Medical products, diagnostic processes and clinical decision-making systems must balance precision and safety, especially as technological advancements enter the market. Artificial intelligence (AI) continues to reshape the industry’s understanding of both and, as new technologies integrate deeper into patient care, global regulators are responding by raising expectations — and establishing requirements — for safety, transparency and accountability. The European Union (EU) AI Act, now adopted and progressively entering into force, signals a shift from aspiration to enforcement, even as certain technical implementation details continue to evolve.
These new regulations represent important steps toward increasing patient safety while also placing the onus on manufacturers. Waiting for final regulatory details is no longer a viable strategy. Organizations that delay preparation risk losing momentum in the market. Establishing a competitive advantage depends on proactively demonstrating the readiness, control and trustworthiness of your AI-enabled medical products before formal enforcement of the requirements.
An overview of the EU AI Act in brief
The EU AI Act introduces a strict, risk-based framework that categorizes AI systems based on their potential to cause harm. Under this architecture, most AI-enabled medical products fall into the high-risk category, which leads to a comprehensive suite of legal and technical obligations that manufacturers must satisfy before entering the EU market.1 However, it is essential to understand that this legislation complements rather than replaces existing regulatory frameworks. These frameworks include:
- The Medical Devices Regulation (MDR)
- The In Vitro Diagnostic Medical Devices Regulation (IVDR)
- The General Data Protection Regulation (GDPR)
The new act extends oversight into AI-specific risks, such as algorithmic drift, data bias and lack of explainability.1 While some implementing guidance, codes of practice, and harmonized standards continue to evolve, the AI Act’s regulatory obligations and application timelines are now firmly established. The signal is clear: AI accountability is a baseline expectation, not a future ambition. And now is the time to take significant steps forward.
Understanding the timelines: phased enforcement, rising expectations
The EU AI Act is being implemented through a phased timeline. The compliance deadline for standalone high-risk AI systems (Annex III) has been extended from August 2, 2026 to December 2, 2027. For high-risk AI systems embedded in regulated products under Annex I, including medical devices and in vitro diagnostic (IVD) devices, the deadline has been deferred from August 2, 2027 to August 2, 2028.
The staged implementation model established for the EU AI Act provides a structure that reflects the complexity of operationalizing AI governance at scale across diverse industries. For manufacturers of AI-enabled medical products, this approach allows for gradual implementation but does not represent a pause on enforcement. Regulatory focus and market surveillance are already sharpening around three core pillars:
- AI risk management and technical documentation – Establishing continuous, life cycle-wide processes to identify and mitigate algorithmic failures.
- Conformity assessment preparedness – Integrating AI-specific compliance obligations directly into existing product compliance pipelines and quality management systems (QMS).
- Post-market monitoring – Implementing mechanisms for incident reporting, feedback loops and continuous performance oversight.
The design, documentation and governance decisions made today will directly affect conformity assessment readiness and market access as the updated applicability date approaches. Organizations waiting for perfect clarity risk compressing years of foundational engineering and documentation work into months of reactive, high-stress effort.
Preparing for AI Act compliance
Compliance under the EU AI Act is an ongoing, dynamic demonstration of transparency and performance. Even as secondary guidance evolves, manufacturers and suppliers must be capable of providing objective, auditable evidence across several critical areas.
Core compliance evidence
Predictable and robust AI behavior across all intended use conditions – Manufacturers must move beyond laboratory performance metrics and prove their models maintain a high level of accuracy, robustness and cybersecurity under real-world clinical conditions. This requires documented evidence of:
- Stress testing and edge cases
- Drift monitoring metrics
- Hardware interoperability
Well-governed data pipelines with bias risks identified and mitigated – High-risk AI medical products demand rigorous data governance practices across the entire data life cycle, from initial ingestion to deployment. To satisfy regulatory expectations, your technical documentation must highlight data provenance, quality and transparency along with bias detection, privacy compliance and mitigation frameworks. Article 10 in the EU AI Act allows providers to collect and use sensitive data, but the language clearly focuses on bias detection and correction to enable de-biasing while protecting the sensitive nature of this information.2
Clear human oversight mechanisms and traceable decision logic – Article 14 of the Act specifies that AI systems must be designed so humans can oversee functionality, and this oversight must correspond to the risks and use of the system.2 For medical product designers, this means embedding user interfaces and logging protocols that explicitly empower healthcare providers to understand, disregard, override or reverse the AI’s outputs or recommendations.
