EU AI Act · medical AI · legally led high-risk compliance
EU AI Act for Medical AI, High-Risk Compliance, Legally Led
Diagnosis, triage and clinical decision-support AI regularly qualifies as high-risk under the EU AI Act and meets the existing medical-device duties under MDR and IVDR. We solve this double burden once, cleanly: risk classification, technical documentation, human oversight and data governance, interlocked with the revised FADP and GDPR. For MedTech manufacturers as much as for hospitals that buy and deploy AI.
legally led (Dr. iur., CIPP/E)AI Act × MDR/IVDR from one partnerDE · FR · EN
Diagnosis, triage and CDSS AI is regularly high-risk
As soon as an AI feature co-determines diagnosis, triage or clinical decisions, it can qualify as a high-risk system under the EU AI Act, with far-reaching duties across the entire lifecycle.
The EU AI Act classifies AI by risk level. Software that qualifies as a medical device or in-vitro diagnostic, or is a safety component of one, typically falls into the high-risk category. This concerns imaging diagnostics, reporting and prioritisation systems, emergency-department triage algorithms and clinical decision support (CDSS).
High-risk concretely means: documented risk management, requirements for data and data-governance quality, technical documentation, logging, transparency towards users, effective human oversight, plus robustness, accuracy and cybersecurity. These duties are not one-off; they must be maintained and evidenced across updates and model changes.
We classify your system legally, clarify whether and in which class it qualifies as high-risk, and translate the abstract duties into a concrete, audit-ready measures list. This baseline assessment is the first step, before you document needlessly much or the wrong things.
The AI Act and MDR/IVDR double burden, solved once, cleanly
Medical AI must satisfy two regimes at once. We run them as one interlocked compliance programme, instead of producing the same evidence twice in two regulatory dialects.
The cybersecurity and risk-management requirements of MDR and IVDR are already in force. Medical software must meet them today. The EU AI Act adds a further layer on top for high-risk AI. Both regimes demand risk management, technical documentation and a quality management system, but with different focus and vocabulary.
We map the requirements onto each other once: a risk-management process that serves both regimes, a technical documentation set with the required AI Act components, a human-oversight concept that fits the clinical workflow, and a data-governance approach that makes training, validation and test data traceable.
We interlock the same work downwards with data protection: where health data is processed, we couple AI governance to the revised FADP and GDPR and run, where required, the data-protection impact assessment (DPIA) so that AI risk assessment and data-protection assessment do not drift apart.
Risk classification of the AI system under the AI Act
Technical documentation interlocked with the MDR/IVDR file
Concept for effective human oversight in the clinical workflow
Data governance for training, validation and test data
Coupling to the revised FADP/GDPR and, where needed, the DPIA
EU AI Act milestones for medical AI
Orientation, not legal advice. Several dates are still politically in motion. We verify timing and scope case by case.
Duty / regulation
What it requires
Timing
Status
Prohibited AI practices
Ban on certain AI uses; build AI literacy within the organisation
since 2025
in force
High-risk AI (medical devices)
Risk management, technical documentation, human oversight, data governance, robustness
from 2026/2027, deadlines under revision (Digital Omnibus)
verify case by case
MDR / IVDR cybersecurity
Security and risk-management duties for medical devices and IVDs
already in force
to be met today
Deployer obligations
Use per instructions, ensure human oversight, keep logs, train staff
with the high-risk duties
verify dates
EU Cyber Resilience Act
Security and vulnerability duties for connected products with digital elements
staggered 2026/2027
verify dates
Revised FADP / GDPR (DPIA)
Data-protection impact assessment for health data, coupled to the AI risk assessment
ongoing on material changes
in force
Three routes into AI Act compliance
AI Governance Check
from CHF 3'900
The entry point: legal risk classification and gap analysis of your medical AI against the AI Act, MDR/IVDR and data protection, with a board-ready report.
Risk classification of the AI system under the AI Act
Gap analysis against high-risk duties and MDR/IVDR
AI Act conformity is primarily a legal and governance task that culminates in technical measures. Purely technical providers start at the wrong end.
Classification is a legal question
Whether your system is high-risk and which duties apply turns on legal criteria. We perform this classification as doctorate-level lawyers with CIPP/E, backed by an in-house technical team that checks feasibility.
One documentation, two regimes
We write technical documentation that serves the AI Act and MDR/IVDR at once, instead of two separate file worlds. That saves effort and prevents contradictory statements towards notified bodies and authorities.
AI governance depth
With three dedicated AI services, AI Governance Check, AI Officer and AI Security, we span the arc from legal classification through the ongoing mandate to technical testing of the software layer.
