Most of the guidance written about the EU AI Act focuses on legal teams, regulatory affairs, and quality management. Very little of it addresses the question that project managers in regulated manufacturing and med-tech need answered: how does this affect how we plan, execute, and govern product development projects?
The answer is: significantly. The EU AI Act (Regulation (EU) 2024/1689, which entered into force on 1 August 2024) introduces governance, documentation, and risk management requirements for AI systems that do not sit in the QMS. They sit in the project. And that means the project manager is responsible for building these requirements into the project plan from the start.
The EU AI Act classifies AI systems by risk level. For regulated manufacturing and med-tech teams, the relevant category is high-risk AI systems, which includes AI embedded in products regulated under the EU Medical Device Regulation (MDR, 2017/745) and the In Vitro Diagnostic Regulation (IVDR, 2017/746), as well as AI used in safety-critical industrial processes.
For high-risk AI systems, the Act specifies the following obligations (Articles 9 to 15, Regulation (EU) 2024/1689):
A documented risk management process specific to the AI system, covering risks arising from AI behaviour, not just product safety risks under MDR/ISO 14971.
Training and validation data must meet documented quality criteria. Data lineage and provenance must be traceable throughout the development process.
Full technical documentation of the AI system, including design decisions, training approach, performance metrics, and limitations. This must be maintained throughout the product lifecycle.
The product must be designed to allow human operators to oversee, correct, or override the AI system. This must be documented as a design requirement, not added retrospectively.
The AI system must meet documented accuracy, robustness, and cybersecurity requirements appropriate to its intended use. Performance must be validated against these requirements.
AI systems must log their operations to enable post-deployment audit. This requirement must be designed in during product development, not retrofitted after CE marking.
The EU AI Act's compliance timeline for med-tech and regulated manufacturing has been subject to revision. As of mid-2026, the position is as follows (Source: European Commission, Digital Omnibus package, 2026):
Do not wait for the final date. The design decisions you make in product development today will need to be documented regardless of which compliance deadline applies. AI systems designed without traceability, human oversight mechanisms, or documented data governance cannot be retroactively fixed before a regulatory deadline. The project is where compliance is built or missed.
The standard ISO 14971 risk management process for medical devices covers safety risks arising from hardware and software behaviour. The EU AI Act requires a separate or extended risk management process for AI-specific risks: model drift, training data bias, unexpected AI outputs, and over-reliance by users. These risks must be on the project risk register from the start of the project, with owners and mitigation plans.
For project managers, this means ensuring that the project risk register explicitly includes AI-specific risks as a category, not just general technical risks. Project management software that supports structured, categorised risk management makes this significantly more tractable than a flat spreadsheet.
In a standard regulated product development project, gate criteria cover design freeze completeness, verification plan approval, and risk review status. For AI-enabled products, gate criteria should also confirm: Is the AI technical documentation current? Has the data governance approach been reviewed? Have human oversight mechanisms been verified against design requirements?
This is a project governance question, not a regulatory affairs question. The project manager defines the gate criteria. If AI documentation completeness is not a gate criterion, it will not be systematically checked at each phase transition.
The EU AI Act requires that the design decisions influencing an AI system's behaviour are documented and traceable. In practice, this means the project plan needs explicit work packages for AI design documentation, and the project management software needs to support linking those work packages to the broader design and development record.
EU AI Act compliance for regulated product development is not primarily a QMS challenge. It is a project governance challenge. The risk management, gate governance, and traceability requirements it introduces need to be embedded in how projects are planned and executed from day one.
Project management software that provides only scheduling does not support this. The platform needs to enable structured risk management with AI-specific risk categories, gate governance with documentation completeness criteria, and an audit trail that links design decisions to project records.
For more on how AI governance requirements intersect with the project management standards your team is likely already using, see the post on the PMI AI Standard and what it means for regulated project managers.
The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive legal framework for artificial intelligence, entered into force on 1 August 2024. For regulated manufacturing teams developing AI-enabled medical devices, compliance requirements for Annex I high-risk categories are under review, with proposed timelines extending to 2027-2028 under the Digital Omnibus package. The governance and project management implications are relevant now, regardless of final compliance dates.
The EU AI Act requires documented risk management, data governance, human oversight mechanisms, and technical documentation for high-risk AI systems (Articles 9-15, Regulation (EU) 2024/1689). For project managers, these requirements must be built into the project plan from the start: AI-specific risks on the risk register, gate criteria that include AI documentation completeness, and traceability from design decisions to AI system outputs.
Med-tech companies developing AI-enabled devices classified under EU MDR/IVDR will be subject to EU AI Act obligations for those devices. The interaction between the AI Act and MDR/IVDR is being clarified through the Digital Omnibus package. Companies should treat AI governance as a project management requirement now, since design decisions made during product development will need to be documented regardless of which regulatory pathway ultimately applies.
Arcturus Pro gives regulated manufacturing and med-tech project teams structured risk management, gate governance, and a full project audit trail in one platform. Book a 30-minute walkthrough to see how it supports AI-enabled product development projects.
Book a Demo