Skip to main content
Skip to main content

When it comes to AI-based medical devices, Europe doesn't lack rules—it lacks a standard.

A new scoping review of 126 publications shows that the MDR, IVDR, and AI Act form a comprehensive framework; however, when it comes to learning systems, everything depends on practical, lifecycle-based implementation.

Certification of Learning AI Systems

AI systems are increasingly supporting diagnosis, prognosis, and clinical decision-making. In the EU, three sets of regulations—the Medical Device Regulation (MDR), the In Vitro Diagnostic Medical Devices Regulation (IVDR), and the Artificial Intelligence Act (AI Act)—interact to address these issues. While the MDR and IVDR were originally designed for traditional medical devices, the AI Act addresses specific requirements for AI systems. However, learning AI in particular changes its behavior over time—through updates, retraining, or “data drift.” Consequently, the practical implementation of these regulations remains challenging, particularly for learning and adaptive systems. This raises the question: How do you certify something that does not remain stable after approval?

We explored this question together with the German Accreditation Body (DAkkS)—led by Svenja Reisinger, a doctoral candidate at the Chair of Digital Public Health. For the scoping review, 126 publications from 2022 to 2025 were systematically evaluated, and the previously fragmented literature on risk-adjusted conformity assessment was systematically synthesized for the first time; the findings coalesce into six thematic areas, ranging from the interface between the AI Act and the MDR/IVDR, through risk classification and lifecycle governance, to liability and market surveillance.

The central finding is counterintuitive. The EU framework is considered comprehensive—the recurring gap lies not in a lack of rules, but in their operationalization. Principles such as robustness, fairness, and human oversight are required; however, uniform metrics and verifiable evidence to substantiate them are largely lacking. To put it bluntly, the framework is strong on principles but weak on metrics.

Specifically, a one-time conformity assessment is ill-suited to systems that are constantly changing, and unclear monitoring obligations risk shifting responsibility onto clinical staff, who can hardly verify the AI’s performance in day-to-day practice. It is also noteworthy that only 6 of the 126 studies (5%) are empirical. The field is well-developed normatively but thin on empirical evidence. Many “challenges” are, as of now, documented concerns rather than systematically observed findings.

This points to clear areas for action. Proportionality could be operationalized through harmonized evidence requirements regarding robustness, bias, and uncertainty. Similarly, clear lifecycle responsibilities are needed for monitoring, documentation, and the triggers for reassessment. Finally, the capacities of the notified bodies should be specifically strengthened, accompanied by practical guidance on how to integrate AI Act obligations into existing MDR/IVDR procedures.

Contact Person

Profilfoto von Professor Christoph Dockweiler