By Rafael Luque Ocaña

AI in the dental clinic: where the real risk sits and what to document now

AI-assisted image diagnosis is already routine in many clinics. Understanding why it's classified the way it is — and which obligation lands first — avoids both panic and carelessness.

In many dental clinics, AI is no longer a promise: it's a tool that reads X-rays every day. Systems like Diagnocat, Overjet or Pearl analyse panoramic and CBCT scans to detect cavities, bone loss or periapical lesions. They work, they save time, and they improve detection. And precisely because of what they do and with what data, they place the clinic in one of the most demanding positions under the AI Act. The good news is that the path to governing it well is clear, once the classification is understood correctly.

Why image diagnosis is a serious case

The system that reads an X-ray touches two sensitive things at once: health data — a special category under Article 9 of the GDPR — and a clinical function that supports decisions about the patient. That combination is what raises the bar.

These products also typically carry CE marking as a medical device under Regulation (EU) 2017/745. That detail isn't minor: it determines the route by which the AI Act reaches them.

The classification, precisely

Here it pays to be exact, because it's easy to mislabel the system and, with it, the calendar.

An image-diagnosis system with CE marking enters the AI Act mainly via Annex I (Article 6(1)): AI that forms part of a product already regulated by sectoral legislation and performs a safety function within it. Under the Digital Omnibus, the date of application of high-risk obligations through this route moves to 2 August 2028.

The Annex III route can also apply concurrently if the system influences access to, or prioritisation of, the patient's treatment, with its own calendar (2 December 2027 after the Omnibus).

This precision has an important practical consequence: the FRIA under Article 27 is an Annex III instrument, not an Annex I one. For the purely clinical core of a medical device that enters via Annex I, the FRIA is not the central obligation. Presenting it as mandatory "because you use diagnostic AI" would be a legal error. The obligation that almost always does apply is a different one.

The obligation that lands first: the DPIA

In a dental clinic using diagnostic AI, the data protection impact assessment (DPIA, Article 35 GDPR) is practically universal. The three factors that trigger it all combine: special-category data (health), large-scale processing, and new technology. This is not a future or provisional obligation — it derives from the GDPR, which is fully in force.

A properly done DPIA for this case addresses, at a minimum:

  • Reinforced legal basis under Article 9: typically the healthcare service contract (Article 6(1)(b)) together with the provision of health care (Article 9(2)(h)).
  • International transfers: if the provider processes data outside the European Economic Area — some are US-based — an appropriate mechanism is needed (standard contractual clauses, transfer impact assessment). An EU-based provider simplifies this; one outside the EU doesn't.
  • Retention of images: governed by national and regional health-sector rules, typically between 5 and 15 years.
  • Technical measures: encryption at rest and in transit, pseudonymisation of identifiers in analytics.

Human oversight is not optional

One principle worth remembering: the system supports, it doesn't decide. Human oversight (Article 26(2) for the deployer) means the clinician reviews the system's output and never decides the treatment based solely on the AI's output. A false negative from the system cannot become a clinical decision without human judgement in between. And it's worth having a written procedure for what to do when a result is anomalous.

And the rest of the clinic's stack

Not everything in a clinic is high-risk diagnosis. The typical inventory includes lower-exposure systems that also need classifying:

  • Appointment-booking chatbot: interacts with patients, so Article 50(1) transparency applies from 2 August 2026 — an obligation of the provider (the system must be designed so patients know they're talking to an AI); as deployer, the clinic checks that its provider has it in place. If the chatbot gets into symptoms or medical guidance, the risk level rises and a DPIA may be required.
  • No-show prediction and schedule optimisation: normally limited risk. Watch out if the system ends up discriminating against patients (for example, denying appointments to those it "predicts" will not show up): that's where Article 22 GDPR issues appear.
  • Office productivity copilots for administrative tasks: general-purpose, low risk, but they still count for the inventory and for Article 4 training.

What to do now, without drama

The message for a clinic isn't alarm; it's order. With the Omnibus, high-risk obligations via the medical-device route have runway until 2028. But there are three things worth closing now:

  1. A complete inventory of every AI system in the clinic — including those at different sites, which often run different software.
  2. A DPIA for image diagnosis and for any other processing that requires one. This is the real, present obligation.
  3. Training and a use policy for clinical staff (Article 4), with traceable evidence.

Getting this right isn't about buying peace of mind or displaying a seal. It's about having documentation that's reviewed, auditable, and ready to defend — with substance — that the clinic uses AI as it should.

Mentions of commercial products are descriptive of the market and do not imply any commercial relationship. This article is for informational purposes only and does not constitute legal advice.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (CIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es). More information in the privacy policy.