Evidence explainer

Health policy, systems, and equity

The EU AI Act's Four Risk Tiers, and Why Clinical AI Usually Lands in the High-Risk Band

The EU AI Act sorts systems into four risk bands. Most clinical AI lands in the high-risk band, because a tool that already counts as a medical device is high-risk by definition.

Fully reviewed by Jasaman (Jasmin) Tojjar, MD, PhD

On this page
  1. The short answer
  2. Key points
  3. Reading the ladder from the bottom up
  4. Two doors into the high-risk band
  5. What the high-risk label demands
  6. A phased timeline that is still moving

The short answer#

The EU AI Act regulates by consequence, not by algorithm. It places every system into one of four risk bands according to the danger it poses to health, safety, and fundamental rights: a narrow prohibited band at the top, a large high-risk band that carries the real regulatory weight, a limited-risk band that mostly asks for honesty about what the system is, and a minimal-risk band that adds almost nothing new. Clinical AI usually lands in the high-risk band, because a system that already qualifies as a medical device (or a safety component of one) is treated as high-risk by definition. What follows is an educational map of that classification logic and the duties that attach to it.

Key points#

Reading the ladder from the bottom up#

It helps to climb the four bands from the least demanding to the most, because that is where almost all software sits.

At the base is minimal risk, home to the vast majority of everyday tools: spam filters, scheduling utilities, inventory systems, most back-office automation. The Act leaves this band essentially alone and points toward voluntary good practice rather than mandatory controls.

One rung up is limited risk, which is really a transparency band. The worry here is not that someone gets hurt but that a person cannot tell a machine from a human. A conversational agent has to disclose that it is one; certain synthetic or altered media has to be labeled. A patient-facing symptom assistant can pick up these disclosure duties in addition to any device rules that apply to it.

Near the top is high-risk, where the heavy obligations live and where most medical AI belongs. This band is the focus of the rest of this piece.

At the very top is the prohibited band, a short list of practices the Act treats as incompatible with fundamental rights, such as untargeted scraping to assemble facial-recognition databases or certain forms of social scoring. Little clinical software comes near this line, but it exists to mark a hard outer boundary.

A single underlying model can appear on more than one rung depending on its purpose, which is the whole point of classifying by use rather than by technology.

Two doors into the high-risk band#

The Act opens two routes into high-risk status, and medical AI almost always takes the first (AI Act, Article 6).

The first route runs through products that are already regulated under existing EU safety law. When an AI system is itself a regulated product, or a safety component of one, and that product must pass third-party conformity assessment, the AI inherits high-risk status. Medical devices and in vitro diagnostic devices sit exactly here. So a tool that qualifies as Software as a Medical Device under the Medical Device Regulation or the In Vitro Diagnostic Regulation, or an AI component built into a physical device, generally counts as high-risk under the AI Act. This is the structural reason so much clinical AI arrives pre-sorted into the band: it was a regulated medical product long before the AI Act existed.

The second route is a named list of use cases the Act singles out, spanning biometrics, critical infrastructure, education, employment, and access to essential services. Health appears on this list too, for instance in certain uses tied to emergency-care triage and to eligibility for public benefits (AI Act, Annex III). A narrow filter is built in: a system that would otherwise be listed can step out of high-risk status if it does not pose a significant risk to health, safety, or rights, provided the maker documents that assessment. The carve-out is deliberately tight, and a tool that meaningfully shapes a diagnosis or a treatment choice rarely qualifies for it.

The practical rule of thumb is short. If your software helps decide what is wrong with a patient, or what to do about it, expect the high-risk label and plan around it.

What the high-risk label demands#

The obligations amount to a written-down version of disciplined medical-device engineering. If you already work under a modern quality system, you will recognize most of it, which is the intended effect.

Risk management means a continuous, documented process that finds and reduces foreseeable harms across the entire lifecycle and is revisited whenever the system changes. It maps closely onto the risk discipline device engineers know from standards such as ISO 14971.

Data governance requires that training, validation, and test data be managed for relevance, representativeness, accuracy, and completeness, with known biases examined and corrected. For clinical tools, questions about who the data represents, and who it leaves out, become formal duties rather than afterthoughts.

Technical documentation and record-keeping call for a defined dossier that demonstrates conformity and stays current as the system evolves.

Logging obliges the system to record events automatically over its lifetime, so its behavior can be traced and audited. In care settings, that traceability pays for itself the first time an output is challenged and someone needs to reconstruct what happened.

Transparency and instructions for use give the people deploying a system clear information about its capabilities, limits, and proper use, so a clinician can interpret an output instead of deferring to it on faith.

Human oversight requires designs that let a competent person understand, monitor, and if needed override the system, keeping a clinician meaningfully in the loop rather than reduced to a signature.

Accuracy, robustness, and cybersecurity ask the system to perform consistently and to resist both error and interference across its intended use.

Post-market monitoring keeps providers watching real-world performance after launch, feeding what they learn back into risk management and reporting serious incidents. It is a standing duty, not a one-time gate at approval.

These AI Act duties are meant to run alongside existing device rules rather than duplicate them. The goal is a single coordinated conformity assessment that satisfies both frameworks at once, so a manufacturer is not forced through two separate processes.

A phased timeline that is still moving#

The Act came into force in 2024 and switches on in stages rather than all together (AI Act high-level summary). The prohibited-practice rules and early AI-literacy duties landed first, and obligations for general-purpose AI models followed. The high-risk obligations arrive later, and the calendar there deserves caution: the schedule for high-risk systems, especially AI tied to already-regulated products like medical devices, has repeatedly shifted, and during 2026 EU institutions worked toward a provisional agreement to postpone parts of the high-risk regime. Rather than fix on a single date that may move again, the safer reading is directional. High-risk duties for medical AI fall among the later phases, and the exact dates are worth checking against the current official text before you build a compliance plan around them.

The steadier lesson is to start early. Risk files, data-governance records, logging, oversight design, and monitoring plans all take time to assemble, and getting a head start is sensible wherever the final dates settle.

Sources and further reading

  1. European Commission EU AI Act regulatory framework
  2. AI Act Article 6 classification rules for high-risk AI
  3. AI Act Annex III high-risk use cases including healthcare triage
  4. High-level summary of the AI Act risk tiers and phased timeline

Questions and answers

Is every medical AI tool automatically high-risk?

Not automatically, but usually. A system counts as high-risk when it is a regulated medical device (or a safety component of one) that needs third-party conformity assessment, which describes most clinical AI. A narrow filter can lift a listed use case out of high-risk status if it poses no significant risk and the maker documents that finding, but tools that shape diagnosis or treatment rarely fit through it.

Do the AI Act duties replace the medical-device rules?

No. They are designed to run alongside the Medical Device Regulation and In Vitro Diagnostic Regulation. The intent is one coordinated conformity assessment that satisfies both frameworks together, not two parallel bureaucracies.

When do the high-risk obligations take effect?

They fall among the later phases of a staged rollout that began in 2024, and the dates for high-risk medical AI have kept changing. Treat any specific date as provisional and confirm it against the current official text before relying on it.