🔍 During the CE certification, the company's auditor works through the technical file and stops at the module that turns a measurement into a patient risk score. "Does the AI Act apply to this one too?"
No one on the team can answer straight away, even though the product has been a medical device for years.
The first question, at that point, is not whether the Company can comply with the AI Act's requirements, but whether the module qualifies as an AI system at all.
The concept is narrower than commercial messaging suggests: it applies to systems that infer, meaning the output was not written by hand and the system learns from data. On looking inside the module, it often turns out that this is not what runs there, but rather a fixed, clinically validated algorithm: deterministic, the same input always producing the same score. If the system works this way, it likely falls outside the AI Act's concept of an AI system, and the full AI Act analysis never even begins.
✅ Genuine relief, and worth recording in the technical file. The reverse is equally true: if the module contains a genuine learning model that draws conclusions from patient data, the Regulation applies to you as well, and the argument that "it is only part of the device" offers no protection in an audit.
👉 Before the next certification, capture in a single sentence what the module actually does: does it infer from the data, or does it run rules the organisation has validated? Development and regulatory affairs need to agree on this before the question arrives from outside.

