top of page

Medical Device Software: Rule 11, MDCG 2019-11 and the AI Act Date That Just Moved

Aug 14
6 min read

Updated: Aug 15

Software has always been two questions under the MDR: is it a device, and if so what class. Since 2024 there is a third, whether it is also a high-risk AI system. In July 2026 the answer to the third question's timing changed, and a good deal of published guidance is now out of date on that point, including the Commission's own.

Qualification comes before classification

Article 2(1) includes software in the definition of a medical device: any instrument, apparatus, appliance, software, implant, reagent, material or other article intended by the manufacturer to be used for one or more specified medical purposes, and which does not achieve its principal intended action by pharmacological, immunological or metabolic means. Prediction and prognosis appear in that list of purposes. Both were added by the MDR and are absent from the old Directive.

MDCG 2019-11 was revised in June 2025, and Rev.1 remains the working document for qualification. It defines medical device software as software intended to be used, alone or in combination, for a purpose specified in the definition of a medical device in the MDR or the IVDR, and it runs qualification as a sequence of decision steps rather than a single judgement.

The step that decides most cases is the one about what the software does to data. Software may be medical device software where it performs an action on data beyond storage, archival, communication, simple search or lossless compression. Note the framing: it is a positive test for action beyond those functions, not a negative list of exempt features. A viewer that only retrieves and displays sits on one side of that line. The same viewer with an algorithm that flags a lesion sits on the other.

Two further steps follow: whether the action is for the benefit of individual patients, and whether the software meets the guidance's definition of MDSW. Software that drives or influences the use of a hardware device, and Annex XVI products, are handled through that device's own route rather than as standalone software.

Rule 11, and why almost nothing lands in class I

Annex VIII Rule 11 has three limbs.

Software intended to provide information which is used to take decisions with diagnosis or therapeutic purposes is class IIa, except where such decisions may cause death or an irreversible deterioration of a person's state of health, in which case class III, or a serious deterioration of a person's state of health or a surgical intervention, in which case class IIb.

Software intended to monitor physiological processes is class IIa, except where it is intended for monitoring vital physiological parameters and the nature of the variations of those parameters is such that it could result in immediate danger to the patient, in which case class IIb.

All other software is classified as class I.

The structure repays reading in the order it is written. The default for decision-support software is class IIa, and the escalations are defined by the consequence of the decision, not by the sophistication of the algorithm. A simple dosing calculator whose output can cause irreversible harm sits in class III. A complex model producing information that only informs a clinician's non-critical choice may sit lower. The third limb is a residual category, not an easy destination.

The implementing rules in Annex VIII Chapter II add the companion point: software that drives a device or influences the use of a device falls in the same class as that device, while software independent of any other device is classified in its own right.

The IVDR has no Rule 11

This trips people who work across both regulations. IVDR Annex VIII contains classification rules 1 to 7 and no Rule 11. IVD software is classified by applying the IVDR's own classification and implementing rules, with implementing rule 1.4 handling software that drives or influences the use of a device. MDCG 2019-11 Rev.1 covers both regulations and gives worked IVD examples. The qualification logic is shared. The classification logic is not.

The AI Act layer

Regulation (EU) 2024/1689 classifies an AI system as high-risk under Article 6(1) where both of two conditions are met: the system is intended to be used as a safety component of a product, or is itself a product, covered by the Union harmonisation legislation listed in Annex I; and that product is required to undergo a third-party conformity assessment under that legislation.

The MDR and the IVDR are both listed in Annex I Section A. The practical result is that an AI-enabled device requiring notified body involvement, which is everything above class I plus the sterile, measuring and reusable surgical class I subsets, meets the second condition automatically.

MDCG 2025-6, the joint FAQ of the MDCG and the AI Board published in June 2025, states the point that saves most of the panic: classification of an AI system as high-risk under Article 6(1) does not imply that the medical device falls into a higher risk class under the MDR or IVDR. The two classifications are independent. Article 43(3) then routes the assessment through the sectoral procedure, so the medical device notified body carries it out and must assess the AI Act's Section 2 requirements as part of it. Article 8(2) allows providers to integrate the AI Act's testing, reporting and documentation into procedures that already exist under the MDR.

The date changed on 27 July 2026

Article 113 of the AI Act originally set 2 August 2027 for Article 6(1) high-risk systems, the Annex I route, which is the medical device route. That is the date printed in MDCG 2025-6, and it is no longer correct.

Regulation (EU) 2026/1744 of 8 July 2026, the Digital Omnibus on AI, entered into force on 27 July 2026. It sets the date of application of Chapter III Sections 1, 2 and 3 to 2 December 2027 for systems high-risk under Article 6(2) and Annex III, and to 2 August 2028 for systems high-risk under Article 6(1) and Annex I, which is the medical device route. The stated reason is the delayed availability of harmonised standards and common specifications and the delayed establishment of national competent authorities.

The same regulation narrows the safety component concept. New Article 6(1a) excludes AI systems used solely for non-safety-related aspects of user assistance, performance optimisation, service efficiency, automation, convenience or quality control. New Article 6(1b) then puts back the case that matters here: systems whose failure or malfunctioning would endanger health and safety do qualify as safety components. For most medical device software the net effect is no change in substance and two more years of runway.

Anyone quoting 2 August 2027 today, including the Commission's own article-by-article AI Act pages, which carry a notice that they have not yet been updated, is quoting superseded law.

Two representatives, not one

A manufacturer outside the Union placing AI-enabled devices on the EU market has two separate appointments to make, and they are frequently conflated.

MDR Article 11 requires a sole authorised representative, appointed by written mandate accepted in writing, effective at least for all devices of the same generic device group, with the non-delegable list in Article 11(4) and joint and several liability for defective devices under Article 11(5).

AI Act Article 22 requires providers of high-risk AI systems established in third countries to appoint, by written mandate, an authorised representative established in the Union before making the system available. Its task list is its own, including keeping the declaration of conformity and technical documentation available to authorities for ten years and supplying logs under the provider's control on reasoned request.

They are different appointments under different instruments with different retention periods. One mandate does not discharge the other, and an MDR mandate drafted before 2024 will not mention the AI Act at all.

MDR Rule 11 risk classes for medical device software alongside AI Act Article 6(1) high-risk status
How MDR Annex VIII Rule 11 and AI Act Article 6(1) classify the same piece of medical device software

Sources

Regulation (EU) 2017/745, Article 2(1) and Annex VIII, Chapters II and III, Rule 11

Regulation (EU) 2017/746, Annex VIII classification and implementing rules

Regulation (EU) 2024/1689, the AI Act, Articles 6, 8, 22, 43 and 113, and Annex I Section A

Regulation (EU) 2026/1744 of 8 July 2026, Digital Omnibus on AI, in force 27 July 2026

MDCG 2019-11 Rev.1, Qualification and classification of software, June 2025

MDCG 2025-6 and AIB 2025-1, FAQ on the interplay between the MDR and IVDR and the Artificial Intelligence Act, June 2025

MDCG 2021-24 Rev.1, Guidance on classification of medical devices, April 2026

Who wrote this

Medex is a medical device manufacturer established in Ankara and a registered authorised representative in EUDAMED under SRN TR-AR-000057550. We read the technical documentation of the software devices we represent before we sign the mandate. We are not a law firm and do not provide legal advice.

 
 
 

Comments


Appoint a representative

Send your device list for a written quote

Device class
bottom of page