ISO 13485 and AI agents: what the notified body will ask
An AI agent that triages complaints or drafts CAPAs is QMS software under ISO 13485 clause 4.1.6. What auditors ask, what the validation file contains, where to start — Deloitte, ISO, EUR-Lex sources.
Nearly half of MedTech companies now say they have an AI agent in production. Only 7 per cent describe it as fully embedded and audit-ready, and a third admit the agent’s output is used informally, with no updated procedure and no validation behind it — Deloitte’s survey of 100 MedTech leaders, July 2026.1 That gap is not an AI Act problem. The Act’s high-risk rules for AI inside a device do not bite until 2 August 2028.2 The agent that reads your complaints, drafts your CAPAs (corrective and preventive actions) and keeps your technical file aligned with a revised standard is regulated today, by the standard you are already certified against. ISO 13485:2016, the quality-system standard every medical device manufacturer is certified against, calls it in clause 4.1.6 software used in the quality management system, and it asks for one thing: validation before first use and after changes, proportionate to risk, with records.3 Your notified body checks that clause at every surveillance audit. This article sets out what the auditor is likely to ask, what a defensible file looks like, and which three processes to start with.
Researched and drafted with AI assistance; reviewed, fact-checked and edited by Primož Verbič.
In brief
- ISO 13485:2016 clause 4.1.6 requires documented procedures for validating computer software used in the QMS, before initial use and after changes, with a risk-proportionate approach and records.3 An AI agent in complaint handling, CAPA or document control is such software.
- The same clause now applies in the United States: the FDA’s Quality Management System Regulation, in force since 2 February 2026, incorporates ISO 13485:2016 by reference.4
- The EU AI Act is not the binding constraint for back-office agents. Regulation (EU) 2026/1744, in force 27 July 2026, moved the high-risk date for AI in regulated products such as medical devices to 2 August 2028; transparency duties apply from 2 August 2026.2, 5
- Deloitte, July 2026: 45 per cent of 100 MedTech leaders have agentic AI in production, 7 per cent call it audit-ready, 33 per cent report informal use without updated procedures, 61 per cent have fragmented tools used differently across functions.1
- The method already exists. ISO/TR 80002-2:2017 explains how to validate QMS software, including complaint handling, and GAMP 5 Second Edition (2022) adds an appendix for AI and machine learning: intended use, data as a system component, change control for model updates, human oversight.6, 7
What the rule actually says
Clause 4.1.6 is short. The organisation documents procedures for validating the application of computer software used in the quality management system. The software is validated before initial use and, as appropriate, after changes. The approach is proportionate to the risk associated with its use, including the effect on the ability of the device to conform to requirements. Records are kept.3 Two sister clauses cover software used in production (7.5.6) and in monitoring and measurement (7.6).8
Nothing in the clause names a technology. It applied to spreadsheets, to electronic QMS platforms and to the macro in the complaints log. It applies to a large-language-model agent in exactly the same way, with one practical difference: the agent changes without anyone in your company editing it. The vendor updates the model; the agent’s behaviour shifts; your validation record describes a version that no longer runs. That is a change-control question nobody has had to answer for a spreadsheet, and it is the question the auditor will reach first.
The legal hook in Europe is Regulation (EU) 2017/745, Article 10(9): manufacturers maintain a quality management system, and for class IIa and above the notified body assesses it under Annex IX, with surveillance audits at least once a year.9 EN ISO 13485:2016 gives presumption of conformity, so the auditor works through its clauses. From February 2026 an FDA investigator does the same, because the QMSR replaced the old Quality System Regulation with ISO 13485 incorporated by reference, and the new inspection programme follows it.4
Where companies are today
Deloitte’s July 2026 survey is the clearest picture available. Of 100 MedTech leaders, 45 per cent say agentic AI is already in production. More than half want to optimise workflows with it; 27 per cent aim to redesign workflows around people and agents working together. Only 6 per cent are operating at that level. On governance, 7 per cent of those with agents in production describe the set-up as fully embedded and audit-ready; 33 per cent say outputs are used informally, without updated procedures or validation; 61 per cent have fragmented tools, used differently from one function to the next. Deloitte names complaint investigation, CAPA, labelling decisions and supplier qualification as the consequential processes where governance matters.1
Read that against clause 4.1.6 and the audit finding writes itself. An agent whose output feeds a complaint file or a CAPA is QMS software. If there is no validation record, the finding is not about AI. It is a plain nonconformity against a clause the company has been certified against since 2016.
