AI for business · Industry guide

🩺 AI rules: Healthcare

Medical AI is usually a medical device and high-risk; health data is a special category under GDPR. The European Health Data Space will open access to data for AI development.

Typical AI uses and their risk level

High risk
AI that supports diagnosis or treatment decisions

Medical device (MDR) and high-risk under the AI Act (Annex I) from 2 Aug 2028.

High risk
Triage of emergency calls

High risk (Annex III).

Minimal
AI transcription of consultations into the medical record

Not high-risk by itself, but health data: DPA, EU hosting, patient information, doctor checks the text.

Transparency
Appointment chatbot

Must say it is AI; no medical advice without safeguards.

What to do

  • Check whether an AI tool is CE-marked as a medical device for your intended use.
  • Never paste identifiable patient data into consumer AI tools.
  • DPIA for any AI processing of health data.
  • Keep the clinician responsible and document review of AI outputs.

Common pitfalls

  • General chatbots are not medical devices — using them for diagnosis shifts liability to you.
  • Emotion recognition of staff is prohibited even in hospitals (except for safety or medical reasons).

Examples

A private clinic wants AI dictation

Choose a provider with a DPA and EU data storage, inform patients, let doctors review each note — then it is an efficient, low-risk use.

General information, not legal advice — consult a lawyer for borderline cases. Regulations reviewed on 29 Sep 2026.