Healthcare AI Learning
Back to Cases

Lab · Module 9

Regulatory Classification Lab

Three proposals arrive in the same governance meeting. They use similar underlying technology and land in completely different places. The skill being practised is routing: asking the right questions in the right order, and knowing which specialist owns each answer.

Situation

You chair the AI governance group of a hospital group in an EU member state. Three proposals are on the agenda and each sponsor wants a decision today.

You are not the regulatory specialist and you are not going to classify anything definitively in this room. What you can do is establish the intended purpose and claims for each proposal, separate the different legal questions so they are not collapsed into one argument, and assign a named owner and a reassessment trigger to each.

Fictional proposals in a teaching scenario. This lab is educational guidance on how to route the questions — it is not legal or regulatory advice, and any real classification must be made with qualified regulatory and data-protection advice against the law in force at the time.

The evidence in front of you

Proposal A — ambient documentation support

Records the consultation and drafts a note that the clinician edits and signs. Vendor markets it as a documentation efficiency tool and makes no diagnostic or triage claim.

The routing question is the stated intended purpose and function: is it presented and designed as an administrative drafting aid, or does it interpret findings and offer clinical conclusions? Ambient documentation tools are not automatically medical devices, and they are not automatically outside device law either — it depends on intended purpose, function and the claims made. It plainly processes special-category health data, and consultation audio raises its own questions.

Proposal B — prognostic deterioration score

Predicts risk of clinical deterioration in the next 24 hours and drives an escalation alert to the outreach team.

This one gives information used for clinical decision-making about an individual patient. That is the characteristic that pulls a tool towards medical-device territory and towards the stricter end of AI Act obligations — but the classification still turns on the stated intended purpose and the applicable rules, not on the fact that it is a model.

Proposal C — internal policy assistant

Answers staff questions about internal HR, procurement and infection-control policies from an internal document library. No patient data in scope.

No clinical purpose and no patient-level personal data means the medical-device question is unlikely to be live and the data-protection question is largely about staff data and internal confidentiality. It is not unregulated — internal information governance, procurement and staff-data obligations still apply — but it does not belong in the same queue as A and B.

The claims file

Two of the three vendors have marketing material that goes further than their formal intended-purpose statement.

What a product claims it does is part of what determines how it is regulated. A tool marketed as identifying deteriorating patients cannot be governed as though it merely displays data, whatever the specification document says.

Who is in the room

Clinical safety officer, data protection officer, procurement lead, a regulatory adviser available on request, and the three sponsors.

The failure mode of governance groups is a single collective opinion with no named owner. Each legal question has a different owner and a different escalation route.

Your decisions

Decision 1. What does the group establish first, for all three proposals?
Decision 2. Proposal A's sponsor argues: 'It is only a scribe, so no device rules and no AI Act obligations apply.' How do you route this?
Decision 3. How does each proposal leave the meeting?

You can change any answer until you confirm.

The routing tree behind these decisions

The same tree used in Module 9. Work each proposal through it from its stated intended purpose. Dates are the applicable dates taught in the module; this is educational guidance, not legal or regulatory advice.

Regulatory routing tree from intended purposeA decision tree starting from the stated intended purpose and claims. Branch A: the product is a medical device or in vitro diagnostic, or AI is a safety component of a product covered by Annex I, and that product also requires third-party conformity assessment. MDR and IVDR apply now. AI Act high-risk duties on that route apply from 2 August 2028 only when both Article 6(1) conditions hold; a self-certified class I device does not meet the second condition and does not become high-risk by this route. Branch B: a use listed in Annex III — AI Act high-risk obligations apply from 2 December 2027. Branch C: systems that interact with people or generate content — AI Act general and transparency obligations apply from 2 August 2026. Branch D: none of these AI Act categories, which does not mean no other obligations, since GDPR, clinical safety, professional duties and procurement still apply.Start: stated intended purpose & claimsNot the technology — what the product says it does, and for whomA.
Is it a medical device or in vitro diagnostic — or AI as a safety component of a product already covered by Annex I — AND does that product require third-party conformity assessment?
Outcome A

MDR / IVDR applies now: intended purpose, conformity assessment, post-market surveillance.

AI Act high-risk duties on the Annex I route apply from 2 August 2028 — but only if BOTH Article 6(1) conditions hold. A self-certified class I device does not meet the second condition and does not become high-risk by this route.

B.
Is the use listed as high-risk in Annex III — for example triage of emergency patients, or access to essential services?
Outcome B

AI Act Annex III high-risk obligations apply from 2 December 2027.

Risk management, data governance, logging, human oversight, technical documentation.

C.
Does it interact with people, or generate or manipulate content, without meeting A or B?
Outcome C

AI Act general and transparency obligations apply from 2 August 2026.

People must be told they are dealing with an AI system; generated content is disclosed.

D.
None of these AI Act categories fits the intended purpose.
Outcome D

Not an AI Act high-risk or transparency case — this does not mean no obligations.

GDPR, clinical safety, professional duties, procurement and information governance still apply.