Compliance & Regulation

The EU AI Act and Regulated Manufacturing Projects: What Project Managers Need to Know

By John  |  11 August 2026  |  9 min read

Most of the guidance written about the EU AI Act focuses on legal teams, regulatory affairs, and quality management. Very little of it addresses the question that project managers in regulated manufacturing and med-tech need answered: how does this affect how we plan, execute, and govern product development projects?

The answer is: significantly. The EU AI Act (Regulation (EU) 2024/1689, which entered into force on 1 August 2024) introduces governance, documentation, and risk management requirements for AI systems that do not sit in the QMS. They sit in the project. And that means the project manager is responsible for building these requirements into the project plan from the start.

What the EU AI Act Actually Requires

The EU AI Act classifies AI systems by risk level. For regulated manufacturing and med-tech teams, the relevant category is high-risk AI systems, which includes AI embedded in products regulated under the EU Medical Device Regulation (MDR, 2017/745) and the In Vitro Diagnostic Regulation (IVDR, 2017/746), as well as AI used in safety-critical industrial processes.

For high-risk AI systems, the Act specifies the following obligations (Articles 9 to 15, Regulation (EU) 2024/1689):

Risk management system

A documented risk management process specific to the AI system, covering risks arising from AI behaviour, not just product safety risks under MDR/ISO 14971.

Data governance

Training and validation data must meet documented quality criteria. Data lineage and provenance must be traceable throughout the development process.

Technical documentation

Full technical documentation of the AI system, including design decisions, training approach, performance metrics, and limitations. This must be maintained throughout the product lifecycle.

Human oversight mechanisms

The product must be designed to allow human operators to oversee, correct, or override the AI system. This must be documented as a design requirement, not added retrospectively.

Accuracy and robustness

The AI system must meet documented accuracy, robustness, and cybersecurity requirements appropriate to its intended use. Performance must be validated against these requirements.

Logging and traceability

AI systems must log their operations to enable post-deployment audit. This requirement must be designed in during product development, not retrofitted after CE marking.

The Compliance Timeline

The EU AI Act's compliance timeline for med-tech and regulated manufacturing has been subject to revision. As of mid-2026, the position is as follows (Source: European Commission, Digital Omnibus package, 2026):

Do not wait for the final date. The design decisions you make in product development today will need to be documented regardless of which compliance deadline applies. AI systems designed without traceability, human oversight mechanisms, or documented data governance cannot be retroactively fixed before a regulatory deadline. The project is where compliance is built or missed.

What This Means for How You Run Regulated Projects

AI risk must be on your risk register

The standard ISO 14971 risk management process for medical devices covers safety risks arising from hardware and software behaviour. The EU AI Act requires a separate or extended risk management process for AI-specific risks: model drift, training data bias, unexpected AI outputs, and over-reliance by users. These risks must be on the project risk register from the start of the project, with owners and mitigation plans.

For project managers, this means ensuring that the project risk register explicitly includes AI-specific risks as a category, not just general technical risks. Project management software that supports structured, categorised risk management makes this significantly more tractable than a flat spreadsheet.

Gate criteria must include AI documentation completeness

In a standard regulated product development project, gate criteria cover design freeze completeness, verification plan approval, and risk review status. For AI-enabled products, gate criteria should also confirm: Is the AI technical documentation current? Has the data governance approach been reviewed? Have human oversight mechanisms been verified against design requirements?

This is a project governance question, not a regulatory affairs question. The project manager defines the gate criteria. If AI documentation completeness is not a gate criterion, it will not be systematically checked at each phase transition.

Traceability from design decisions to AI outputs

The EU AI Act requires that the design decisions influencing an AI system's behaviour are documented and traceable. In practice, this means the project plan needs explicit work packages for AI design documentation, and the project management software needs to support linking those work packages to the broader design and development record.

The Project Management Software Implication

EU AI Act compliance for regulated product development is not primarily a QMS challenge. It is a project governance challenge. The risk management, gate governance, and traceability requirements it introduces need to be embedded in how projects are planned and executed from day one.

Project management software that provides only scheduling does not support this. The platform needs to enable structured risk management with AI-specific risk categories, gate governance with documentation completeness criteria, and an audit trail that links design decisions to project records.

For more on how AI governance requirements intersect with the project management standards your team is likely already using, see the post on the PMI AI Standard and what it means for regulated project managers.

Frequently Asked Questions

What is the EU AI Act and when does it apply to regulated manufacturing?

The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive legal framework for artificial intelligence, entered into force on 1 August 2024. For regulated manufacturing teams developing AI-enabled medical devices, compliance requirements for Annex I high-risk categories are under review, with proposed timelines extending to 2027-2028 under the Digital Omnibus package. The governance and project management implications are relevant now, regardless of final compliance dates.

What does the EU AI Act require for project management of AI-enabled products?

The EU AI Act requires documented risk management, data governance, human oversight mechanisms, and technical documentation for high-risk AI systems (Articles 9-15, Regulation (EU) 2024/1689). For project managers, these requirements must be built into the project plan from the start: AI-specific risks on the risk register, gate criteria that include AI documentation completeness, and traceability from design decisions to AI system outputs.

Does the EU AI Act apply to med-tech product development projects?

Med-tech companies developing AI-enabled devices classified under EU MDR/IVDR will be subject to EU AI Act obligations for those devices. The interaction between the AI Act and MDR/IVDR is being clarified through the Digital Omnibus package. Companies should treat AI governance as a project management requirement now, since design decisions made during product development will need to be documented regardless of which regulatory pathway ultimately applies.

Managing a Regulated Project with AI Components?

Arcturus Pro gives regulated manufacturing and med-tech project teams structured risk management, gate governance, and a full project audit trail in one platform. Book a 30-minute walkthrough to see how it supports AI-enabled product development projects.

Book a Demo
J
John

Founder of Arcturus Pro. IPMA Level C certified with 8 years running regulated manufacturing and med-tech programmes. Built Arcturus Pro because he lived the problem of managing complex regulated projects without the right tools.