Artificial Intelligence (AI) is becoming part of everyday healthcare delivery, from radiology and pathology tools to predictive analytics and patient monitoring. Innovation brings a growing set of regulatory obligations, as the EU Artificial Intelligence Act (AI Act) sits alongside the General Data Protection Regulation (GDPR), medical device rules and product liability legislation. This note sets out the key legal and regulatory developments Luxembourg healthcare operators should be aware of, including topics discussed during 2026 Healthcare Week Luxembourg.
High-risk AI in clinical and diagnostic settings
Many AI tools used for diagnosis, clinical decision support or laboratory analysis are likely to fall within the AI Act's high-risk category. Under Article 6, a system is high-risk where it is a safety component of, or is itself, a product requiring third-party conformity assessment under EU legislation such as the Medical Devices Regulation (MDR) or the In Vitro Diagnostic Regulation (IVDR); a narrower set of Annex III use cases can also apply. In healthcare, high-risk status typically arises through this medical-device route: devices requiring notified-body assessment under the MDR or IVDR. Providers are subject to risk-management, data-governance, accuracy, robustness and cybersecurity requirements. Deployers, including hospitals and clinics, carry human oversight obligations and, where required, a fundamental rights impact assessment before deployment.
The picture has also shifted recently. A December 2025 proposal to move AI-enabled medical devices out of the AI Act's strictest track did not survive negotiations: under the Digital Omnibus on AI (Regulation (EU) 2026/1744), such devices remain fully high risk, though the deadline has moved to 2 August 2028. Luxembourg is also progressing its national AI governance framework. Under bill of law n°8476, currently before the Chambre des Députés, the Luxembourg Agency for Medicines and Health Products (ALMPS) would act as both the notifying authority and the market surveillance authority for high-risk AI systems falling within Article 6(1) of the AI Act in the medical devices and in vitro diagnostic sectors, while the National Commission for Data Protection (CNPD) would serve as the default market surveillance authority and Luxembourg's single point of contact for AI Act matters.
Key data protection considerations
AI governance cannot be separated from data protection. Clinical AI typically involves large volumes of health data, a special category under GDPR, raising several practical points:
- an appropriate lawful basis under Article 9 GDPR, given organisations often rely on bases other than consent for clinical activities, together with Data Protection Impact Assessments (DPIAs) before large-scale processing.
- transparency to patients about how AI contributes to their care, alongside data minimisation built into system design; and
- safeguards under Article 22 GDPR where AI is used in decisions producing legal or similarly significant effects and that article's conditions are met, together with due diligence on how vendors source and secure data.
- The European Health Data Space Regulation adds a further layer on use of electronic health data and its interaction with the AI Act and medical devices framework.
Liability and compliance challenges
Liability exposure for AI-related harm is shifting, but unevenly. Directive (EU) 2024/2853 on defective products, due for transposition by 9 December 2026, confirms software, including AI, is a product for no-fault liability purposes, with AI providers potentially liable as manufacturers. It also eases claimants' evidentiary burden: courts may order disclosure of technical evidence, and causation may be presumed where non-compliance with a safety duty, combined with technical complexity, makes a claim excessively difficult to prove. By contrast, the proposed AI Liability Directive was withdrawn by the European Commission in 2025, after no political agreement could be reached. Operators must navigate liability through the product liability regime, national tort and medical liability law, and contractual risk allocation with vendors.
What does this mean for healthcare operators?
Much of the AI Act addresses providers. But hospitals, laboratories and clinics are deployers, and deployer obligations, though narrower, are still enforceable.
In practice, this means procurement due diligence before signing; human oversight that lets clinicians override a tool's output; clear internal ownership of AI risk rather than splitting it across teams; staff training to spot anomalies and automation bias; and ongoing vendor monitoring as tools are updated.
AI governance is no longer solely a technology issue for healthcare organisations. It is now a regulatory, contractual and clinical governance matter, and those who integrate it into existing compliance frameworks today will be best placed to innovate safely as the framework matures.

_11zon.jpg?crop=300,495&format=webply&auto=webp)



_11zon.jpg?crop=300,495&format=webply&auto=webp)


_11zon.jpg?crop=300,495&format=webply&auto=webp)

_11zon.jpg?crop=300,495&format=webply&auto=webp)







.jpg?crop=300,495&format=webply&auto=webp)
