What the EU AI Act adds to your device's instructions for use
Article 13 of the EU AI Act sets its own list of IFU contents for high-risk AI. For an MDR or IVDR device it lands on top of Annex I, from 2 August 2028.
The EU AI Act has been amended once already. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026. It moved the application date for AI systems embedded in regulated products to 2 August 2028. The consolidated text is now stable enough to plan against. This post takes one requirement from it, the instructions for use, and sets it beside the requirement you already meet under Annex I of the MDR or IVDR.
The wider question is how the AI Act’s quality system, risk management and post-market duties fold into an ISO 13485 system. MDCG 2025-6, the joint guidance of the AI Board and the MDCG, covers that. The guidance was written in June 2025 and still carries the pre-Omnibus dates, so read its timing answers against the new text. The instructions for use are a narrower topic. Both regulations require an IFU, and for an AI-enabled device it will be one document that has to satisfy both.
Which devices this concerns
An AI system is high-risk under Article 6(1)Article 6(1)Irrespective of whether an AI system is placed on the market or put into service independently of the products referred to in points (a) and (b), that AI system shall be considered to be high-risk where both of the following conditions are fulfilled:(a) the AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I;(b) the product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service of that product pursuant to the Union harmonisation legislation listed in Annex I.AI Act · consolidated 2026-07-27. Consolidated text is a documentation tool with no legal effect. of the AI Act when two conditions are met. It must be a safety component of a product, or a product in itself, covered by the legislation listed in Annex I. That product must also undergo a third-party conformity assessment. The MDR and the IVDR are points 11 and 12 of Annex I. The second condition is therefore notified body involvement. MDCG 2025-6 sets it out in a table it labels non-exhaustive, reproduced here with the device classes it names.
| MDR or IVDR classification | Notified body involved | Second condition met |
|---|---|---|
| MDR Class I, non-sterile, non-measuring, non-reusable surgical | No | No |
| MDR Class I sterile, measuring or reusable surgical | Yes | Yes |
| MDR Class IIa, IIb and III | Yes | Yes |
| MDR Annex XVI products, except non-invasive Class I | Yes | Yes |
| IVDR Class A, non-sterile | No | No |
| IVDR Class A sterile | Yes | Yes |
| IVDR Class B, C and D | Yes | Yes |
| In-house devices under Article 5(5) MDR or IVDR | No | No |
The first condition still has to be met as well: the AI must be a safety component of the device, or be the device itself.
The Omnibus narrowed that first condition. AI used solely for non-safety aspects of user assistance, performance optimisation, service efficiency, automation, convenience or quality control does not count as a safety component (Article 6(1a)Article 6(1a)For the purposes of this Regulation, including paragraph 1 of this Article, AI systems that are solely used for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation or convenience or quality control shall not qualify as safety components.AI Act · consolidated 2026-07-27. Consolidated text is a documentation tool with no legal effect. of the AI Act). The carve-out falls away where a failure of that AI would endanger health and safety (Article 6(1b)Article 6(1b)Notwithstanding paragraph 1a, AI systems the failure or malfunctioning of which would endanger health and safety shall qualify as safety components.AI Act · consolidated 2026-07-27. Consolidated text is a documentation tool with no legal effect. of the AI Act). High-risk status under the AI Act does not change the device’s MDR or IVDR class. The dependency runs in one direction only: the device classification decides whether the AI system is high-risk, and nothing in the AI Act moves a device to a higher class.
Two definitions of the same document
Both regulations define instructions for use, and both aim them at the person who operates the device. The AI Act’s definition is “the information provided by the provider to inform the deployer of, in particular, an AI system’s intended purpose and proper use” (Article 3(15)Article 3(15)‘instructions for use’ means the information provided by the provider to inform the deployer of, in particular, an AI system’s intended purpose and proper use;AI Act · consolidated 2026-07-27. Consolidated text is a documentation tool with no legal effect. of the AI Act). Where the AI system is itself the device, the manufacturer is the provider under the ordinary definition. Where it is a safety component sold under the device manufacturer’s name or trade mark, that manufacturer is treated as the provider (Article 25(3)Article 25(3)In the case of high-risk AI systems that are safety components of products covered by the Union harmonisation legislation listed in Section A of Annex I, the product manufacturer shall be considered to be the provider of the high-risk AI system, and shall be subject to the obligations under Article 16 under either of the following circumstances:(a) the high-risk AI system is placed on the market together with the product under the name or trademark of the product manufacturer;(b) the high-risk AI system is put into service under the name or trademark of the product manufacturer after the product has been placed on the market.AI Act · consolidated 2026-07-27. Consolidated text is a documentation tool with no legal effect. of the AI Act). The deployer is the hospital, laboratory or practice that uses the device under its own authority. In device terms, the deployer is your professional user.
That matters because the AI Act gives the deployer duties of its own, and those duties refer to the instructions. Deployers must use the system in accordance with the instructions for use (Article 26(1)Article 26(1)Deployers of high-risk AI systems shall take appropriate technical and organisational measures to ensure they use such systems in accordance with the instructions for use accompanying the systems, pursuant to paragraphs 3 and 6.AI Act · consolidated 2026-07-27. Consolidated text is a documentation tool with no legal effect. of the AI Act). They must also monitor its operation on the basis of those instructions (Article 26(5)Article 26(5)Deployers shall monitor the operation of the high-risk AI system on the basis of the instructions for use and, where relevant, inform providers in accordance with Article 72. Where deployers have reason to consider that the use of the high-risk AI system in accordance with the instructions may result in that AI system presenting a risk within the meaning of Article 79(1), they shall, without undue delay, inform the provider or distributor and the relevant market surveillance authority, and shall suspend the use of that system. Where deployers have identified a serious incident, they shall also immediately inform first the provider, and then the importer or distributor and the relevant market surveillance authorities of that incident. If the deployer is not able to reach the provider, Article 73 shall apply mutatis mutandis. This obligation shall not cover sensitive operational data of deployers of AI systems which are law enforcement authorities.For deployers that are financial institutions subject to requirements regarding their internal governance, arrangements or processes under Union financial services law, the monitoring obligation set out in the first subparagraph shall be deemed to be fulfilled by complying with the rules on internal governance arrangements, processes and mechanisms pursuant to the relevant financial service law.AI Act · consolidated 2026-07-27. Consolidated text is a documentation tool with no legal effect. of the AI Act). Where use in accordance with the instructions may present a risk, they must inform the provider and the market surveillance authority. Whether a hospital has complied with Article 26 will therefore be judged against what your IFU says.
