EXECUTIVE SUMMARY
This week’s briefing highlights an active IMDRF public consultation on an AI/ML Lifecycle Management Framework (open through July 10, 2026), and critical approaching regulatory deadlines for EU AI Act high-risk AI obligations (August 2026) and the EU Cyber Resilience Act vulnerability-reporting mandate (September 11, 2026). Manufacturers are encouraged to review the IMDRF consultation and submit comments before the July deadline.
IMDRF — INTERNATIONAL MEDICAL DEVICE REGULATORS FORUM
AI/ML Lifecycle Management Framework — Public Consultation Open
IMDRF opened a public consultation on April 10, 2026 for its draft Technical Framework for Artificial Intelligence Life Cycle Management. Comments are accepted through July 10, 2026 via the IMDRF Consultation Hub on Citizen Space.
The draft covers the full product lifecycle for AI-enabled medical devices: planning, data collection and governance, model building and tuning, verification and validation, clinical evaluation, deployment, operations, real-world performance evaluation, and sunsetting.
Key cybersecurity-relevant elements in the draft include:
Model drift: The framework explicitly addresses the risk that AI-enabled devices can degrade as real-world inputs shift from training data, requiring drift detection, alerting, and controlled recalibration or retraining processes.
Data quality and bias: Manufacturers must address dataset representativeness, traceability, and bias mitigation — with particular attention to performance across diverse patient groups and care settings.
Lifecycle responsibility: IMDRF frames AI oversight as an ongoing total-lifecycle obligation, not a one-time premarket submission exercise.
Cybersecurity integration: The draft is designed to complement existing IMDRF work on cybersecurity, SaMD, Good Machine Learning Practice, and software guidance.
Feedback should be submitted through the IMDRF Consultation Hub. Inquiries may be directed to the IMDRF AI/ML Working Group at imdrf-aiwg@fda.hhs.gov with the subject line ‘Public Consultation on Technical Framework for Artificial Intelligence Life Cycle Management.’
| Action Required — Comment Deadline: July 10, 2026 Manufacturers developing or planning AI/ML-enabled medical devices should review the draft framework and consider submitting comments. This document is expected to influence global regulatory expectations across IMDRF member authorities including FDA, Health Canada, TGA, MHRA, and others. |
|---|
UPCOMING REGULATORY DEADLINES — NEXT 3–6 MONTHS
The following milestones represent significant compliance dates for medical device manufacturers operating in global markets. Manufacturers should assess readiness and take appropriate action ahead of each deadline.
| Date | Milestone | Jurisdiction(s) |
|---|---|---|
| July 10, 2026 | Deadline to submit public comments on IMDRF draft Technical Framework for Artificial Intelligence Life Cycle Management. | Global (IMDRF member authorities) |
| August 2026 | EU AI Act high-risk AI obligations become fully applicable. All new AI-powered Software as a Medical Device (SaMD) placed on the EU market must comply with high-risk AI requirements, including cybersecurity and adversarial robustness provisions. MDR and AI Act apply simultaneously. | European Union |
| September 11, 2026 | EU Cyber Resilience Act (CRA) Article 14 vulnerability and incident reporting obligations take effect. Software supply chain suppliers must report actively exploited vulnerabilities within 24 hours. Note: Medical devices regulated under MDR are exempt from CRA product requirements, but software suppliers in the medical device supply chain are not. | European Union |
| October 2026 (est.) | FDA continues active enforcement under QMSR (21 CFR Part 820, effective February 2, 2026). Inspectors are expected to evaluate cybersecurity integration throughout the quality management system, from design controls through postmarket CAPA processes. | United States |
| December 11, 2027 | EU Cyber Resilience Act full product-level requirements apply. Products with digital elements not exempt under MDR must comply with all CRA requirements, including SBOM obligations. | European Union |
REGULATORY LANDSCAPE CONTEXT
United States — FDA QMSR and Cybersecurity Guidance (In Effect)
The FDA’s Quality Management System Regulation (QMSR, 21 CFR Part 820) became effective February 2, 2026, formally aligning FDA’s framework with ISO 13485:2016 and embedding cybersecurity as a mandatory element of design controls, risk management, and postmarket surveillance. Concurrently, the FDA reissued its premarket cybersecurity guidance (‘Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions’) to update references from QSR to QMSR — core requirements remain unchanged.
Manufacturers are required to:
Implement a Secure Product Development Framework (SPDF) across the total product lifecycle.
Submit a Security Risk Management Report, Cybersecurity Management Plan, and machine-readable Software Bill of Materials (SBOM) with premarket submissions.
Maintain Coordinated Vulnerability Disclosure (CVD) policies with defined timelines: customer notification within 30 days of an uncontrolled vulnerability identified; resolution within 60 days.
Conduct four types of security testing: security requirements testing, threat mitigation testing, vulnerability hunting, and independent penetration testing.
European Union — MDCG and EU AI Act
Notified Bodies in 2026 are applying heightened scrutiny to cybersecurity documentation under MDCG 2019-16. Missing or inadequate security documentation is among the top causes of major non-conformities for Software as a Medical Device (SaMD). Additionally, the EU AI Act introduces cybersecurity-related obligations for AI-powered SaMD from August 2026, including adversarial robustness requirements that partially overlap with and complement MDCG 2019-16.
SOURCES AND FURTHER READING
IMDRF — AI/ML Lifecycle Framework Consultation
IMDRF — AI/ML Working Group
FDA — Cybersecurity in Medical Devices (QMSR-aligned guidance)
RAPS — FDA reissues cybersecurity guidance to align with QMSR
EU AI Act compliance timeline — Trilateral Research
EU Cyber Resilience Act — Hogan Lovells 2026 milestones
EU CRA + NIS2 impact on medical devices
MDCG 2019-16 cybersecurity guidance (EU MDR)
FedTech — FDA tightens medical device cybersecurity guidance
Disclaimer: This briefing is prepared by Aktriva for informational purposes only and does not constitute legal, regulatory, or compliance advice. Information is drawn from publicly available sources; while we aim for accuracy, errors or omissions may occur despite our review process. Readers should independently verify developments against primary regulatory sources and consult qualified advisors before making compliance decisions.
Want this tailored to your regulatory strategy?
Talk to our team about what this week's developments mean for your specific device and timeline.