Resource

    The Overlap Problem: Where the AI Act Meets the MDR

    For a growing class of medical devices, compliance is no longer a single-framework exercise. The harder question is how to run one evidence base across two.

    A second framework settles in

    For most of the last decade, the regulatory story in European medtech has been a single-word story: MDR. Reclassifications, notified body bottlenecks, technical files that tripled in size, clinical evidence expectations that nobody quite agreed on. Teams spent years rebuilding their quality systems around it, and many are still in the middle of that work.

    Now a second framework is settling into place beside it. The EU AI Act introduces its own obligations for high-risk AI systems - and because software that performs a medical function is already regulated as a device, a meaningful slice of AI-enabled medical devices will sit inside both regimes at once. Not sequentially. Not by choice. Simultaneously, for the same product, across the same lifecycle, using largely the same underlying evidence.

    This is not "another regulation." It is an overlap problem, and overlap problems behave differently from single-framework problems. They don't get solved by reading the text more carefully. They get solved - or not - by how well a company's operating model can hold two sets of expectations against one product without the seams tearing.

    The problem is not interpretation - it is operation

    The legal reading of the AI Act / MDR intersection is, for most companies, the easiest part. Consultants can map the requirements. Notified bodies will issue guidance. In-house regulatory leads can produce a crosswalk in an afternoon. The interpretive work is finite.

    The operational work is not.

    Consider what actually has to happen inside a company when the same AI-enabled device sits under both regimes. Risk management is no longer a single document tree - it has to reconcile device-level harm analysis with AI-specific risks around data, drift, bias, and human oversight, and the two views have to stay consistent as the product evolves. Post-market surveillance has to feed signals into two obligation sets that ask for overlapping but not identical things. Change management becomes denser: a model retrain is no longer just a design change under the QMS, it is also an event that may ripple into AI Act obligations around logging, transparency, and human oversight documentation. Technical documentation stops being one artifact and becomes a set of artifacts that need to reference each other without drifting.

    And crucially, the underlying evidence - the training data justification, the performance study, the clinical evaluation, the risk file, the PMS data - is largely the same evidence. It just needs to be presented, linked, and kept current across two frameworks at once.

    That is where the difficulty lives. Not in knowing what to do. In doing it repeatedly, consistently, across teams, as the product changes.

    Why current ways of working are already fragile

    Most medtech companies still run their regulatory evidence as a collection of static documents. A Word file for the clinical evaluation report. A spreadsheet for the risk register. A shared drive for PMS inputs. A separate folder for design history. A PDF for the technical file. The links between them live, informally, in someone's head - usually the head of the most senior RA person in the building.

    This model is already under pressure under the MDR alone. Anyone who has tried to update a CER mid-cycle and then trace the downstream impact across the risk file, PMS plan, IFU, and declaration of conformity knows the feeling: you are not really updating a document, you are chasing a web of implicit dependencies that nobody wrote down. It works, more or less, because the regulatory cadence is slow enough that the human memory holding it together has time to catch up.

    AI-enabled products break that assumption in two ways. They change faster - retrains, threshold adjustments, data refreshes - and now they have to answer to two frameworks whose expectations do not perfectly align. The same fragmented documentation stack is being asked to do twice the work at several times the cadence, and to stay internally consistent while it does. That is not a workload problem that a bigger team quietly solves. It is a structural problem that shows up as missed updates, inconsistent versions across documents, and audit findings that feel unfair to the people who were doing their best with the tools they had.

    A new category of regulatory pain

    It is worth naming this clearly, because the industry tends to absorb new obligations quietly and then discover eighteen months later that something has shifted. The AI Act / MDR overlap is the first real instance of a pattern that is going to repeat: multiple frameworks, one product, shared evidence, divergent paperwork. IVDR is already in the same conversation. Cybersecurity obligations will join it. US expansion adds another layer on top. The "one regulation at a time" mental model is quietly expiring.

    What this creates, for the companies living inside it, is a category of pain that existing tools do not really address. Document management systems store files. eQMS platforms manage workflows. Neither of them understands that a single change to a training dataset should propagate into six documents, flag two obligations, and trigger one human-oversight review - and that the same change has to be represented differently to two different audiences without the underlying facts diverging.

    Solving that is not a search problem or a checklist problem. It is a connectivity problem. The object that needs to exist is closer to a living dossier: a representation of the product where obligations, evidence, documents, and changes are linked to each other, so that when one thing moves, the consequences are visible instead of hidden. Whether the industry ends up calling it that or something else matters less than the underlying shift - from managing documents to managing the relationships between them.

    Where this is going

    The companies that handle the next few years well will not necessarily be the ones with the biggest regulatory teams. They will be the ones whose systems let a smaller team see the whole picture: what has changed, what it affects, what still needs to be updated, and how the same underlying evidence reads against each framework it has to answer to.

    Right now this still feels like a niche concern - relevant only to the subset of medtech companies building AI-enabled products sophisticated enough to trigger the overlap. That framing will not last long. The overlap is the leading edge of how regulatory operations in medtech are going to work from here: more frameworks, more interdependence, faster change cycles, and less tolerance for the informal scaffolding that used to hold everything together.

    The rulebooks are not the hard part. The seams between them are.

    A note from Artifakt

    We are building Artifakt because we think the next decade of medtech regulatory work is going to be defined by exactly this kind of problem: one product, multiple frameworks, shared evidence, and a documentation model that was never designed to carry it. Our focus is on helping medtech teams move from managing files to managing the connections between them - so that when something changes, the consequences are visible instead of buried. If the overlap problem we have described here sounds familiar, we would like to hear how you are thinking about it.

    Artifakt is building the infrastructure for multi-framework compliance - starting with EU MDR. Talk to us.

    Talk to us