This is new. The MDR is addressed to manufacturers, authorised representatives, importers and distributors, and it asks almost nothing of the hospital that uses the device. Health institutions must store the UDI of class III implantable devices (Article 27(9)Article 27(9)Health institutions shall store and keep preferably by electronic means the UDI of the devices which they have supplied or with which they have been supplied, if those devices belong to class III implantable devices.For devices other than class III implantable devices, Member States shall encourage, and may require, health institutions to store and keep, preferably by electronic means, the UDI of the devices with which they have been supplied.Member States shall encourage, and may require, healthcare professionals to store and keep preferably by electronic means, the UDI of the devices with which they have been supplied with.MDR · consolidated 2026-07-19. Consolidated text is a documentation tool with no legal effect.) and may make in-house devices under conditions (Article 5(5)Article 5(5)With the exception of the relevant general safety and performance requirements set out in Annex I, the requirements of this Regulation shall not apply to devices, manufactured and used only within health institutions established in the Union, provided that all of the following conditions are met:Member States may require that such health institutions submit to the competent authority any further relevant information about such devices which have been manufactured and used on their territory. Member States shall retain the right to restrict the manufacture and the use of any specific type of such devices and shall be permitted access to inspect the activities of the health institutions.This paragraph shall not apply to devices that are manufactured on an industrial scale.(a) the devices are not transferred to another legal entity,(b) manufacture and use of the devices occur under appropriate quality management systems,(c) the health institution justifies in its documentation that the target patient group's specific needs cannot be met, or cannot be met at the appropriate level of performance by an equivalent device available on the market,(d) the health institution provides information upon request on the use of such devices to its competent authority, which shall include a justification of their manufacturing, modification and use;(e) the health institution draws up a declaration which it shall make publicly available, including: (i) the name and address of the manufacturing health institution; (ii) the details necessary to identify the devices; (iii) a declaration that the devices meet the general safety and performance requirements set out in Annex I to this Regulation and, where applicable, information on which requirements are not fully met with a reasoned justification therefor,(f) the health institution draws up documentation that makes it possible to have an understanding of the manufacturing facility, the manufacturing process, the design and performance data of the devices, including the intended purpose, and that is sufficiently detailed to enable the competent authority to ascertain that the general safety and performance requirements set out in Annex I to this Regulation are met;(g) the health institution takes all necessary measures to ensure that all devices are manufactured in accordance with the documentation referred to in point (f), and(h) the health institution reviews experience gained from clinical use of the devices and takes all necessary corrective actions.MDR · consolidated 2026-07-19. Consolidated text is a documentation tool with no legal effect.). On the instructions for use the MDR says nothing to the user. It contains no duty to use a device in accordance with its IFU and no duty to monitor it. Even incident reporting by healthcare professionals is something Member States are asked to encourage, not something the regulation requires of them (Article 87(10)Article 87(10)The Member States shall take appropriate measures such as organising targeted information campaigns, to encourage and enable healthcare professionals, users and patients to report to the competent authorities suspected serious incidents referred to in point (a) of paragraph 1.The competent authorities shall record centrally at national level reports they receive from healthcare professionals, users and patients.MDR · consolidated 2026-07-19. Consolidated text is a documentation tool with no legal effect.). Under the MDR the IFU defines the conditions under which you stand behind the device; use outside them shifts responsibility, but the user’s compliance is not measured by EU law. From 2 August 2028 the AI Act measures it, for the AI part of the device, against the document you wrote. MDCG 2025-6 describes what that asks of the content: the instructions should put the deployer in a position to choose the system correctly, to know the intended and precluded uses, and to use it as appropriate.
The AI Act binds the user to the instructions for use, which the MDR never did.
What Article 13 adds to Annex I
Article 13(3)Article 13(3)The instructions for use shall contain at least the following information:(a) the identity and the contact details of the provider and, where applicable, of its authorised representative;(b) the characteristics, capabilities and limitations of performance of the high-risk AI system, including: (i) its intended purpose; (ii) the level of accuracy, including its metrics, robustness and cybersecurity referred to in Article 15 against which the high-risk AI system has been tested and validated and which can be expected, and any known and foreseeable circumstances that may have an impact on that expected level of accuracy, robustness and cybersecurity; (iii) any known or foreseeable circumstance, related to the use of the high-risk AI system in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, which may lead to risks to the health and safety or fundamental rights referred to in Article 9(2); (iv) where applicable, the technical capabilities and characteristics of the high-risk AI system to provide information that is relevant to explain its output; (v) when appropriate, its performance regarding specific persons or groups of persons on which the system is intended to be used; (vi) when appropriate, specifications for the input data, or any other relevant information in terms of the training, validation and testing data sets used, taking into account the intended purpose of the high-risk AI system; (vii) where applicable, information to enable deployers to interpret the output of the high-risk AI system and use it appropriately;(c) the changes to the high-risk AI system and its performance which have been pre-determined by the provider at the moment of the initial conformity assessment, if any;(d) the human oversight measures referred to in Article 14, including the technical measures put in place to facilitate the interpretation of the outputs of the high-risk AI systems by the deployers;(e) the computational and hardware resources needed, the expected lifetime of the high-risk AI system and any necessary maintenance and care measures, including their frequency, to ensure the proper functioning of that AI system, including as regards software updates;(f) where relevant, a description of the mechanisms included within the high-risk AI system that allows deployers to properly collect, store and interpret the logs in accordance with Article 12.AI Act · consolidated 2026-07-27. Consolidated text is a documentation tool with no legal effect. of the AI Act lists the minimum content of the instructions for use of a high-risk AI system. Set against Section 23.4 of Annex I to the MDR, two of its items are already there in full, four are there in a weaker form, and six are new. The IVDR list in Annex I, Section 20.4, is built the same way, so the comparison holds for IVDs.