Secure and resilient AI components throughout the entire product life cycle – AI-enabled medical devices must be inherently resilient against operational failures, hardware faults and malicious exploits. Cybersecurity, life cycle management and fail-safe instructions that minimize risk support this effort.
Throughout this transitional period, organizations must look beyond the letter of the text to the underlying safety science principles of robustness, non-discrimination and accuracy.
How manufacturers can prepare now
Market leaders often treat regulatory uncertainty as a catalyst for early action rather than a reason to wait. At UL Solutions, we encourage this approach as it can help build a strong compliance posture as you prepare for future requirements.
Before the AI Act requirements become applicable to most AI-enabled medical devices, you can identify and categorize all AI systems across your product portfolio to determine legal exposure. This will provide you with a comprehensive understanding of what parts of your business may be affected. You should also benchmark current engineering practices and documentation against expected high-risk AI requirements and adjacent medical device obligations to identify current gaps that may become obstacles.
A review of your data, and the processes surrounding it, should also take place. Your organization can begin to integrate data governance, risk management and algorithmic monitoring into your existing ISO 13485 quality life cycles and software development workflows. Part of this process should involve an evaluation of training data quality and model performance early in the design phase.
Why independent assessment matters for AI Act preparedness
Independent assessments help provide the objectivity, consistency and confidence required to help you navigate ambiguous regulatory landscapes as requirements and standards are emerging. Third-party validation helps you de-risk development pipelines by providing an unbiased evaluation of AI safety, robustness and life cycle risk before submitting files to notified bodies. Leveraging independent evaluation also aligns your internal processes with internationally recognized best-practice standards, such as ISO/IEC 420013. This proactive alignment helps you build trust with regulators, notified bodies, healthcare providers and patients.
UL Solutions applies decades of safety science expertise to assessment of AI-enabled technologies. This experience helps us support your responsible innovation even during complex regulatory evolution. Programs such as UL 3115, the Outline of Investigation for Safety of AI-Based Products, help manufacturers demonstrate compliance to safety, performance and related requirements as regulatory expectations solidify around AI-enabled medical products.
From regulatory readiness to market leadership
Demonstrating strong AI governance sends a powerful signal that reaches across legislative timelines and helps overcome hesitancy from risk-averse procurement departments. Early investment also encourages stronger, more collaborative engagement with notified bodies, helping to streamline approval pathways. Ultimately, acting now will help you manage compliance with EU AI Act requirements and define how trusted AI looks in the healthcare sector.
Acting early is the AI advantage
The EU AI Act has already transformed the operational realities of AI-enabled medical products. The period leading up to the revised compliance deadlines provides organizations with an opportunity to strengthen governance, documentation, risk management, and post-market monitoring capabilities before the requirements take effect. However, this timeline should not be viewed as an opportunity to pause compliance efforts or delay internal change. Before regulations fully set in, now is the time to better understand your processes and products. With the right frameworks, robust governance foundations and independent safety science support, you can turn regulatory uncertainty into operational clarity as compliance becomes a point of differentiation.
Contact UL Solutions today to start assessing your AI readiness and positioning your organization to manage compliance under upcoming regulatory changes.
References
European Parliament. (2024). Artificial Intelligence Act. Regulatory Framework for AI. https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
van Bekkum, M. (2025). Using sensitive data to de-bias AI systems: Article 10(5) of the EU AI act. Computer Law & Security Review, 56, 106115. https://doi.org/10.1016/j.clsr.2025.106115
International Organization for Standardization. (2023). Information technology — Artificial intelligence — Management system (ISO/IEC Standard No. 42001:2023).
Get connected with our sales team
Thanks for your interest in our products and services. Let's collect some information so we can connect you with the right person.