EU AI Act · medical AI · legally led high-risk compliance

EU AI Act for Medical AI, High-Risk Compliance, Legally Led

Diagnosis, triage and clinical decision-support AI regularly qualifies as high-risk under the EU AI Act and meets the existing medical-device duties under MDR and IVDR. We solve this double burden once, cleanly: risk classification, technical documentation, human oversight and data governance, interlocked with the revised FADP and GDPR. For MedTech manufacturers as much as for hospitals that buy and deploy AI.

legally led (Dr. iur., CIPP/E) AI Act × MDR/IVDR from one partner DE · FR · EN
EU AI Act high-risk compliance for medical AI

For MedTech manufacturers, diagnostic AI, clinical AI leads and AI-buying hospitals

Legally led Dr. iur. · CIPP/E
EU AI Act high-risk duties
MDR / IVDR interlocked
Manufacturers & deployers both roles
CH · EU multilingual DE/FR/EN
Dr. Dominic Staiger

Responsible for this mandate

Dr. Dominic Staiger

LL.M., Dr. iur., CIPP/E · Attorney at Law (New York) · Solicitor (UK)

LinkedIn

Diagnosis, triage and CDSS AI is regularly high-risk

As soon as an AI feature co-determines diagnosis, triage or clinical decisions, it can qualify as a high-risk system under the EU AI Act, with far-reaching duties across the entire lifecycle.

The EU AI Act classifies AI by risk level. Software that qualifies as a medical device or in-vitro diagnostic, or is a safety component of one, typically falls into the high-risk category. This concerns imaging diagnostics, reporting and prioritisation systems, emergency-department triage algorithms and clinical decision support (CDSS).

High-risk concretely means: documented risk management, requirements for data and data-governance quality, technical documentation, logging, transparency towards users, effective human oversight, plus robustness, accuracy and cybersecurity. These duties are not one-off; they must be maintained and evidenced across updates and model changes.

We classify your system legally, clarify whether and in which class it qualifies as high-risk, and translate the abstract duties into a concrete, audit-ready measures list. This baseline assessment is the first step, before you document needlessly much or the wrong things.

The AI Act and MDR/IVDR double burden, solved once, cleanly

Medical AI must satisfy two regimes at once. We run them as one interlocked compliance programme, instead of producing the same evidence twice in two regulatory dialects.

The cybersecurity and risk-management requirements of MDR and IVDR are already in force. Medical software must meet them today. The EU AI Act adds a further layer on top for high-risk AI. Both regimes demand risk management, technical documentation and a quality management system, but with different focus and vocabulary.

We map the requirements onto each other once: a risk-management process that serves both regimes, a technical documentation set with the required AI Act components, a human-oversight concept that fits the clinical workflow, and a data-governance approach that makes training, validation and test data traceable.

We interlock the same work downwards with data protection: where health data is processed, we couple AI governance to the revised FADP and GDPR and run, where required, the data-protection impact assessment (DPIA) so that AI risk assessment and data-protection assessment do not drift apart.

  • Risk classification of the AI system under the AI Act
  • Technical documentation interlocked with the MDR/IVDR file
  • Concept for effective human oversight in the clinical workflow
  • Data governance for training, validation and test data
  • Coupling to the revised FADP/GDPR and, where needed, the DPIA

EU AI Act milestones for medical AI

Orientation, not legal advice. Several dates are still politically in motion. We verify timing and scope case by case.

Duty / regulationWhat it requiresTimingStatus
Prohibited AI practicesBan on certain AI uses; build AI literacy within the organisationsince 2025in force
High-risk AI (medical devices)Risk management, technical documentation, human oversight, data governance, robustnessfrom 2026/2027, deadlines under revision (Digital Omnibus)verify case by case
MDR / IVDR cybersecuritySecurity and risk-management duties for medical devices and IVDsalready in forceto be met today
Deployer obligationsUse per instructions, ensure human oversight, keep logs, train staffwith the high-risk dutiesverify dates
EU Cyber Resilience ActSecurity and vulnerability duties for connected products with digital elementsstaggered 2026/2027verify dates
Revised FADP / GDPR (DPIA)Data-protection impact assessment for health data, coupled to the AI risk assessmentongoing on material changesin force

Three routes into AI Act compliance

AI Officer

from CHF 500/month

Ongoing AI governance as a mandate: your AI Act duties stay current and evidenced across updates, new models and new use cases.

  • Upkeep of risk management and technical documentation
  • Support for model changes and material modifications
  • Training and AI literacy for your team
  • Point of contact for regulator and customer enquiries

AI Security

from CHF 8,000

Technical testing of the software layer: security of your LLM, RAG and agent components, robust, audit-ready evidence for the cybersecurity duties.