| Article 13(3) of the AI Act requires | Annex I, Section 23.4 of the MDR already requires | What the AI Act adds |
|---|---|---|
| Provider identity and contact details, and the authorised representative where there is one (point (a)Article 13(3)(a)the identity and the contact details of the provider and, where applicable, of its authorised representative;AI Act · consolidated 2026-07-27. Consolidated text is a documentation tool with no legal effect.) | The same particulars, carried over from the label (23.4(a)Annex I, Section 23.4(a)(a) the particulars referred to in points (a), (c), (e), (f), (k), (l), (n) and (r) of Section 23.2;MDR · consolidated 2026-07-19. Consolidated text is a documentation tool with no legal effect.) | Nothing; the item is already covered |
| Intended purpose (point (b)(i)Article 13(3)(b)the characteristics, capabilities and limitations of performance of the high-risk AI system, including: (i) its intended purpose; (ii) the level of accuracy, including its metrics, robustness and cybersecurity referred to in Article 15 against which the high-risk AI system has been tested and validated and which can be expected, and any known and foreseeable circumstances that may have an impact on that expected level of accuracy, robustness and cybersecurity; (iii) any known or foreseeable circumstance, related to the use of the high-risk AI system in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, which may lead to risks to the health and safety or fundamental rights referred to in Article 9(2); (iv) where applicable, the technical capabilities and characteristics of the high-risk AI system to provide information that is relevant to explain its output; (v) when appropriate, its performance regarding specific persons or groups of persons on which the system is intended to be used; (vi) when appropriate, specifications for the input data, or any other relevant information in terms of the training, validation and testing data sets used, taking into account the intended purpose of the high-risk AI system; (vii) where applicable, information to enable deployers to interpret the output of the high-risk AI system and use it appropriately;AI Act · consolidated 2026-07-27. Consolidated text is a documentation tool with no legal effect.) | Intended purpose with indications, contra-indications, patient target groups and intended users (23.4(b)Annex I, Section 23.4(b)(b) the device's intended purpose with a clear specification of indications, contra-indications, the patient target group or groups, and of the intended users, as appropriate;MDR · consolidated 2026-07-19. Consolidated text is a documentation tool with no legal effect.) | Nothing; the item is already covered |
| The level of accuracy, including its metrics, robustness and cybersecurity, against which the system was tested and validated, and the circumstances that may affect that level (point (b)(ii)Article 13(3)(b)the characteristics, capabilities and limitations of performance of the high-risk AI system, including: (i) its intended purpose; (ii) the level of accuracy, including its metrics, robustness and cybersecurity referred to in Article 15 against which the high-risk AI system has been tested and validated and which can be expected, and any known and foreseeable circumstances that may have an impact on that expected level of accuracy, robustness and cybersecurity; (iii) any known or foreseeable circumstance, related to the use of the high-risk AI system in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, which may lead to risks to the health and safety or fundamental rights referred to in Article 9(2); (iv) where applicable, the technical capabilities and characteristics of the high-risk AI system to provide information that is relevant to explain its output; (v) when appropriate, its performance regarding specific persons or groups of persons on which the system is intended to be used; (vi) when appropriate, specifications for the input data, or any other relevant information in terms of the training, validation and testing data sets used, taking into account the intended purpose of the high-risk AI system; (vii) where applicable, information to enable deployers to interpret the output of the high-risk AI system and use it appropriately;AI Act · consolidated 2026-07-27. Consolidated text is a documentation tool with no legal effect.) | Performance characteristics, and the degree of accuracy claimed for a measuring function (23.4(e)Annex I, Section 23.4(e)(e) the performance characteristics of the device;MDR · consolidated 2026-07-19. Consolidated text is a documentation tool with no legal effect., 23.4(h)Annex I, Section 23.4(h)(h) specifications the user requires to use the device appropriately, e.g. if the device has a measuring function, the degree of accuracy claimed for it;MDR · consolidated 2026-07-19. Consolidated text is a documentation tool with no legal effect.) | The accuracy, robustness and cybersecurity figures the system was validated against, and the circumstances under which those figures no longer hold |
| Known or foreseeable circumstances, including reasonably foreseeable misuse, that may lead to risks to health, safety or fundamental rights (point (b)(iii)Article 13(3)(b)the characteristics, capabilities and limitations of performance of the high-risk AI system, including: (i) its intended purpose; (ii) the level of accuracy, including its metrics, robustness and cybersecurity referred to in Article 15 against which the high-risk AI system has been tested and validated and which can be expected, and any known and foreseeable circumstances that may have an impact on that expected level of accuracy, robustness and cybersecurity; (iii) any known or foreseeable circumstance, related to the use of the high-risk AI system in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, which may lead to risks to the health and safety or fundamental rights referred to in Article 9(2); (iv) where applicable, the technical capabilities and characteristics of the high-risk AI system to provide information that is relevant to explain its output; (v) when appropriate, its performance regarding specific persons or groups of persons on which the system is intended to be used; (vi) when appropriate, specifications for the input data, or any other relevant information in terms of the training, validation and testing data sets used, taking into account the intended purpose of the high-risk AI system; (vii) where applicable, information to enable deployers to interpret the output of the high-risk AI system and use it appropriately;AI Act · consolidated 2026-07-27. Consolidated text is a documentation tool with no legal effect.) | Residual risks, contra-indications and side-effects; warnings, precautions and limitations of use (23.4(g)Annex I, Section 23.4(g)(g) any residual risks, contra-indications and any undesirable side-effects, including information to be conveyed to the patient in this regard;MDR · consolidated 2026-07-19. Consolidated text is a documentation tool with no legal effect., 23.4(s)Annex