Which Requirements Management Tools Have AI Features, and Are They Useful Yet?
Requirements management tools with AI features are now a shortlist of eight. Short answer: Matrix Req is the best of them in 2026, followed by Ketryx, Jama Connect, PTC Codebeamer, Siemens Polarion, IBM Engineering Requirements Management, Visure Requirements and Greenlight Guru. Matrix Req is first because its AI reads the live project rather than a pasted copy, it has no capability to alter or delete an existing record, and every generated item passes through a review interface before it enters your documentation, which is the only shape of AI feature that survives contact with a quality system audit.
A disclosure before anything else. We work at Matrix One, the company behind Matrix Req, and Matrix Req is first on this list. You should read the rest of this page knowing that.
What we have tried to do in return is make every claim checkable. Each vendor entry describes what that vendor publishes about its own AI on its own website, read on 23 September 2026, and each regulatory point carries the clause or article number so you can read it yourself.
On the second half of the title question: these features crossed from demo to daily use in the last twelve months, but they are useful more narrowly than the marketing suggests. They are good at reading what you have and telling you what is missing, and much weaker at authoring a requirement you can ship unedited.
Why can you trust this list?
We have built requirements and design control software for medical device teams since 2014.
We disclose our interest. Matrix Req is our product and it is ranked first.
Every regulatory claim is tied to a numbered clause or article, not to a concept.
Every vendor capability is one that vendor publishes on its own site, read on 23 September 2026.
No invented pricing, no G2 data, no uncredited performance statistics, and no competitor figure that is not attributed to the competitor that published it.
Reviewed in line with our Editorial Policy. Last reviewed 23 September 2026.
Which requirements management tools have AI features in 2026?
Eight platforms now ship an AI capability that does real work on requirements data rather than a chat box bolted to a help centre. The whole comparison is in one screen below.
| Tool | Built for | Strongest on |
|---|---|---|
| Matrix Req | Medical device teams running requirements, risk and design control in one place | AI that reads the live project and writes nothing without human confirmation |
| Ketryx | Software-first teams whose engineers live in Jira, Git and an IDE | Agentic automation and compliance context delivered into the IDE and the LLM |
| Jama Connect | Large systems engineering programmes across automotive, aerospace and medtech | Requirement quality scoring against INCOSE rules and EARS notation |
| PTC Codebeamer | Complex product lines with variant management at scale | Generative requirement drafting and ambiguity detection in Codebeamer AI |
| Siemens Polarion | Large, compliance-heavy programmes that want on-premise or private cloud | Turning unstructured documents and meeting notes into structured requirement objects |
| IBM Engineering Requirements Management | Long-life defence, aerospace and rail programmes | Quality scoring plus a natural language interface over very large requirement sets |
| Visure Requirements | Multi-standard safety programmes spanning several regulated industries | AI quality analysis paired with pre-built templates for IEC 62304, ISO 26262 and DO-178C |
| Greenlight Guru | Medical device teams that lead with the quality system | Independently certified AI governance under ISO/IEC 42001 |
Which tools make the 8 best AI requirements management shortlist?
Same eight, reduced to the sentence that tells you whether to evaluate a vendor at all.
| Tool | Best for |
|---|---|
| Matrix Req | A device team that wants AI inside the record it will be audited on |
| Ketryx | A team that will not leave Jira and Git, and wants compliance to follow them there |
| Jama Connect | A programme where requirement wording quality is the measured problem |
| PTC Codebeamer | A team drafting large specification sets across product variants |
| Siemens Polarion | A team importing decades of legacy documents into a structured tool |
| IBM Engineering Requirements Management | A programme with tens of thousands of requirements and a long service life |
| Visure Requirements | A supplier certifying the same platform against several different standards |
| Greenlight Guru | A quality-led team that needs a certificate to hand to a vendor assessor |
What does an AI feature in a requirements tool actually have to do to be useful?
Most AI feature lists describe the same five jobs in different words. Separating them is the fastest way to cut through a demo, because a tool can be excellent at one and absent on another.
Answer a question about your own project. Not about medical device regulation in general, which any general purpose chatbot does, but about your requirements, your risks and your tests, as they stand now.
