What is Clinical Decision Support?
Clinical Decision Support Systems (CDSS) are software tools that assist healthcare providers in making diagnostic, treatment, and care decisions. These systems analyze patient data, medical literature, and clinical guidelines to provide recommendations, alerts, or insights at the point of care.
Types of Clinical Decision Support
Diagnostic Support
AI systems that analyze symptoms, lab results, imaging, or patient history to suggest potential diagnoses. Examples include radiology AI, pathology analysis, and differential diagnosis engines.
Treatment Recommendations
Systems that suggest treatment protocols, medication dosing, or therapeutic interventions based on patient characteristics, clinical guidelines, and outcomes data.
Drug Interaction Checking
Automated alerts for contraindications, drug-drug interactions, allergy warnings, and dosing errors. Critical safety systems in electronic health records and pharmacy systems.
Risk Stratification
Predictive models that identify high-risk patients for conditions like sepsis, deterioration, readmission, or adverse events. Used for early intervention and resource allocation.
Annex III Category Analysis
The EU AI Act classifies AI systems as high-risk through two pathways. For CDSS, the primary classification derives from Article 6(1) combined with Annex I, which covers products subject to EU harmonization legislation including medical devices.
Primary Classification Pathway: Medical Devices (Annex I)
Under Article 6(1), an AI system is high-risk if it is:
- A product, or safety component of a product, covered by EU harmonization legislation listed in Annex I
- Subject to third-party conformity assessment under that legislation
The Medical Device Regulation (EU) 2017/745 and In Vitro Diagnostic Regulation (EU) 2017/746 are listed in Annex I. That is only part of Article 6(1): the AI must be a safety component or itself the covered product, and the product must require third-party conformity assessment under the applicable legislation.
Key Determination
If CDSS meets the MDR or IVDR device definition, continue the Article 6(1) analysis: determine whether it is the product or a safety component and whether third-party conformity assessment is required. Medical-device status alone does not eliminate that assessment.
When Does CDSS Qualify as a Medical Device?
Under MDR Article 2(1), software qualifies as a medical device if it is intended by the manufacturer for medical purposes including:
- Diagnosis, prevention, monitoring, prediction, prognosis, treatment, or alleviation of disease
- Diagnosis, monitoring, treatment, alleviation of, or compensation for an injury or disability
- Investigation, replacement, or modification of anatomy or physiological/pathological process
Some CDSS may meet the MDR or IVDR device definitions. The manufacturer’s intended purpose is central to that analysis, but clinical use alone does not settle product classification, software-function exclusions, device class, or the applicable conformity-assessment route.
When CDSS Are High-Risk
The following CDSS scenarios warrant an Article 6 high-risk analysis. The result still depends on the system’s intended purpose, whether it is a covered product or safety component, and whether the applicable product legislation requires third-party conformity assessment:
Diagnostic AI in Radiology, Pathology, or Dermatology
AI that analyzes medical images to detect, classify, or characterize disease. Examples: chest X-ray analysis, mammography screening, skin lesion classification, histopathology analysis.
Treatment Protocol Recommendation Engines
AI systems that suggest treatment plans, chemotherapy regimens, surgical approaches, or therapy protocols based on patient characteristics and outcomes data.
Medication Safety and Drug Interaction Systems
Automated alerts for contraindications, drug-drug or drug-gene interactions, dosing recommendations, and allergy warnings integrated into prescribing workflows.
Early Warning and Deterioration Prediction
Sepsis prediction, patient deterioration scores, ICU mortality risk, and other predictive models used to trigger clinical interventions or escalation of care.
Genomic and Precision Medicine AI
AI that interprets genetic data to guide treatment selection, predict drug response, or identify hereditary disease risk for clinical action.
Limited Exemption Scenarios
Very few CDSS scenarios escape high-risk classification. Potential exemptions are narrow:
Potentially Lower-Risk CDSS Scenarios
- Pure research tools: AI used exclusively for clinical research without influencing patient care decisions may not require MDR classification, potentially avoiding high-risk status.
- Administrative and operational AI: Scheduling optimization, resource allocation, or workflow management that doesn’t influence clinical decisions.
- Simple data retrieval: Systems that only retrieve and display existing information without analysis, inference, or recommendations (rare for true AI systems).
- Wellness applications: Consumer fitness apps or general wellness tools not intended for medical purposes (though misuse can trigger reclassification).
Critical warning: These exemptions are narrowly construed. Regulators are expected to examine actual use, not just intended purpose. A “research tool” used in clinical practice becomes a medical device. An “administrative tool” that influences patient prioritization may affect care decisions.