I, Section 23.4(s)(s) information that allows the user and/or patient to be informed of any warnings, precautions, contra-indications, measures to be taken and limitations of use regarding the device. That information shall, where relevant, allow the user to brief the patient about any warnings, precautions, contra-indications, measures to be taken and limitations of use regarding the device. The information shall cover, where appropriate: — warnings, precautions and/or measures to be taken in the event of malfunction of the device or changes in its performance that may affect safety, — warnings, precautions and/or measures to be taken as regards the exposure to reasonably foreseeable external influences or environmental conditions, such as magnetic fields, external electrical and electromagnetic effects, electrostatic discharge, radiation associated with diagnostic or therapeutic procedures, pressure, humidity, or temperature, — warnings, precautions and/or measures to be taken as regards the risks of interference posed by the reasonably foreseeable presence of the device during specific diagnostic investigations, evaluations, or therapeutic treatment or other procedures such as electromagnetic interference emitted by the device affecting other equipment, — if the device is intended to administer medicinal products, tissues or cells of human or animal origin, or their derivatives, or biological substances, any limitations or incompatibility in the choice of substances to be delivered, — warnings, precautions and/or limitations related to the medicinal substance or biological material that is incorporated into the device as an integral part of the device; and — precautions related to materials incorporated into the device that contain or consist of CMR substances or endocrine-disrupting substances, or that could result in sensitisation or an allergic reaction by the patient or user;MDR · consolidated 2026-07-19. Consolidated text is a documentation tool with no legal effect.) | Risks to fundamental rights, alongside health and safety; foreseeable misuse named as a category of its own |
| Where applicable, the technical capabilities that help explain the output (point (b)(iv)Article 13(3)(b)the characteristics, capabilities and limitations of performance of the high-risk AI system, including: (i) its intended purpose; (ii) the level of accuracy, including its metrics, robustness and cybersecurity referred to in Article 15 against which the high-risk AI system has been tested and validated and which can be expected, and any known and foreseeable circumstances that may have an impact on that expected level of accuracy, robustness and cybersecurity; (iii) any known or foreseeable circumstance, related to the use of the high-risk AI system in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, which may lead to risks to the health and safety or fundamental rights referred to in Article 9(2); (iv) where applicable, the technical capabilities and characteristics of the high-risk AI system to provide information that is relevant to explain its output; (v) when appropriate, its performance regarding specific persons or groups of persons on which the system is intended to be used; (vi) when appropriate, specifications for the input data, or any other relevant information in terms of the training, validation and testing data sets used, taking into account the intended purpose of the high-risk AI system; (vii) where applicable, information to enable deployers to interpret the output of the high-risk AI system and use it appropriately;AI Act · consolidated 2026-07-27. Consolidated text is a documentation tool with no legal effect.) | No equivalent | The whole item: a description of any feature that shows the user why the system produced a given output |
| When appropriate, performance on specific persons or groups (point (b)(v)Article 13(3)(b)the characteristics, capabilities and limitations of performance of the high-risk AI system, including: (i) its intended purpose; (ii) the level of accuracy, including its metrics, robustness and cybersecurity referred to in Article 15 against which the high-risk AI system has been tested and validated and which can be expected, and any known and foreseeable circumstances that may have an impact on that expected level of accuracy, robustness and cybersecurity; (iii) any known or foreseeable circumstance, related to the use of the high-risk AI system in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, which may lead to risks to the health and safety or fundamental rights referred to in Article 9(2); (iv) where applicable, the technical capabilities and characteristics of the high-risk AI system to provide information that is relevant to explain its output; (v) when appropriate, its performance regarding specific persons or groups of persons on which the system is intended to be used; (vi) when appropriate, specifications for the input data, or any other relevant information in terms of the training, validation and testing data sets used, taking into account the intended purpose of the high-risk AI system; (vii) where applicable, information to enable deployers to interpret the output of the high-risk AI system and use it appropriately;AI Act · consolidated 2026-07-27. Consolidated text is a documentation tool with no legal effect.) | The patient target groups the device is intended for, as part of the intended purpose (23.4(b)) | A performance figure for each group, rather than only the name of the group |
| When appropriate, specifications for the input data, or information on the training, validation and testing data sets (point (b)(vi)Article 13(3)(b)the characteristics, capabilities and limitations of performance of the high-risk AI system, including: (i) its intended purpose; (ii) the level of accuracy, including its metrics, robustness and cybersecurity referred to in Article 15 against which the high-risk AI system has been tested and validated and which can be expected, and any known and foreseeable circumstances that may have an impact on that expected level of accuracy, robustness and cybersecurity; (iii) any known or foreseeable circumstance, related to the use of the high-risk AI system in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, which may lead to risks to the health and safety or fundamental rights referred to in Article 9(2); (iv) where applicable, the technical capabilities and characteristics of the high-risk AI system to provide information that is relevant to explain its output; (v) when appropriate, its performance regarding specific persons or groups of persons on which the system is intended to be used; (vi) when appropriate, specifications for the input data, or any other relevant information in terms of the training, validation and testing data sets used, taking into account the intended purpose of the high-risk AI system; (vii) where applicable, information to enable deployers to interpret the output of the high-risk AI system and use it appropriately;AI Act · consolidated 2026-07-27. Consolidated text is a documentation tool with no legal effect.) | IT and network requirements to run software; devices used in combination (23.4(ab)Annex I, Section 23.4(ab)(ab) for devices that incorporate electronic programmable systems, including software, or software that are devices in themselves, minimum requirements concerning hardware, IT networks characteristics and IT security measures, including protection against unauthorised access, necessary to run the software as intended.MDR · consolidated 2026-07-19. Consolidated text is a documentation tool with no legal effect., 23.4(q)Annex I, Section 23.4(q)(q) for devices intended for use together with other devices and/or general purpose equipment: — information to identify such devices or equipment, in order to obtain a safe combination, and/or — information on any known restrictions to combinations of devices and equipment;MDR · consolidated 2026-07-19. Consolidated text is a documentation tool with no legal effect.) | What input data the system needs, and what it was trained, validated and tested on |
