10 October 2026 · 21 min
Will the AI Act Break European Medtech? Inside the MDR/IVDR Revision
MedTech Europe's position paper outlines a critical juncture for medical device regulation in the EU. We unpack their proposed amendments to the MDR and IVDR, focusing on how AI should be regulated, the fight over cybersecurity reporting, and why one in three manufacturers is deprioritising the EU for product launches.
Key points
- One in three manufacturers is currently deprioritising the European Union for first regulatory approvals due to administrative burden and costs.
- MedTech Europe strongly supports embedding AI Act requirements into the MDR and IVDR to allow for a single conformity assessment, preventing dual-regulatory overlap.
- They propose a 12-month deadline for the European Commission to adopt delegated acts integrating high-risk AI requirements into existing safety frameworks.
- The position paper calls for structurally separating cybersecurity vulnerability reporting from traditional patient safety vigilance to avoid false alarms and regulatory confusion.
- For in vitro diagnostics, MedTech Europe wants the orphan device threshold changed from 1 in 12,000 to 5 in 10,000 to align with the established rare disease definition.
- The industry opposes a proposed regulatory shift that would make devices reusable by default, arguing that single-use engineering is fundamental to patient safety.
Source: MDR/IVDR Revision: A regulatory system at a crossroads - MedTech Europe, 2026
This spot is available. Reach clinicians, health-system leaders and medtech and pharma teams following AI in medicine. Sponsor the show
This episode is an AI-generated conversation summarising a public document; the hosts' voices are synthetic. It is for information only and is not medical advice. Always refer to the original source.
Transcript
Maya: Right now, one in three medical device manufacturers is actively deprioritising the European Union for their first regulatory approvals. That is a stunning statistic for what has historically been a premier launch market for medical innovation.
Sam: It is a massive shift. The EU used to be the default starting point for global medtech. So what exactly broke, and more importantly, how are they trying to fix it? And before we dive in, a quick reminder that our voices are AI-generated, and this is a summary of a public document.
Maya: We are going to answer exactly that today. We are unpacking a major position paper published by MedTech Europe on May 5, 2026. The document is titled MDR/IVDR Revision: A regulatory system at a crossroads. It lays out the industry's exact proposed amendments to the European Commission's plan to revise the medical device and in vitro diagnostic regulations.
Sam: And the stakes here are incredibly high. MedTech Europe represents an ecosystem of over 37,000 medical technology companies in Europe, and 90% of them are small and medium-sized enterprises, or SMEs. They are arguing that the current regulatory system is basically putting an existential strain on these smaller companies.
Maya: The numbers from the front lines of healthcare are honestly just as stark as the business metrics. According to the document, 1 in 2 clinicians has experienced issues with the availability of medical devices since the introduction of the MDR. Furthermore, 1 in 2 hospital pharmacists reports that medical device shortages constitute a problem in delivering the best care to patients.
Sam: Which totally explains why companies are looking elsewhere. The paper notes that approximately 60% of manufacturers cite administrative burden and costs of regulatory approval as the most important barrier to bringing innovative devices to the EU market. More than 70% have had to allocate additional resources just for regulatory compliance.
Maya: So, the European Commission has finally put forward a proposal to revise these regulations. MedTech Europe structures their response into three very distinct tiers. They have things they strongly welcome, things they want to strengthen to close implementation gaps, and things they are urging regulators to fundamentally rethink.
Sam: Let us start with the welcome tier. Simplification seems to be the core theme here, which makes sense given the administrative nightmare you just described.
Maya: Yes, MedTech Europe is strongly supporting the move to open-validity certificates with periodic risk-based reviews. Right now, devices go through fixed five-year recertification cycles. Removing that fixed timeline eliminates an artificial bottleneck for well-controlled, stable products. Instead, oversight will rely on ongoing surveillance and annual audits.
Sam: That makes total sense from a boardroom perspective. If a device has been perfectly safe on the market for five years, forcing a massive, redundant administrative review just because a calendar deadline hit does not actually make the patient any safer. It just clogs up the Notified Bodies.
Maya: Exactly. They also welcome the broader recognition of clinical evidence. The Commission's proposal explicitly recognizes what it calls a well-established technology device. But MedTech Europe wants a very specific legal amendment there. The Commission defined this as a device that has not been associated with safety issues in the past. MedTech Europe says that is far too vague.
Sam: How so? What is the fix they are proposing for that definition?
Maya: They want the term safety issues explicitly tied to Article 87 of the MDR. Without that specific cross-reference, the term safety issue could be interpreted so broadly that it leads to endless ambiguity and completely unnecessary discussions with Notified Bodies.
