Regulation, Governance & ComplianceNazeeha Hasan-Rao

What the EU AI Act Means for Digital Health

If your digital health product uses AI, the EU AI Act is the piece of regulation most likely to shape how you build and sell over the next few years. And if you're UK-based and thinking "that's an EU problem" — it probably isn't, and that's the first thing worth clearing up.

Let me walk through what the Act actually does, why healthcare AI tends to land in its strictest category, what the obligations look like in practice, and what to do about it now. I'll keep to what's well established and flag anything uncertain rather than inventing specifics.

What does the EU AI Act actually do?

The EU AI Act is the first comprehensive law governing artificial intelligence, and it works by classifying AI systems according to risk. The more a system can affect people's safety or fundamental rights, the more obligations it carries.

There are broadly four tiers: unacceptable-risk systems that are banned outright, high-risk systems that carry the heaviest compliance load, limited-risk systems with transparency duties, and minimal-risk systems with little to no obligation. The Act entered into force in August 2024, and its obligations phase in over the following years, with the high-risk requirements arriving on the later end of that phase-in. The exact dates have moved and been debated, so check the current timeline rather than relying on any single month-and-year claim — including one you might read here.

For digital health, almost all the action is in one tier: high-risk.

Why does most healthcare AI count as high-risk?

Because Annex III of the Act lists the contexts that make a system high-risk, and healthcare use cases keep landing squarely inside it. A high-risk AI system is one used where it could materially affect people's safety or fundamental rights — and decisions about diagnosis, triage, access to care or clinical workflow do exactly that.

If your AI helps decide who gets seen first, flags a possible diagnosis, prioritises a waiting list, or influences a clinician's decision, you should assume you're in high-risk territory. AI that qualifies as, or is a safety component of, a medical device brings a further layer under existing device rules on top.

The practical takeaway: for most digital health teams, the question isn't "are we high-risk?" but "how do we meet high-risk obligations without it swallowing the roadmap?"

What do high-risk obligations look like in practice?

They come down to proving your system is safe, well-governed and kept that way — with evidence, not assurances. The core obligations for high-risk systems include:

  • Risk management. A continuous process to identify, evaluate and mitigate risks across the system's lifecycle — not a one-off document at launch.
  • Data governance. Training, validation and testing data that's relevant, representative and appropriately managed, with attention to bias. In healthcare, where data gaps translate into unequal care, this matters more, not less.
  • Technical documentation. Detailed records of how the system was built, what it does, and how it meets requirements — the file an auditor or regulator will ask to see.
  • Human oversight. Real mechanisms that keep a human meaningfully in control, not rubber-stamping outputs under time pressure. Overstretched clinical teams are exactly where automation bias creeps in, so oversight has to be designed, not assumed.
  • Accuracy and robustness. The system has to perform reliably, resist manipulation, and behave predictably — and you have to be able to show it does.

None of these are exotic. They're the disciplined version of what a responsible health tech team already wants to be doing. The Act just makes them mandatory and evidenced.

Does the EU AI Act apply to UK companies?

Yes — the Act has extraterritorial reach, and this is the point UK founders most often miss. It applies based on where your AI is used, not where your company sits. If your system touches EU patients, EU markets, or produces outputs used in the EU, it applies to you regardless of your UK base.

So a UK digital health company selling a triage tool into a German hospital, or offering a diagnostic aid to clinicians treating EU patients, is inside scope. Post-Brexit geography doesn't get you out of it. If Europe is a market you're in or planning to enter, plan for the Act now, because retrofitting compliance to win a deal you've already lost time on is the expensive route. This is a large part of the healthcare AI governance consulting work I do with UK-based teams selling into Europe.

It's also worth remembering that EU AI Act obligations sit alongside, not instead of, your UK data protection duties. If you want the data protection side, I've written separately on why your GDPR setup is probably out of date — the two regimes overlap heavily for anyone using AI on personal data.

How does ISO 42001 fit in?

ISO/IEC 42001 is likely to be the most practical route to demonstrating conformity — though this is hedged, not yet final. ISO/IEC 42001:2023 is the international standard for AI management systems, and it's expected to be designated as a harmonised standard under the EU AI Act. If that designation lands, certification against it would become the primary conformity route for most Annex III high-risk systems.

In plain terms: rather than assembling a bespoke compliance case from scratch, you'd build your governance to a recognised standard and certify against it. That's why the standard the market is converging on is worth understanding early. I've written a founder-level explainer on ISO 42001 for healthcare if you want the detail on what the standard actually involves.

The honest caveat: "expected to be designated" is not "designated". But building toward 42001 is a low-regret move — the underlying governance work is required either way, and doing it against a recognised framework makes it reusable and defensible. Getting that framework in place early is the heart of my AI implementation and governance work.

What should digital health teams do now?

Start by working out where you stand, then close the gaps that carry the most risk. A sensible order:

  • Confirm your classification. Assume high-risk if your AI influences clinical decisions, triage or access to care — and check whether medical device rules also apply.
  • Check your market reach. If you sell into the EU or plan to, treat the Act as in scope now, not later.
  • Inventory your AI and assess the highest-stakes systems first — you can't govern what you haven't listed.
  • Build the management system the obligations require: risk management, data governance, documentation, human oversight, monitoring — ideally mapped to ISO/IEC 42001 so it's reusable for conformity.
  • Check the current timeline for the obligations that affect you, and work back from there rather than from a date you half-remember.

If you'd like a concrete starting structure, I've turned all of this into an AI governance checklist for clinics and health tech you can work through.

You don't have to solve the whole Act this quarter. But if you sell health tech into Europe, you do need to know you're in scope — and start the governance work while it's cheap.

Wondering if the EU AI Act applies to you?

If you sell health tech into Europe — or plan to — the EU AI Act almost certainly reaches you, even from the UK. The good news is that most of the work is the same work you'd want to do anyway. If you'd like to know where you stand and what to prioritise, let's have a conversation about your AI governance readiness.

Book a conversationAI governance services