By sector · Healthcare and life sciences
AI regulation in healthcare and life sciences
Healthcare AI sits under two regimes at once: medical-device and safety law for the product, and AI and data-protection law for the decision. A diagnostic or triage system is usually high-risk under AI law and a regulated device under health law, so its technical file, clinical evaluation and post-market surveillance have to satisfy both.
- Jurisdictions
- 4
- Evidence items
- 43
One technical file, two regulators
The documentation duties overlap heavily. The controls below are counted by the duties they serve so that the technical documentation and post-market monitoring work can be planned once and cited twice.
Data governance is the hard part
Training data provenance, representativeness across patient groups and lawful basis for health data are where healthcare AI programmes stall. The dataset documentation and privacy controls carry those duties.
Which controls meet these duties?
Sorted by how many of the duties on this page each control satisfies, so the ones worth building first are at the top. A control page lists every other duty it serves, in every jurisdiction.
| Control | Satisfies | Supports | Owner · frequency |
|---|---|---|---|
| AI interaction and use disclosure notices Process | 5 | 0 | Product owner · at launch and on material change |
| AI risk assessment and lifecycle risk register Process | 3 | 1 | AI system owner · once per ai system |
| AI governance policy and accountability structure Policy | 2 | 1 | Executive sponsor for AI · annual |
| Technical documentation, model cards and instructions for use Process | 2 | 1 | Product or model owner · at launch and on material change |
| AI impact and fundamental-rights impact assessment Process | 2 | 0 | AI system owner · once per ai system |
| AI incident management and regulatory reporting Process | 2 | 0 | Incident coordinator · continuous |
| Decision explanation, human review and appeal route Process | 2 | 0 | Customer operations lead · once per ai system |
| Human oversight design and override procedure Process | 1 | 0 | AI system owner · once per ai system |
| AI system inventory and classification Process | 0 | 3 | AI governance lead · continuous |
| Post-deployment monitoring and drift detection Technical measure | 0 | 2 | AI system owner · continuous |
| Privacy and data-protection controls for AI Process | 0 | 1 | Data protection officer · once per ai system |
| Prohibited and unacceptable-use screening gate Process | 0 | 1 | AI governance lead · once per ai system |
| Training-data provenance and copyright register Process | 0 | 1 | Model development lead · at launch and on material change |
| Accuracy, robustness, fairness and security testing Technical measure | 0 | 1 | Quality or testing lead · at launch and on material change |
Which duties are recorded?
Every published duty whose record names this audience. It is the recorded set, not every rule in the world; a jurisdiction missing here may simply not be mapped yet (open gaps).
Colorado (United States) 10 duties
-
Legal requirementColorado AI Act · C.R.S. 6-1-1704applies from 30 Jun 2026Deployers and developers must disclose to consumers that they are interacting with an AI system
-
Legal requirementColorado AI Act · C.R.S. 6-1-1703(3)applies from 30 Jun 2026Deployers must complete impact assessments for high-risk AI
-
Legal requirementColorado AI Act · C.R.S. 6-1-1703(2)applies from 30 Jun 2026Deployers must implement a risk management policy and programme
-
Legal requirementColorado AI Act · C.R.S. 6-1-1703(7)applies from 30 Jun 2026Deployers must notify the Attorney General of discovered algorithmic discrimination
-
Legal requirementColorado AI Act · C.R.S. 6-1-1703(5)applies from 30 Jun 2026Deployers must publish a statement about the high-risk AI systems they use
-
Legal requirementColorado AI Act · C.R.S. 6-1-1703(1)applies from 30 Jun 2026Deployers must use reasonable care to avoid algorithmic discrimination
-
Legal requirementColorado AI Act · C.R.S. 6-1-1702applies from 30 Jun 2026Developers must document high-risk systems and disclose known risks
-
Legal requirementColorado AI Act · C.R.S. 6-1-1702(5)applies from 30 Jun 2026Developers must notify the Attorney General and deployers of discovered algorithmic discrimination
-
Legal requirementColorado AI Act · C.R.S. 6-1-1702(1)applies from 30 Jun 2026Developers must use reasonable care to avoid algorithmic discrimination
-
Legal requirementColorado AI Act · C.R.S. 6-1-1703(4)applies from 30 Jun 2026Notify consumers and explain adverse consequential decisions
European Union 1 duty
-