Data protection built in
Because medical AI processes especially sensitive data, we couple AI governance to the revised FADP and GDPR and run the DPIA where required, from one partner, without handover loss.
Multilingual & independent
We advise in German, French and English, relevant for French-speaking Switzerland, EU parent companies and international approval bodies. Because we do not sell an in-house SOC, our recommendations stay independent.
Manufacturers and deployers
We know both roles: the manufacturer placing a high-risk system on the market, and the hospital buying and operating AI. So we advise both sides precisely and mediate between their duties.
Deployer or manufacturer, your role defines your duties
The EU AI Act clearly distinguishes those who place an AI system on the market from those who deploy it. Both carry duties, but different ones.
Manufacturers (providers) of high-risk AI bear the main load: risk management, technical documentation, quality management, conformity assessment, registration and post-market monitoring. For MedTech manufacturers this runs in parallel with MDR/IVDR conformity. This is exactly the interlock we solve.
Deployers, for example a hospital buying a diagnostic AI, a triage service, a clinical chatbot or an ambient-scribe system, have their own, often underestimated duties: use per the manufacturer's instructions, ensuring effective human oversight, keeping the required logs, training staff and informing affected persons where required.
Buying AI does not automatically transfer the manufacturer's conformity and can, through improper use, turn you into a provider yourself, with all the attendant duties. We clarify your role, review the manufacturer's assurances in the procurement contract and align your internal processes so that you stand on solid ground as a deployer.
Quick check: is your AI affected?
A few questions give you a first indication of whether your AI system could fall under the high-risk duties.
Why we work with LexCommand, our own Swiss legal AI
LexCommand is our in-house, citation-backed legal AI for the law of Switzerland, Germany, Austria and the EU. Developed and run sovereignly in Switzerland by Priverion GmbH, the company behind SIDD. We do not just preach data sovereignty and provability, we built them into our own tool, alongside the Priverion Platform.
01
Sovereign in Switzerland
The AI runs self-hosted on Swiss infrastructure, with no external cloud LLMs. As an independent Swiss company with no foreign parent, we process your documents in an environment we control.
02
No citation, no claim
Every legal statement traces back to a retrievable primary source, or it does not appear at all. That makes our recommendations auditable and verifiable, instead of merely sounding plausible.
03
From effort to judgement
LexCommand takes over searching, cross-checking and sourcing. That shortens turnaround times and frees our senior advisors for judgement and client dialogue, with no loss of diligence.
04
Three disciplines, one picture
We look at data protection, information security and AI security on a shared source base with a framework crosswalk. So you see overlapping obligations in one consolidated picture, instead of three isolated analyses.
For your interlocked technical documentation, concretely: LexCommand sets the duties from the EU AI Act, MDR/IVDR and revised FADP/GDPR side by side via crosswalk, so overlaps surface together and every line in the risk management and the DPIA traces to a cited primary source.
Temporally deterministic (as of today or any reference date), with jurisdiction isolation (CH/DE/AT/EU) and a citation verifier at the end of every answer.
Frequently asked questions
Is my medical AI really high-risk?
Often yes, but not always. Software that qualifies as a medical device or IVD, or is a safety component of one, typically falls into the high-risk category. The exact classification depends on intended purpose and function, we assess that in the AI Governance Check and the free triage tool.
We are a hospital and only buy AI, does the AI Act concern us?
Yes. As a deployer you have your own duties: use per the manufacturer's instructions, effective human oversight, log-keeping, staff training and, where applicable, informing affected persons. We align your internal processes accordingly and review the manufacturer's assurances in the procurement contract.
Do we have to document everything twice, for the AI Act and for MDR/IVDR?
No. Both regimes require risk management, technical documentation and quality management with large overlap. We map the requirements onto each other once and maintain interlocked documentation, instead of two separate file worlds.
Are the AI Act deadlines fixed?
Not all. Several timings for high-risk AI sit from 2026/2027 and are still politically under revision (Digital Omnibus). We verify the relevant timing for your system case by case and treat the table as orientation, not as guaranteed dates.
Do you also test our device firmware?
No. Our AI Security tests the software layer, LLM, RAG and agent components. Hands-on device-firmware testing we route to a specialised testing partner. Our strength is legally led governance and software-side testing.
Can you also act as external data protection officer for our AI?
Yes. Where medical AI processes especially sensitive data, we take on the role of external data-protection advisor under the revised FADP or DPO under GDPR and couple it to AI governance. This way, AI and data-protection assessments do not drift apart.
Ready to put your medical AI on solid legal ground?
Start with the AI Governance Check: legal risk classification and gap analysis against the AI Act, MDR/IVDR and data protection, with a board-ready report. Or try our free AI Act triage tool first.