Sam: Got it. So it is about tightening the legal language to prevent regulatory creep. They also talk a lot about streamlined change control. This feels like a huge deal for engineering teams that are constantly trying to iterate and update their products.
Maya: It is a massive deal. The proposal makes a clearer distinction between product changes a manufacturer can just implement versus those requiring prior approval. But MedTech Europe wants to take it one step further. They want to limit mandatory pre-approval strictly to changes that could adversely affect the safety and performance of the device.
Sam: Wait, so if a company makes a design change that actually improves the safety of the device, they currently have to wait for a Notified Body to approve it before they can roll it out to patients?
Maya: In many cases, yes. MedTech Europe argues that if a change has a positive impact, like modifying a connector to reduce misconnections, or extending a shelf life based on solid post-market data, companies should be able to implement it immediately. The Notified Body would then review it later during an annual surveillance assessment.
Sam: That is a brilliant distinction. Focus the pre-market scrutiny on changes that might actually introduce new risks. It just seems like a much better allocation of everyone's time.
Maya: They actually point out that this risk-based approach is already embedded in European guidance, specifically citing documents known as MDCG 2020-3 and MDCG 2022-6. They just want it formally codified in the actual regulation to ensure harmonised interpretation across all Member States.
Sam: Let us pivot to software, because that is where things get incredibly complicated. There is a whole section here on the classification of medical device software, specifically Rule 11 of the MDR.
Maya: Rule 11 has been a massive thorn in the side of digital health companies. Under the current rule, a lot of software gets automatically up-classified without sufficient differentiation in its actual clinical impact. The European Commission has proposed amending this to provide wider possibility for software to be regulated in Class I when the actual patient risk is low.
Sam: Which means lower regulatory hurdles for simple, low-risk apps. But MedTech Europe says the Commission's new drafting is still too ambiguous, right?
Maya: Yes. MedTech Europe proposes an amendment that aligns the EU rules with the International Medical Devices Regulators Forum. They want to clearly expand Class I for low-risk software, but they are precise about the boundaries. For example, software intended to treat or diagnose in a non-serious situation is classified as Class IIa, while software handling serious or critical situations falls into Class IIb or Class III.
Sam: That brings us right into one of the most critical parts of this entire document, which is how they handle artificial intelligence. This is in the strengthen category, and it feels like the editor's top pick for a reason. Device manufacturers are terrified of getting caught between the medical device rules and the new AI Act.
Maya: And rightfully so. For decades, medical technology software, including AI, has been regulated under the medical devices or IVD framework. But the new AI Act introduces additional product requirements covering risk management, data governance, transparency, and human oversight. Applying both regimes in parallel would create massive points of friction.
Sam: So MedTech Europe is asking for a unified approach. They want to regulate the AI product requirements entirely under the IVDR and MDR, to ensure a single conformity assessment process.
Maya: Exactly. They are explicitly stating that this is not about deregulation. The AI safeguards will still exist. The relevant requirements from the AI Act simply need to be reflected in the General Safety and Performance Requirements of the MDR and IVDR, maintaining the same level of safety while eliminating duplication.
Sam: They actually point to the aviation sector as a working model for this, right? The European Union Aviation Safety Agency.
Maya: Correct. EASA integrates AI-specific requirements into its existing airworthiness and safety management framework rather than applying a separate, overlapping AI regime on top of sectoral product rules. MedTech Europe argues the exact same principle should apply to medical devices and diagnostics.
Sam: But they are asking for a very specific legal mechanism to make this happen, aren't they? They want a hard timeline forcing the Commission to act.
Maya: They do. They want to add a clause stating that within 12 months of the regulation entering into force, the European Commission must adopt a delegated act. That act would take the requirements for devices deemed high-risk AI systems under Chapter III, Section 2 of the AI Act, and formally embed them into Annex I of the medical device regulations.
Sam: So if you are a company building an AI diagnostic tool, you do not have to go through two separate massive regulatory bodies and two separate sets of audits. You just go through your Notified Body under the MDR, and they check you against the integrated AI rules. That is a huge relief for the boardroom.
Maya: And it is better for patient safety, too. AI-enabled devices frequently operate as part of a system with other medical devices or IVDs. By using a unified system, events or incidents can be reported to the same market surveillance authorities that oversee all medical technologies, ensuring a coherent and rapid response to safety signals.
Sam: Speaking of safety signals and incidents, let us talk about cybersecurity. Because MedTech Europe makes a really sharp, structural distinction here between standard medical vigilance and cybersecurity vulnerability reporting.
Maya: This is a fascinating regulatory nuance. A cybersecurity event can result in two fundamentally different things. First, it could have a direct or indirect impact on patient safety. That is a traditional vigilance issue, and it should absolutely follow established MDR and IVDR reporting channels.
