Article #10 introduced ISO 42001 as an emerging, certifiable standard for AI management systems, a way to prove governance maturity the same way ISO 13485 already proves quality management maturity.
This article looks at why that standard is arriving at exactly the right moment: regulators on both sides of the Atlantic are independently arriving at strikingly similar expectations, and the companies treating this as two separate compliance problems are about to find that's no longer true.
(Governing the Algorithm, Article #11)
Two Regulatory Systems, Converging Independently
The FDA and the European Union didn't coordinate on AI governance requirements: they arrived at similar conclusions from different regulatory traditions, because the underlying risk profile of AI-based medical devices is the same regardless of which side of the Atlantic evaluates it.
The EU AI Act (Regulation (EU) 2024/1689) automatically classifies AI-powered medical devices as high-risk under Annex III. Its most relevant provisions for medical device AI became applicable starting August 2026, with manufacturers of SaMD carrying AI components required to comply by August 2026, or August 2027 for CE-marked devices under Notified Body review through MDR or IVDR. That timeline is not theoretical anymore. It's active now.
Meanwhile, the FDA has been building its own version of the same expectations through Predetermined Change Control Plans, its evolving AI/ML guidance, and growing emphasis on post-market performance monitoring. Everything this series has covered in Phases 1 through 3.
Where the Two Frameworks Actually Overlap
Despite different legal structures, both frameworks are converging on the same core demands:
✔ A documented AI-specific risk management process: the EU AI Act requires this explicitly, integrated with but separate from existing ISO 14971 risk management under MDR/IVDR; FDA guidance is moving toward the same expectation through its AI/ML risk framework
✔ Data governance requirements: both frameworks require demonstrable evidence that training and monitoring data is representative and well-managed, not just a validation study result
✔ Human oversight mechanisms: both explicitly require meaningful human oversight of AI-assisted decisions, not just nominal human presence in the workflow
✔ Technical documentation and traceability: both require an auditable record of how the AI system was developed, validated, and is being maintained, in a form regulators or notified bodies can actually review
A company that has genuinely built out the five governance layers covered earlier in this series (data governance, model risk management, human oversight, change control, accountability) is already most of the way toward satisfying both frameworks, because both frameworks are really asking for the same underlying discipline in different regulatory language.
Why "We'll Handle the EU Later" Is a Riskier Strategy Than It Used to Be
Non-U.S. companies entering the U.S. market sometimes treat FDA clearance as the finish line and assume EU compliance is a separate, later problem for a separate market. That sequencing is becoming harder to justify:
- The EU AI Act's obligations are now active, not upcoming, for companies with any EU market presence
- Hospital and health-system buyers in the U.S. are increasingly aware of these international frameworks and treat alignment with them as another credibility signal, not just a foreign regulatory detail
- Building governance infrastructure twice (once loosely for the FDA, once more rigorously for the EU) is significantly more expensive than building one robust system that satisfies both from the start
What Convergence Means for How Companies Should Build
The practical implication isn't "wait for full regulatory harmonization before acting." It's the opposite: build a single governance system now, mapped to the common core both frameworks share, and treat jurisdiction-specific requirements as an overlay rather than a separate system.
This is precisely the strategic case for ISO 42001 certification raised in Article #10: a single, internationally recognized standard that maps cleanly onto both FDA expectations and EU AI Act requirements, reducing duplicated governance work rather than doubling it.
Final Thought
Two different regulatory systems have independently concluded that AI-based medical devices need documented risk management, real human oversight, and auditable change control.
That's not a coincidence. It's convergence.
Different regulators. Same underlying risk
One governance system, built well, satisfies both.
Companies still treating U.S. and EU AI governance as two separate problems are doing twice the work for a result that increasingly could have come from doing it once, correctly.
Next in the Governing the Algorithm Series (Finale):
The Governance Stack: Five Layers Every SaMD AI Company Needs Before Scale
#HealthcareAI #EUAIAct #FDA #AIGovernance #SaMD #RegulatoryStrategy #Compliance #DigitalHealth #HealthcareInnovation #ArtificialIntelligence #MedTech #QscriptionTechnologies