AI used as a safety component of a medical device, or that is itself a medical device, is high-risk under Annex I. Clinical decision tools also fall under Annex III, point 5.
AI that assists clinicians in diagnosing conditions, recommending treatments, or prioritising patients based on clinical data.
Systems that analyse medical images, lab results, or patient records to detect disease, flag abnormalities, or suggest diagnoses.
AI that determines urgency of care, allocates hospital resources, or scores patient risk for emergency or surgical settings.
Systems that assess mental health conditions, predict deterioration, or recommend psychiatric interventions from behavioural patterns.
Administrative and operational AI generally won't trigger Annex III, unless it directly influences clinical outcomes for individual patients.
Even if your system isn't high-risk, Article 50 transparency may still apply. Run the free classifier to find out.
If your AI qualifies as a medical device under the MDR or IVDR, the AI Act conformity assessment integrates with your existing CE-marking process, and the notified body handling your MDR/IVDR assessment also evaluates AI Act compliance. So you won't need a separate assessment, but you do need the AI-specific documentation: bias testing, model accuracy records, and continuous post-market monitoring.
See the full regulatory overlap mappingEach must be in place before December 2, 2027. Non-compliance risks fines up to €15 million or 3% of global turnover.
Healthcare organisations handling patient data under GDPR already run data protection impact assessments and keep processing records. Those partially cover Article 10 (data governance) and Article 9 (risk management). You'll still need AI-specific work: model accuracy and bias testing, conformity assessment, and continuous post-market monitoring.
See the full GDPR overlap mappingThe classifier is free, no account required. Classify your system and start generating the compliance documentation you need.
Classify your AI system