EU AI ACT - AI-Enabled Medical Devices & Software as a Medical Device (SaMD)
Consulting Expertise Bridging the EU AI Act, EU MDR and GDPR
Artificial Intelligence is transforming healthcare and creating new opportunities for software, digital health and medical device manufacturers.
As AI increasingly becomes part of medical devices and Software as a Medical Device (SaMD), organisations must navigate an evolving regulatory landscape where multiple legal, technical and clinical frameworks apply simultaneously.
AI-enabled medical devices may be required to comply with the EU Medical Device Regulation (MDR 2017/745), the EU Artificial Intelligence Act (EU AI Act 2024/1689) and the General Data Protection Regulation (GDPR). Together, these frameworks introduce requirements that extend beyond traditional medical device compliance, including AI risk management, data governance, human oversight, validation, lifecycle management and post-market surveillance.
The challenge is no longer understanding each regulation individually.
The challenge is understanding how these regulatory frameworks work together throughout the entire product lifecycle—from concept and intended medical purpose through design and development, risk management, validation, clinical evaluation, market access and post-market activities.
Tox Regulatory Advisor ApS helps organisations bridge these requirements by integrating regulatory affairs, quality management, clinical affairs, design assurance, validation, risk management and AI governance into practical product development strategies.
Our Consulting Expertise
Regulatory Strategy
- Qualification and classification of AI-enabled medical devices and SaMD
- Regulatory pathway and conformity assessment strategy
- Gap analysis against the EU MDR, EU AI Act and GDPR
- Regulatory implementation planning
AI Risk Management & Governance
- Integration of AI-specific considerations into medical device risk management
- AI governance throughout the product lifecycle
- Human oversight strategies
- Data governance
- Cybersecurity considerations
- Change management and lifecycle management
Design Assurance & Validation
- Design controls and Design Assurance
- Verification and Design Validation
- AI model validation &Medical device validation
Clinical validation &Human factors and usability engineering
Quality Management & Lifecycle Support
- Integration of AI requirements into Quality Management Systems
- Technical Documentation
- Performance monitoring, Post-Market Surveillance &CAPA
- Continuous regulatory compliance
Our Approach
Rather than treating the EU AI Act, the EU MDR and the GDPR as separate regulatory requirements, we help organisations integrate them into a coherent product development and lifecycle strategy.
By bridging regulatory affairs, quality management, clinical affairs, design assurance, validation and AI governance, we support organisations in developing AI-enabled medical devices that are not only compliant, but also safe, effective and prepared for long-term lifecycle management.