The three questions the auditor will ask
Whatever the technology, an auditor asks for the same three things: a procedure, a record and an owner. For an agent, that becomes three questions.
1. What is it for, and what does it never decide alone? The auditor wants an intended-use statement. Not a product brochure, a page: which process step the agent performs, what inputs it receives, what it produces, what a person does with the output, and which decisions stay with a person. ISO/TR 80002-2 builds its whole method on this step, because the risk classification and therefore the depth of validation follow from the intended use.6
2. How do you know it works, and how will you know when it stops? The validation file. For a deterministic tool, a test script and the results were enough. For an agent, the auditor will look for a defined test set of real cases with known correct outcomes, acceptance criteria, the results at the model version in use, and a monitoring plan for drift. GAMP 5’s AI appendix calls data and the model system components in their own right, with a lifecycle of concept, project and operation, and treats retraining or a model update as a controlled change that triggers re-validation.7
3. Who answers for the result? A named person, not “the AI team”. The clause does not say so in those words, but every auditor reads the quality manual for responsibilities, and an agent without an owner has no one to sign the record. Deloitte’s 33 per cent of informal use is exactly this gap.1
Vendor documentation is not an answer to any of the three. Notified-body auditors expect to see the manufacturer’s own testing against its own intended use; a supplier’s certificate or validation pack supports the file, it does not replace it.10
What a defensible validation file looks like
Keep it to what a reviewer can read in an hour. The table shows the minimum and the proportionality: an agent that drafts meeting summaries for the quality team needs the first row and little else; an agent that classifies incoming complaints needs all of it.
| Element | What it contains | Why the auditor wants it |
|---|---|---|
| Intended-use statement | Process step, inputs, outputs, human decision points, exclusions | Fixes the scope of validation and the risk class |
| Risk assessment | What happens if the output is wrong, late or missing; controls in place | Clause 4.1.6 ties validation depth to risk |
| Configuration record | Model name and version, prompt or instruction set, connected data sources, access rights | Defines what was validated |
| Test set and acceptance criteria | Real historical cases with known outcomes; pass thresholds agreed before testing | Evidence that the agent meets its intended use |
| Results at version | The run, the score, deviations and their disposition, sign-off | The record the clause requires |
| Change control | Trigger list (model update, prompt change, new data source); re-validation rule per trigger | Answers the “it changes by itself” question |
| Monitoring plan | Sampling of live outputs, drift indicators, review frequency, who reviews | Shows the validation is maintained, not a one-off |
| Owner and training | Named process owner; who may use the agent and what they were trained on | Responsibility and competence, clauses 5.5 and 6.2 |
One rule saves most of the effort: validate the application, not the model. You cannot validate a frontier model. You can validate that your configured agent, on your cases, within your process, meets your acceptance criteria. That is what the clause asks for.
Three processes to start with
Start where the agent already runs and the risk is highest if it is wrong.
Complaint intake and triage. This is the first place most companies put an agent, and the first place a notified body looks, because complaint handling feeds vigilance reporting with legal deadlines. Test set: the last two hundred complaints, with the classification and the reportability decision the quality team actually made. Acceptance: no missed reportable event, ever; agreed tolerance on the rest. Human decision point: reportability stays with a person.
CAPA drafting. An agent that drafts root-cause analyses and action plans from investigation notes. Lower patient risk than triage, higher risk of a plausible-sounding file that nobody checked. Test set: closed CAPAs, compared with the agent’s draft. Human decision point: effectiveness check and closure.
Technical documentation maintenance. The agent that flags where a revised standard touches the technical file and proposes the edits. Risk sits in omissions. Test set: the last standard revision the company worked through by hand. Human decision point: every change to a controlled document is approved by its owner.