| Where applicable, information to enable the deployer to interpret the output and use it appropriately (point (b)(vii)Article 13(3)(b)the characteristics, capabilities and limitations of performance of the high-risk AI system, including: (i) its intended purpose; (ii) the level of accuracy, including its metrics, robustness and cybersecurity referred to in Article 15 against which the high-risk AI system has been tested and validated and which can be expected, and any known and foreseeable circumstances that may have an impact on that expected level of accuracy, robustness and cybersecurity; (iii) any known or foreseeable circumstance, related to the use of the high-risk AI system in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, which may lead to risks to the health and safety or fundamental rights referred to in Article 9(2); (iv) where applicable, the technical capabilities and characteristics of the high-risk AI system to provide information that is relevant to explain its output; (v) when appropriate, its performance regarding specific persons or groups of persons on which the system is intended to be used; (vi) when appropriate, specifications for the input data, or any other relevant information in terms of the training, validation and testing data sets used, taking into account the intended purpose of the high-risk AI system; (vii) where applicable, information to enable deployers to interpret the output of the high-risk AI system and use it appropriately;AI Act · consolidated 2026-07-27. Consolidated text is a documentation tool with no legal effect.) | No stated equivalent | The whole item: guidance on reading the output and acting on it, which a software IFU may already partly contain |
| The changes to the system and its performance pre-determined at the initial conformity assessment (point (c)Article 13(3)(c)the changes to the high-risk AI system and its performance which have been pre-determined by the provider at the moment of the initial conformity assessment, if any;AI Act · consolidated 2026-07-27. Consolidated text is a documentation tool with no legal effect.) | No equivalent | The whole item: the list of changes you pre-specified in the change plan, so the user knows what may change without a new assessment |
| The human oversight measures under Article 14, including technical measures that help interpret outputs (point (d)Article 13(3)(d)the human oversight measures referred to in Article 14, including the technical measures put in place to facilitate the interpretation of the outputs of the high-risk AI systems by the deployers;AI Act · consolidated 2026-07-27. Consolidated text is a documentation tool with no legal effect.) | Special training or particular qualifications the user needs (23.4(j)Annex I, Section 23.4(j)(j) any requirements for special facilities, or special training, or particular qualifications of the device user and/or other persons;MDR · consolidated 2026-07-19. Consolidated text is a documentation tool with no legal effect.) | The measures that let a person supervise and override the system, beyond stating what training the user needs |
| Computational and hardware resources, expected lifetime, and maintenance including software updates and their frequency (point (e)Article 13(3)(e)the computational and hardware resources needed, the expected lifetime of the high-risk AI system and any necessary maintenance and care measures, including their frequency, to ensure the proper functioning of that AI system, including as regards software updates;AI Act · consolidated 2026-07-27. Consolidated text is a documentation tool with no legal effect.) | Hardware and IT requirements; preventive and regular maintenance (23.4(ab), 23.4(k)Annex I, Section 23.4(k)(k) the information needed to verify whether the device is properly installed and is ready to perform safely and as intended by the manufacturer, together with, where relevant: — details of the nature, and frequency, of preventive and regular maintenance, and of any preparatory cleaning or disinfection, — identification of any consumable components and how to replace them, — information on any necessary calibration to ensure that the device operates properly and safely during its intended lifetime, and — methods for eliminating the risks encountered by persons involved in installing, calibrating or servicing devices;MDR · consolidated 2026-07-19. Consolidated text is a documentation tool with no legal effect.) | How long the AI system is expected to remain fit for use, and how often it will be updated |
| Where relevant, how the deployer collects, stores and interprets the logs generated under Article 12 (point (f)Article 13(3)(f)where relevant, a description of the mechanisms included within the high-risk AI system that allows deployers to properly collect, store and interpret the logs in accordance with Article 12.AI Act · consolidated 2026-07-27. Consolidated text is a documentation tool with no legal effect.) | No equivalent | The whole item: how the user retrieves and reads the event logs, which requires the logging capability to be designed into the product first |