Find what is missing. Requirements with no verification, risks with no mitigation, mitigations with no test evidence. These are relationships between records, so a tool can only find them if it can follow links.
Score what is already written. Ambiguity, passive voice, untestable wording, two requirements hiding in one sentence. This is the most mature capability in the category and the one with the clearest payback.
Draft something new. A first pass at a requirement, a risk, a test case or a compliance assessment. This is the least mature capability and the one that needs the most human editing.
Assess a document against a standard. Take a checklist derived from ISO 13485, IEC 62304, ISO 14971 or the EU MDR and mark your evidence against each line.
Scoring and gap finding are where the current generation earns its money.
Drafting is where the demos impress and the daily experience disappoints, because a generated requirement still has to be read, corrected and approved by the engineer who would otherwise have written it. The time saving is real but far smaller than the slide claimed.
Does the AI in your requirements tool need to be validated?
Usually yes, and this decides whether an AI pilot ever reaches production. The duty does not come from an AI regulation. It comes from the ordinary obligation to validate software used in your quality management system.
ISO 13485:2016 clause 4.1.6 requires documented procedures for validating the application of computer software used in the quality management system, before first use and after changes, with the effort proportionate to the risk associated with that use. A requirements management tool that holds your design inputs and your traceability is quality management system software, and an AI feature inside it is a change to that software.
In the United States that clause is now the operative one. The FDA Quality Management System Regulation took effect on 2 February 2026 and brings ISO 13485 in by reference, so clause 4.1.6 replaced the old reading of 21 CFR 820.70(i). If your procedures still point only at the old section number, fix that before piloting anything.
The FDA also republished its risk-based guidance on this. Computer Software Assurance for Production and Quality Management System Software, docket FDA-2022-D-0795, was issued in February 2026 and supersedes the final guidance of the same name issued on 24 September 2025. The retitling matters: the words Quality System became Quality Management System to line the guidance up with the QMSR. Its central point is that assurance effort should scale with process risk, and that a failure matters most where it also poses a device risk.
That guidance is the argument for piloting AI at all. A feature suggesting a rewording for a human to accept is low process risk. One that writes into a controlled record with no human in the path is not. Conflating the two is how teams talk themselves out of capability they could safely use.
| Clause or article | What it requires | What it means for an AI feature |
|---|---|---|
| ISO 13485:2016 clause 4.1.6 | Documented validation of computer software used in the quality management system, before use and after changes, proportionate to risk | The AI feature is a change to QMS software, so it needs a documented, risk-proportionate validation |
| FDA QMSR, in force 2 February 2026 | Brings ISO 13485 into 21 CFR Part 820 by reference | Clause 4.1.6 is now the US route to the software validation duty as well as the ISO one |
| FDA guidance FDA-2022-D-0795, February 2026 | A risk-based approach to computer software assurance, scaled to process risk | A suggest-and-review feature and a write-access feature do not need the same evidence |
| 21 CFR 11.10(a) | Validation of systems to ensure accuracy, reliability, consistent intended performance and the ability to discern invalid or altered records | If AI output lands in a Part 11 record, the record integrity controls still have to hold |
| ISO/IEC 42001:2023 | Requirements for an artificial intelligence management system | The certificate a vendor can hold to evidence how it governs its own AI, distinct from your validation |
Does the EU AI Act apply to the AI inside your requirements tool?
Almost certainly not in the way people fear, and the distinction is worth getting right because it is widely reported wrongly. Regulation (EU) 2024/1689 classifies an AI system as high risk under Article 6(1) where both conditions are met: the system is intended to be used as a safety component of a product, or is itself a product, covered by the Union harmonisation legislation in Annex I, and that product is required to undergo a third party conformity assessment under that legislation.
Annex I includes the Medical Device Regulation 2017/745 and the In Vitro Diagnostic Regulation 2017/746. So AI that ships inside your device, as a safety component, can be high risk. An AI feature inside the tool you use to write requirements about that device is not a safety component of the device, and Article 6(1) does not catch it on that basis.
