AI, Cybersecurity, Regulations Risks in MedTech
Medical device manufacturers are no strangers to a highly regulated environment. But when it comes to AI and managing these new technologies and their specific regulations as well as emerging cybersecurity risks, it’s a brand-new world.
“Typically, most companies have all of the documents, all of the policies, everything,” Rajiv Dalal, managing director at Strategic eServices Ltd., told Design News. “And so, the illusion of governance is very much there. But that just gives the appearance of control,” he emphasized. “It doesn't actually prove the practical ability to exercise it.”
Dalal said one of the problems is that most companies have separate teams who look after individual aspects of AI, regulatory, and cybersecurity, but never share information with each other. This is fine when everything is going well, he noted.
“But when something doesn't work and you don't know where the problem lies, not having a cross-functional team that understands the impact throughout, that’s when most of these companies will have issues,” he continued. “And unfortunately, this is not an if, it’s a when.”
Related:Engineers Tease Out Impacts of Anthropic’s Invisible Watermark
Dalal will speak in the upcoming session at MD&M Midwest, “The Compliance Triple Threat: When AI, Cybersecurity, and Global Regulation Collide in MedTech,” in which he’ll share how to identify the gaps between cybersecurity, AI, and regulatory teams and offer some steps on how to mitigate them.
In the meantime, we asked him a few questions.
Why is this topic important for medical device manufacturers?
Dalal: Medical device manufacturers already operate in one of the most tightly regulated environments in any country. What's changed is the nature of the risk.
AI has introduced a new category of failure that compliance frameworks weren't built to catch. A device can pass every required test, carry the right certifications, and still behave in ways nobody anticipated once it's deployed in a clinical setting. The frameworks—FDA, IEC standards, among several others—were designed around predictable, deterministic systems. Unfortunately, AI is neither of those things.
At the same time, cybersecurity requirements are expanding rapidly. The Radio Equipment Directive made mandatory requirements for wireless-connected medical devices in August 2025. The EU Cyber Resilience Act is rolling in. The IEC 62443 standard is increasingly being applied to medical devices in OT environments. And regulatory requirements are diverging across jurisdictions; for example, the EU AI Act has a different definition of “high-risk AI” than the FDA's SaMD framework, and neither of them map cleanly onto what manufacturers actually build.
Related:AI Adoption Needs Organizational Change Management to Succeed
The problem isn't that any one of those frameworks is wrong. The problem is that manufacturers are managing all three—AI risk, cybersecurity, and regulatory compliance—through separate teams with separate processes. That works well enough in normal operating conditions. It fails at exactly the moment it matters most: when something goes wrong across all three at once.
That's what my session is about. Failure doesn't respect organizational boundaries. The question is whether your governance structure does.
Dalal: Because several deadlines have already passed, and most manufacturers haven't fully reckoned with that.
The Radio Equipment Directive requirements came into force in August 2025. Body-worn devices, cardiac monitors, CGMs—all of them are now subject to mandatory cybersecurity obligations under EU law.
I speak to regulatory teams who are still conducting gap assessments. That's not a readiness problem; it's a structural one. The teams responsible for each of these domains aren't coordinating quickly enough because they're not designed to.
Then on June 12th, 2026, something happened that I think crystallized the issue for anyone paying attention. The U.S. Department of Commerce issued an order pulling two frontier AI models (Fable 5 and Mythos 5 from Anthropic) offline overnight. Healthcare organizations that had built clinical workflows around those models lost access without warning, without written justification, and without any meaningful recourse. One major pharmaceutical company had signed a strategic agreement weeks earlier to run drug discovery on those models. Gone, Friday afternoon, no appeal.
Related:Helping Customers Integrate Agentic AI Into Their Design Cycle
People have focused on the AI regulation angle. What they've missed is what that incident actually demonstrated: even a company with exemplary governance—thousands of hours of red-team testing, government cooperation, independent audits—had no way to protect its customers when a regulator decided to act. Governance was present. The ability to intervene on behalf of customers who depended on those tools was absent. That distinction matters enormously for the medtech companies in my session who are building clinical dependencies on AI platforms right now.
The EU AI Act Digital Omnibus amendments from June 2026 are another signal. The EU pushed the mandatory medical device AI obligations to August 2028 specifically because the governance standards to enforce them don't yet exist in practice. The regulator itself acknowledged the gap. That's where we are.
What are some of the gaps you have seen between the three domains of AI, cybersecurity, and global regulation?
Dalal: The most consistent gap I see is structural: separate teams, separate budgets, separate reporting lines, and no shared trigger for when to bring them together.
A cybersecurity incident in a hospital network isn't just a cybersecurity problem if clinical AI tools go offline as a result. A regulatory change isn't just a compliance problem if it alters which AI capabilities you can use in which markets. An AI system behaving anomalously isn't just an AI problem if the cybersecurity team is the first to notice it and doesn't have a direct line to the regulatory affairs team.
