AI and regulatory

AI for medical device regulatory work, with guardrails

AI in medical device regulatory work means using language models to draft, summarise, translate and cross-check regulatory documents. The risk is that a model writes plausible but untrue statements, such as a retention period, an authority or a test result, into a controlled document. MDRpilot uses AI as an assistant inside a regulatory workspace: templates lock document headings, company facts come from the profile, unconfirmed points are marked [TO BE CONFIRMED], and every draft must be reviewed and approved by a person. A company owner can switch external AI off for the whole workspace.

Who it is for

  • Regulatory teams evaluating AI tools
  • Quality managers who must control AI-generated content
  • Data protection officers reviewing AI processing

Key capabilities

  • Controlled templates

    Headings and preamble are fixed; AI writes within them.

  • Fact card

    Every draft lists the company facts it used and the facts still to confirm.

  • Human approval

    Drafts go through review and approval before they are effective.

  • Workspace opt-out

    Owners can disable external AI processing in Settings.

Where AI helps and where it should not decide

TaskRole of AI in MDRpilot
Drafting procedures and sectionsFills section bodies inside locked templates using confirmed facts
Reading test reportsExtracts the standard and pass or fail verdict and proposes links; a user confirms
Literature screening supportHelps structure search and summaries; evaluators appraise the papers
TranslationTranslates documents with medical terminology handling for review
ClassificationNot AI: the Annex VIII assistant is rule-based and shows its reasoning
Approval and releaseNever AI: always a named user with the right role

Guardrails that are built in

  • Facts used and facts still to confirm are shown next to every procedure draft
  • In procedure drafts, statements such as retention years or notified body numbers that are not in your profile are removed from AI output
  • AI generation and approvals are recorded in the activity log
  • Provider API keys stay on the server and never reach the browser
  • External AI can be turned off per company; non-AI workflows keep working

The EU AI Act and your own devices

Regulation (EU) 2024/1689, the AI Act, treats AI systems that are medical devices, or safety components of them, requiring notified body assessment under MDR as high-risk AI systems, with obligations applying from 2 August 2027. That concerns AI inside your device. MDRpilot is a documentation tool used by manufacturers, not a medical device and not part of one.

How the workflow runs

  1. 1

    Confirm facts

    Complete the company profile.

  2. 2

    Answer specifics

    Answer the questions for the procedure or section.

  3. 3

    Draft

    Generate within the template.

  4. 4

    Review

    Check, edit and approve.

Connected to the rest of the file

MDRpilot is not a stand-alone document generator. Requirements, evidence and documents share one product record.

  1. Requirements
  2. Evidence
  3. Documents
  4. Risk
  5. Clinical
  6. PMS
  7. QMS
  8. Audit

Each step reads from the same product record. A test report linked to a GSPR row can verify a risk control, a change to the device class flags the documents that depend on it, and the audit readiness view counts what is still open across all of them.

Limitations

  • AI can still misread or misphrase; review is mandatory, not optional.
  • When external AI is used, relevant excerpts are processed by the configured providers, for example OpenAI or Anthropic, under the terms described in the privacy policy.
  • AI does not replace qualified clinical evaluators, risk managers or the PRRC.

MDRpilot is documentation and workflow software. It is not a medical device, not a notified body and not a regulatory authority. It does not certify devices or guarantee compliance; AI-generated drafts must be reviewed and approved by qualified people in the manufacturer's organisation.

Frequently asked questions

Does MDRpilot use AI to make regulatory decisions?

No. AI drafts and proposes. Classification is rule-based with visible reasoning, and approvals are always made by people.

Can we turn AI off?

Yes. A company owner can disable external AI processing for the workspace in Settings.

Is our data used to train AI models?

Excerpts are sent to the configured providers only to generate the output you request. Where providers offer contractual options, MDRpilot configures them not to use customer data for training public models, as described in the privacy policy.

What stops AI from inventing a retention period or authority?

Those facts come from your profile. If they are missing, the procedure draft shows [TO BE CONFIRMED], and unconfirmed claims of that type are removed from the AI output.

Is MDRpilot itself subject to the AI Act as a high-risk system?

MDRpilot is not a medical device and is not a safety component of one. The AI Act's high-risk rules for medical devices concern AI inside regulated devices. For your own assessment, consult the regulation text.

References

  1. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (AI Act) — EUR-Lex, Publications Office of the European Union.
  2. Regulation (EU) 2017/745 on medical devices (MDR) — EUR-Lex, Publications Office of the European Union.
  3. MDCG 2019-11 Qualification and classification of software (MDR and IVDR) — Medical Device Coordination Group. Listed under medical device software.

Always check the consolidated text of the regulation and the current version of each guidance document before relying on it.

See it with your own device

Create an account, add your company and one real device. The Suite demo runs for 3 days and the first procedure opens straight away, not an empty dashboard.