| Question | Short answer | What to remember |
|---|---|---|
| Who can be sued when AI misdiagnoses? | Both the AI provider and the hospital can be liable. | Liability splits depend on contract and oversight. |
| Does the AI Act remove hospital responsibility? | No, it adds mandatory human oversight. | Hospitals must keep a qualified professional in the loop. |
| Is every clinical AI a high‑risk device? | Only AI used for diagnosis, treatment planning, or triage is high‑risk. | Low‑risk tools (e.g., administrative chatbots) are exempt. |
| What documentation is required? | Risk assessment, validation reports, and post‑market monitoring logs. | All records must be audit‑ready for regulators. |
| How does Swarm Learning help? | It lets hospitals improve models without sharing raw data. | Data never leaves the hospital, but governance still applies. |
| Can AI errors be covered by insurance? | Yes, but policies require proof of compliance with the AI Act. | Transparent documentation reduces premium. |
| What is the role of the clinician? | Final clinical judgement remains their responsibility. | Human oversight is a legal safeguard, not optional. |
Clinical AI promises faster diagnoses, personalised treatment plans, and lower costs. Yet every year, misclassifications or algorithmic drift surface, raising the inevitable question: who is liable when clinical AI gets it wrong? The answer is never simple, because responsibility weaves through manufacturers, hospitals, and the clinicians who ultimately press “accept”.
Since 2016, Galeon has been co‑creating an intelligent EHR with front‑line caregivers. Deployed in 19 hospitals—including two university medical centres—Galeon now supports more than 3 million patient records and 10 000+ health professionals. The platform’s Swarm Learning® engine lets hospitals collaboratively improve AI models while keeping data on‑premise, a model that aligns with emerging European data‑sovereignty expectations.
With the EU AI Act entering full application in 2024 and the new MDR (Medical Device Regulation) amendments in 2026, regulators are demanding concrete human oversight and rigorous post‑market surveillance. This article untangles the legal framework, highlights the gray zones, and shows how hospitals can structure their processes to minimise exposure.
“Liability is not transferred by technology – it is reshaped by the contracts, controls and documentation you put in place.” – Legal counsel, European HealthTech Association, 2025.
Both the AI supplier and the health‑care institution can be held accountable, depending on contractual terms, the level of integration, and the presence of human oversight.
The typical chain includes:
When an error occurs, courts look at who had “effective control” over the decision. If the AI was a “black‑box” with no explainability and the clinician relied blindly, liability may tilt toward the manufacturer for inadequate safeguards. Conversely, if the hospital failed to implement mandatory oversight, it can be deemed negligent.
The AI Act classifies most AI used for diagnosis, treatment planning, or triage as “high‑risk” and mandates real‑time human supervision.
Key obligations include:
The Act does **not** absolve hospitals of responsibility; instead, it formalises the supervisory role that clinicians already perform.
Reference: European Commission, AI Act (Regulation (EU) 2021/0106), EUR‑Lex.
When an AI tool is classified as a medical device under the EU MDR, the manufacturer must obtain a CE mark and comply with the device’s conformity‑assessment procedures.
Consequences for liability:
In practice, the safest route is to keep the AI unchanged from the version that received the CE mark and to document any local customisation.
Source: European Medicines Agency – “Guidance on the clinical evaluation of medical devices”, EMA Guideline.
Hospitals must maintain a comprehensive “AI‑use dossier” that proves adherence to both the AI Act and MDR requirements.
The dossier typically contains:
All records must be audit‑ready and stored on an HDS‑certified (Health Data Hosting) platform that aligns with ISO 27001:2022. Failure to produce this documentation on request can result in fines up to €30 million or 6 % of annual turnover under the AI Act.
Reference: ANSSI – “HDS certification in 2026: what hospitals must check before signing”, HDS 2026 guide.
Under the AI Act, validation is a continuous activity, not a one‑off checkpoint.
Key shifts include:
Galeon’s smart EHR integrates automated drift detection and audit trails, making it easier for hospitals to stay compliant while preserving data sovereignty.
Read more about the differences between a smart EHR and a traditional one: Smart EHR vs Traditional EHR.
Prioritise secure, HDS‑certified hosting, robust API governance, and seamless integration with existing EHR workflows. Ensure that all data used in Swarm Learning® stays on‑premise and that audit logs are immutable.
Establish clear accountability matrices, allocate budget for ongoing validation, and embed AI‑ethics committees that review risk assessments quarterly.
| Criterion | Traditional AI Deployment | Galeon‑Enabled Deployment |
|---|---|---|
| Data residency | Centralised cloud, cross‑border transfers | On‑premise storage; Swarm Learning keeps data local |
| Compliance documentation | Ad‑hoc records, often incomplete | Auto‑generated AI‑use dossier with audit trail |
| Human‑in‑the‑loop design | Optional, rarely enforced | Built‑in decision checkpoints aligned to AI Act |
| Model updating | Manual, risky, no version control | Federated Swarm Learning with versioned releases |
| Risk‑assessment frequency | Yearly or after major incident | Continuous monitoring, automatic alerts |
| Audit readiness | Paper‑based, time‑consuming | Digital logs searchable by regulator |
| Stakeholder training | One‑off sessions | Embedded learning modules, usage analytics |
| Scalability across sites | Limited, siloed deployments | Swarm Learning enables cross‑hospital model improvement without data sharing |
Can a hospital delegate all AI decisions to the vendor?
No. The AI Act requires a qualified clinician to verify AI outputs before any clinical action.
Is every radiology AI tool automatically high‑risk?
Only those that influence diagnosis or treatment planning are high‑risk; tools that merely organise images are low‑risk.
What happens if an AI model drifts after deployment?
Hospitals must trigger a post‑market review, suspend the model if safety thresholds are breached, and retrain using validated data.
Do Swarm Learning models need separate CE‑marking?
Each participating hospital must ensure that the federated model complies with the original CE‑marked version; updates are considered a change in the technical file.
How long must incident logs be retained?
At least 10 years, in line with the EU Medical Device Regulation and national health‑data retention rules.
Is there a “no‑fault” shield for AI manufacturers?
No. While product‑liability law provides some defence if the device met all standards, negligence in risk management can still lead to liability.
Can clinicians be personally sued for relying on AI?
Only if they ignored required oversight procedures or acted contrary to documented SOPs.
Liability when clinical AI gets it wrong is a shared, multi‑layered construct that involves AI manufacturers, hospitals, and the clinicians who ultimately approve a recommendation. The EU AI Act crystallises the need for real‑time human supervision, continuous risk management, and a robust AI‑use dossier—elements that hospitals must embed into their governance framework. Galeon’s intelligent EHR, powered by Swarm Learning®, offers a practical pathway: on‑premise data residency, automated compliance artifacts, and built‑in human‑in‑the‑loop checkpoints that align with both the AI Act and MDR. By coupling rigorous documentation with transparent, federated model improvement, hospitals can mitigate legal exposure while still benefitting from cutting‑edge AI assistance.
Want to know more about our smart EHR ?
Book a demoDiscover how data quality fuels predictive medicine – read our deep‑dive.




