By Rafael Luque Ocaña

AI medical devices: what changes on 2 August 2028 for manufacturers and for the clinics that use them

From 2 August 2028, the AI Act's high-risk rules reach AI medical devices that need a notified body. For the manufacturer it is one procedure, not two; for the clinic, Article 26, and not the FRIA.

On 2 August 2028, the AI Act's high-risk rules start to apply to a group of products that has been regulated for years: medical devices with AI that need a notified body. Two very different organisations are affected. The manufacturer, who already lives inside the medical device regulation and wants to know whether a second procedure is coming. And the clinic that uses the device, which wants to know what it will be asked to do, and what it won't.

The short answer: for the manufacturer it is one procedure, not two. For the clinic, it is the deployer obligations in Article 26, and not the FRIA.

Which devices: two conditions at once

The route is Article 6(1) of Regulation (EU) 2024/1689. An AI system is high-risk by this route when both conditions are met: it is a product, or a safety component of a product, covered by the legislation listed in Annex I; and that product has to undergo a third-party conformity assessment under that legislation.

Medical devices and in vitro diagnostic medical devices — Regulations (EU) 2017/745 and 2017/746 — are in Section A of Annex I, and the Digital Omnibus did not move them. The only change it made to Annex I was to take machinery out of Section A and put the new Machinery Regulation in Section B.

The second condition is the one that filters. Recital 51 explains it: being high-risk under the AI Act does not mean the device is high-risk under its own legislation, and the medical device regulations provide for third-party assessment of medium and high-risk products. In practice: AI software that the manufacturer can assess on its own, without a notified body, does not enter by this route.

Healthcare also has a second route to high risk, Annex III, point 5(d), for emergency triage, with its own date. We covered both routes in the post on private healthcare; this one stays with the first.

The date, and the systems already on the market

The date comes from Article 113, third paragraph, point (c)(ii), as amended by Regulation (EU) 2026/1744: Sections 1, 2 and 3 of Chapter III apply from 2 August 2028 to systems classified as high-risk under Article 6(1) and Annex I.

There is one nuance that changes the picture for anyone already selling or using these devices. Article 111(2), also amended, says that the Regulation applies to operators of high-risk systems placed on the market or put into service before the date of application of Chapter III only if, from that date, those systems are subject to significant changes in their design. For an Annex I device, that date is 2 August 2028. The exception is systems intended to be used by public authorities, whose providers and deployers must comply by 2 August 2030 at the latest. We explain the mechanism, and why the type and model matter, in the post on the grace period.

The manufacturer, who is the provider

First, who the provider is. Under Article 25(3), for high-risk systems that are safety components of products covered by Annex I, Section A, the product manufacturer is considered the provider when the AI system is placed on the market together with the product under the manufacturer's name or trademark, or put into service under that name after the product has been placed on the market.

One procedure. Article 43(3), in the wording that Regulation (EU) 2026/1744 gave it, is clear:

"For high-risk AI systems covered by the Union harmonisation legislation listed in Section A of Annex I, the provider of the system shall follow the relevant conformity assessment procedure as required in accordance with the relevant Union harmonisation legislation. The requirements set out in Section 2 of this Chapter shall apply to those high-risk AI systems and shall be part of that assessment."

It is not a second procedure: it is the medical device procedure, with the AI requirements inside. The same paragraph adds the assessment of the quality management system of Article 17, and that notified bodies under the medical device legislation may assess compliance with Section 2, subject to conditions. It also clarifies that classification as high-risk under Article 6(1) does not oblige the manufacturer to choose a procedure with a third party if the medical device legislation does not require one.

Integrated documentation and monitoring. Three provisions point in the same direction:

  • Article 11(2): for a system linked to a product in Annex I, Section A, a single set of technical documentation is drawn up, with the AI Act information and the information that legislation requires.
  • Article 8(2): the provider may integrate the testing, reporting, information and documentation into the procedures and documentation that the medical device legislation already requires.
  • Article 72(4): where a post-market monitoring system and plan already exist under that legislation, the provider may integrate the AI Act elements into them, as long as the level of protection is equivalent.

Serious incidents. Article 73(10) limits the notification under the AI Act, for systems that are medical devices or safety components of them, to the incidents in Article 3, point (49)(c) — infringements of obligations under Union law intended to protect fundamental rights — and it is made to the national competent authority chosen for that purpose by the Member State where the incident occurred.

