Mission series · H
Transparency is not a banner
How Regulation (EU) 2024/1689 applies to Notified Body assessment infrastructure: classification honesty, Article 50 transparency, voluntary rigor when high-risk duties do not apply, and why compliance theater fails regulated judgment.
Regulation (EU) 2024/1689, the EU Artificial Intelligence Act, has become the default vocabulary for “responsible AI” in procurement. That is useful when it forces plain questions: What is the system for? Who decides? What happens before output becomes an official record? It is harmful when it collapses into a badge row: “AI Act compliant,” as if conformity assessment for software were the same product category as CE marking under the Act’s high-risk chapter.
For Notified Bodies assessing medical-device technical documentation under Regulation (EU) 2017/745, the harder standard was already institutional: qualified judgment, traceability, impartiality, and quality systems that survive audit. Series F defined what human-in-the-loop must mean when the work product is a conformity judgment (Human-in-the-loop, redefined for regulated assessment). This essay adds the EU AI Act layer as the legal frame that now tracks that philosophy for AI-assisted assessment infrastructure.
Empty human-in-the-loop and empty “AI Act compliance” share the same failure mode: fluent surfaces that hide who owns the conclusion.
Two different things called “AI in medical devices”
Series E separated AI as product function, devices whose intended purpose includes machine learning, from generative tools used to build documentation faster (The AI acceleration gap). The AI Act forces a parallel distinction for tools used inside conformity assessment: software that helps NB staff review manufacturer dossiers is not automatically a medical device, a safety component of a device, or a high-risk Annex III system merely because poor assistance could, indirectly, affect patient safety.
That indirect pathway is a real risk-management concern, and an MDR/NB quality issue. It is not, on a plain reading of the Act’s closed high-risk lists, the same as saying every system that can influence safety outcomes is high-risk under Article 6. Intended purpose matters. So does honesty about what the software does not do: it does not certify, it does not replace designation, it does not inherit institutional responsibility by marketing copy.
Classification honesty
For professional assessment-style assistance, drafting analyses, surfacing evidence, supporting auditor chat; the primary Article 6 reading we document publicly is not high-risk: not an Annex I product requiring third-party conformity assessment as SaMD, and not an Annex III listed use case such as credit scoring, law enforcement, or administration of justice before courts. Notified Bodies are conformity assessment bodies under MDR; they are not judicial authorities, and manufacturer technical-documentation review is not the same activity as the Annex III examples the list was written to capture.
Aggressive alternative readings exist, stretching “public services” or “applying law to facts” to capture any official legal-adjacent work. Providers should monitor Commission classification guidance and legal debate, document their Art. 6 reasoning, and avoid marketing that sounds like automated legal certification. Classification is not a one-time sticker; feature creep into autonomous conclusions or patient-level decisions would break the analysis.
What still applies when you are “not high-risk”
Regulation (EU) 2024/1689 still applies. AI literacy for provider and deployer organisations (Article 4) is already in force. Prohibited practices (Article 5) require a negative screen and change-control discipline when new features ship. And from 2 August 2026, Article 50 transparency bites for many real-world stacks: users who interact directly with AI should know they do; generative text and related outputs may need marking and detectable metadata where technically feasible, not only when a system wears a high-risk label.
- Article 50(1): auditor-facing chat and assistants should disclose AI interaction clearly; “obvious to an expert” is not a substitute for evidence in procurement.
- Article 50(2): drafts, summaries, and image descriptions used in review should be identifiable as machine-generated material in the UI and, where proportionate, in stored records.
- Parallel law: GDPR, cybersecurity, contracts, and manufacturer confidentiality in technical documentation do not wait for risk tier.
Transparency as product design
Article 50 is often discussed as a deadline. For assessment infrastructure, it is better read as a design specification that Series F already stated in institutional language: assisted output is material for professional review until a qualified person records disposition; the basis must be openable; silence or auto-promotion into the record is capture, not oversight.
A banner that says “AI-powered” on login day and never again is not transparency. Neither is a model that produces unlinked legal citations or confident language over missing evidence. The product behaviors that satisfy skeptical auditors, source linkage, editable drafts, disposition gates, run traceability, are the same behaviors that make Article 50 auditable.
Do not confuse MDR Notified Bodies with AI Act notified bodies
Chapter III of the AI Act creates conformity assessment pathways for high-risk AI systems, including entities designated as notified bodies under that regime. MDR Notified Bodies who assess manufacturer devices are customers and deployers of assessment tools, not the same legal role. Public sites that imply AI Act CE marking for NB assistance software, or that blur the two “notified body” phrases, will lose the audience that actually understands designation.
Voluntary rigor when the chapter does not apply
Articles 9-15, risk management, data governance, technical documentation, logging, human oversight, and accuracy, are the legal core of high-risk AI. For not-high-risk professional tools, they are not automatically mandatory in full. They are still a sensible blueprint when outputs can influence whether nonconformities are caught before devices reach patients.
Article 95 codes of conduct invite exactly this: adopt selected high-risk practices proportionately (Infrastructure for judgment). That is not imitation of compliance; it is alignment between law, ethics, and the series G mission: infrastructure for judgment, not automated certification.
- Hard human gates before final disposition in the assessment record.
- Evaluation when models or prompts change, not only at marketing launches.
- Visible limitations and AI-literacy support for deployer organisations.
- Supply-chain diligence on routing through GPAI models.
- NB quality-system integration for how AI involvement appears in inspectable assessment records.
Posture for procurement, not a badge
We publish an EU AI Act posture for TDVeriX Med: intended purpose, primary classification, applicable articles, product controls, explicit non-claims, and how MDR and the AI Act interact. It is engineering and governance language for quality, legal, and security review, not legal advice and not a substitute for customer contracts.
The EU AI Act does not replace Notified Body judgment. It asks whether AI assistance makes that judgment more legible or less accountable.
Sources
- 01Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)
EU horizontal framework for AI systems and GPAI models, including risk classification (Art. 6), literacy (Art. 4), prohibitions (Art. 5), transparency (Art. 50), and high-risk requirements.
- 02Regulation (EU) 2017/745 of the European Parliament and of the Council on medical devices (MDR)
Primary EU legal framework for medical devices, including notified-body designation, conformity-assessment procedures, and manufacturer obligations. Cited for institutional responsibility of assessment, not for product claims.