When the Device Thinks: AI/ML in Trial DHTs and the Stacking of Obligations
How an on-device model adds an AI overlay on top of the device rules — and why the 2028 application date is a trap, not a reprieve.
An on-device model that produces a clinical inference is regulated twice — as medical device software and as high-risk AI. The regimes stack; they do not substitute.
The device-embedded high-risk date is fixed at 2 August 2028, but the evidence the AI Act assesses — data governance, technical documentation, human-oversight design — is generated during development and cannot be reconstructed. Decide the AI question in the RIA before model lock; build the artifacts now.
Three regimes stack on one model — MDR / IVDR, AI Act, FDA lifecycle
Is the software a device, and what class? Conformity assessment, technical file, clinical evaluation.
Once Art. 6(1) is met: risk management, data governance, tech file, logging, oversight (Arts. 9–15, 17, 72)
Total-product-lifecycle approach (draft, Jan 2025) and Predetermined Change Control Plans (final, Aug 2025).
Four positions that turn "not yet" into "now"
Article 6(1) has two cumulative conditions: the AI is, or is a safety component of, an MDR / IVDR device, and that device needs third-party conformity assessment. Class IIa and up qualify.
The research exclusions (Art. 2(6), 2(8)) do not cover testing in real-world conditions, and MDCG 2025-6 treats a clinical investigation of medical-device AI as exactly that.
Regulation (EU) 2026/1744 fixed 2 August 2028 for device-embedded AI. The artifacts it assesses are produced two to three years earlier; a model built without them cannot acquire them.
A substantial modification needs new conformity assessment unless pre-determined in the technical documentation (Art. 43(4)); in the US, a PCCP. An unplanned retrain breaks validation.
Five deployment facts, each answered by evidence built pre-lock
- 1Run the RIA to fix device status and class; apply the Article 6(1) test and scope the high-risk duties early.
- 2Build the AI Act technical documentation and data-governance records alongside the MDR technical file — one set (Art. 11(2)).
- 3Agree a PCCP up front — modifications, modification protocol, impact assessment — and pre-determine changes in the EU file.
- 4Document training, validation and test data governance (Art. 10) and test transfer to the enrolled population (QPP-01).
- 5Design human oversight in where output is acted on without clinician review; record the oversight measures and decision pathway.
EU MDR / IVDR · EU AI Act, Reg. (EU) 2024/1689 as amended by Reg. (EU) 2026/1744, Arts. 2, 6(1), 8–15, 17, 43, 72 · MDCG 2025-6 · FDA AI lifecycle draft (Jan 2025) · FDA PCCP guidance (Aug 2025) · COM(2025) 1023
© qointa 2026 – Public – Uncontrolled when printed · Not legal advice; this summary does not classify any device.
sales@qointa.com · qointa.com
More from the library
Digital Health Technologies in Clinical Trials — A Regulatory Position-Paper Series
One device, several perimeters: a framework for assessing the regulatory impact of the technologies a trial relies on.
Read more →Who Is the Manufacturer? Economic-Operator Roles in DHT Supply Chains
How provisioning, importing, kitting and modifying a device assign manufacturer, importer and distributor duties — often by operation of law.
Read more →You Can Delegate the Work, Not the Accountability: Vendor Qualification and Oversight under ICH E6(R3)
The sponsor’s duty to qualify and oversee its DHT vendors — distinct from who holds the economic-operator role.
Read more →Talk to a specialist
Bring one device and one protocol — a wearable, a sensor, an app, anything. We will tell you which regulatory perimeters it opens and what it takes to close them.
Book a 15-minute call