AIPolicyTracker

By sector · Healthcare and life sciences

AI regulation in healthcare and life sciences

Healthcare AI sits under two regimes at once: medical-device and safety law for the product, and AI and data-protection law for the decision. A diagnostic or triage system is usually high-risk under AI law and a regulated device under health law, so its technical file, clinical evaluation and post-market surveillance have to satisfy both.

Recorded duties
17
16 legally binding
Jurisdictions
4
Controls
14
that meet these duties
Evidence items
43

One technical file, two regulators

The documentation duties overlap heavily. The controls below are counted by the duties they serve so that the technical documentation and post-market monitoring work can be planned once and cited twice.

Data governance is the hard part

Training data provenance, representativeness across patient groups and lawful basis for health data are where healthcare AI programmes stall. The dataset documentation and privacy controls carry those duties.

Which controls meet these duties?

Sorted by how many of the duties on this page each control satisfies, so the ones worth building first are at the top. A control page lists every other duty it serves, in every jurisdiction.

Controls for this audience
ControlSatisfiesSupportsOwner · frequency
AI interaction and use disclosure notices
Process
50Product owner · at launch and on material change
AI risk assessment and lifecycle risk register
Process
31AI system owner · once per ai system
AI governance policy and accountability structure
Policy
21Executive sponsor for AI · annual
Technical documentation, model cards and instructions for use
Process
21Product or model owner · at launch and on material change
AI impact and fundamental-rights impact assessment
Process
20AI system owner · once per ai system
AI incident management and regulatory reporting
Process
20Incident coordinator · continuous
Decision explanation, human review and appeal route
Process
20Customer operations lead · once per ai system
Human oversight design and override procedure
Process
10AI system owner · once per ai system
AI system inventory and classification
Process
03AI governance lead · continuous
Post-deployment monitoring and drift detection
Technical measure
02AI system owner · continuous
Privacy and data-protection controls for AI
Process
01Data protection officer · once per ai system
Prohibited and unacceptable-use screening gate
Process
01AI governance lead · once per ai system
Training-data provenance and copyright register
Process
01Model development lead · at launch and on material change
Accuracy, robustness, fairness and security testing
Technical measure
01Quality or testing lead · at launch and on material change

Which duties are recorded?

Every published duty whose record names this audience. It is the recorded set, not every rule in the world; a jurisdiction missing here may simply not be mapped yet (open gaps).

Colorado (United States) 10 duties

European Union 1 duty

South Korea 5 duties

Texas (United States) 1 duty

What evidence would a reviewer expect?

  • AI data-flow and legal-basis record Register entry
  • AI decision challenge and human review procedure Procedure or standard operating process
  • AI governance forum minutes Governance meeting record
  • AI impact assessment Impact assessment
  • AI incident record Incident record
  • AI incident response playbook Procedure or standard operating process
  • AI intake and classification procedure Procedure or standard operating process
  • AI interaction or use notice Disclosure or notice
  • AI policy Policy document
  • AI responsibility map Register entry
  • AI system register Register entry
  • AI system risk assessment Risk assessment
  • Adverse-decision explanation template Disclosure or notice
  • Board or executive approval of the AI policy Approval or sign-off record
  • Challenge and reversal log Monitoring record
  • Copyright and rights-reservation policy Policy document
  • Data protection impact assessment for an AI system Data protection impact assessment
  • Human oversight and override procedure Procedure or standard operating process
  • Human-involvement design rationale Approval or sign-off record
  • Impact assessment approval Approval or sign-off record
  • Impact assessment procedure and template Procedure or standard operating process
  • Incident report to an authority Regulatory filing or notification
  • Independent data audit or DPO review Audit or assurance report
  • Instructions for use Disclosure or notice
  • Model card or deployer information pack Model documentation
  • Monitoring dashboard or periodic monitoring report Monitoring record
  • Monitoring review decision Approval or sign-off record
  • Notice catalogue Register entry
  • Notice wording approval Approval or sign-off record
  • Overseer training completion Training record
  • Per-system AI risk register Risk register
  • Post-market monitoring plan Procedure or standard operating process
  • Pre-release test report Evaluation or test report
  • Privacy notice section on AI use Disclosure or notice
  • Prohibited-use screening record Approval or sign-off record
  • Public summary of training content Disclosure or notice
  • Release test sign-off Approval or sign-off record
  • Residual-risk acceptance Approval or sign-off record
  • Risk-tier classification sign-off Approval or sign-off record
  • Screening list and escalation procedure Procedure or standard operating process
  • Technical documentation file Technical documentation file
  • Test plan and acceptance criteria Procedure or standard operating process
  • Training source register Register entry

Latest changes to these instruments

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

Is clinical decision support high-risk?
Under several instruments, systems that inform or take decisions about access to health services or that act as safety components of medical devices are high-risk. Check the annex or schedule the duty page cites.
Which evidence overlaps with device regulation?
The technical file, clinical or performance evaluation, risk management file, and post-market surveillance records. Keep one set that references both regimes.