  • Testing of LLM, RAG and agent software layers
  • Prompt injection, data leakage and permission boundaries
  • Findings report with prioritised recommendations

Legally led conformity, not just technical tests

AI Act conformity is primarily a legal and governance task that culminates in technical measures. Purely technical providers start at the wrong end.

Classification is a legal question

Whether your system is high-risk and which duties apply turns on legal criteria. We perform this classification as doctorate-level lawyers with CIPP/E, backed by an in-house technical team that checks feasibility.

One documentation, two regimes

We write technical documentation that serves the AI Act and MDR/IVDR at once, instead of two separate file worlds. That saves effort and prevents contradictory statements towards notified bodies and authorities.

AI governance depth

With three dedicated AI services, AI Governance Check, AI Officer and AI Security, we span the arc from legal classification through the ongoing mandate to technical testing of the software layer.

Data protection built in

Because medical AI processes especially sensitive data, we couple AI governance to the revised FADP and GDPR and run the DPIA where required, from one partner, without handover loss.

Multilingual & independent

We advise in German, French and English, relevant for French-speaking Switzerland, EU parent companies and international approval bodies. Because we do not sell an in-house SOC, our recommendations stay independent.

Manufacturers and deployers

We know both roles: the manufacturer placing a high-risk system on the market, and the hospital buying and operating AI. So we advise both sides precisely and mediate between their duties.

Deployer or manufacturer, your role defines your duties

The EU AI Act clearly distinguishes those who place an AI system on the market from those who deploy it. Both carry duties, but different ones.

Manufacturers (providers) of high-risk AI bear the main load: risk management, technical documentation, quality management, conformity assessment, registration and post-market monitoring. For MedTech manufacturers this runs in parallel with MDR/IVDR conformity. This is exactly the interlock we solve.

Deployers, for example a hospital buying a diagnostic AI, a triage service, a clinical chatbot or an ambient-scribe system, have their own, often underestimated duties: use per the manufacturer's instructions, ensuring effective human oversight, keeping the required logs, training staff and informing affected persons where required.

Buying AI does not automatically transfer the manufacturer's conformity and can, through improper use, turn you into a provider yourself, with all the attendant duties. We clarify your role, review the manufacturer's assurances in the procurement contract and align your internal processes so that you stand on solid ground as a deployer.

Quick check: is your AI affected?

A few questions give you a first indication of whether your AI system could fall under the high-risk duties.

Our tool: LexCommand

Why we work with LexCommand, our own Swiss legal AI

LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.

Sovereign in Switzerland

The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.

No citation, no claim

Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.

From effort to judgement

LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.

Three disciplines, one picture

We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.

For your interlocked technical documentation, concretely: LexCommand sets the duties from the EU AI Act, MDR/IVDR and revised FADP/GDPR side by side via crosswalk, so overlaps surface together and every line in the risk management and the DPIA traces to a cited primary source.

Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.

Frequently asked questions

Is my medical AI really high-risk?

Often yes, but not always. Software that qualifies as a medical device or IVD, or is a safety component of one, typically falls into the high-risk category. The exact classification depends on intended purpose and function, we assess that in the AI Governance Check and the free triage tool.

We are a hospital and only buy AI, does the AI Act concern us?

Yes. As a deployer you have your own duties: use per the manufacturer's instructions, effective human oversight, log-keeping, staff training and, where applicable, informing affected persons. We align your internal processes accordingly and review the manufacturer's assurances in the procurement contract.

Do we have to document everything twice, for the AI Act and for MDR/IVDR?

No. Both regimes require risk management, technical documentation and quality management with large overlap. We map the requirements onto each other once and maintain interlocked documentation, instead of two separate file worlds.

Are the AI Act deadlines fixed?

Not all. Several timings for high-risk AI sit from 2026/2027 and are still politically under revision (Digital Omnibus). We verify the relevant timing for your system case by case and treat the table as orientation, not as guaranteed dates.

Do you also test our device firmware?

No. Our AI Security tests the software layer, LLM, RAG and agent components. Hands-on device-firmware testing we route to a specialised testing partner. Our strength is legally led governance and software-side testing.

Can you also act as external data protection officer for our AI?

Yes. Where medical AI processes especially sensitive data, we take on the role of external data-protection advisor under the revised FADP or DPO under GDPR and couple it to AI governance. This way, AI and data-protection assessments do not drift apart.

Ready to put your medical AI on solid legal ground?

Start with the AI Governance Check: legal risk classification and gap analysis against the AI Act, MDR/IVDR and data protection, with a board-ready report. Or try our free AI Act triage tool first.