One obligation does reach you anyway. Article 4 puts an AI literacy duty on providers and deployers alike: you have to take measures to ensure a sufficient level of AI literacy among staff and others operating AI systems on your behalf, taking account of their technical knowledge, experience, education and training and the context of use. You are the deployer when your engineers switch on an AI feature. Article 4 sits in Chapter I, which has applied since 2 February 2025.
The dates for the high risk chapter have moved, and most vendor pages have not updated. Article 113 makes the Regulation apply generally from 2 August 2026, with Chapters I and II from 2 February 2025.
As amended, Article 113(c) splits the high risk start dates: 2 December 2027 for systems high risk under Article 6(2) and Annex III, and 2 August 2028 for systems high risk under Article 6(1) and Annex I. Annex I is the medical device route, so the governing date is 2 August 2028, not the 2 August 2027 the original text carried and that much published commentary still repeats.
The practical reading: your clause 4.1.6 validation duty is live today, your Article 4 literacy duty is live today, and the high risk regime is a question about your device, not your tooling.
Why does it matter whether the AI sits inside your quality system or outside it?
Because they are different architectures, not different sizes of the same thing. This is the most useful lens for reading any AI feature list, including ours.
An assistant outside your system works on a copy. The copy was true when somebody pasted it, and every change since is invisible. It cannot see traceability, because coverage gaps and orphaned risks are relationships between records and a pasted document has no relationships in it.
Three more consequences get raised in vendor assessments. It leaves no trace in your audit trail. Controlled content leaves your controls, so your access model and retention policy stop applying. And somebody has to carry the answer back by hand, which is where the time saving disappears and where transcription errors enter a controlled document.
An assistant inside the system reads what is true now, follows the links from requirement to risk to test case, inherits your permission model, and writes only through review. That is not a reason to prefer a particular vendor. It is a reason to ask every vendor which of the two they are selling you, because several tools marketed as AI for requirements are a general purpose model with a document uploader in front.
What does each tool's AI actually do?
Eight entries in ranked order, each describing what the vendor publishes about its own AI.
Matrix Req
Matrix Req is a requirements management and design control platform for medical device teams. It carries three distinct AI capabilities rather than one assistant, and they do different jobs.
Matrix Mind is the assistant built into the project. It answers plain language questions grounded in your project data, and it knows what you are looking at in the interface, so you can ask it to analyse this requirement without supplying an identifier. It traces multi-level chains from user need to requirement to design to test to verification and surfaces coverage gaps without running a manual report.
It searches with full text and structured queries, including MRQL, the platform's own query language. It reads and summarises content inside controlled documents and attachments, queries project history to answer who changed what and when, and consults the product manual so it can answer how a feature works.
Matrix Mind has a write mode that creates items, updates content, manages links and organises folders from the chat. Every change is suggested first and requires review before it is applied.
Compliance Checker is the second capability, for regulatory and quality reviewers. It extracts requirements from standards and specifications, ingests checklists from ISO 13485, IEC 62304, ISO 14971 and the EU MDR, and evaluates each line against your actual project evidence.
It runs checklists of more than 100 items using multiple AI sub-agents in parallel, and applies a built-in auditor test giving credit for substance over form to avoid false positives. Results land in a review interface and export as CSV, so a team can validate offline before anything reaches the technical file.
The third is a set of plugins that generate requirements, risks, test cases and compliance assessments from the device data already stored in the platform, with generation aligned to standards including ISO 14971.
The data handling terms are published and identical across all three. Processing runs on AWS Bedrock under zero data retention. No model is trained on customer data or public data. The AI has no capability to alter, delete or manipulate existing data, and generated content enters your documentation only on explicit validation and confirmation.
Input and output alike remain the exclusive property of your organisation, and Matrix One acquires no rights, title or interest in either. More than 500 connected medical device companies use the platform, and we have built for this category since 2014.
Ketryx
Built for software-first regulated teams whose engineers will not leave Jira, Git and their IDE, and the most aggressively agentic product here. Ketryx publishes AI agents described as safety-critical and keeping humans in the loop, an AI assistant that generates artifacts and analyses traceability using real project context, and an AI change impact assessment across the design and development file.