Three rows deserve a note. On performance for specific groups, Annex I asks you to name the patient groups the device is intended for. The AI Act asks, when appropriate, how well the system performs for each of them, for example sensitivity and specificity stated separately for patients over 75 or for a skin type the training data covered thinly. This follows from the data governance duty in Article 10Article 101. High-risk AI systems which make use of techniques involving the training of AI models with data shall be developed on the basis of training, validation and testing data sets that meet the quality criteria referred to in paragraphs 2, 3 and 4 of this Article and in Article 4a(1) whenever such data sets are used.2. Training, validation and testing data sets shall be subject to data governance and management practices appropriate for the intended purpose of the high-risk AI system. Those practices shall concern in particular:(a) the relevant design choices;(b) data collection processes and the origin of data, and in the case of personal data, the original purpose of the data collection;(c) relevant data-preparation processing operations, such as annotation, labelling, cleaning, updating, enrichment and aggregation;(d) the formulation of assumptions, in particular with respect to the information that the data are supposed to measure and represent;(e) an assessment of the availability, quantity and suitability of the data sets that are needed;(f) examination in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law, especially where data outputs influence inputs for future operations;(g) appropriate measures to detect, prevent and mitigate possible biases identified according to point (f);(h) the identification of relevant data gaps or shortcomings that prevent compliance with this Regulation, and how those gaps and shortcomings can be addressed.3. Training, validation and testing data sets shall be relevant, sufficiently representative, and to the best extent possible, free of errors and complete in view of the intended purpose. They shall have the appropriate statistical properties, including, where applicable, as regards the persons or groups of persons in relation to whom the high-risk AI system is intended to be used. Those characteristics of the data sets may be met at the level of individual data sets or at the level of a combination thereof.4. Data sets shall take into account, to the extent required by the intended purpose, the characteristics or elements that are particular to the specific geographical, contextual, behavioural or functional setting within which the high-risk AI system is intended to be used.6. For the development of high-risk AI systems not using techniques involving the training of AI models, paragraphs 2, 3 and 4 of this Article and Article 4a(1) shall apply only to the testing data sets.AI Act · consolidated 2026-07-27. Consolidated text is a documentation tool with no legal effect. of the AI Act, which requires the training, validation and testing data to be representative of the intended population. MDCG 2025-6 lists age, gender, sex, race, ethnicity, geographical location, medical condition, intended use environment and measurement inputs as characteristics the training, validation and testing data should represent. The pre-determined changes row connects to the change plan in Annex IV, point 2(f), of the AI Act. Changes you describe in that plan at the initial conformity assessment must also be listed in the IFU. MDCG 2025-6 says a change executed under that plan is not a substantial modification. In its view such a change should not be treated as a change to the certified device under Annex IX, Section 4.10, of the MDR or Section 4.11 of the IVDR. The human oversight row is where MDCG 2025-6 reads the Annex I training requirement alongside the AI Act’s training and AI literacy expectations.
MDCG 2025-6 treats these transparency requirements as essential requirements. They are handled inside the manufacturer’s risk and quality management systems and verified through the conformity assessment. Under Article 43(3)Article 43(3)For high-risk AI systems covered by the Union harmonisation legislation listed in Section A of Annex I, the provider of the system shall follow the relevant conformity assessment procedure as required in accordance with the relevant Union harmonisation legislation. The requirements set out in Section 2 of this Chapter shall apply to those high-risk AI systems and shall be part of that assessment. Assessment of the quality management system set out in Article 17 shall also be undertaken, and points 3, 4.3, 4.4. and 4.5, the fifth paragraph of point 4.6 and point 5 of Annex VII shall apply.For the purposes of that conformity assessment, notified bodies which have been notified under the Union harmonisation legislation listed in Section A of Annex I shall have the power to assess the conformity of high-risk AI systems with the requirements set out in Section 2 of this Chapter, provided that the compliance of those notified bodies with the requirements laid down in Article 31(4), (5), (10) and (11) has been assessed in the context of the notification procedure in accordance with the relevant Union harmonisation legislation, which is evidenced through the assessment as part of the existing notification. Without prejudice to Article 28, such notified bodies which have been notified under the Union harmonisation legislation in Section A of Annex I, shall apply for designation in accordance with Section 4 of this Chapter by 28 January 2028.Where Union harmonisation legislation listed in Section A of Annex I provides the product manufacturer with an option to rely on a conformity assessment that does not involve a third-party, provided that that manufacturer has applied harmonised standards to ensure compliance with all the relevant requirements, that manufacturer may use that option only if it has also applied harmonised standards or, where applicable, common specifications referred to in Article 41, covering all requirements set out in Section 2 of this Chapter. The classification of a product as a high-risk AI system in accordance with Article 6(1) does not affect the choice of the conformity assessment procedure provided to the manufacturers of products covered by Union harmonisation legislation listed in Section A of Annex I, including, where applicable, an option to rely on harmonised standards. The manufacturers of such products are not required to choose a conformity assessment procedure involving third-party conformity assessment only because the product includes a high-risk AI system as a safety component, if this is not required by the Union harmonisation legislation listed in Section A of Annex I.Where a high-risk AI system is both covered by the Union harmonisation legislation listed in Section A of Annex I and it falls within one of the categories listed in Annex III, the provider of that system shall follow the relevant conformity assessment procedure as required pursuant to the relevant Union harmonisation legislation listed in Section A of Annex I.AI Act · consolidated 2026-07-27. Consolidated text is a documentation tool with no legal effect. of the AI Act that verification is done by your MDR or IVDR notified body as part of the device procedure. The condition is that the body has been assessed against the AI Act’s own notified body requirements. Bodies notified under the MDR or IVDR must apply for that designation by 28 January 2028. The guidance also notes, on the MDR and IVDR side, that how the AI contributes to the device’s performance must be reflected in the instructions for use or the user interface. Article 13 itself requires the listed content in the instructions that accompany the system. Interface elements can support those instructions without replacing them. Record which screen elements support which instruction, because the notified body will want to see that link.
