Healthcare · Clinical AI

MDR and EU AI Act, joined up.

Clinical AI sits in the overlap: a medical device under the MDR, a high-risk AI system under the Act. Veritome is built around that overlap — shared evidence between technical files, the FRIA where Annex III says it applies, and a deployer journey a hospital can run without a chief AI officer.

No card · EU-hosted · 5 minutes to a first classification
Veritome assessments — FRIA, DPIA and conformity assessments per system, with their status and sealed reports
What clinical leaders ask

Three places the regulations actually pinch.

What we hear

Our notified body wants EU AI Act conformity referenced in the MDR technical file.

What the product does

Annex IV is built in sections, each reusable as an MDR technical-file annex. One source of evidence, two regulations.

What we hear

We're a hospital deploying vendor radiology AI. What do we actually owe?

What the product does

The deployer set — Art. 26, and Art. 27 where the FRIA applies. The classification reads your role and skips the provider-only items.

What we hear

The FRIA is new. We don't have a template, and our DPIA isn't a substitute.

What the product does

The FRIA runs when the system is Annex III and you deploy it in a public-services capacity; the DPIA overlap is mapped so shared questions are answered once.

What changes for clinical AI

Built for the regulation that shares evidence with another.

01

MDR and EU AI Act overlap

Annex IV sections — training data, performance, post-market surveillance — reusable as MDR technical-file annexes. Same hash, same trust.

02

Annex VII pathway support

Clinical AI usually reaches high-risk through the Annex I product route, so conformity follows your notified-body procedure. The Art. 43 step records which pathway applies.

03

FRIA with the DPIA mapped

The fundamental-rights impact assessment for Annex III deployers, with clinical context in the prompts and the DPIA overlap done once.

04

Deployer journey

Hospitals are deployers, not providers. IFU receipt, oversight plan, monitoring, worker notification — without provider-only obligations cluttering the dashboard.

05

Vendor to hospital IFU handoff

Vendors send a sealed IFU package; the hospital imports it. The hash chain links the deployer's record back to the vendor's seal.

06

Periodic review for clinical safety

The Art. 9 review schedule fits clinical-governance cycles — annual, post-incident, on substantial change.

In practice

Three clinical contexts.

Use case 01

A medical-AI vendor selling diagnostic imaging software into EU hospitals.

  • Annex I (MDR product) classification recorded; conformity runs through the device's notified body.
  • Annex IV reused as the MDR technical-file annex — one source of truth, two regulators.
  • The Art. 13 IFU package built once, sealed, sent per hospital with a unique sharing token.
  • A public verify URL on the dossier — procurement checks the seal before raising a purchase order.
Veritome Annex IV technical-file builder — sections assembled from live system data with a hash-sealed export
Use case 02

A 600-bed hospital deploying vendor AI for radiology and cardiology.

  • Deployer role detected; provider-only obligations hidden from the dashboard.
  • Each system's IFU imported from the vendor; the oversight plan templated from the imported fields.
  • The FRIA runs because the system reaches patients; the clinical-governance committee is the assessor.
  • Worker notification (Art. 26(7)) tracked for radiographers and cardiologists.
Veritome Article 13 instructions-for-use package — provider identity, intended purpose and the required elements for provider-to-deployer handoff
Use case 03

A life-sciences group with internal AI for drug discovery and external AI in clinical operations.

  • Separate organisations keep the R&D provider obligations apart from the operational deployer obligations.
  • Models used solely for scientific research sit outside the Regulation; operational systems are classified on their own facts.
  • The AI-literacy programme covers research scientists and clinical operations, tracked separately.
  • A group-level view for the audit committee; per-subsidiary dossiers for inspections.
Veritome obligations register — engine-derived duties with owners, dates and status
What clinical leans on

The capabilities that map to MDR-shaped governance.

Straight answers

Questions clinical teams ask

Our AI is already a medical device under the MDR. Does the EU AI Act add a second conformity assessment?

Usually not a separate one. Clinical AI reaches high-risk through the Annex I product route, so the EU AI Act conformity assessment travels with the MDR notified-body procedure. Veritome records which pathway applies at the Art. 43 step and reuses the Annex IV sections as the MDR technical-file annex.

A hospital deploying vendor AI — what do we actually owe?

The deployer duties: Art. 26 (use per the instructions, human oversight, logs, worker notification) and, where the system is Annex III and you act in a public-services capacity, the Art. 27 fundamental-rights impact assessment. The classification reads your role and skips the provider-only items.

Does patient data change the register?

Yes. Special-category health data brings GDPR Art. 9 and a DPIA into the system's register, and the FRIA and DPIA share their common parts so the assessment is done once. The ISO/IEC 27001 programme covers the information-security controls a hospital IT review expects.

Is a DPIA a substitute for the FRIA?

No. The FRIA is its own assessment under Art. 27, but where a DPIA exists the overlap is mapped so the shared questions are answered once and both records stay consistent.