Legal requirementEU AI Act · Article 50(3)applies from 2 Aug 2026Deployers of emotion recognition or biometric categorisation must inform exposed persons
South Korea 5 duties
-
Legal requirementFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1)applies from 22 Jan 2026Operators of high-impact AI must be able to explain outputs and the main criteria behind them
-
Legal requirementFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1)applies from 22 Jan 2026Operators of high-impact AI must ensure human management and supervision
-
Legal requirementFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1)applies from 22 Jan 2026Operators of high-impact AI must establish and operate a risk management plan
-
Legal requirementFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1)applies from 22 Jan 2026Operators of high-impact AI must prepare user-protection measures and keep records of their safety and trust measures
-
VoluntaryFramework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 35applies from 22 Jan 2026Operators of high-impact AI should assess its impact on fundamental rights before use
Texas (United States) 1 duty
-
Legal requirementTexas Responsible AI Governance Act (TRAIGA) · Business and Commerce Code Section 551.051applies from 1 Jan 2026Health-care providers must disclose the use of AI in patient services
What evidence would a reviewer expect?
- AI data-flow and legal-basis record Register entry
- AI decision challenge and human review procedure Procedure or standard operating process
- AI governance forum minutes Governance meeting record
- AI impact assessment Impact assessment
- AI incident record Incident record
- AI incident response playbook Procedure or standard operating process
- AI intake and classification procedure Procedure or standard operating process
- AI interaction or use notice Disclosure or notice
- AI policy Policy document
- AI responsibility map Register entry
- AI system register Register entry
- AI system risk assessment Risk assessment
- Adverse-decision explanation template Disclosure or notice
- Board or executive approval of the AI policy Approval or sign-off record
- Challenge and reversal log Monitoring record
- Copyright and rights-reservation policy Policy document
- Data protection impact assessment for an AI system Data protection impact assessment
- Human oversight and override procedure Procedure or standard operating process
- Human-involvement design rationale Approval or sign-off record
- Impact assessment approval Approval or sign-off record
- Impact assessment procedure and template Procedure or standard operating process
- Incident report to an authority Regulatory filing or notification
- Independent data audit or DPO review Audit or assurance report
- Instructions for use Disclosure or notice
- Model card or deployer information pack Model documentation
- Monitoring dashboard or periodic monitoring report Monitoring record
- Monitoring review decision Approval or sign-off record
- Notice catalogue Register entry
- Notice wording approval Approval or sign-off record
- Overseer training completion Training record
- Per-system AI risk register Risk register
- Post-market monitoring plan Procedure or standard operating process
- Pre-release test report Evaluation or test report
- Privacy notice section on AI use Disclosure or notice
- Prohibited-use screening record Approval or sign-off record
- Public summary of training content Disclosure or notice
- Release test sign-off Approval or sign-off record
- Residual-risk acceptance Approval or sign-off record
- Risk-tier classification sign-off Approval or sign-off record
- Screening list and escalation procedure Procedure or standard operating process
- Technical documentation file Technical documentation file
- Test plan and acceptance criteria Procedure or standard operating process
- Training source register Register entry
Latest changes to these instruments
Texas TRAIGA takes effect
European Commission proposes Digital Omnibus adjustments to AI Act timelines
Colorado delays the AI Act effective date to 30 June 2026
EU AI Act general-purpose AI, governance and penalty provisions start to apply
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Is clinical decision support high-risk?
- Under several instruments, systems that inform or take decisions about access to health services or that act as safety components of medical devices are high-risk. Check the annex or schedule the duty page cites.
- Which evidence overlaps with device regulation?
- The technical file, clinical or performance evaluation, risk management file, and post-market surveillance records. Keep one set that references both regimes.