Governing medical AI under the EU AI Act: an integrated compliance-by-design framework.
Authors
Affiliations (1)
Affiliations (1)
- Empirical Software Engineering in Software, Systems and Services (M3S), Faculty of Information Technology and Electrical Engineering, University of Oulu, Oulu, Finland.
Abstract
Artificial intelligence (AI) is becoming an increasingly important component of healthcare, supporting diagnosis, clinical decision-making, medical imaging, triage, and patient-facing services. While these technologies offer significant opportunities to improve healthcare delivery, they also raise important questions about patient safety, fairness, privacy, transparency, cybersecurity, and accountability. This paper examines the regulatory framework governing medical AI in the European Union, focusing on the interaction between the Artificial Intelligence Act (AI Act), the Medical Device Regulation (MDR), the In Vitro Diagnostic Medical Device Regulation (IVDR), the General Data Protection Regulation (GDPR), and the European Health Data Space (EHDS). Drawing on doctrinal and conceptual regulatory analysis, it argues that many AI-enabled medical systems should be regulated through continuous lifecycle compliance rather than by relying primarily on a one-time assessment at market entry. The analysis identifies the training and validation dataset as a particularly important point of regulatory convergence, especially among the EHDS, GDPR, and AI Act data-governance requirements, and examines how responsibility is allocated across the general-purpose AI value chain under Article 25. Building on this analysis, the paper proposes a compliance-by-design framework that translates overlapping legal requirements into a set of auditable governance artefacts covering system classification, regulatory mapping, data governance, validation, human oversight, conformity assessment, post-market monitoring, and change control. The framework is illustrated through two contested use cases and complemented by recommendations tailored to the responsibilities of different stakeholder groups. The analysis incorporates Regulation (EU) 2026/1744 (Digital Omnibus on AI), while recognising that supporting guidance, harmonised standards, and implementation of the EHDS continue to evolve and should be checked when the framework is applied. The framework is conceptually derived and illustrated through constructed use cases rather than empirically validated; future work should assess its usability, consistency, and discriminating power through structured expert assessment and Delphi-based consensus methods.