Sam: But what is the second scenario?
Maya: The second scenario is the identification of a cybersecurity vulnerability that requires remediation, but does not actually result in patient harm. For example, a vulnerability identified within a device's logging functionality that does not impact its clinical performance, or a temporary loss of connectivity that poses no risk to patients.
Sam: And the document argues those two things demand completely distinct regulatory responses. Because words like incident and severity mean one thing when you are talking about clinical harm, and something entirely different in horizontal cybersecurity legislation.
Maya: Exactly. Embedding cybersecurity provisions within the clinical vigilance structure risks generating massive legal uncertainty. So MedTech Europe proposes creating a structurally separate section on cybersecurity within Chapter VII of both regulations.
Sam: Quick note before we carry on. This spot is open for a sponsor. If your company builds or sells AI for healthcare and wants to reach the clinicians, health-system leaders and industry teams who listen to this show, the link to our sponsorship page is in the show notes.
Maya: And now, back to the document.
Sam: And what are the actual reporting mechanics they are proposing for those pure cybersecurity vulnerabilities?
Maya: They want manufacturers to report actively exploited vulnerabilities or severe incidents impacting security directly to the computer security incident response teams, known as CSIRTs, and to the European Union Agency for Cybersecurity, or ENISA. And the proposed deadline is not later than 30 days after becoming aware of the vulnerability.
Sam: That 30-day window is critical. It gives engineering teams the necessary time to actually develop, test, and deploy software patches without immediately triggering a clinical safety panic across the entire health system.
Maya: Precisely. Let us pivot to some of the clinical trial and diagnostic issues, because this is an area where the EU is aggressively losing its competitive edge to the United States.
Sam: Yeah, the paper specifically calls out how the current IVDR framework treats routine blood draws and finger-pricks in performance studies. That section was pretty eye-opening.
Maya: It is a perfect example of regulatory overreach. Hundreds of millions of blood tests are performed every year across the EU. Yet under the current IVDR framework, routine blood draws are treated as having the same risk as high-risk procedures like biopsies or spinal taps.
Sam: And the real-world consequence of that classification is that companies are literally relocating their performance studies to the US just to avoid EU regulatory delays.
Maya: Which directly limits European patient access to innovative diagnostics. The Commission claimed they wanted to narrow the scope of this authorization requirement for low-risk specimen collection, but MedTech Europe says the drafted text for Article 58 still inadvertently captures routine blood draws. They want it explicitly amended so full authorization is only triggered if the invasive procedure poses a major clinical risk to subjects.
Sam: There is also a major point in here about orphan devices. These are technologies targeting small, very specific patient populations. The paper notes that Europe is currently the last major regulatory jurisdiction without a dedicated breakthrough and orphan device pathway.
Maya: The Commission is proposing to finally create those pathways, aligning the EU with approaches that have already proven their value in jurisdictions like the US and Japan. But MedTech Europe has a big issue with the math on the IVD side. The proposed IVDR threshold defines an orphan device as one for a disease presenting in not more than 1 in 12,000 individuals in the Union per year.
Sam: And MedTech Europe wants that changed to 5 in 10,000. Why that specific ratio?
Maya: Because 5 in 10,000 is the firmly established European threshold for rare diseases. If they leave it at 1 in 12,000, it risks excluding critical diagnostics, like tests for rare blood groups and rare tissue typing, which are absolutely key for successful transplantation and transfusion.
Sam: That makes a lot of sense. Aligning the definitions across the board, especially bringing coherence with the orphan medicinal products framework, just creates a cleaner ecosystem for combination diagnostics. What about the MDR side of these innovation pathways?
Maya: On the medical device side, they want to ensure paediatric devices are explicitly included in the scope of Article 52a. Not all paediatric devices will qualify mathematically as orphan or breakthrough, but they still desperately need adapted assessment pathways so children can benefit from tailored innovations.
Sam: Let us talk about hospitals and labs for a second. There is a whole section on health institutions manufacturing their own devices, things like lab-developed tests or custom software tools.
Maya: Right. The Commission's proposal significantly simplifies the rules for health institutions, which MedTech Europe broadly supports as beneficial for patient care. But they draw a very hard line on one principle: if a CE-marked device is available for the exact same purpose, the hospital or lab should be required to use it as the standard.
Sam: Because the CE-marked device has actually gone through the rigorous conformity assessment under the MDR or IVDR, providing a level of regulatory assurance that homegrown lab tests just do not replicate by design.
Maya: Exactly. The Commission's proposal would allow significantly wider use of devices manufactured by health institutions even when a commercial alternative exists. MedTech Europe wants to reinstate Article 5.5(d) of the IVDR. This would legally require health institutions to justify in their documentation why a target patient group's needs cannot be met by an equivalent CE-marked device.
