Skip to content
For healthcare & medtech

Healthcare AI is high-risk under the EU AI Act.

Clinical decision support, diagnostic imaging AI, and triage systems fall under Annex III, and as safety components of medical devices under Annex I. If your AI influences patient care decisions, you have until December 2, 2027 to comply.
01 / High-risk

Which healthcare AI is high-risk?

AI used as a safety component of a medical device, or that is itself a medical device, is high-risk under Annex I. Clinical decision tools also fall under Annex III, point 5.

Clinical decision support systems

AI that assists clinicians in diagnosing conditions, recommending treatments, or prioritising patients based on clinical data.

Diagnostic & imaging AI

Systems that analyse medical images, lab results, or patient records to detect disease, flag abnormalities, or suggest diagnoses.

Triage & risk stratification

AI that determines urgency of care, allocates hospital resources, or scores patient risk for emergency or surgical settings.

Mental health & behavioural AI

Systems that assess mental health conditions, predict deterioration, or recommend psychiatric interventions from behavioural patterns.

02 / Probably fine

What's not high-risk in healthcare?

Administrative and operational AI generally won't trigger Annex III, unless it directly influences clinical outcomes for individual patients.

  • Hospital scheduling and bed-management optimisation without clinical decisions
  • Administrative chatbots for appointment booking (transparency obligations only)
  • Supply chain AI for pharmaceutical logistics (no patient impact)
  • Research-only models not deployed in clinical settings

Even if your system isn't high-risk, Article 50 transparency may still apply. Run the free classifier to find out.

03 / MDR / IVDR overlap

Medical Device Regulation overlap

If your AI qualifies as a medical device under the MDR or IVDR, the AI Act conformity assessment integrates with your existing CE-marking process, and the notified body handling your MDR/IVDR assessment also evaluates AI Act compliance. So you won't need a separate assessment, but you do need the AI-specific documentation: bias testing, model accuracy records, and continuous post-market monitoring.

See the full regulatory overlap mapping
04 / Obligations

What high-risk healthcare AI must do

Each must be in place before December 2, 2027. Non-compliance risks fines up to €15 million or 3% of global turnover.

  1. 01Risk management system (Article 9)
  2. 02Data governance & bias documentation (Article 10)
  3. 03Full Annex IV technical documentation
  4. 04Automatic event logging (Article 12)
  5. 05Transparency & instructions for deployers (Article 13)
  6. 06Human oversight measures (Article 14)
  7. 07Accuracy, robustness & cybersecurity (Article 15)
  8. 08Conformity assessment (Article 43)
  9. 09EU database registration (Article 49)
  10. 10Post-market monitoring (Article 72)
05 / GDPR overlap

Already GDPR compliant?

Healthcare organisations handling patient data under GDPR already run data protection impact assessments and keep processing records. Those partially cover Article 10 (data governance) and Article 9 (risk management). You'll still need AI-specific work: model accuracy and bias testing, conformity assessment, and continuous post-market monitoring.

See the full GDPR overlap mapping

Find out where your healthcare AI stands.

The classifier is free, no account required. Classify your system and start generating the compliance documentation you need.

Classify your AI system