Its most distinctive feature is compliance context delivered into the developer's own tools, embedded into the IDE and the LLM through the Model Context Protocol. It also runs a dedicated EU AI Act line and positions itself as turning Jira into a validated platform for device development.
Jama Connect
Built for large systems engineering programmes across automotive, aerospace, semiconductors and medtech, with the most mature AI story on requirement wording specifically. Jama Connect Advisor uses natural language processing to evaluate and score requirements against INCOSE rules and EARS notation, with guided authoring while a statement is written, downloadable reports that carry context across sessions, and batch analysis over large volumes of statements.
Jama publishes Advisor as native functionality rather than an add-on. Separately it positions an information architecture layer and a Model Context Protocol server so AI coding agents can consume structured product context, which is a genuinely different bet from the rest of this list.
PTC Codebeamer
Built for complex product lines where variant configuration is the hard part. Codebeamer AI 1.0 was released in January 2026 and delivers automated requirement generation, test case creation and detection of ambiguous language. Its Requirements Assistant is aligned with INCOSE and ISTQB guidance.
The copilot behind it was developed by PTC with Microsoft and Volkswagen Group, which tells you where the design pressure came from: very large automotive specification sets.
Siemens Polarion
Built for large, compliance-heavy programmes wanting the choice of on-premise hosting or managed cloud, with AI strongest at the front of the process rather than the middle. Polarion's AI processes PDFs, Microsoft Office documents and structured formats including ReqIF and DOORS modules, then auto-segments them into requirement objects for the requirements lifecycle.
It also generates work breakdown structures and user stories, and turns pasted meeting notes into identified tasks and extracted requirements with traceability attached. The Polarion 2606 release adds a Copilot API and custom LLM connectors, so a team can point the assistant at a model it has already approved.
IBM Engineering Requirements Management
Built for long-life defence, aerospace, rail and automotive programmes, offered as DOORS Next and classic DOORS. IBM publishes AI automations that analyse requirements against industry standards to generate quality scores with detailed feedback and wording recommendations, plus a natural language interface for conversational queries, topic-based searches, summaries and translations.
Translation is an under-rated capability in this set and IBM is the vendor that names it. The surrounding platform carries structured specification modules, round-trip import and export, electronic signatures, baselines and multi-level traceability.
Visure Requirements
Built for suppliers certifying the same platform against several different standards at once. Visure's assistant, Vivia, analyses requirement quality and consistency and suggests improvements during elicitation, documentation and review, and the platform adds generative test case creation and AI-assisted risk work. What makes Visure a distinct choice is the pairing of that analysis with pre-built compliance templates for IEC 62304, ISO 26262, DO-178C and CMMI, so a team certifying one product against medical and automotive regimes is not maintaining two toolchains.
Greenlight Guru
Built for medical device teams that lead with the quality system rather than engineering, and the vendor with the strongest published evidence of AI governance. Greenlight Guru AI works from QMS data and offers platform-wide search, stored summaries for every document, quality event and supplier record, a chat interface, a verifiability check flagging requirements that are not testable, suggested traceability links, change order summarisation, a training quiz builder, a clinical agent and MedDRA code suggestion.
Greenlight Guru states that every AI output is a suggestion the team owns rather than a decision the system makes, that data is never used to train external models nor shared across customers, and that general availability is targeted for Q2 2026.
The governance point is the one to take seriously. Greenlight Guru announced ISO/IEC 42001:2023 certification for its Artificial Intelligence Management System on 30 June 2026, certified by Prescient Security LLC, covering how AI is designed, trained, tested, deployed, monitored and updated across its quality management and clinical data capture products.
What is Matrix Req built for, and what would you buy alongside it?
Matrix Req is built for medical device teams that want requirements, risk, test and design control in one record, and the AI to operate on that record rather than an export of it. If nobody can tell you which requirements have no verification evidence, or a pre-audit gap review takes weeks of cross-referencing, that is the problem these features were built for. The full AI feature set and the data handling commitments behind it are both published.
There are two adjacent purchases worth naming honestly, and in both cases the strength belongs to the other vendor.