Sam: And from a business perspective, you can see why the industry is pushing for this. If you allow commercial labs to just bypass regulated tests and build their own lower-cost alternatives, you destroy the incentive for manufacturers to invest heavily in developing and validating CE-marked diagnostics. It creates an unequal playing field.
Maya: It risks creating a two-tier system with lower regulatory standards. Now, beyond the big strategic shifts, there are a few highly specific administrative amendments MedTech Europe is pushing back on simply because they create headaches with zero safety benefit.
Sam: Give me an example of the administrative noise they want to cut.
Maya: For one, the Commission proposed a new mandatory data validation role where Notified Bodies must confirm in the Eudamed database that a manufacturer's device registration data is correct. MedTech Europe wants that deleted. They argue the manufacturer is the data owner and is legally accountable for it. Forcing Notified Bodies to validate it goes beyond the scope of conformity assessment, creates delays in market access, and just drives up fees.
Sam: There is also a fascinating linguistic debate in here about labeling. The Commission proposed changing the term active ingredient to critical ingredient in the IVDR labeling requirements.
Maya: Yes, and MedTech Europe is asking regulators to reverse that and keep the original text. They point out there is currently no clear definition of critical ingredient in the IVDR. The term active ingredient is already well understood and consistently applied in risk assessments. Changing the terminology would force companies to do massive updates to procedures, labeling, and instructions for use, without any clear demonstration of added value for users.
Sam: It is exactly that kind of administrative busywork that distracts from actual safety improvements. Which brings us to the rethink section of the position paper. This is where MedTech Europe fundamentally disagrees with the Commission's direction.
Maya: This centers on the reprocessing of single-use devices. The Commission's proposal fundamentally shifts the regulatory default. It assumes that devices will be reusable unless manufacturers justify a single-use designation.
Sam: So basically, the new default is reusable by default, rather than single-use.
Maya: Yes. And MedTech Europe states that this is a departure from established patient safety principles, and it departs from the approach of every other major jurisdiction globally.
Sam: The paper mentions that the single-use design principle is deeply grounded in patient safety, specifically pointing to lessons learned from serious historic incidents, like HIV transmission risks in the 1990s.
Maya: Exactly. They also note that the Commission's own 2024 study on reprocessing highlights evidence gaps regarding safety. These devices are specifically engineered to be used once. Forcing manufacturers to legally prove a negative, to justify why a device that was never designed to be reused cannot be reused, places a totally unrealistic burden on the vast majority of single-use devices.
Sam: They want the indication for single-use only to be based on the manufacturer's risk management documentation, identifying the actual characteristics and technical factors that could pose a risk if the device were reused.
Maya: Right. And if a single-use device is going to be fully refurbished, MedTech Europe wants the regulation to clearly state that the natural or legal person carrying out that refurbishing is considered the manufacturer, assuming full obligations relating to the labeling and traceability of that fully refurbished device.
Sam: Let us touch on one more structural issue they raised before we wrap up: international cooperation. The paper strongly advocates for the EU's full membership in the Medical Devices Single Audit Programme, or MDSAP.
Maya: This is absolutely vital for European competitiveness. Historically, the CE mark served as a passport to global markets. But because of the scale and complexity of MDR and IVDR implementation, non-EU regulators have lost confidence. The paper explicitly notes that Brazil has removed its recognition of CE marking, and Australia has reduced it. Even critical trading partners like the UK and Switzerland are reconsidering their reliance pathways.
Sam: Meanwhile, markets like the US and Japan are increasingly viewed as more stable. The Medical Devices Single Audit Programme allows a single quality management system audit to satisfy requirements for multiple jurisdictions. If the EU fully integrates into that and uses MDSAP certificates for CE marking, it radically reduces costs and duplication for European companies.
Maya: Exactly. To sum up their entire position, MedTech Europe is telling Parliament and the Council that the window to act is now. They cannot afford to let this legislative process take years. They argue that a simpler, more predictable system is not a shortcut on safety. It is the condition for safety.
Sam: Because when 1 in 2 clinicians is facing shortages, the administrative bottlenecks are actively harming patient care today. The integration of the AI Act requirements, the separation of cybersecurity from vigilance, and the fixes to the orphan device pathways are all about making the EU a place where medtech innovation can actually reach patients.
Maya: Well said. The complete position paper, with all of their proposed legislative amendments laid out line by line, is an essential read for anyone managing regulatory strategy right now.
Sam: As always, you can find a link to the full source document in our show notes. And a quick reminder that this podcast is not medical advice. See you next time!