One IFU, not two
Nothing in either regulation asks for a separate AI Act document. A provider that already draws up technical documentation under Annex I legislation must produce a single set containing both (Article 11(2)Article 11(2)Where a high-risk AI system related to a product covered by the Union harmonisation legislation listed in Section A of Annex I is placed on the market or put into service, a single set of technical documentation shall be drawn up containing all the information set out in paragraph 1, as well as the information required under those legal acts.AI Act · consolidated 2026-07-27. Consolidated text is a documentation tool with no legal effect. of the AI Act). The AI Act also gives such a provider the choice of integrating its testing, reporting, information and documentation duties into the procedures already established under that legislation (Article 8(2)Article 8(2)Where a product contains an AI system, to which the requirements of this Regulation as well as requirements of the Union harmonisation legislation listed in Section A of Annex I apply, providers shall be responsible for ensuring that their product is fully compliant with all applicable requirements under applicable Union harmonisation legislation. In ensuring the compliance of high-risk AI systems referred to in paragraph 1 with the requirements set out in this Section, and in order to ensure consistency, avoid duplication and minimise additional burdens, providers shall have a choice of integrating, as appropriate, the necessary testing and reporting processes, information and documentation they provide with regard to their product into documentation and procedures that already exist and are required under the Union harmonisation legislation listed in Section A of Annex I.AI Act · consolidated 2026-07-27. Consolidated text is a documentation tool with no legal effect. of the AI Act). MDCG 2025-6 strongly encourages manufacturers to use that flexibility. For the IFU this means one document. The Article 13(3) items are added to the Section 23.4 template where they are missing and expanded where Annex I already has a heading.
One point from the guidance needs stating plainly. Integrating the two sets of requirements into one document and one set of procedures saves you from maintaining two. It does not reduce what the document has to contain. Every item required by the AI Act and every item required by Annex I still has to be present and correct, and the notified body will check for both.
The format question
Article 13(2)Article 13(2)High-risk AI systems shall be accompanied by instructions for use in an appropriate digital format or otherwise that include concise, complete, correct and clear information that is relevant, accessible and comprehensible to deployers.AI Act · consolidated 2026-07-27. Consolidated text is a documentation tool with no legal effect. of the AI Act requires the instructions for use “in an appropriate digital format or otherwise”. The AI Act does not itself constrain the medium. For a device, the medium is governed by Annex I, which allows a non-paper IFU only to the extent and under the conditions of the eIFU implementing rules (Annex I, Section 23.1(f)Annex I, Section 23.1(f)(f) Instructions for use may be provided to the user in non-paper format (e.g. electronic) to the extent, and only under the conditions, set out in Regulation (EU) No 207/2012 or in any subsequent implementing rules adopted pursuant to this Regulation.MDR · consolidated 2026-07-19. Consolidated text is a documentation tool with no legal effect.). Today that means Regulation (EU) 2021/2226 as amended in 2025. The AI Act does not displace it. A device whose instructions are intended for lay persons still needs paper for those instructions. A professional-use device may go electronic only after the risk assessment and under the conditions of Article 5 of that regulation. Software may carry its own instructions, within those same conditions (Article 3(3)Article 3(3)For software covered by Regulation (EU) 2017/745, manufacturers may provide instructions for use in electronic form by means of the software itself instead of in paper form.eIFU Regulation · consolidated 2025-07-16. Consolidated text is a documentation tool with no legal effect.). For IVDs there is no implementing regulation; the IVDR allows non-paper instructions for professional-use devices directly, near-patient testing excepted.
The AI Act does affect one practical aspect of the IFU: how often it will need revising. Declared accuracy metrics, performance on specific groups, the list of pre-determined changes and the update cadence all describe the current version of the model. When the model changes, those statements may stop being true. The trigger for a revision is a change in what the instructions declare, not the retraining as such. A retraining that stays within a performance envelope the IFU already states, and that the change plan pre-specified, does not need a new IFU. One that moves the declared accuracy, the input specifications or the known limitations does. A model change outside the change plan is a substantial modification, with a conformity assessment of its own. How you write the change plan therefore decides how often the IFU has to be revised. When a revision is needed, the eIFU regulation already sets out how users are told. It requires a system to indicate clearly when the instructions have been revised, and to inform each user where the revision was necessary for safety (Article 5(8)Article 5(8)they shall have a system in place to clearly indicate when the instructions for use have been revised and to inform each user of the device thereof if the revision was necessary for safety reasons;eIFU Regulation · consolidated 2025-07-16. Consolidated text is a documentation tool with no legal effect.). It also requires every issued electronic version, with its publication date, to remain available on the website, or on request for obsolete versions (Article 5(13)Article 5(13)during the periods set out in points (9) and (10), all issued electronic versions of the instructions for use and their date of publication shall be available on the website or, as regards versions that are obsolete, be made available upon request.eIFU Regulation · consolidated 2025-07-16. Consolidated text is a documentation tool with no legal effect.).
The change plan, not the retraining schedule, decides how often the instructions for use have to be revised.
For a professional-use device that qualifies, an electronic IFU is therefore a reasonable choice for an IFU that will be revised more often. A manufacturer already providing one has a revision notice and a version history in place because Article 5 requires them. A manufacturer providing paper will need to set up a procedure for issuing revisions and telling users about them. Ydntfy’s hosting supports the website-side conditions of Article 5, including the revision notice and the availability of every version. The larger piece of work is deciding what the IFU must now say and validating it with users, and that work is the same whichever format you use.
Timing
- 2 August 2028. Chapter III, Sections 1 to 3, of the AI Act, which include Article 13, apply to high-risk AI systems classified under Article 6(1) and Annex I from this date, with the exception of Article 6(5) (Article 113, point (c)Article 113(c)Chapter III, Sections 1, 2, and 3, with the exception of Article 6(5), shall apply from: (i) 2 December 2027 as regards AI systems classified as high-risk pursuant to Article 6(2) and Annex III; and (ii) 2 August 2028 as regards AI systems classified as high-risk pursuant to Article 6(1) and Annex I;AI Act · consolidated 2026-07-27. Consolidated text is a documentation tool with no legal effect. of the AI Act, as amended by Regulation (EU) 2026/1744). Stand-alone Annex III systems apply from 2 December 2027.