Three files, written to the table above, will take a small quality team a few weeks, mostly in building the test sets. Those test sets are also the asset: the next model update is validated against them in a day. This is the fifth of the eight measures for a sustainable AI transition — the one most companies have not started.
A note on scope
This article is about AI used in the quality management system, which ISO 13485 treats as QMS software. It is not about AI inside a medical device. Software that is itself a device or a safety component of one follows the MDR conformity route, and when it is AI-based and class IIa or above, it is high-risk under the AI Act, with obligations assessed inside the notified-body procedure from 2 August 2028.2, 5 ISO/TR 80002-2 draws the same line: it covers software used in the QMS and in production, and excludes software that is part of the device.6 If the same agent does both, treat it as two systems with two files.
What to do next
If you run a mid-sized producer: list every AI tool that touches a QMS record, this week. For each, write the intended-use page and name the owner. Pick the one with the highest consequence if wrong, usually complaints, and build its test set from your own history. Then put the agent in the software validation procedure you already have, with model updates added as a change trigger. Your next surveillance audit is on the calendar; this is a smaller job than the gap it closes. If you want a second pair of eyes on the process map before the auditor sees it, that is what a Scale Sprint is for.
If you are a distributor or a country manager: ask your principal which of their QMS processes now run through an agent, and whether the complaint-handling procedure you follow on their behalf has been updated. Your field complaints enter their system through you. If the agent that receives them is unvalidated, the finding lands on both sides.
Common questions
Is an AI agent used in our quality system a medical device? No, if it never forms part of a device or a device’s safety component. It is software used in the quality management system under ISO 13485 clause 4.1.6 and must be validated as such. The device rules of the MDR and the AI Act’s high-risk obligations do not apply to it.3, 6
Does the EU AI Act apply to our internal agents at all? The transparency obligations of Article 50 apply from 2 August 2026 where people interact with an AI system or content is AI-generated; the high-risk obligations for AI in medical devices apply from 2 August 2028 under Regulation (EU) 2026/1744. Neither replaces the validation duty under ISO 13485, which applies now.2, 5
The vendor says their platform is validated. Is that enough? No. The clause requires the manufacturer to validate the application of the software in its own QMS. Vendor evidence supports the file; the manufacturer’s own testing against its own intended use is what the auditor expects to see.10
What counts as a change that triggers re-validation? Anything that can alter the output: a model version update by the vendor, a change to the prompt or instruction set, a new connected data source, a change in access rights or in the process around the agent. GAMP 5’s AI appendix treats model retraining and updates as controlled changes.7
Does this apply to US submissions too? Yes. The FDA’s QMSR, effective 2 February 2026, incorporates ISO 13485:2016 by reference, so the same validation expectation applies in an FDA inspection.4
All source material is paraphrased from the linked publications.
Sources
- Deloitte Insights, Medtech’s agentic AI moment: turning ambition into enterprise advantage, 30 July 2026.
- EUR-Lex, Regulation (EU) 2026/1744 of the European Parliament and of the Council (Digital Omnibus on AI), Official Journal 24 July 2026.
- ISO, ISO 13485:2016 Medical devices — Quality management systems — Requirements for regulatory purposes, 2016, clause 4.1.6.
- Ropes & Gray, A QMSR state of mind: FDA adopts new inspection approach for medical devices as Quality Management System Regulation takes effect, 17 February 2026.
- Hunton Andrews Kurth, EU Digital Omnibus on AI enters into force, July 2026.
- ISO, ISO/TR 80002-2:2017 Medical device software — Part 2: Validation of software for medical device quality systems, 2017.
- IntuitionLabs, AI/ML validation in GxP: a guide to GAMP 5 Appendix D11, 2 February 2026 (on ISPE GAMP 5 Second Edition, 2022).
- Greenlight Guru, Understanding the new requirements for QMS software validation in ISO 13485:2016, updated 18 September 2026.
- EUR-Lex, Regulation (EU) 2017/745 on medical devices (MDR), Article 10(9) and Annex IX.
- Zechmeister Solutions, Validating QMS software tools under MDR (EN ISO 13485 clause 4.1.6), 2026.
Where's your constraint?
Five minutes tells you which of the five drivers is capping your growth.
Take the Scale Scorecard →