AI governance for hospitals, medical devices, insurers, and life sciences — under the EU AI Act, MDR/IVDR, and sector clinical safety frameworks.
The regulatory picture
The regulatory landscape for AI in healthcare is distinctive. It is not just the EU AI Act — it is the EU AI Act read together with sector-specific supervision, standards, and case law. A defensible AI compliance posture in this sector engages with all of the following:
- EU AI Act — Annex III covers biometric categorisation, access to essential services (health), and some employment uses. Most clinical AI is regulated in parallel as a medical device.
- EU MDR / IVDR — Software-as-a-medical-device rules for clinical AI. The AI Act sits alongside, not instead of.
- MHRA (UK) — UK medical device regulations, the Software and AI as a Medical Device change programme.
- FDA (US) — The pre-cert pathway and the Good Machine Learning Practice guidance — reference material even for non-US deployments.
- DCB0129 / DCB0160 (NHS) — Clinical safety standards applicable to any organisation deploying AI in NHS care pathways.
- UK GDPR / DSPT / Common Law of Confidentiality — Special-category data, patient consent, and the specific overlay of clinical confidentiality.
Where AI is being used
The AI systems most commonly deployed or being procured in healthcare:
- Diagnostic imaging (radiology, pathology, ophthalmology)
- Clinical decision support at the point of care
- Triage and prioritisation systems
- Patient-facing chatbots and symptom checkers
- Population-health risk stratification
- Drug discovery and clinical trial recruitment
- Administrative and coding automation
Recommended pathway
A six-programme sequence for professionals building AI governance capability specifically for healthcare. Delivered as individual enrolments or as a cohort licence.
Foundations of AI for Non-Technical Professionals
Bring clinical governance, quality, and compliance teams to a common baseline.
EU AI Act Foundations
Understand where the Act applies and where medical device regulation takes over.
EU AI Act — High-Risk Systems
For the AI Act obligations that apply alongside MDR/IVDR.
AI Risk and Assurance
Integrate AI risk with clinical risk management and clinical safety.
AI Incident Response
Because in healthcare an AI incident is often a patient safety incident.
Third-Party AI Risk
For the vendor AI now appearing throughout the EHR, imaging, and admin stack.
A representative scenario
A hospital trust has procured a CE-marked AI radiology triage tool. The vendor is the manufacturer for MDR purposes. The trust is the deployer under the EU AI Act. Clinical safety is governed by DCB0160. The information governance team, the clinical safety officer, and the AI governance lead need a shared framework for what each party is responsible for, where the obligations overlap, and how to evidence compliance without duplicating work. The SAAII Healthcare pathway builds that framework in sequence.
The sector overlay
The Healthcare overlay adds sector-specific worked examples (MDR/AI Act interface, DCB0129/0160 integration, clinical safety officer engagement) and a sector-specific assessment brief to every relevant programme.
Ready to build healthcare AI capability at scale?
Request a briefing to discuss cohort licensing, the sector overlay, and pathway design tailored to your organisation.
Request a briefing → or write to teams@thesaaii.com