ARTICLE
26 August 2026

AI In MedTech Is Not Just Another Software Project

FP
FABIAN PRIVACY LEGAL GmbH

Contributor

We are a boutique law firm specializing in data, privacy and data protection laws and related issues, information security, data and privacy governance, risk management, program implementation and legal compliance. Our strengths are the combination of expert knowledge and practical in-house experience as well as a strong network with industry groups, privacy associations and experts around the world.
A fundamental mistake in MedTech is to treat AI as another software project. It is not. An AI-enabled medical product can involve product safety, clinical performance, quality management, data protection, cybersecurity and AI regulation at the same time.
Switzerland Technology
Daniela Fabian’s articles from FABIAN PRIVACY LEGAL GmbH are most popular:
  • within Technology topic(s)
  • with readers working within the Media & Information industries
FABIAN PRIVACY LEGAL GmbH are most popular:
  • within Technology, Food, Drugs, Healthcare and Life Sciences topic(s)

A fundamental mistake in MedTech is to treat AI as another software project. It is not. An AI-enabled medical product can involve product safety, clinical performance, quality management, data protection, cybersecurity and AI regulation at the same time.

That creates a particular challenge for MedTech organisations: the issues are connected, but the teams dealing with them often are not.

  • Product develops the functionality.
  • Regulatory manages MDR or IVDR.
  • Quality owns the QMS.
  • Legal assesses AI, data protection and contracts.
  • Cybersecurity manages security risks.

Each team may do an excellent job. But who connects the pieces?

Where the risks overlap

The difficulty is that one product decision can trigger questions across several areas at the same time. For example:

  • A model update may improve the product's performance. But it may also need to be assessed from a validation, documentation and change-control perspective.
  • A new dataset may support development or product improvement. At the same time, the company may need to consider data rights, privacy, data quality and whether the data is suitable for the intended purpose.
  • A cybersecurity incident may start as a technical issue. But depending on the circumstances, it may also have implications for product safety, data protection, contractual obligations and regulatory reporting.

This is where fragmented workstreams create risk. The key question is not only which rules apply. It is whether the organisation can identify how one change or incident affects the product across Product, Regulatory, Quality, Data, Privacy and Cybersecurity.

For an AI-enabled medical product, these questions need to be connected rather than assessed in isolation.

Another AI compliance workstream will not solve the problem

The intuitive response to new regulation is often to create another project: an AI Act project alongside the MDR or IVDR workstream, the GDPR programme, cybersecurity and Data Act implementation. But the organisation is not launching five compliance projects. It is launching one product.

For MedTech companies, AI governance should therefore be integrated into the processes that already govern that product. That means connecting AI, data, privacy and cybersecurity considerations with:

  • product design and development;
  • validation and change management;
  • relevant QMS processes and controls;
  • post-market activities; and
  • incident management.

The applicable legal requirements still need to be assessed separately. Not every regime applies in the same way to every product. But internally, their consequences cannot be managed effectively in isolation.

One product needs one governance view

This is where MedTech differs from much of the generic AI-governance discussion. The goal is not simply to make an AI system "AI Act compliant". The real management question is broader:

Can we develop, validate, launch and operate this product within one coherent product-governance framework?

That requires Product, Regulatory, Quality, AI, Data, Privacy and Cybersecurity to work as parts of the same product journey.

For a CEO, the question is therefore simple: Is AI governance already embedded in my product lifecycle, or is it still treated as a separate Legal or IT workstream?

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More