Healthcare · Clinical AI

MDR and AI Act, joined up.

Clinical AI sits in the overlap: medical device under MDR, high-risk AI system under the Act. Veritome is built around that overlap — shared evidence between technical files, FRIA where Annex III §5 says it's mandatory, and a deployer journey hospitals can actually run without a Chief AI Officer.

Run the readiness checkTalk to us

No credit card · EU-hosted · 5-min

What clinical leaders ask

Three places the regulations actually pinch.

Our notified body wants AI Act conformity referenced in the MDR technical file.

Annex IV technical doc is built modularly — sections reusable as MDR technical-file annexes. One source of evidence, two regulations.

We're a hospital deploying vendor radiology AI. What do we actually owe?

Deployer obligations under Art. 26 + Art. 27 (FRIA where applicable) are the materialised set. The wizard reads your role and skips the provider-only items.

FRIA is new. We don't have a template, and our DPIA isn't a substitute.

FRIA wizard runs when the system is Annex III §5 and you're a public-services / public-impact deployer. Auto-skipped where the law doesn't require it.
What changes for clinical AI

Built for the regulation that shares evidence with another.

MDR + AI Act overlap

Annex IV sections (training data, performance metrics, post-market surveillance) reusable as MDR technical-file annexes. Same hash, same trust.

Annex VII pathway support

Most clinical AI lands in §1 biometrics or as MDR-class device — Annex VII (notified body) is the default, and the Art. 43 wizard locks the choice.

FRIA wizard

Fundamental Rights Impact Assessment for Annex III §5 deployers. Clinical context built into the prompts; auto-skipped on private deployments.

Deployer journey

Hospitals are deployers, not providers. The journey reflects that — IFU receipt, oversight plan, monitoring, worker notification — without provider-only obligations cluttering the dashboard.

Vendor → hospital IFU handoff

Vendors send a sealed IFU package; the hospital paste-imports it. Hash chain links the deployer's record back to the vendor's seal.

Periodic review for clinical safety

Art. 9(8) review schedule integrates with clinical-governance review cycles. Annual, post-incident, on-substantial-change — all captured.

In practice

Three clinical contexts.

USE CASE 01

A medical-AI vendor selling diagnostic imaging software into EU hospitals.

  • Annex III §1 biometric-adjacent classification; Annex VII pathway (notified body) locked.
  • Annex IV technical doc reused as MDR technical-file annex — one source of truth, two regulators.
  • Art. 13 IFU package built once, sealed, sent per hospital with a unique sharing token.
  • Public verify URL on the dossier — procurement teams check the seal before raising a PO.
Veritome Annex IV technical-file builder — eleven sections assembled from live system data with a hash-sealed export
USE CASE 02

A 600-bed hospital deploying vendor AI for radiology and cardiology.

  • Deployer role detected; provider-only obligations hidden from the dashboard.
  • Each system's IFU paste-imported from the vendor; oversight plan auto-templated from the imported fields.
  • FRIA runs because the system reaches end-users; clinical-governance committee is the assessor.
  • Worker notification (Art. 26(7)) tracked for radiographers and cardiologists.
Veritome Article 13 Instructions-for-Use package — provider identity, intended purpose and the nine required elements for provider-to-deployer handoff
USE CASE 03

A lifesciences group with internal AI for drug-discovery + external AI deployed in clinical operations.

  • Multi-org architecture separates the R&D provider obligations from the operational deployer obligations.
  • Internal models classified mostly Limited Risk (research use); operational systems classified High-Risk under §5/§6.
  • AI literacy programme covers both research scientists and clinical operations, tracked separately.
  • Group-level dossier rolls up to the audit committee; per-subsidiary dossiers used for inspections.
Veritome obligation workbench — engine-derived obligations across the six-phase journey, filterable by phase and system with per-item status
What clinical leans on

The capabilities that map to MDR-shaped governance.