Introduction
The EU AI Act is not a life sciences regulation. It is a horizontal law meant to govern artificial intelligence across every sector, from hiring algorithms to credit scoring to facial recognition. But because a meaningful share of the AI systems it captures happen to be embedded in medical devices, in vitro diagnostics, and increasingly in drug development and manufacturing processes, it has become something regulatory affairs teams in life sciences cannot treat as background noise. It sits on top of frameworks many teams already know well - MDR, IVDR, GMP - and it does not replace any of them.
This is a working explanation of what the Act actually requires, how it interacts with the regulatory frameworks regulatory affairs professionals already navigate, and what is changing in the day-to-day work as a result.
What the EU AI Act Actually Covers
The Act sorts AI systems into risk tiers. A small category of uses is prohibited outright - manipulative systems, certain biometric categorization, social scoring. General-purpose AI models, the large foundation models that power many downstream applications, carry their own set of transparency and, for the most capable ones, systemic-risk obligations. The tier that matters most for life sciences is "high-risk," which the Act defines partly by naming specific use cases and partly by reference to existing EU product safety legislation.
That second route is the important one here. Under Annex I of the Act, AI systems that are safety components of products already regulated under sectoral legislation - including the Medical Device Regulation and the In Vitro Diagnostic Regulation - and that are required to undergo third-party conformity assessment under that legislation, are automatically classified as high-risk under the AI Act as well. In plain terms: if your AI-enabled device already needs a notified body to sign off on it under MDR or IVDR, the AI Act's high-risk obligations almost certainly apply to it too.
Where It Layers Onto MDR, IVDR, and GMP
The Act does not ask regulatory teams to build a second, parallel approval process. Its structure explicitly aims for the AI Act's conformity assessment obligations to be absorbed into the conformity assessment procedures that already exist under MDR and IVDR, so that a single notified body review can, in principle, cover both sets of requirements. In practice this means the technical documentation a device manufacturer already prepares - risk management files, clinical evaluation reports, post-market surveillance plans - has to be extended to address AI-specific requirements: data governance and quality of training data, human oversight measures, accuracy and robustness testing, and record-keeping that allows the system's behavior to be reconstructed and audited.
For drug and biologic manufacturers, the touchpoints are less direct but growing, particularly where AI systems support manufacturing process control, batch release decisions, or safety signal detection in pharmacovigilance - areas where an AI system's output feeds into a regulated decision even though the product itself is not "AI-enabled" in the way a device might be.
What Changes for Regulatory Affairs Teams
The most immediate practical change is that regulatory affairs can no longer assume AI oversight belongs entirely to a company's data science or IT function. Because the AI Act's obligations attach to products that already carry regulatory obligations under MDR, IVDR, or related legislation, regulatory affairs ends up being one of the few functions positioned to see both sides: what the AI Act requires and what the sectoral product legislation already requires, and where the two overlap or diverge.
That has translated into a few concrete tasks showing up on regulatory affairs teams' plates: building or maintaining an inventory of AI systems embedded in the company's products, so nothing gets classified late; mapping which of those systems fall into the high-risk tier and therefore need AI Act-specific technical documentation; working directly with notified bodies earlier in development to understand how they intend to assess the AI-specific requirements alongside the usual MDR or IVDR review; and translating AI Act obligations - many of them written by people who were not thinking primarily about medical devices - into requirements that make sense inside an existing quality management system.
How the EU's Approach Compares to FDA's
The EU AI Act is a classification-heavy, horizontal law: it sorts AI systems into tiers based on use case and risk, and the obligations follow largely from which tier a system lands in. FDA's approach to AI in medical devices, by contrast, has leaned more heavily on tools like the Predetermined Change Control Plan, which lets a manufacturer pre-specify how an AI-enabled device is allowed to learn and change after clearance, reviewed within the existing device framework rather than a separate horizontal AI statute. Neither approach is strictly stricter than the other - they solve a similar problem, keeping AI-driven product changes safe, from different starting points, and companies operating in both markets increasingly need regulatory strategies that can satisfy both without duplicating effort unnecessarily.
