Independent EU AI Act information resourceLegal text verified against EUR-Lex

Sector guide

The EU AI Act for healthcare and life sciences

Most clinical AI is high-risk through the product-safety route in Article 6(1), not through Annex III — which means the classification turns on device law rather than on how clinical the use feels. Annex III adds two further hooks for public services and emergency response.

What the Act actually names in this sector

These are the provisions that reach healthcare and life sciences, quoted from the Official Journal. Everything below follows from them.

  • the AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I
    Article 6(1) →
  • AI systems intended to evaluate and classify emergency calls by natural persons or to be used to dispatch, or to establish priority in the dispatching of, emergency first response services
    Annex III, 5(d) →
  • to evaluate the eligibility of natural persons for essential public assistance benefits and services, including healthcare services
    Annex III, 5(a) →

Common use cases, classified

High-risk

Permitted, but carries the full Chapter III obligations: risk management, data governance, documentation, logging, human oversight, accuracy and cybersecurity.

  • Clinical decision support or diagnostic AI

    Where the AI is a safety component of a medical device, or is itself such a device requiring third-party conformity assessment, Article 6(1) makes it high-risk.

    This route depends on the device classification under the medical devices regulation, not on how clinical the use feels.

    Article 6(1) with Annex I →
  • Emergency call triage and dispatch

    Point 5(d) names evaluating and classifying emergency calls and establishing priority in dispatching emergency first response services.

    Annex III, 5(d) →
  • Eligibility for public healthcare or benefits

    Point 5(a) covers systems used by or for public authorities to evaluate eligibility for essential public assistance benefits and services, including healthcare.

    Annex III, 5(a) →

Depends on the detail

The Act does not settle this from the description alone. The note says what decides it.

  • Clinical documentation and administration

    Administrative support is not named in Annex III and is usually not a safety component, so it commonly falls outside the high-risk tiers.

    If output feeds a diagnostic or triage decision rather than a record, assess it as clinical support instead.

    Article 6 →

What gets misread here

Over-classification is the quieter failure: treating something as high-risk when the Act carves it out costs real money and never triggers a complaint, so nobody catches it.

  • “It touches patients, so it is high-risk.”

    The Article 6(1) route depends on whether the product requires third-party conformity assessment under the device legislation in Annex I. Clinical feel is not the test.

    Annex I →
  • “Ambient scribes and coding tools are clinical, so they are caught.”

    Documentation and administration are not named in Annex III and are usually not safety components. The answer changes if the output drives a diagnostic or triage decision rather than a record.

    Article 6 →

Dates that matter in this sector

  • 2 Aug 2028Annex I product-safety high-risk obligations apply — AI systems that are safety components of products already regulated under EU harmonisation law (medical devices, machinery, vehicles, lifts, toys and the rest of Annex I) come into scope on 2 August 2028. (date changed by the Omnibus)
  • 2 Dec 2027Annex III high-risk obligations apply — Providers of Annex III high-risk systems (including AI used in employment, education, credit scoring, life and health insurance pricing, essential services, law enforcement and migration) must meet the full Chapter III requirements from 2 December 2027. (date changed by the Omnibus)

Dates are as amended by the Digital Omnibus. See the full timeline for what each one covers.

What the Commission has said

These guidelines are not binding, but they are the Commission’s own reading of the provisions above, and they are the first place a supervisory authority will look. Where they and this guide differ, follow them.

What to do next

Screen your own systems with the scope finder, run a single system through the risk classifier, or work the obligations in order with the checklist.

This guide points you at the provisions that govern your sector. It is not legal advice, and whether a particular system meets a provision turns on facts about that system and on whether you hold it as provider or deployer — see Article 3 and Article 25.