Summary
Artificial intelligence is evolving faster than the regulatory frameworks around it. But that gap is beginning to close, with a growing body of AI medical device standards now moving towards publication and wider regulatory recognition.
In his latest article, Leon Doorn examines the advancing standards landscape and what manufacturers of AI/ML-enabled medical devices should be watching as the EU AI Act and other regulatory requirements move closer to practical application. For manufacturers navigating AI medical device regulation, understanding which standards actually support regulatory conformity is becoming increasingly important.
The article looks across the main organisations shaping this landscape, including ISO/IEC JTC 1/SC 42, CEN-CENELEC JTC 21, IEC TC 62, ISO/TC 210, ISO/TC 215 and the IMDRF. It explores developments across quality management, medical device risk management, cybersecurity, data management, software development, performance evaluation and post-market surveillance.
One important distinction is between standards developed for AI systems generally and those designed specifically for medical devices. ISO/IEC 42001 and ISO/IEC 23894, for example, address organisational AI management and risk management, while newer European standards such as EN 18286 and EN 18228 are being developed to address safety and fundamental-rights concerns relevant to the AI Act medical devices framework. At the same time, international work is progressing on areas such as risk management through ISO/TS 24971-2. This also raises broader questions around management systems and how AI-specific requirements fit alongside established medical device quality frameworks.
Cybersecurity and privacy are also moving forward, with standards and specifications emerging to address AI-specific concerns alongside established medical device frameworks such as IEC 81001-5-1 and ISO 14971. Medical device-specific work is also underway for verification testing, performance evaluation, post-market surveillance and other aspects of the AI/ML lifecycle.
Leon also highlights a practical challenge: the number of standards and committees involved makes it difficult for manufacturers to know which developments are relevant and which can actually support regulatory conformity. Some widely referenced AI standards may not be suitable for demonstrating compliance with medical device requirements, making it important to verify claims against the original standards and regulatory sources.
The article concludes that the AI/ML risk management gap is increasingly being addressed, cybersecurity is relatively well covered, and more medical device-specific AI/ML standards are on the way. However, an international quality management solution tailored to AI/ML-enabled medical devices remains an open gap.
For manufacturers, the message is practical: follow the committees doing the work, monitor the standards landscape closely, verify requirements against primary sources, and begin aligning processes with relevant emerging standards rather than waiting for requirements to become mandatory.
Read the full LinkedIn article, Advancements in AI/ML Standards, to explore the evolving AI/ML standards landscape and what it means for AI-enabled medical devices.