The Change Healthcare attack in 2024 is a good illustration. What started as a ransomware incident affecting UnitedHealth's subsidiary cascaded downstream through over a hundred medical device and healthcare AI integrations. Manufacturers had dependencies on Change Healthcare's infrastructure that their own security teams hadn't mapped. A cybersecurity event became an AI availability event became a regulatory reporting question—all in the same 48-hour window, hitting teams who had no joint response protocol.
HSE Ireland is another one. The ransomware attack on Ireland's health service took clinical AI tools offline alongside patient records. The three domains—clinical AI, cybersecurity, and regulatory reporting—were handled sequentially. By teams who had never run a cross-domain incident before. Recovery took months.
A more recent example: Clinical organizations using general-purpose AI notetakers in clinical settings discovered that HIPAA compliance and wiretap consent are separate legal gates. A tool that cleared one framework wasn't automatically cleared under the others. The compliance team, the cybersecurity team, and the clinical governance team each assumed someone else had assessed it. Federal litigation is now working through exactly that gap.
What these cases share isn't technical failure. They're governance failures that AI exposed, and, unfortunately, at AI speed. The systems were doing what they were built to do. Nobody had built the cross-domain decision-making structure to catch what happened next.
What can manufacturers do to minimize these gaps?
Dalal: The starting point is a distinction I draw between governance and governability.
Governance is what most organizations already have: policies, procedures, sign-off matrices, audit trails. Governability is different. It's the practical ability to intervene when something goes wrong. Those two things are not the same and confusing them is expensive.
There are three questions I use to test whether an organization has governability, not just governance:
Can you trace any AI decision to its source in real time—not in a post-incident review, but while the system is running?
Can you halt or override an AI-driven process before consequences cascade?
And is there a named individual—not a committee, not a team—who is personally accountable for each AI system right now?
Most manufacturers, if they're honest, can't answer all three with confidence. That's where the work begins.
Practically speaking, the first step is deceptively simple: name the person accountable for each AI system in your portfolio. Not the team. Not the approval committee. The individual. Then ask them if they know they hold that responsibility. That single question surfaces the gap in most organizations within minutes.
The second step is to stop reviewing AI risk, cybersecurity risk, and regulatory compliance as sequential agenda items. They need to be reviewed together, against shared criteria, by people who understand all three. The FDA's own Action Plan for AI/ML-based SaMD uses the language of 'predetermined change control plans,’ which is essentially a governability framework by another name. Manufacturers who have implemented those seriously are ahead. Manufacturers treating them as a documentation exercise are not.
The third step is harder: test your intervention protocols. Not on paper. Under simulated pressure. Can you actually halt an AI-driven clinical process in 20 minutes? Have you ever tried? The answer, for most organizations, is no. And that's a problem that no compliance framework will solve on its own.
Dalal: Honestly, and I know this may sound broad, but anyone who has responsibility for a system that makes decisions in a clinical context and isn't certain those three questions above have good answers.
More specifically: regulatory affairs leads who are managing FDA, state-level regulations, and EU AI Act obligations simultaneously and don't yet have a single integrated view of those exposures. Quality and compliance professionals who built their frameworks before AI changed what “significant change” means and haven't fully updated them. CISOs and VPs of Engineering responsible for connected device security who aren't routinely in the room when AI governance decisions get made.
General counsels are an increasingly relevant audience. And Boards. D&O exposure, as I had mentioned, on AI governance failures is no longer theoretical. And many D&O providers are removing AI activities from their coverage. The FTC's July 2026 policy statement, the Commerce Department's June action—these are board-level events now, not just compliance ones. The session is technical enough to be useful to practitioners and accessible enough that a board member or C-suite executive would follow it.
What is the most important message you hope your attendees take away from your session?
Dalal: That compliance and control are not the same thing.
You can have every framework in place—every policy written, every audit completed, every committee convened—and still find, when something goes wrong, that you cannot intervene at the speed that matters. Vermont didn’t ban AI therapy chatbots because those companies lacked governance documentation. They banned these because even when the documentation was fine, real people were still harmed. Governance without governability isn't a risk management strategy. It's a liability.
The session I'm going to give in Minneapolis is built around that gap. What it looks like, what it costs, and what it would take to close it before a regulator, a court, or a patient closes it for you.
Dalal will present, “The Compliance Triple Threat: When AI, Cybersecurity, and Global Regulation Collide in MedTech,” on Thursday, October 29, 11:45 a.m. to 12:30 p.m., in Room 101H at MD&M Midwest 2026 in Minneapolis.
Related Stories
AI News
Holy See: The use of AI in agrifood systems needs to place humans at the center
59 minutes ago
AI News
Lambda Targets $14.5 Billion Valuation in Final Pre
1 hour ago
AI News
Nvidia stock rises to new highs as market cap closes in on $6 trillion
1 hour ago
AI News
US man arrested as second suspect in Canada mass school shooting planned with ChatGPT
2 hours ago
AI News
Ex
2 hours ago
AI News
Georgia Tech Announces New Online Master’s Degree in Artificial Intelligence
2 hours ago
AI News
Italy PM Giorgia Meloni files to protect her voice from AI deepfakes
3 hours ago
AI News
Building a context
5 hours ago