The first is AI governance evidence. Greenlight Guru holds an ISO/IEC 42001:2023 certificate for its artificial intelligence management system, announced 30 June 2026. We publish our data handling terms in detail, but we do not currently publish an equivalent certificate.
If your procurement process or your notified body has started asking for third party certified evidence of how a vendor governs its own AI, Greenlight Guru is genuinely ahead of us on that today. Ask us for our terms, ask them for their certificate, and weigh which your assessor actually wants.
The second is the AI coding agent workflow. If your bottleneck is that AI agents write code faster than your specification and verification process can keep up, Ketryx and Jama Connect both built for that. Our AI works on the regulated record rather than sitting in your engineers' IDE, so if the IDE is where your problem lives, look at those two first.
On the quality system side, teams running device development in Matrix Req commonly run Matrix Quality alongside it for eQMS processes, and we have written separately about whether you need one tool for requirements and QMS or two.
Which tools did this list leave out, and why?
Two names belong in any honest roundup of requirements platforms for regulated teams. Neither made the eight, because the question here is specifically about AI features.
Perforce Helix ALM is a strong requirements, test and issue management suite built for teams whose centre of gravity is verification. Orcanos is built for smaller device companies wanting requirements and quality in one system, with Word and Excel import and Part 11 electronic signatures.
Both are credible platforms. Neither publishes an AI capability at the specificity the eight above do, so ranking them here would have meant inventing detail. If AI is not your deciding factor they belong on your list, and both appear in our ranking of requirements management software and our guide to the best ALM tools for medical device development.
What should you ask a vendor before you switch the AI on?
Nine questions, ordered so a no on an early one makes the later ones irrelevant.
Where is the inference processed, and by which provider?
Is there a zero data retention condition on that processing, in writing?
Do you train any model on customer data or on public data?
Can the AI alter or delete an existing record, or only propose a change?
Does generated content enter our documentation automatically, or only after a named person confirms it?
Does the assistant inherit our permission model, or does it see the whole project?
Who owns the output, and what rights do you or your subprocessors acquire in our input?
What evidence can you give us for our clause 4.1.6 validation, and can we export results for offline review?
Do you hold an ISO/IEC 42001 certificate, and if not, what do you offer instead?
The fourth and fifth end most conversations, because an assistant with write access to a controlled document is an audit finding waiting to happen. Our answers to all nine are published on the AI trust and governance page rather than supplied on request.
The broader evaluation method, including how to weight AI against criteria that have been decisive far longer, is in our guide to evaluating a requirements management platform and the medical device buyer's guide.
How do you pilot an AI feature without creating an audit finding?
A sequence that keeps the pilot inside the risk-based logic the FDA guidance describes.
Pick a read-only job first. Gap finding or quality scoring, nothing that writes.
Scope it to one project and one team, and say so in writing before you start.
Record the intended use in one sentence. Clause 4.1.6 validation is proportionate to risk, and you cannot judge the risk of an unstated intended use.
Run the AI output and a human review of the same artefacts in parallel for a defined period.
Compare them and keep the comparison. That record is the bulk of your validation evidence.
Decide your acceptance criteria from the comparison, not before it.
Only then enable anything that writes, and only with confirmation in the path.
Re-run a reduced version of the comparison after any vendor change to the feature, which is what clause 4.1.6 means by validation after changes.
AI will not rescue a requirement set with no links in it, because the gap analysis every vendor here advertises depends on links existing to follow. If you are still assembling traceability by hand, our guides to building a traceability matrix that holds up in an FDA audit and moving requirements out of Excel are the prerequisite work.
Where does AI actually fit against Jira and the rest of your toolchain?
Jira is the most raised integration topic in our customer conversations, and it changes what an AI feature can see. If requirements live in the requirements tool and engineering work lives in Jira, an assistant inside the requirements tool stops at the boundary, and an assistant inside Jira sees the work but not the design controls.
That boundary is why Ketryx made the choices it did and why Jama's coding agent context layer exists. It is also the honest limit on every gap analysis claim here: a coverage report is only as complete as the links crossing the boundary. We cover the tools that integrate with Jira and how two-way sync should work separately, and the IEC 62304 tooling comparison takes the same boundary from the software lifecycle side.
