechanism applies through the risk-based classes of the IVDR. The classification under product law therefore also determines whether the AI Act applies in its strictest form.

The second route runs through Art. 6 (2) and the use-case list in Annex III. This captures AI in certain fields of application irrespective of product law. For medical device and IVD manufacturers, the product route under para. 1 dominates in practice, because it ties directly into the MDR/IVDR conformity assessment that is already under way.

Why the Order of Assessment Matters

The risk class is not a label applied after the fact, but the first step. Only once it has been established whether a system is high-risk AI can you determine whether the obligations under Art. 8 to 15 apply at all. Skip this classification and you fail in two directions: either you build evidence for a scope of obligations that does not apply, or you overlook requirements you should have been meeting long ago.

A typical pitfall: the classification is discussed internally but not formally documented. Art. 9 of the EU AI Act requires a documented risk management system. An undocumented classification is treated as not met in an audit and forces rework before any further obligations can be meaningfully addressed. The justification for the risk class, which Art. 6 route, which product class, which notified body, should therefore be kept on record in writing from the outset.

Which Obligations Apply to High-Risk AI

Once the classification as high-risk AI is settled, the requirements from Art. 8 to 15 of the EU AI Act apply. The points central to life-science systems:

  • Risk management (Art. 9): a continuous, documented system across the entire lifecycle, not a one-off assessment.
  • Data and data governance (Art. 10): evidence on the sources, bias review and representativeness of the training, validation and test data. The bar is higher than in usual ML development practice, with representativeness and demographic coverage required to be demonstrated, not assumed.
  • Technical documentation (Art. 11 + Annex IV): system description, training data documentation, performance metrics, a description of human oversight and a robustness assessment. These AI-specific contents go beyond classic MDR technical documentation.
  • Human oversight (Art. 14): implemented as a design principle and evidenced through design and UX documentation. The fact that a user can intervene in theory is not sufficient without a documented mechanism.
  • Accuracy, robustness, cybersecurity (Art. 15): demonstrated performance limits and resilience against errors and manipulation.
  • Post-market monitoring (Art. 72): monitoring that captures model performance, concept drift and unintended outputs in operation.

The real bottleneck lies in the parallelism. Software as a Medical Device is subject to the MDR or IVDR and the AI Act at the same time. Running both frameworks as separate projects with their own document sets creates redundant maintenance effort and conflicting versions. Post-market monitoring under Art. 72, for example, can be dovetailed with the existing MDR/IVDR post-market surveillance instead of being run in parallel. Where AI is used in GxP processes, such as pharmaceutical production, quality control and laboratory systems, the draft EU GMP Annex 22 (in consultation 2025, not yet final) adds a further layer on top of GMP Annex 11 on computerised systems. These requirements should be factored in early, even though the annex has not yet been adopted.

Which Application Dates Matter

The EU AI Act has been in force since August 2024 and applies in stages. Three dates are relevant for life sciences:

  • The prohibition of certain AI practices under Art. 5 has applied since February 2025.
  • The obligations for high-risk AI in the Annex III use cases apply from 2 August 2026.
  • For AI that falls under the MDR or IVDR as a product or safety component via Art. 6 (1), the longer deadline of 2 August 2027 applies.

For most medical device and IVD manufacturers, 2 August 2027 is therefore the decisive date, because their AI follows the product route. These application dates are subject to change: a postponement of the high-risk deadlines is under discussion at EU level and, as of the editorial deadline, had not yet been formally adopted and published in the Official Journal. The current status should be checked before planning. This does not change the approach: classification, gap analysis and the build-up of the evidence required under Annex IV all need lead time, especially since the notified body is involved in the assessment. Anyone who dismisses the deadline as far off underestimates the effort required for data governance and technical documentation.

What to Do

The first step is the documented classification under Art. 6: the product route under para. 1 or the use-case list under para. 2, with a traceable justification. This is followed by a gap analysis against Art. 8 to 15, and on that basis an integration model that maps the AI Act evidence onto the existing technical documentation, the QMS and the post-market system, rather than building a second set of records.

Entourage steps in at exactly this point: with the classification under Art. 6, the gap analysis against the high-risk requirements and the integration with the MDR, IVDR and, where applicable, the draft Annex 22. The goal is an evidence framework in which each requirement is demonstrated once and maintained consistently.

Relevant for your project?

Similar questions in your current project?

In a first call we clarify what is specifically relevant for your situation, without obligation.

Request a call

Life Science Journal

Regulatory updates, straight to your inbox.

New requirements, authority decisions and practice notes. Once a month, unsubscribe any time.

Regulations & standards considered

  • Regulation (EU) 2024/1689 (EU AI Act)
  • EU AI Act Art. 5 (Prohibited AI Practices)
  • EU AI Act Art. 6 (1) (High-Risk AI as a Product or Safety Component under Harmonisation Legislation)
  • EU AI Act Art. 6 (2) + Annex III (High-Risk AI per Use-Case List)
  • EU AI Act Art. 8 to 15 (Requirements for High-Risk AI Systems)
  • EU AI Act Art. 9 (Risk Management System)
  • EU AI Act Art. 10 (Data and Data Governance)
  • EU AI Act Art. 11 + Annex IV (Technical Documentation)
  • EU AI Act Art. 14 (Human Oversight)
  • EU AI Act Art. 15 (Accuracy, Robustness, Cybersecurity)
  • EU AI Act Art. 72 (Post-Market Monitoring)
  • EU 2017/745 (MDR)
  • EU 2017/746 (IVDR)
  • EU GMP Annex 22 - Draft (AI in GxP Processes)
  • EU GMP Annex 11 (Computerised Systems)
Sources
  • Regulation (EU) 2024/1689 (EU AI Act) - primary text, Art. 5, 6, 8-15, 72, Annex III, Annex IV
  • Regulation (EU) 2017/745 (MDR) - primary text
  • Regulation (EU) 2017/746 (IVDR) - primary text
  • EU GMP Annex 22 (draft, consultation 2025) - AI in GxP processes; EU GMP Annex 11 - computerised systems
  • Entourage landing page ai-compliance (EU AI Act Readiness Check, internal source material)
  • https://theentourage.de/ki-compliance/

Your project

Have a concrete project?

Briefly outline your situation. We'll respond with an initial assessment, usually within one business day.

Prefer direct? +41 61 271 23 80
info@theentourage.ch

  • Reply usually within one working day
  • 4 offices: DE · CH · IT · US
  • 100% life sciences