Blog
CyberbezpieczeństwoGuide

EU AI Act in Healthcare — What Clinicians and Practice Owners Must Know

The AI Act is changing the rules for AI use in the clinic. We explain practice obligations, fines up to €15 million and why using free ChatGPT for notes is a very costly shortcut.

By Cora AI Team6 June 202611 min read

The AI Act is now in force and is reshaping the rules for every medical facility in the EU. If a physician pastes a visit transcript into the free version of ChatGPT, the facility is already violating several layers of regulations at once. We explain exactly what the AI Act says about the use of artificial intelligence in healthcare, what risks hospitals and clinics are taking on, and why using only proven, purpose-built tools is the only sensible path.

€15 m

maximum fine under the AI Act for violations relating to high-risk systems

€20 m

maximum fine under GDPR for unlawful processing of medical data

3%

of global annual turnover — alternative fine threshold under the AI Act

6 months

minimum log retention period for a high-risk AI system

What is the AI Act and why it applies to every medical facility

The AI Act (Regulation 2024/1689) is the world's first comprehensive law regulating artificial intelligence. It adopts a risk-based approach — the greater the impact of an AI system on human health, rights and safety, the stricter the obligations. Healthcare was placed squarely in the category of high-risk systems.

Importantly, the AI Act does not regulate only model developers. It also covers so-called deployers — every facility that uses an AI system in its operations. A hospital, clinic or private practice in which a physician uses AI for documentation or clinical decision support becomes a responsible party before supervisory authorities.

When AI becomes a "high-risk system"

The AI Act — in Annex III and in conjunction with the Medical Device Regulation (MDR) — clearly identifies AI systems used for:

  • supporting diagnosis and triage,
  • analysing patient health data,
  • generating medical documentation,
  • assessing clinical risk or prioritising care,
  • monitoring vital signs,

— as high-risk systems. It makes no difference whether the physician "only copied a snippet of the conversation into ChatGPT." What matters is the purpose of processing and the medical context.

The most common misinterpretation
"It's just a general chatbot, not a medical device." Under the AI Act, what determines classification is the manner of use, not the manufacturer's marketing. Generating visit notes from patient data is a medical use case — regardless of which tool was used to do it.

Obligations of a facility that uses AI in healthcare

A deployer of a high-risk AI system must fulfil a set of binding obligations under Article 26 of the AI Act. The most important are:

  1. Human oversight — a designated, qualified person responsible for monitoring the system's operation.
  2. Log retention for at least 6 months, in a form that enables auditing.
  3. Informing patients that AI was used in the diagnostic or therapeutic process.
  4. Fundamental Rights Impact Assessment (FRIA) for public bodies and certain private entities.
  5. Use only CE-marked systems entered in the EU database.
  6. Compliance with the instructions for use provided by the supplier and incident monitoring.

Building this compliance layer around the free version of ChatGPT is practically impossible — because a consumer-grade LLM supplies neither logs, nor compliance documentation, nor a data processing agreement, nor any guarantee of where data is processed.

The AI Act does not replace GDPR — it operates alongside it

Many facility managers ask: "If we have GDPR, what do we need the AI Act for?" The answer is straightforward — both regimes apply in parallel and their sanctions are cumulative. Entering a visit transcript into the consumer version of ChatGPT, Claude or Gemini simultaneously causes:

  • a breach of medical confidentiality (professional secrecy obligations),
  • unauthorised transfer of special-category data outside the EEA (Articles 9 and 44 of GDPR),
  • absence of a data processing agreement with the processor (Article 28 of GDPR),
  • breach of AI Act obligations relating to high-risk systems,
  • in some configurations — use of patient data to train models.
Default settings of consumer AI
In the free and most standard versions of ChatGPT (Plus), Claude or Gemini, input data is used by default to train models and stored by providers for up to 5 years. This means that a snippet of a patient visit transcript enters a dataset over which the facility has no further access or control.

Real financial penalties

€15 m

or 3% of turnover — AI Act fine for violations relating to high-risk systems

€20 m

or 4% of turnover — GDPR fine for unlawful processing of medical data

€35 m

or 7% of turnover — maximum AI Act fine for prohibited practices

Civil penalties also apply (patient claims), as well as professional liability for physicians and the risk of losing public health insurance contracts in the event of serious incidents. For many facilities, a single fine close to the maximum would mean the end of the business.

