Risk Pyramid: Assessing AI Compliance for Medical Devices

DIA Europe: Assessing AI Compliance in Medical Devices

At the recent DIA Europe 2025 conference held in Basel, Switzerland, experts discussed the implications of the EU’s Artificial Intelligence Act for medical device manufacturers. A significant focus was placed on the use of a risk pyramid to determine the classification of medical devices and their necessity for conformity assessments by notified bodies.

The Risk Pyramid Explained

According to regulatory strategy specialists, the risk pyramid is pivotal for understanding whether a device is classified as high-risk. The pyramid categorizes AI applications based on their potential risks, ranging from minimal-risk devices at the base to unacceptable-risk systems at the apex. Systems classified as unacceptable risk, which include harmful AI-based manipulation or social scoring, are prohibited under the act.

Medical devices leveraging AI-embedded software for diagnosis or detection of abnormalities are considered high-risk and necessitate assessment by a notified body. On the other hand, devices categorized as limited-risk do not diagnose or detect abnormalities but must still comply with specific transparency obligations under the AI Act.

Implementation Timeline

The AI Act officially came into effect on August 1, 2024, and will begin to apply to products with high-risk applications from August 2, 2026. This includes medical devices classified in the Class IIa category or higher. A broader application of the regulations is anticipated by August 2, 2027, with full implementation expected by December 31, 2030.

Regulatory Requirements for High-Risk AI Systems

Manufacturers of high-risk AI systems must adhere to several stringent requirements prior to placing their products on the market. These include:

  • Conformity Assessment: A thorough evaluation of the AI system must be conducted.
  • Labeling Requirements: Products must display essential information, including the manufacturer’s name, registered trade name, trademarks, contact address, and CE marking.
  • Risk Management Teams: Teams should be established to assess the AI system throughout its lifecycle.
  • Technical Documentation: Manufacturers are required to maintain comprehensive records regarding the AI system’s performance and safety over time.

Experts emphasized that while the AI regulations may be novel, the integration of AI into medical devices has been in practice for some time. The transition to compliance is largely seen as an administrative exercise focused on organizing the necessary documentation.

Future of AI in Medical Technology

As the industry prepares for a new wave of applications utilizing advanced AI tools, the emphasis on non-invasive technologies to diagnose diseases is evident. For instance, a notable application is the LiverMultiScan software, which has received both FDA clearance and EU CE marking. This software serves as a non-invasive alternative to liver biopsies, using algorithms to assess liver health through MRI scans.

Such advancements highlight the significant role of AI in transforming medical diagnostics, offering more accurate and less invasive options for patients.

As the landscape evolves, manufacturers are urged to stay informed and ready for the compliance challenges that lie ahead under the EU’s AI regulations.

More Insights

Revolutionizing Drone Regulations: The EU AI Act Explained

The EU AI Act represents a significant regulatory framework that aims to address the challenges posed by artificial intelligence technologies in various sectors, including the burgeoning field of...

Revolutionizing Drone Regulations: The EU AI Act Explained

The EU AI Act represents a significant regulatory framework that aims to address the challenges posed by artificial intelligence technologies in various sectors, including the burgeoning field of...

Embracing Responsible AI to Mitigate Legal Risks

Businesses must prioritize responsible AI as a frontline defense against legal, financial, and reputational risks, particularly in understanding data lineage. Ignoring these responsibilities could...

AI Governance: Addressing the Shadow IT Challenge

AI tools are rapidly transforming workplace operations, but much of their adoption is happening without proper oversight, leading to the rise of shadow AI as a security concern. Organizations need to...

EU Delays AI Act Implementation to 2027 Amid Industry Pressure

The EU plans to delay the enforcement of high-risk duties in the AI Act until late 2027, allowing companies more time to comply with the regulations. However, this move has drawn criticism from rights...

White House Challenges GAIN AI Act Amid Nvidia Export Controversy

The White House is pushing back against the bipartisan GAIN AI Act, which aims to prioritize U.S. companies in acquiring advanced AI chips. This resistance reflects a strategic decision to maintain...

Experts Warn of EU AI Act’s Impact on Medtech Innovation

Experts at the 2025 European Digital Technology and Software conference expressed concerns that the EU AI Act could hinder the launch of new medtech products in the European market. They emphasized...

Ethical AI: Transforming Compliance into Innovation

Enterprises are racing to innovate with artificial intelligence, often without the proper compliance measures in place. By embedding privacy and ethics into the development lifecycle, organizations...

AI Hiring Compliance Risks Uncovered

Artificial intelligence is reshaping recruitment, with the percentage of HR leaders using generative AI increasing from 19% to 61% between 2023 and 2025. However, this efficiency comes with legal...