The Documentation Burden in Practice
For a regulatory affairs professional used to MDR or IVDR technical files, the AI Act's documentation requirements will feel familiar in structure but unfamiliar in content. Alongside the risk management and clinical evaluation records already required, an AI-enabled device now needs documentation describing the data used to train and validate the system, including how that data's quality, representativeness, and potential bias were assessed. It needs a description of the human oversight measures built into the system, since the Act places significant weight on a human's ability to understand, monitor, and if necessary override an AI system's output. And it needs logging and record-keeping sufficient to reconstruct the system's behavior after the fact, which is a different kind of traceability than most quality management systems were originally built to capture. None of this is exotic to build, but it does require regulatory affairs to ask data science and engineering teams for artifacts that were not previously part of the standard product development file.
New Skills and Roles This Is Creating
A distinct hiring pattern has started to show up in job postings: regulatory affairs roles, particularly in medical devices, that explicitly ask for familiarity with the EU AI Act alongside the usual MDR or IVDR experience. Some larger organizations have created dedicated AI regulatory liaison roles that sit between regulatory affairs, quality, and data science, translating between the three groups. For most regulatory affairs professionals, this does not mean becoming a data scientist - it means becoming fluent enough in how AI systems are validated and monitored to ask the right questions and to know when a system's design choices create regulatory exposure.
Practical Steps Teams Are Taking Now
Companies that are ahead of this are doing a few things consistently: building and maintaining a live inventory of every AI system embedded in a regulated product, rather than discovering them during a submission crunch; engaging notified bodies and, where relevant, national competent authorities early to understand how AI-specific and MDR or IVDR reviews will be coordinated; and assigning clear ownership - usually a joint regulatory and quality responsibility - for monitoring the delegated and implementing acts the European Commission continues to issue, since much of the Act's practical detail is still being filled in through secondary legislation and standards work rather than the base text alone.
Operating Across Multiple Jurisdictions
Few life sciences companies sell only in the EU, and that is where the compliance picture gets more complicated. A device manufacturer might be managing FDA's device-specific approach, the EU AI Act's horizontal classification scheme, and an emerging patchwork of national AI rules in other markets, all at once, for the same underlying product. The practical response most regulatory affairs teams are converging on is not to build separate compliance programs for each jurisdiction, but to design the underlying technical documentation - the risk management file, the data governance records, the validation evidence - broadly enough that it can be adapted to each jurisdiction's specific requirements rather than rebuilt from scratch. That only works if regulatory affairs is involved in how those foundational documents are structured from the start, rather than being asked to retrofit jurisdiction-specific requirements onto a document built for one market.
Mistakes Companies Are Making Early
A few patterns show up repeatedly among companies that are behind on this. The most common is treating AI governance as purely an IT or data science responsibility, with regulatory affairs looped in only once a submission is imminent - by which point decisions about training data provenance or model validation approach are already locked in and difficult to unwind. A second is assuming that because a product already has MDR or IVDR clearance, the AI Act obligations are automatically satisfied; the two frameworks are designed to be assessed together, but the AI Act's requirements are additive, not automatically inherited. A third is underestimating how much of the Act's practical meaning is still being defined through delegated acts, implementing acts, and harmonized standards, which means a compliance approach that looked complete based on the base regulation alone can fall behind as that secondary detail is published.
Conclusion
The EU AI Act does not ask regulatory affairs professionals in life sciences to start from scratch. It asks them to extend frameworks they already know - risk management, technical documentation, notified body engagement - to cover a new dimension of product behavior. The teams handling this well are the ones treating it as an extension of existing regulatory strategy rather than a separate compliance project, and the professionals who can operate comfortably at that intersection are becoming noticeably more valuable in the job market.