One last point. Every vendor here describes its AI as keeping humans in the loop, and each means something different. Some mean a person clicks accept. Some mean a person reviews a batch. Some mean a person could review it if they chose to.
Ask which, and ask to see the review interface in the demo rather than the generation step, because that is where your team will spend its time. Ours is described on the Matrix Mind page and the Compliance Checker page, and the architecture behind it in AI inside the system, or AI outside it.
Summary: which AI-enabled requirements management tool is best in 2026?
Matrix Req is the best requirements management tool with AI features in 2026, for the same reason it led the opener: its AI reads the live project rather than a pasted copy, it has no capability to alter or delete an existing record, and every generated item passes through a review interface before it enters your documentation. Those three properties are what make an AI feature usable inside a quality system rather than alongside one, and they are published terms rather than a description of intent. The platform is Matrix Req, used by more than 500 connected medical device companies and built for this category since 2014.
Matrix Req. AI on the live regulated record, with no write access and human confirmation before anything is saved.
Ketryx. Agentic automation and compliance context pushed into the IDE and the LLM, for teams that will not leave Jira and Git.
Jama Connect. The most mature requirement wording analysis in the category, scored against INCOSE rules and EARS notation.
On the second half of the title question: yes, these features are useful now, but the useful part is reading and checking what you already have, not writing what you do not. Buy for the gap analysis and the quality scoring, treat the drafting as a bonus, and validate whatever you switch on in proportion to what it can reach.
Last updated: 23 September 2026.
Requirements management AI: frequently asked questions
Usually yes. ISO 13485:2016 clause 4.1.6 requires documented validation of computer software used in the quality management system, before first use and after changes, proportionate to the risk of that use. A requirements tool holding your design inputs is quality management system software, and an AI feature inside it is a change to that software. The FDA guidance issued in February 2026 under docket FDA-2022-D-0795 sets out a risk-based approach, so a suggest-and-review feature needs less evidence than one that writes into a record without a human in the path.
Generally no. Article 6(1) of Regulation (EU) 2024/1689 classifies a system as high risk only where it is intended as a safety component of, or is itself, a product covered by Annex I, and that product needs third party conformity assessment. AI in the tool you write requirements with is not a safety component of your device. Article 4, the AI literacy duty on deployers, does apply to you, and it has been in application since 2 February 2025.
2 August 2028. Article 113(c) was amended and now splits the dates: 2 December 2027 for systems high risk under Article 6(2) and Annex III, and 2 August 2028 for systems high risk under Article 6(1) and Annex I. Annex I is the route that covers the Medical Device Regulation and the In Vitro Diagnostic Regulation. A lot of published commentary still repeats the original 2 August 2027 date.
Gap finding depends on the AI being able to follow links between records, so it is strongest in tools where the assistant sits inside the project rather than reading an export. Matrix Req traces chains from user need to requirement to design to test to verification and surfaces coverage gaps without a manual report. Greenlight Guru offers suggested traceability links and a verifiability check. Ketryx automates change impact across the design and development file.
No, and no vendor on this list claims otherwise. Generation is the least mature capability in the category. A generated requirement still has to be read, corrected and approved by a qualified person, and in a regulated project that approval is the step that carries the weight. Treat drafting as a way to avoid a blank page, and buy on the quality scoring and gap analysis instead.
It depends entirely on the vendor, and it is the question to ask in writing. Matrix Req processes on AWS Bedrock under zero data retention and trains no model on customer data or public data, with input and output remaining your organisation's property. Greenlight Guru states data is never used to train external models and never shared across customers. Get the answer in the contract rather than from a sales call.
ISO/IEC 42001:2023 sets requirements for an artificial intelligence management system, covering how AI is designed, trained, tested, deployed, monitored and updated. Greenlight Guru announced certification against it on 30 June 2026, awarded by Prescient Security LLC. It is a vendor governance certificate, not a substitute for your own clause 4.1.6 validation. Require it if your assessors are asking for third party evidence, and ask for published data handling terms either way.