Why "free ChatGPT for notes" is an extremely costly saving

The most common objection from managers is: "Why do we need a dedicated assistant if physicians can paste the transcript into ChatGPT and get a note for free?" From an AI Act and GDPR perspective, this saving is illusory for at least three reasons.

1. Non-compliance = exposure to fines of up to €15 million

Using a general-purpose LLM for medical purposes immediately brings the facility into the high-risk system regime — without satisfying any of the AI Act's requirements. This constitutes open exposure to fines, investigations and the loss of operating licences.

2. Leakage of medical data and breach of medical confidentiality

Patient data entered into a consumer-grade ChatGPT leaves the EEA (typically ending up in the United States), is stored for up to 5 years and may be used to train models. This is a textbook violation of Article 9 of GDPR and of professional medical secrecy obligations.

3. No logs, no oversight, no documentation = no auditability

The AI Act requires the facility to be able to demonstrate who used the AI system, when and how. ChatGPT accessed through a physician's personal account generates no such logs. In the event of an inspection, the facility has nothing to defend itself with.

AI systems used in healthcare should be designed and deployed in a manner that ensures an appropriate level of transparency, human oversight and accountability to patients."
Legal commentary on the AI Act, Recital 58

Consumer LLM vs purpose-built medical assistant

AI Act / GDPR requirementFree ChatGPT / ClaudePurpose-built medical assistant (e.g. Cora AI)
Data processing locationTypically USA, outside the EEAEEA only, in certified data centres
Data processing agreement (DPA)Absent or limited, does not cover medical dataFull DPA signed with the facility
Training the model on patient dataYes by default (free/Plus)Never — contractual guarantee
Logs and auditabilityNone on the facility's sideFull event logs, exportable for auditors
Human oversightUndefinedPhysician authorises every entry
AI Act compliance documentationNoneProvided together with the system
Status in the event of an inspectionMultiple regulatory violationsCompliance demonstrable by documentation

Why only verified, proven sources should be used

Artificial intelligence in healthcare is not "just another office tool." It is a technology that touches the most sensitive data in the entire economy — data about human health. For that reason, the choice of tool should be a deliberate management decision based on verifiable criteria, not on a physician's familiarity with a free consumer application.

A verified source is a supplier that:

  • is a European entity subject to the AI Act and GDPR,
  • processes data exclusively within the EEA,
  • signs a data processing agreement covering health data,
  • does not train models on patient data,
  • provides full system logs and compliance documentation,
  • designs the interface so that the physician remains the decision-maker (human-in-the-loop),
  • publishes a security policy and undergoes independent audits.
A practical rule for the facility manager
If a supplier cannot answer — in a single document — the questions: where is the data, who can see it, for how long, who logs events and whether it is used for training — that supplier should not be trusted with medical documentation.

How Cora AI addresses AI Act requirements

Cora AI was designed from the ground up as a dedicated medical assistant for the European market. This translates into specific technical and legal decisions that deliver regulatory compliance for the facility:

  • EEA-only data processing — no transfers outside the EU.
  • No training of models on patient data — guaranteed contractually.
  • Full data processing agreement (DPA) covering special-category data.
  • Complete system logs satisfying the 6-month retention requirement under the AI Act.
  • Human-in-the-loop — every entry requires physician authorisation.
  • Ready-made compliance documentation to hand over to the DPO and supervisory authorities.

In practice, this means that a facility using Cora AI does not have to build compliance on its own — it comes bundled with the tool.

Checklist for the facility manager

Before your physicians begin using any AI tool to work with patient data, verify:

  1. Does the supplier sign a data processing agreement covering medical data?
  2. Where is the data physically processed — is it exclusively within the EEA?
  3. Is input data used to train models?
  4. How long are transcripts and recordings retained?
  5. Does the system log events, and are those logs available to an auditor?
  6. Is there ready-made AI Act compliance documentation available for handover?
  7. Does the interface require physician authorisation for every entry?
  8. Does the facility have an internal "AI Policy" and a designated AI supervisor?

If the answer to any of these questions is "I don't know" or "no," the tool should not be used in patient care.