High-Risk CDSS Requirements (Articles 9-15)
High-risk CDSS must comply with the core requirements in Articles 9-15 of the EU AI Act. These requirements layer on top of existing MDR obligations.
| Article | Requirement | CDSS Implication |
|---|---|---|
| Article 9 | Risk Management System | Continuous identification and mitigation of AI-specific risks throughout the CDSS lifecycle, including diagnostic errors, recommendation failures, and edge cases. |
| Article 10 | Data Governance | Training, validation, and testing data must be relevant, sufficiently representative and, to the best extent possible, free of errors and complete in view of the intended purpose. For CDSS, examine performance and bias across relevant patient populations. |
| Article 11 | Technical Documentation | Comprehensive documentation of AI system design, development, capabilities, limitations, and performance. Must enable regulatory assessment. |
| Article 12 | Automatic Logging | Automatic logging must enable traceability appropriate to the intended purpose, including events relevant to identifying risks or substantial modifications and facilitating post-market monitoring. The Act does not prescribe every input, output, or human action as a universal minimum. |
| Article 13 | Transparency | Instructions for use must enable clinicians to interpret outputs, understand limitations, and exercise appropriate oversight. |
| Article 14 | Human Oversight | CDSS must be designed to allow effective human oversight. Clinicians must be able to understand, intervene, and override AI recommendations. |
| Article 15 | Accuracy, Robustness, Cybersecurity | CDSS must achieve appropriate accuracy levels, be robust against errors, and include cybersecurity protections against adversarial manipulation. |
Article 12 Logging: Core GLACIS Relevance
Article 12 of the EU AI Act mandates automatic logging capabilities for high-risk AI systems. For CDSS, this requirement is particularly critical given patient safety implications and the need for post-incident investigation.
What Article 12 requires. What a CDSS team may record.
Article 12 states the logging objective at a functional level for high-risk systems; it does not create a universal list of every input, output, recommendation, or clinician action. The additional minimum fields in Article 12(3) apply specifically to high-risk remote biometric identification systems, not to CDSS generally. A CDSS team should define the events needed for its intended purpose, risk management and post-market monitoring. That design may include:
- System operation periods: When the CDSS was active, where this is relevant to traceability and monitoring
- Input references: References or characteristics needed to investigate a risk-relevant event, with data-minimization and patient-privacy protections
- AI outputs: Recommendations or alerts relevant to the defined traceability purpose, rather than every output by default
- Human oversight actions: Clinician acceptance, rejection, or modification where system design or another applicable rule calls for that evidence
- System anomalies: Any errors, failures, or unusual behavior that may affect reliability
Retention Requirements
Do not treat the AI Act’s provider-documentation and deployer-log rules as the same retention obligation:
- Provider documentation: Article 18 generally requires specified technical and conformity documentation to be kept for 10 years after the system is placed on the market or put into service
- Deployer logs: Article 26(6) requires deployers to keep automatically generated logs under their control for a period appropriate to the intended purpose, of at least six months unless other applicable EU or national law provides otherwise
- Medical-device records: MDR, clinical-safety, privacy, product-liability or national rules may independently require different or longer periods; confirm the system-specific schedule
GLACIS can provide cryptographically verifiable operational records identifying which configured supervision step reported an outcome for a covered event. That can support an Article 12 logging design and an audit file, but it does not by itself prove execution, establish that every required event was captured, show that retention obligations were met, or establish that the CDSS conforms to the AI Act or MDR.
Interaction with Medical Device Regulation
Where an AI-enabled medical device falls within the material and territorial scope of both regimes, the applicable EU AI Act and MDR requirements work in tandem. Determine the organization’s role, device and AI classifications, pathway, and application dates rather than inferring dual obligations from the product label alone.
Complementary Requirements
MDR Provides
- Clinical safety and performance requirements
- Quality management system (ISO 13485)
- Clinical evaluation and post-market surveillance
- Notified body conformity assessment
AI Act Adds
- AI-specific risk management (Article 9)
- Data governance for training data (Article 10)
- Automatic logging requirements (Article 12)
- Explicit human oversight provisions (Article 14)
Conformity Assessment
For an AI system that is a regulated product or safety component under Article 6(1), Article 43 provides for AI Act requirements to be assessed as part of the applicable product-law conformity procedure. That coordinates the process; an MDR assessment does not automatically establish substantive compliance with every AI Act duty, and the relevant conformity-assessment body must be notified for the applicable requirements.
US FDA SaMD Comparison
Organizations operating in both EU and US markets must navigate parallel regulatory frameworks. While philosophically similar, important differences exist.
| Aspect | EU AI Act + MDR | FDA SaMD Framework |
|---|---|---|
| Risk Classification | Use- and product-specific: Article 6 and Annex III analysis required | Risk-based (Class I, II, III) with IMDRF SaMD categories |
| Logging Requirements | Mandatory automatic logging (Article 12) | Good Machine Learning Practice guidance; less prescriptive |
| Human Oversight | Explicit requirements (Article 14) | Considered in labeling; less formalized |
| Update Pathway | Substantial modification triggers reassessment | Predetermined Change Control Plan (PCCP) for certain AI updates |
| Transparency | Detailed instructions for use requirements | Labeling requirements; proposed transparency rules |
The EU AI Act is currently more prescriptive on AI-specific requirements like logging and human oversight. Organizations building for both markets should design to the higher standard (typically EU) and document how they satisfy each framework’s requirements.
