Using AI for quality control, inspection or manufacturing medical devices? Learn what the EU AI Act means, key deadlines and how manufacturers should prepare.

01

AI is already part of manufacturing

Computer vision can detect defects. Algorithms can inspect components, identify unusual production patterns, analyse images and support quality teams. Across Ireland's medical-device and pharmaceutical sector, AI is increasingly embedded in production equipment, laboratory tools and third-party software.

That makes AI governance more than an IT question. Manufacturers need to know where AI is used, what decisions it influences and how those decisions fit within existing quality, regulatory and risk-management controls.

  • Visual inspection and automated defect detection.
  • Predictive maintenance and manufacturing optimisation.
  • Laboratory analysis and quality-control software.
  • AI functions embedded in production equipment.
  • Generative AI used by QA, engineering and other teams.
02

Is AI used for quality control automatically high-risk?

No. An AI camera inspecting packaging, detecting cosmetic defects or helping optimise a process does not automatically become a high-risk AI system because it operates in a medical-device factory.

The legal classification depends on the system's intended purpose and the conditions in Article 6. Under the product route, an AI system can be high-risk where it is intended as a safety component of a product, or is itself a regulated product covered by Annex I, and that product requires third-party conformity assessment. Medical devices are included in that framework.

A separate factory quality-control tool is not automatically part of the medical device itself. Even where it falls outside the AI Act's high-risk category, however, an incorrect result can create serious product-quality, patient-safety, validation, data-protection or contractual risk. That still deserves proportionate governance.

  • Does the AI form part of the medical device or another Annex I regulated product?
  • Is it intended to perform a safety function or operate as a safety component?
  • Does it materially influence release, rejection or another safety-critical decision?
  • What happens if the system misses a defect or produces an unusual result?
  • Which person reviews, challenges and can override the output?
03

When do manufacturers need to comply?

The AI Act is already in force and several provisions already apply. AI-literacy requirements have applied since 2 February 2025. Governance and general-purpose AI provisions began applying in August 2025, while further transparency and enforcement provisions applied from August 2026.

Following the AI Omnibus timetable change, the high-risk requirements for AI embedded in regulated products, including qualifying medical devices, apply from 2 August 2028. The later date creates preparation time, not a reason to ignore AI use until 2028.

The Commission's detailed high-risk classification guidance is still draft at the date of publication. Manufacturers should distinguish that draft guidance from obligations already contained in the legislation and monitor the final guidance when adopted.

04

What should manufacturers put in place now?

These controls can often be integrated into existing quality and governance structures. The aim is not to create another compliance department. It is to prevent AI from becoming an unidentified decision-maker inside a regulated process.

  • Create an AI inventory covering production, inspection, laboratory, quality, maintenance and employee-use systems.
  • Record the intended purpose, supplier, system owner, data used and decisions influenced by each system.
  • Screen each use against the AI Act's high-risk test and any relevant medical-device, pharmaceutical, GDPR and cybersecurity requirements.
  • Define human oversight: who reviews the output, when intervention is required and who can override the system.
  • Set clear rules for approved AI, validation, verification, supplier review, incidents and escalation.
  • Provide role-appropriate AI literacy for operators, QA teams, engineers and managers, and retain evidence of the measures taken.
05

Blanche perspective

The difficult part is usually not writing an AI policy. It is discovering where AI is already being used and how much influence those systems have.

Start with three questions: what AI are you using, what rules apply and what needs to happen next? A clear inventory and ownership model lets detailed compliance work follow the actual risk instead of assumptions or software marketing labels.

Doing nothing is not the same as not using AI, particularly when AI functionality arrives through equipment, software suppliers or employees' everyday tools.

S

Sources

Primary and authoritative sources used for this Insight.

  1. Regulation (EU) 2024/1689, consolidated text
  2. European Commission: current AI Act timetable and high-risk classification
  3. European Commission: draft high-risk AI classification guidelines
  4. European Commission: artificial intelligence in healthcare
  5. European Commission: AI literacy questions and answers
Share this Insight