EU AI ACT · OPERATING ENVIRONMENTKnow what applies · prove why · preserve change? LEARN THIS PAGE
EU AI ACT · HEALTHCARE · MEDICAL DEVICES · CLINICAL AI

IN HEALTHCARE, THE QUESTION ISN’T JUST
WHETHER THE MODEL WORKS.

Medical and clinical AI sits where technical performance, product regulation, human oversight, patient safety, and evidence continuity meet. The business needs to know what the AI is, what regulated product it belongs to, what decision it influences, and whether the current evidence still supports that use.

BOUNDARYThis page is educational and operational guidance. It is not legal advice, certification, conformity assessment or regulatory approval.
CURRENT SOURCE ANCHOR

EUR-Lex · Regulation (EU) 2024/1689 · Article 6, Annex I and High-Risk Requirements

Article 6 classifies certain AI systems as high-risk when they are products or safety components covered by Annex I legislation and subject to third-party conformity assessment. The Regulation specifically includes medical devices and in vitro diagnostic medical devices among the relevant product categories and requires continuing risk management and other high-risk controls.

OPEN OFFICIAL EU SOURCE ↗
WHAT BUSINESSES NEED TO ESTABLISH

Do not start with a generic checklist.

Start with the actual system, role, use case and evidence boundary. The same regulation can produce different obligations for different actors and systems.

01

IS THE AI ITSELF A MEDICAL DEVICE OR A SAFETY COMPONENT?

Article 6 can classify AI as high-risk when it is a product, or a safety component of a product, covered by Annex I legislation and the product requires third-party conformity assessment. Medical devices and in vitro diagnostic medical devices are specifically included in that product framework.

02

IS THE SYSTEM SUPPORTING A CLINICAL OR HEALTH DECISION?

Clinical decision support, diagnostics, triage, treatment recommendations, monitoring, prioritization, and other health-related uses should be classified by intended purpose and actual decision role—not by the fact that the product uses AI.

03

WHAT HUMAN OVERSIGHT AND RISK CONTROLS EXIST?

For high-risk systems, the Act requires a continuous risk-management process and human-oversight measures appropriate to the intended purpose. Preserve who can review, override, interrupt, or refuse reliance on the AI output.

04

CAN THE EVIDENCE SURVIVE A MODEL OR WORKFLOW CHANGE?

Healthcare systems evolve. Preserve versions, validation data, performance evidence, risk controls, instructions, post-market information, material changes, and the revalidation basis so an old clinical claim does not silently attach to a new system state.

THE TA-14 OPERATING ROUTE

Turn the question into a governed record.

The goal is not merely to reach an answer. It is to preserve what facts, evidence, scope and limitations supported that answer at that time.

01

Define the regulated product and AI system boundary

Separate the medical device or IVD, the AI component, external models, cloud services, clinical workflow, and downstream human decision. The correct boundary determines which product and AI Act obligations attach.

02

Classify under Article 6 and intended purpose

Determine whether the system enters the Annex I product route, an Annex III route, or another obligation pathway. Preserve the basis for the classification rather than relying on a generic “healthcare AI” label.

03

Bind risk, performance, oversight and documentation evidence

Connect risk management, technical documentation, validation, data governance, logging, instructions, human oversight, accuracy, robustness, cybersecurity, and post-market evidence to the claims they support.

04

Revalidate after clinical, technical or regulatory change

A changed model, dataset, intended purpose, indication, workflow, threshold, user population, product integration, or legal-source state can change whether yesterday’s evidence remains admissible for today’s use.

READY TO OPERATE · START PAID ACCESS NOW

Choose the smallest operating tier that fits the portfolio today. Upgrade when system count, team size or governance scope actually requires it.

1–3 AI systems

Evidence Passport

$19/MO

Keep a living system-level evidence record with obligations, gaps, versions and revalidation state.

START EVIDENCE PASSPORT
Up to 10 AI systems

Compliance Workspace

$49/MO

Coordinate evidence, owners, documentation, incidents and team compliance work in one governed workspace.

START COMPLIANCE WORKSPACE
Up to 25 AI systems

Governance Pro

$99/MO

Operate broader high-risk, GPAI, FRIA, post-market and material-change governance across a growing portfolio.

START GOVERNANCE PRO
Up to 50 AI systems

Institution

$499/MO

Run institutional governance with expanded users, authority workflows, examiner rooms and portfolio reporting.

START INSTITUTION
Need an independent human readiness examination?A governed readiness review is separate from software access and starts at $750.
REQUEST READINESS REVIEW →
START WITH ONE SYSTEM

Not ready to subscribe? Classify first.

Use the free classifier to establish the system, intended purpose, possible actor role, EU exposure and unresolved facts. When continuing evidence infrastructure is needed, paid access begins at $19 per month. Independent human readiness review remains a separate service.

COMMON QUESTIONS

Questions businesses are asking now.

Are medical-device AI systems high-risk under the EU AI Act?

They can be. Article 6 treats an AI system as high-risk when it is a product, or a safety component of a product, covered by Annex I legislation and the relevant product requires third-party conformity assessment. Medical devices and in vitro diagnostic medical devices are included among those product categories.

Does “high-risk under the AI Act” mean the medical device itself is high-risk under MDR or IVDR?

Not necessarily. The Regulation expressly distinguishes AI Act high-risk classification from the risk classification used in the relevant product legislation. The two regimes can apply together without using the same risk labels.

What does the AI Act require for high-risk healthcare AI?

Among other requirements, high-risk systems are subject to risk management, data governance, technical documentation, record-keeping, transparency and instructions for use, human oversight, and requirements relating to accuracy, robustness and cybersecurity.

What is especially important for clinical decision support?

The intended purpose and degree of influence over the clinical decision are critical. Organizations should preserve the system’s role, performance evidence, limitations, human-review requirements, escalation paths, and the exact conditions under which outputs may or may not be relied upon.

Can healthcare AI rely on the same evidence forever once validated?

No. Model updates, new data, changed clinical workflows, new patient populations, revised thresholds, changed intended purpose, or altered product integration can make prior validation or classification evidence stale.

Does TA-14 certify a healthcare AI system as compliant?

No. TA-14 can preserve the classification basis, evidence, gaps, review history, change events, and revalidation state. It does not itself provide legal advice, medical-device conformity assessment, certification, or regulatory approval.

EU AI ACT WORLD · TA-14 AUTHORITY GOVERNANCE INSTITUTION

Understand the requirement. Preserve the evidence. Revalidate when reality changes.

TA-14 Exchange Activity

Public network activity

Live cumulative activity recorded across the public Exchange surface.

Refreshing public totals

···

Visitors

Recorded public visitors

···

Page Views

Recorded Exchange views