Implementation Checklist
Use this checklist to assess and plan your CDSS compliance program:
CDSS EU AI Act Compliance Checklist
Classification and Assessment
- Confirm CDSS qualifies as medical device under MDR
- Document high-risk classification rationale
- Identify applicable MDR class and notified body requirements
Risk Management (Article 9)
- Establish AI-specific risk management process
- Identify and document CDSS-specific risks (diagnostic errors, bias, edge cases)
- Implement and document risk mitigation measures
Data Governance (Article 10)
- Document training data sources and characteristics
- Assess and document data representativeness and bias testing
- Establish validation and testing data governance
Logging Infrastructure (Article 12)
- Implement automatic logging of CDSS operations
- Define and capture events appropriate to the CDSS intended purpose, risk management and post-market monitoring
- Document separate provider-document and deployer-log retention schedules, plus any longer medical-device requirement
Human Oversight (Article 14)
- Design CDSS for effective clinician oversight
- Ensure outputs are interpretable and overridable
- Document human oversight procedures in instructions for use
Conformity Assessment
- Prepare technical documentation per Article 11
- Engage notified body with AI assessment capability
- Confirm assessment scope, evidence needs, availability, and timing with the applicable notified body
Frequently Asked Questions
Is clinical decision support software high-risk under the EU AI Act?
Not automatically. Classification depends on intended purpose and the Article 6 pathway. For the Annex I product route, the AI must be a safety component or itself a covered product and the product must require third-party conformity assessment. Annex III may apply to specified uses, subject to Article 6 conditions and exceptions.
What EU AI Act requirements apply to high-risk CDSS?
High-risk CDSS must comply with Articles 9-15 of the EU AI Act, including: risk management systems (Article 9), data governance (Article 10), technical documentation (Article 11), automatic logging (Article 12), transparency and instructions for use (Article 13), human oversight provisions (Article 14), and accuracy, robustness, and cybersecurity requirements (Article 15).
How does the EU AI Act interact with the Medical Device Regulation for CDSS?
For a covered AI system that is a regulated product or safety component under Article 6(1), Article 43 coordinates AI Act requirements with the applicable product-law conformity procedure. That integration does not make every medical-device AI high-risk or automatically establish substantive compliance with every AI Act duty.
Are there any exemptions for clinical decision support under the EU AI Act?
The Act contains scope exclusions and Article 6 classification conditions and exceptions. A research-only system, a function outside the AI-system definition, or a tool that does not meet an Annex I or Annex III pathway may fall outside high-risk classification. Recommendations or alerts still require intended-purpose and product-law analysis.
What logging requirements apply to clinical decision support AI?
Article 12 requires high-risk CDSS to have automatic logging capabilities that enable traceability appropriate to the intended purpose, support identification of risk-relevant situations or substantial modifications, and facilitate post-market monitoring. It does not generally require every input, output, decision trace, or human intervention. Under Article 26, deployers keep logs under their control for an appropriate period of at least six months unless other EU or national law applies; separate provider documentation and medical-device rules may require different periods.
How does US FDA regulation of Software as Medical Device compare to EU AI Act?
FDA treatment of clinical decision support is function-specific. Under FD&C Act section 520(o)(1)(E), some CDS functions are excluded from the device definition; other functions are devices, and some device functions may fall within enforcement discretion. FDA’s January 29, 2026 final CDS guidance explains that analysis. EU AI Act classification separately turns on intended purpose, role, Annex III, and Article 6’s product-law conditions.
When must clinical decision support systems comply with the EU AI Act?
A CDSS is not high-risk solely because it supports healthcare. Classification depends on intended purpose and whether it falls under Annex III or is a safety component of an Annex I regulated product. Under the AI Omnibus, relevant Annex III high-risk obligations apply from December 2, 2027 and relevant Annex I product-embedded obligations from August 2, 2028.
References
- [1] European Union. “Regulation (EU) 2024/1689 of the European Parliament and of the Council.” Consolidated text current to 27 July 2026.
- [2] European Union. “Regulation (EU) 2017/745 on Medical Devices (MDR).” Official Journal of the European Union, May 5, 2017. EUR-Lex 32017R0745
- [3] FDA. “Clinical Decision Support Software.” Final Guidance, January 29, 2026. fda.gov
- [4] European Commission. “Questions and Answers: Artificial Intelligence Act.” March 13, 2024. europa.eu
- [5] IMDRF. “Software as a Medical Device: Possible Framework for Risk Categorization and Corresponding Considerations.” IMDRF/SaMD WG/N12, 2014. imdrf.org
- [6] FDA. “Clinical Decision Support Software: Frequently Asked Questions.” fda.gov