- Devices already on the market. For a high-risk AI system placed on the market or put into service before that date, the AI Act applies only if the system undergoes a significant change in its design from that date onwards (Article 111(2)Article 111(2)Without prejudice to the application of Article 5 as referred to in Article 113, third paragraph, point (a), this Regulation shall apply to operators of high-risk AI systems, other than the systems referred to in paragraph 1 of this Article, that have been placed on the market or put into service before the date of application of Chapter III referred to in Article 113, only if, as from that date, those systems are subject to significant changes in their designs. In any case, the providers and deployers of high-risk AI systems intended to be used by public authorities shall take the necessary steps to comply with the requirements and obligations laid down in this Regulation by 2 August 2030.AI Act · consolidated 2026-07-27. Consolidated text is a documentation tool with no legal effect. of the AI Act). Systems intended for use by public authorities must comply by 2 August 2030 in any case, which will matter for devices used in public hospitals. The Omnibus rewrote this paragraph. The original text named 2 August 2026 as the date from which a significant change would bring a system into scope, a year before the high-risk rules applied to devices at all. MDCG 2025-6 dealt with that mismatch in its Question 31 by assuming the later date was meant. The amended text now says so: the date that counts is the date from which Chapter III applies to the device.
- Per unit, not per type. MDCG 2025-6 applies the Blue Guide’s rule that placing on the market refers to each individual product. A unit placed on the market after 2 August 2028 falls under the AI Act even if the same device type was on the market for years before that date.
- Standards and guidelines. When MDCG 2025-6 was published, CEN-CENELEC JTC 21 was still developing the harmonised standards on data and bias, and the Commission’s horizontal guidelines on Article 10 were still to come. The IFU content in Article 13(3) does not depend on either, so it can be drafted now.
What to do with this before 2028
Three steps fit inside an ordinary design change or the next scheduled IFU review.
- Map the two lists. Put the six points of Article 13(3), twelve items once the sub-points of point (b) are counted, beside Section 23.4 of Annex I, or Section 20.4 of the IVDR, in the IFU template. Mark each as present, present but to be expanded, or new. The table above is a starting point; the mapping for your device may differ.
- Decide what the interface carries. The instructions have to contain the listed content. Interpretation aids and oversight controls may also be shown on screen, at the point where the user needs them. Record which screen elements support which instruction, because the notified body assesses the instructions and the interface together.
- Write the IFU revision into the change plan. If you intend to use a pre-determined change plan under Annex IV, point 2(f), each pre-specified change should state the performance range the IFU already declares, which IFU sections must be revised if a change takes the system outside that range, and how users will be told. Without that, a change may be permitted under the plan while the users are left with an IFU that no longer describes their device.
Sources
Primary sources. Every claim in this post is traceable to one of these, and the sub-provision detail sits here rather than in the body.
Show 6 sources
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated text of 27 July 2026, EUR-Lex: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02024R1689-20260727. Article 3(15), definition of instructions for use; Article 6(1), (1a) and (1b), classification; Article 8(2), integration into existing procedures; Article 10, data and data governance; Article 11(2), single technical documentation; Article 13(2) and (3), instructions for use; Article 25(3), product manufacturer as provider; Article 26(1) and (5), deployer duties; Article 43(3), conformity assessment under Annex I legislation; Article 111(2), systems already on the market; Article 113, third paragraph, point (c), application dates; Annex I, Section A, points 11 and 12; Annex IV, point 2(f).
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal L 2026/1744 of 24 July 2026: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32026R1744. Amends Articles 6, 111 and 113 of the AI Act, among others.
- Regulation (EU) 2017/745 (MDR), consolidated text: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02017R0745-20260719. Article 5(5), in-house devices; Article 27(9), UDI storage by health institutions; Article 87(10), reporting by healthcare professionals and users; Annex I, Section 23.1(f) on non-paper instructions; Section 23.4, points (a), (b), (e), (g), (h), (j), (k), (q), (s) and (ab); Annex IX, Section 4.10.
- Regulation (EU) 2017/746 (IVDR), consolidated text: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02017R0746-20250110. Annex I, Section 20.1(f) on non-paper instructions; Section 20.4; Annex IX, Section 4.11.
- Commission Implementing Regulation (EU) 2021/2226 on electronic instructions for use, consolidated text of 16 July 2025: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:02021R2226-20250716. Article 3(2) and (3); Article 5, points (1), (3), (8) and (13).
- MDCG 2025-6 / AIB 2025-1, FAQ on the interplay between the Medical Devices Regulation and In Vitro Diagnostic Medical Devices Regulation and the Artificial Intelligence Act, June 2025: https://health.ec.europa.eu/latest-updates/mdcg-2025-6-faq-interplay-between-medical-devices-regulation-vitro-diagnostic-medical-devices-2025-06-19_en. Introduction (Article 8(2) integration), Question 2 and Table 1 (classification), Question 11 (data representativeness, standards and guidelines), Questions 14 and 15 (transparency and instructions for use), Question 30 (pre-determined changes), Question 31 (timing), Question 36 (training and AI literacy).
About this post
Ydntfy runs electronic instructions for use for medical device and IVD manufacturers, built to the conditions in Articles 4 to 7 of Regulation (EU) 2021/2226 for devices under the MDR and to Annex I, Section 20.1(f) of the IVDR for in vitro diagnostics. You can see how it works at ydntfy.com.
Originally published at https://ydntfy.com/en/blog/ai-act-instructions-for-use-medical-devices/ on 27 August 2026. You are welcome to quote or reuse this, with a link back.