Back to articles

Navigating the EU AI Act: Is Your Clinical Documentation Software a High Risk Medical Device?

In hospital settings, AI in hospitals is transforming tasks like documentation automation and enabling direct KIS integration. Tools like Olingo Medical offer on premise medical AI that converts unstructured notes into structured health records. Under EU law, these systems face strict requirements. This article explains when your documentation software becomes a 'high risk' device and how to comply by the August 2026/2027 deadlines.

Articles

Could Your Documentation Software Be a Medical Device?

Under the Medical Device Regulation (MDR), software intended for diagnosis or therapy is considered a medical device. The EU guidance clarifies that *<em>software used solely to record, store or display patient data is generally </em>not* a medical device (dev.bayoocare.com)**. However, any software that provides information to support clinical decisions will be regulated (usually class IIa or higher). For example, a simple vitals tracker with no analysis wouldn’t typically count as a device, whereas a tool that interprets those vitals to suggest treatment would.

Unsure how this applies to your system? Consult our experts at [email protected] for a classification review.

When Is Your AI-Powered Software &#x27;High Risk&#x27; Under the AI Act?

The EU AI Act uses two paths to define high-risk in healthcare. First, **Article 6(1) automatically classifies any AI in a regulated medical device as high risk (fontvera.eu)**. In other words, if your documentation tool is part of a CE-marked system (or is a safety component of a device), the AI Act rules apply fully. Second, standalone AI used by public authorities to allocate care (Annex III) is also high risk. In practice, most clinical AI systems – including those that help with diagnostics or resource planning – will be covered by high-risk requirements.

If you need help evaluating your system’s risk level, our team can advise – just write to [email protected].

How Do the MDR and AI Act Requirements Overlap for Clinical Software?

For AI that qualifies as a medical device, the MDR and AI Act work in tandem. In fact, a single conformity assessment under MDR can cover the AI Act’s requirements (per Article 43(3) of the AI Act) (docs.team-ra.org). **If your software is CE-marked via a Notified Body, you perform one technical review that satisfies both MDR and AI Act standards (docs.team-ra.org).** All relevant AI documentation is integrated into the existing device file.

Both laws also demand strict quality systems. The AI Act’s Article 17 requires high-risk AI providers to have a documented quality management system (QMS) (clearact.net). This mirrors the MDR’s requirements for documented design, risk management and post-market procedures (www.medical-device-regulation.eu). In practice, you will need ISO 13485–style processes covering design control, testing and incident reporting.

Tech Tip: Q: Why is a Quality Management System needed? A: The AI Act (Article 17) explicitly mandates QMS for high-risk AI systems, including written procedures for design, testing and incident handling (clearact.net). This essentially mirrors the MDR’s ISO-13485 framework, so a single integrated QMS can satisfy both regulations.

For guidance aligning your QMS and documentation, contact our compliance specialists at [email protected].

What Are the Key Compliance Deadlines?

The AI Act enforcement is phased. Notably, transparency obligations (Article 50) come into effect on 2 August 2026, and full high-risk requirements by late 2027 (fontvera.eu) (agenticfluxus.com). For clinical applications, this means you must prepare labels, documentation and processes now. The MDR obligations (e.g. updated risk files and technical documentation) are already in force. **Don’t wait – Article 50’s rules start in August 2026, and most high-risk AI controls apply by the end of 2027 (fontvera.eu) (agenticfluxus.com).**

Tech Tip: Q: Why are August 2026 and 2027 important? A: The EU AI Act phases in key controls. By Aug 2026, transparency rules (like AI output labeling) apply (fontvera.eu). High-risk compliance steps (risk management, validation, CE marking of AI-enabled devices) follow by late 2027. Planning now ensures you meet these legal checkpoints.

Need a compliance roadmap? Our experts at [email protected] can advise on schedules and documentation strategies.

How Does Olingo Medical Mitigate These Compliance Risks?

Olingo Medical is built with these challenges in mind. <strong>All processing is on your hospital servers.</strong> Patient data never leaves the firewall – fully meeting GDPR and NIS2 requirements. Our OCR pipeline digitizes referral letters and PDFs into structured formats (FHIR/HL7), solving the unstructured data chaos. Olingo Speech transcribes consultation notes and rounds directly into the KIS (via HL7), cutting documentation time by about 60% while reducing errors. Our LLM engine is fine-tuned on medical data and runs locally, avoiding generic model hallucinations. We also offer AI-assisted coding to detect untapped reimbursement opportunities. In short, Olingo turns compliance obstacles into automated workflows.

For a demonstration of these solutions or to discuss deployment, write to [email protected].

Conclusion

AI will only grow in healthcare, but hospitals must not overlook compliance. Converting chaotic patient notes into <strong>FHIR</strong>-standard data and integrating AI outputs into HL7 workflows prepares you for both the MDR and AI Act. <strong>Olingo Medical is the specialized platform for capturing and structuring clinical data safely within your network.</strong> If you don’t want to risk data leaks or inefficiency, trust the professionals at Ollsoft GmbH. Contact us at [email protected].

FAQ

1. Q: Why isn’t basic note-taking software treated as a medical device? A: As noted, software that only logs or shows patient information is generally <strong>not</strong> a medical device (dev.bayoocare.com). It only becomes regulated if it provides diagnostic or treatment guidance. 2. Q: What qualifies as a high-risk AI system in healthcare? A: High risk applies when AI is embedded in a CE-marked device or used in critical health decisions. For example, a tool predicting treatments or managing triage is high risk (fontvera.eu). Our team can clarify if your AI use case is covered. 3. Q: Do I need a formal QMS for hospital AI projects? A: Yes. Article 17 of the AI Act requires a documented QMS (design, testing, incident procedures) for any high-risk AI (clearact.net). This typically means following ISO 13485 processes. Ollsoft can help build the necessary management system for you. 4. Q: How does on-premise deployment help with compliance? A: Keeping AI servers in-house retains full control over patient data, avoiding any cloud transfers. This satisfies GDPR and the upcoming NIS2 cybersecurity rules. Discuss on-premise integration with our experts at [email protected].