Summary

The AI Act is not an abstract regulation from Brussels. It changes the practice of every clinic in which a physician reaches for AI to document patient visits. Using free, consumer-grade models means exposure to fines of up to €15 million under the AI Act, up to €20 million under GDPR, and professional liability.

Safe use of AI in healthcare is possible — provided the tool was designed with these requirements in mind. A verified, purpose-built medical assistant takes the compliance burden off the facility and lets the team focus on the patient rather than on legal risk.

FAQ — AI Act in healthcare

Can a physician use free ChatGPT to create visit notes?+
Practically, no. Entering a visit transcript, symptoms or diagnosis into the consumer version of ChatGPT, Claude or Gemini means transferring sensitive medical data outside the EEA, typically with input data used to train models by default. This simultaneously violates GDPR, medical confidentiality obligations, and the AI Act requirements for high-risk systems.
Does the AI Act apply to small clinics and private practices?+
Yes. The AI Act grants no exemption for smaller entities. Every facility that deploys an AI system to support diagnosis, medical documentation or clinical decision-making becomes a deployer and bears responsibility for compliance, human oversight, logging and patient notification.
What are the penalties for non-compliant use of AI in healthcare?+
The AI Act provides for fines of up to €15 million or 3% of global annual turnover for violations of obligations relating to high-risk systems. GDPR penalties apply in parallel — up to €20 million or 4% of turnover — for unlawful processing of health data.
Is a note generated by ChatGPT considered medical documentation?+
If it is inserted into the patient record, then yes — it becomes part of the record and is subject to the same requirements: integrity, authorisation, 20-year retention and auditability. Generating it with a tool that produces no event logs and provides no data processing agreement means the documentation is formally defective.
What distinguishes a certified medical AI assistant from a general-purpose LLM?+
A dedicated tool includes a data processing agreement (DPA), processes data within the EEA, does not train models on patient data, maintains full logs, has physician oversight mechanisms built in, and provides the compliance documentation required by the AI Act. Consumer-grade ChatGPT provides none of these as standard.
Is patient consent to recording sufficient to use ChatGPT?+
No. Patient consent does not cure the absence of a legal basis for data transfers outside the EEA, the absence of a DPA, the absence of logs, or the absence of the mechanisms required by the AI Act for high-risk systems. A patient also cannot effectively consent to their medical data being used to train a third party's model.
Can a physician use free ChatGPT to create visit notes?+
Practically, no. Entering a visit transcript, symptoms or diagnosis into the consumer version of ChatGPT, Claude or Gemini means transferring sensitive medical data outside the EEA, typically with input data used to train models by default. This simultaneously violates GDPR, medical confidentiality obligations, and the AI Act requirements for high-risk systems.
Does the AI Act apply to small clinics and private practices?+
Yes. The AI Act grants no exemption for smaller entities. Every facility that deploys an AI system to support diagnosis, medical documentation or clinical decision-making becomes a deployer and bears responsibility for compliance, human oversight, logging and patient notification.
What are the penalties for non-compliant use of AI in healthcare?+
The AI Act provides for fines of up to €15 million or 3% of global annual turnover for violations of obligations relating to high-risk systems. GDPR penalties apply in parallel — up to €20 million or 4% of turnover — for unlawful processing of health data.
Is a note generated by ChatGPT considered medical documentation?+
If it is inserted into the patient record, then yes — it becomes part of the record and is subject to the same requirements: integrity, authorisation, 20-year retention and auditability. Generating it with a tool that produces no event logs and provides no data processing agreement means the documentation is formally defective.
What distinguishes a certified medical AI assistant from a general-purpose LLM?+
A dedicated tool includes a data processing agreement (DPA), processes data within the EEA, does not train models on patient data, maintains full logs, has physician oversight mechanisms built in, and provides the compliance documentation required by the AI Act. Consumer-grade ChatGPT provides none of these as standard.
Is patient consent to recording sufficient to use ChatGPT?+
No. Patient consent does not cure the absence of a legal basis for data transfers outside the EEA, the absence of a DPA, the absence of logs, or the absence of the mechanisms required by the AI Act for high-risk systems. A patient also cannot effectively consent to their medical data being used to train a third party's model.

Related articles