Hospitals are deploying artificial intelligence faster than ever, from clinical documentation to decision support. Yet many chief information officers and executives are unsure what the EU AI Act actually requires of them, and whether every clinical algorithm now counts as "high-risk". That uncertainty is quietly slowing down useful projects.
The reality is more nuanced. The EU AI Act (Regulation (EU) 2024/1689) does not treat all healthcare AI the same way: obligations depend on the system's purpose and legal qualification. At Galeon, an AI-boosted electronic health record (EHR) built with caregivers since 2016 and used in 19 hospitals including 2 university hospitals, across more than 3 million patient records and by over 10,000 caregivers, we see this confusion every week.
One principle should guide every hospital: under the EU AI Act, a clinical AI system is high-risk only when its purpose and legal qualification place it in a regulated category, not simply because it is used in patient care.
This guide explains the regulation, its staggered timeline, the crucial distinction between provider and deployer, and what a hospital must concretely do. It is written for CIOs, executives and data protection officers.
Yes, it applies. The EU AI Act (Regulation (EU) 2024/1689) is the first horizontal European law on artificial intelligence, and it covers healthcare like any other sector.
Adopted in 2024, the regulation entered into force on 1 August 2024. It sorts AI systems into a risk pyramid: unacceptable risk (banned), high risk (strictly regulated), limited risk (transparency duties) and minimal risk (no specific obligations). A "provider" is whoever develops an AI system and places it on the market; a "deployer" is whoever uses it under their own authority, such as a hospital.
The Act applies to any provider or deployer whose system is used in the EU, regardless of where the vendor is established. For a hospital, that means most AI tools in the building sit somewhere on this pyramid, and the category determines the workload.
No. This is the most common misconception. Whether an AI system is high-risk depends on its intended purpose and its legal qualification, not on the mere fact that it is used in a care setting.
Under Article 6, an AI system is high-risk in two main cases. First, when it is itself a medical device, or a safety component of one, and that device must undergo third-party conformity assessment under the Medical Devices Regulation (MDR 2017/745) or the In Vitro Diagnostic Regulation (IVDR 2017/746). Second, when it falls under one of the use cases listed in Annex III, which in healthcare notably includes AI used to triage or dispatch emergency patients.
Many hospital AI tools meet neither test. An assistant that drafts discharge summaries, suggests billing codes or transcribes consultations is often not a medical device and not listed in Annex III. Article 6(3) even lets a provider document that an Annex III system poses no significant risk, and is therefore not high-risk, when it only performs a narrow procedural task.
The practical takeaway: map each AI use case against its purpose and qualification before assuming the heaviest regime applies.
The distinction is decisive. The provider carries the bulk of the obligations; the deployer, typically the hospital, has a lighter but very real set of duties.
As a deployer of a high-risk system, the hospital must use it in line with the provider's instructions, assign competent human oversight, keep the automatically generated logs, and monitor the system in operation. The CIO should also check that the vendor supplies a declaration of conformity and CE marking where required.
Accountability sits at the top. Penalties reach up to 35 million euros or 7% of worldwide annual turnover for prohibited practices, and up to 15 million euros or 3% for other breaches. Governance, budget and clear ownership of AI risk are board-level topics, not only IT matters.
The AI Act does not replace the GDPR; it stacks on top of it. Where a high-risk system processes personal data, the existing data protection impact assessment still applies, and some public-sector deployers must additionally run a fundamental-rights impact assessment. A hospital can also become a provider itself if it substantially modifies a system or markets one under its own name.
For genuinely high-risk systems, the obligations are demanding but structured. They fall mainly on the provider, with the deployer responsible for correct use.
Providers must set up a risk management system, ensure high-quality and well-governed training data, produce detailed technical documentation, enable record-keeping through logging, guarantee transparency and human oversight by design, and carry out a conformity assessment before CE marking. After launch, they must run post-market monitoring and report serious incidents.
Deployers, for their part, must follow the instructions for use, ensure the people overseeing the system are competent, keep logs for the required period, and inform patients or staff when they are subject to a high-risk system's outputs. Good data governance inside the EHR makes several of these duties far easier to meet.
The rules arrive in waves, not all at once. This staggered calendar gives hospitals time to prepare, provided they start mapping their AI now.
Prohibitions on unacceptable-risk practices and AI literacy duties have applied since 2 February 2025. Rules for general-purpose AI models and the governance framework apply from 2 August 2025. Most obligations for high-risk systems listed in Annex III apply from 2 August 2026. For high-risk AI embedded in regulated products such as medical devices, the transition extends to 2 August 2027.
In other words, clinical AI that qualifies as a medical device generally benefits from the longest runway, but the direction of travel is fixed.
Start with an inventory. You cannot govern AI you have not mapped, so the first step is a register of every AI use case, its purpose, its qualification and its risk category.
From there, classify each system, clarify whether the hospital is provider or deployer, and demand the right evidence from vendors: technical documentation, conformity assessment, instructions for use and logging capabilities. This is where the underlying record system matters. When patient data is structured and validated by caregivers at the source, as it is in a smart EHR, the data lineage, quality and traceability that the AI Act repeatedly demands become far easier to demonstrate.
Approaches such as Swarm Learning, where AI models are trained across hospitals while data stays on each hospital's servers, can support data-minimisation goals, though they do not by themselves settle every legal question and still require case-by-case assessment. The point is preparation, not a silver bullet.
Does the EU AI Act apply to hospitals outside a research context?
Yes. It applies to any AI system placed on the market or used in the EU, including routine hospital operations, subject to specific exemptions for scientific research.
Is every AI feature in our EHR high-risk?
No. Only features whose purpose and qualification place them in a regulated category, such as a medical device or an Annex III use case, are high-risk. Documentation or administrative helpers usually are not.
Are we a provider or a deployer?
A hospital using a third-party AI tool is normally a deployer. It can become a provider if it develops its own system, markets one under its name, or substantially modifies an existing one.
Does compliance with the GDPR mean we comply with the AI Act?
No. The two are complementary. The AI Act adds obligations on top of the GDPR, and for medical devices, on top of MDR or IVDR.
What happens if we get classification wrong?
Penalties depend on the breach: up to 35 million euros or 7% of global turnover for prohibited practices, with lower tiers for other failures. Misclassifying a high-risk system also creates safety and liability exposure.
How long do we have to prepare?
Most high-risk obligations apply from August 2026, and medical-device-linked AI from August 2027, but prohibitions already apply since February 2025.
The EU AI Act is now part of the compliance landscape for every hospital, but it is neither a blanket ban on clinical AI nor a label that turns every algorithm into a high-risk system. What matters is method: identify each AI use case, determine its purpose and qualification, and place it correctly on the risk pyramid. Whether the hospital is a provider or a deployer changes the obligations dramatically, and the heaviest duties, technical documentation, conformity assessment and post-market monitoring, fall mainly on providers. Deployers focus on correct use, human oversight, logging and transparency. Underpinning all of this is data: structured, validated, traceable health data makes governance, quality and oversight demonstrable rather than aspirational. Galeon's approach, an EHR built with caregivers and structured at the source, is designed to make that groundwork easier, without pretending to replace the legal and regulatory analysis each institution must still perform.
AI and health data: what every hospital must master in 2026