The clinic, which is the deployer

For the clinic, the AI system becomes a high-risk system that it uses under its authority, and Article 26 applies to it from 2 August 2028 for these Annex I systems. The duties that matter in a clinic:

  • Article 26(1): take appropriate technical and organisational measures to use the system in accordance with its instructions for use.
  • Article 26(2): assign human oversight to natural persons who have the necessary competence, training and authority.
  • Article 26(5): monitor the operation of the system on the basis of the instructions for use and, where there is reason to consider that it presents a risk, inform the provider or distributor and the market surveillance authority, and suspend use; a serious incident is reported immediately, first to the provider and then to the importer or distributor and the market surveillance authority. If the clinic cannot reach the provider, Article 73 applies mutatis mutandis.
  • Article 26(6): keep the logs that the system generates automatically, to the extent they are under its control, for a period appropriate to the intended purpose and of at least six months, unless other law provides otherwise.
  • Article 26(12): cooperate with the competent authorities in any action they take in relation to the system.

What does not apply to the clinic

The FRIA. Article 27(1) only covers the high-risk systems referred to in Article 6(2), that is, Annex III. A system that is high-risk under Annex I is outside its scope, so the fundamental rights impact assessment is not an obligation for a clinic using an AI medical device.

The provider's obligations. The quality management system (Article 17), the conformity assessment (Article 43), the technical documentation of Annex IV, post-market monitoring (Article 72) and serious incident reporting under Article 73 belong to the manufacturer. The clinic informs; it does not take over the provider's role.

What already applies today

Two things do not wait for 2028:

  • Article 4, in force since 2 February 2025: providers and deployers take measures to support the AI literacy of the people who operate the systems on their behalf, taking into account their knowledge, experience and training, the context of use and the persons on whom the systems are used. The Article itself states that it does not require any specific level of AI literacy of any individual. More in the post on Article 4 after the Omnibus.
  • The GDPR. These devices process health data, a special category under Article 9. Article 35(3)(b) requires a data protection impact assessment where special categories are processed on a large scale; outside that case, it has to be assessed whether the processing is likely to result in a high risk, and the AEPD's list requires one where two or more of its criteria are met.

What makes sense to do before 2028

No invented calendar: the date is the one above, and the work is what each role already knows how to do.

If you manufacture:

  • bring the requirements of Section 2 of Chapter III into the technical documentation and the quality management system that the medical device regulation already requires;
  • decide how the AI Act elements fit into your existing post-market monitoring plan;
  • record, for each type and model, when it was first placed on the market, and which design changes count as significant.

If you are a clinic:

  • keep an inventory of the AI systems you use, with the manufacturer and the instructions for use on file;
  • classify each one and record the route: Annex I, and its section, where that is the case;
  • prepare the base of Article 26: who exercises human oversight of each system, how long the logs are kept and who handles communications with the manufacturer.

Where Alethexis comes in

In the platform's dental clinic demo, the AI systems are inventoried with their classification, and the classification records the route — Annex I or Annex III — and, for Annex I, its section. A manufacturer that registers its own product sees, in the product block, the provider's high-risk rows for that product, separate from the deployer's controls. Neither replaces the notified body's assessment or the manufacturer's documentation: they keep the decisions and the evidence in one place, with the date of their last review.

Content in accordance with Articles 4, 6, 8, 11, 25, 26, 27, 43, 72, 73, 111 and 113, and Annex I, of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (Official Journal of the EU, 24 July 2026).

This article is for informational purposes only and does not constitute legal advice.

Frequently asked questions

Does every AI medical device become high-risk on 2 August 2028?

No. Under Article 6(1), the device has to be covered by Regulation (EU) 2017/745 or 2017/746 and, in addition, require a third-party conformity assessment under that legislation. A device the manufacturer can assess without a notified body does not enter by this route.

Does the manufacturer go through two conformity assessments?

No. Article 43(3) sends the provider to the procedure required by the medical device legislation, and the AI Act requirements in Section 2 of Chapter III form part of that assessment.

Does a clinic that uses an AI medical device have to carry out a FRIA?

No. Article 27(1) only covers the high-risk systems referred to in Article 6(2), that is, Annex III. A system that is high-risk under Annex I falls outside its scope.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Data protection — newsletter

Controller: ALETHEXIS, S.L. (NIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Recipients and transfers: we use providers acting on behalf of Alethexis for hosting, security and email delivery. No disclosure of your data to third parties for their own purposes is planned, except where required by law. Some providers may process data outside the EEA with the safeguards set out in the additional information. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es) or with the supervisory authority of your Member State (Article 77 GDPR). More information in the privacy policy.