Shaping the Future of AI in EU Healthcare 

DG SANTE was delighted to be part of yesterday’s landmark event on AI readiness in EU health systems, co-organised by the Commission and WHO Regional Office for Europe. 

 

Director Marco Marsella and Head of Unit for Digital Health Fulvia Raffaelli joined policymakers, experts and Member States to discuss this important topic. 

 

The discussions were timely, urgent, and solution-focused - how can the EU harness AI’s transformative potential while ensuring readiness, equity, and ethical implementation? 

 

AI is already delivering - from administrative automation reducing clinician burnout to AI-assisted diagnostics cutting wait times. Yet, only 43% of healthcare professionals report real-world use. The deployment gap is real. 

 

The EU is leading the way in ethical AI governance, but implementation is key: 

🔸 Regulatory frameworks like the AI Act and GDPR provide a solid backbone, but we need real-world monitoring to track performance, bias, and harm. 

🔸 AI is a multidisciplinary effort, but implementation within healthcare requires the unique expertise of its context. 

 

Moving forward, the event underscored the need for: 

🔸Systemic frameworks - including monitoring real-world impact. 

🔸Anticipating future needs together with the Member States. 

🔸Platforms for sharing best practices to avoid duplication and foster innovation.

who PICTURE 1
who PICTURE 2
Clibeanna
healthcare and pharma ai innovation

Tráchtanna

Profile picture for user n00kw9t7
Curtha isteach ag Ahmad Hasan an Sat, 11/07/2026 - 13:55

The EU AI Act (Regulation EU 2024/1689) is now progressively binding, yet corporate compliance is still demonstrated primarily through self-assessment reports and paper files. Regulatory authorities have no independent technical means to verify these claims, and cannot access corporate environments directly due to trade secrecy and data protection constraints.

This is the gap I have been working on: translating binding legal obligations into technical requirements that can be verified without requiring companies to disclose trade secrets or regulators to access internal systems directly.

The approach covers the provisions of the Act that speak directly to a technical system rather than to institutional or administrative processes: Article 5 (prohibited practices), Articles 9 through 15 (high-risk system requirements), Article 50 (transparency), and Articles 53 and 55 (GPAI obligations).

Each provision is translated through a shared four-layer technical architecture:

- An interception layer positioned between the system and the user, inspecting outputs before they are delivered

- A rule engine converting each legal requirement into an executable trigger-predicate-enforcement structure

- A behavioral monitor tracking patterns over time rather than single events

- An immutable, hash-chained audit log with automatic alerting to the competent authority upon violation, without disclosing underlying data content

The methodology is grounded in internationally peer-reviewed academic literature and recognized standards (ISO, NIST, IEEE, ACM), with every technical claim traceable to a specific reference. It is jurisdiction-agnostic by design and does not constitute a legal instrument — it is a technical research framework intended for review and validation by qualified engineers, security specialists, and legal experts before any practical deployment.

I am glad to discuss the framework, its scope, or specific provisions with anyone working on the same problem.