← All briefings Weekly Briefing

Issue: May 17, 2026

EXECUTIVE SUMMARY

This week’s briefing highlights an active IMDRF public consultation on an AI/ML Lifecycle Management Framework (open through July 10, 2026), and critical approaching regulatory deadlines for EU AI Act high-risk AI obligations (August 2026) and the EU Cyber Resilience Act vulnerability-reporting mandate (September 11, 2026). Manufacturers are encouraged to review the IMDRF consultation and submit comments before the July deadline.

IMDRF — INTERNATIONAL MEDICAL DEVICE REGULATORS FORUM

AI/ML Lifecycle Management Framework — Public Consultation Open

IMDRF opened a public consultation on April 10, 2026 for its draft Technical Framework for Artificial Intelligence Life Cycle Management. Comments are accepted through July 10, 2026 via the IMDRF Consultation Hub on Citizen Space.

The draft covers the full product lifecycle for AI-enabled medical devices: planning, data collection and governance, model building and tuning, verification and validation, clinical evaluation, deployment, operations, real-world performance evaluation, and sunsetting.

Key cybersecurity-relevant elements in the draft include:

Model drift: The framework explicitly addresses the risk that AI-enabled devices can degrade as real-world inputs shift from training data, requiring drift detection, alerting, and controlled recalibration or retraining processes.

Data quality and bias: Manufacturers must address dataset representativeness, traceability, and bias mitigation — with particular attention to performance across diverse patient groups and care settings.

Lifecycle responsibility: IMDRF frames AI oversight as an ongoing total-lifecycle obligation, not a one-time premarket submission exercise.

Cybersecurity integration: The draft is designed to complement existing IMDRF work on cybersecurity, SaMD, Good Machine Learning Practice, and software guidance.

Feedback should be submitted through the IMDRF Consultation Hub. Inquiries may be directed to the IMDRF AI/ML Working Group at imdrf-aiwg@fda.hhs.gov with the subject line ‘Public Consultation on Technical Framework for Artificial Intelligence Life Cycle Management.’

Action Required — Comment Deadline: July 10, 2026 Manufacturers developing or planning AI/ML-enabled medical devices should review the draft framework and consider submitting comments. This document is expected to influence global regulatory expectations across IMDRF member authorities including FDA, Health Canada, TGA, MHRA, and others.

UPCOMING REGULATORY DEADLINES — NEXT 3–6 MONTHS

The following milestones represent significant compliance dates for medical device manufacturers operating in global markets. Manufacturers should assess readiness and take appropriate action ahead of each deadline.

DateMilestoneJurisdiction(s)
July 10, 2026Deadline to submit public comments on IMDRF draft Technical Framework for Artificial Intelligence Life Cycle Management.Global (IMDRF member authorities)
August 2026EU AI Act high-risk AI obligations become fully applicable. All new AI-powered Software as a Medical Device (SaMD) placed on the EU market must comply with high-risk AI requirements, including cybersecurity and adversarial robustness provisions. MDR and AI Act apply simultaneously.European Union
September 11, 2026EU Cyber Resilience Act (CRA) Article 14 vulnerability and incident reporting obligations take effect. Software supply chain suppliers must report actively exploited vulnerabilities within 24 hours. Note: Medical devices regulated under MDR are exempt from CRA product requirements, but software suppliers in the medical device supply chain are not.European Union
October 2026 (est.)FDA continues active enforcement under QMSR (21 CFR Part 820, effective February 2, 2026). Inspectors are expected to evaluate cybersecurity integration throughout the quality management system, from design controls through postmarket CAPA processes.United States
December 11, 2027EU Cyber Resilience Act full product-level requirements apply. Products with digital elements not exempt under MDR must comply with all CRA requirements, including SBOM obligations.European Union

REGULATORY LANDSCAPE CONTEXT

United States — FDA QMSR and Cybersecurity Guidance (In Effect)

The FDA’s Quality Management System Regulation (QMSR, 21 CFR Part 820) became effective February 2, 2026, formally aligning FDA’s framework with ISO 13485:2016 and embedding cybersecurity as a mandatory element of design controls, risk management, and postmarket surveillance. Concurrently, the FDA reissued its premarket cybersecurity guidance (‘Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions’) to update references from QSR to QMSR — core requirements remain unchanged.

Manufacturers are required to:

Implement a Secure Product Development Framework (SPDF) across the total product lifecycle.

Submit a Security Risk Management Report, Cybersecurity Management Plan, and machine-readable Software Bill of Materials (SBOM) with premarket submissions.

Maintain Coordinated Vulnerability Disclosure (CVD) policies with defined timelines: customer notification within 30 days of an uncontrolled vulnerability identified; resolution within 60 days.

Conduct four types of security testing: security requirements testing, threat mitigation testing, vulnerability hunting, and independent penetration testing.

European Union — MDCG and EU AI Act

Notified Bodies in 2026 are applying heightened scrutiny to cybersecurity documentation under MDCG 2019-16. Missing or inadequate security documentation is among the top causes of major non-conformities for Software as a Medical Device (SaMD). Additionally, the EU AI Act introduces cybersecurity-related obligations for AI-powered SaMD from August 2026, including adversarial robustness requirements that partially overlap with and complement MDCG 2019-16.

SOURCES AND FURTHER READING

IMDRF — AI/ML Lifecycle Framework Consultation

IMDRF — AI/ML Working Group

FDA — Cybersecurity in Medical Devices (QMSR-aligned guidance)

RAPS — FDA reissues cybersecurity guidance to align with QMSR

EU AI Act compliance timeline — Trilateral Research

EU Cyber Resilience Act — Hogan Lovells 2026 milestones

EU CRA + NIS2 impact on medical devices

MDCG 2019-16 cybersecurity guidance (EU MDR)

FedTech — FDA tightens medical device cybersecurity guidance

Disclaimer: This briefing is prepared by Aktriva for informational purposes only and does not constitute legal, regulatory, or compliance advice. Information is drawn from publicly available sources; while we aim for accuracy, errors or omissions may occur despite our review process. Readers should independently verify developments against primary regulatory sources and consult qualified advisors before making compliance decisions.

Want this tailored to your regulatory strategy?

Talk to our team about what this week's developments mean for your specific device and timeline.

Schedule a Consultation