By Rafael Luque Ocaña

Private healthcare: the sector where high risk really is in the core activity — and through two different routes

In most companies, high risk sits in Human Resources. Not in healthcare: there it sits in the consulting room. But it arrives by two paths that get confused — Annex I with its two conditions, and Annex III for emergency triage.

In most organisations, high risk isn't in the business — it's in Human Resources: the AI that decides something about people is the one that screened candidates, not the one that optimises operations.

Private healthcare is one of the exceptions, and it's worth saying plainly: here, high risk is exactly where you'd expect it. In the consulting room.

What almost nobody distinguishes is that it arrives by two different routes, with different requirements, and confusing them leads to misclassification in both directions.

Route 1 — Annex I, which requires two conditions, not one

This is the route for systems built into medical devices. Article 6(1) states that a system is high-risk when it meets both of the following conditions:

"...that AI system shall be considered to be high-risk where both of the following conditions are fulfilled:

(a) the AI system is intended to be used as a safety component of a product, or the AI system is itself a product, covered by the Union harmonisation legislation listed in Annex I;

(b) the product whose safety component pursuant to point (a) is the AI system, or the AI system itself as a product, is required to undergo a third-party conformity assessment, with a view to the placing on the market or the putting into service of that product pursuant to the Union harmonisation legislation listed in Annex I."

"Both," not "either." Both conditions must be met.

The practical consequence is that not all clinical software with AI falls under this route. What does fall under it is software that is — or is part of — a medical device that needs conformity assessment by a notified body. Image-analysis tools that detect and quantify findings usually belong to that group. A support tool that isn't a regulated medical device doesn't.

A practical point that saves arguments: you don't determine that condition. The product's marking and its documentation do. If the manufacturer places it on the market as a medical device with its conformity assessment, the first route is active; if not, you need to look at the second.

Route 2 — Annex III, and here's the surprise

Triage doesn't arrive through Annex I. It arrives through Annex III, point 5(d):

"AI systems intended to evaluate and classify emergency calls by natural persons or to be used to dispatch, or to establish priority in the dispatching of, emergency first response services… as well as of emergency healthcare patient triage systems."

It's a point almost never cited when talking about healthcare, because its heading — "access to essential services" — doesn't sound clinical. And yet there it is: emergency triage is high-risk in its own right, with no need to be a medical device.

Two routes, two criteria, and neither substitutes for the other. A system can enter through the first, through the second, or through neither.

What isn't high-risk, and is often assumed to be

It's worth saying, because the cost of fear is just as real as the cost of carelessness.

AI-assisted clinical documentation — generating the note from the conversation —, appointment management, transcription, the assistant that drafts administrative reports: none of that enters either route on its own. It doesn't decide on access to a service, and it isn't a safety component of a regulated product.

That doesn't leave them without obligations. They process health data — a special category under Article 9 of the GDPR — and often trigger a DPIA through that route, which is separate from AI Act classification and doesn't depend on it. The costliest mistake in this sector isn't over-classifying: it's believing that if something isn't high-risk, there's nothing to do about the data.

And the part it does share with every other sector

This is where this article meets the previous one.

A clinic, a private hospital or a healthcare group also has a people department, and that department uses software to hire and evaluate. Annex III, point 4 applies to it exactly as it does to a logistics company, and for the same reasons.

So in healthcare, it isn't that high risk sits somewhere else. It's that it sits in both places: in clinical activity and in Human Resources. And the second one is the one that gets forgotten, because all the attention goes to the first.

The date, which matters here more than in any other sector

Neither route is in application yet.

The Annex III regime starts on 2 December 2027 — and the date circulating in many guides is a different one. The Annex I regime starts on 2 August 2028. Today, no non-compliance is possible through either one.

This is emphasised here because it's the sector where urgency has most often been used as a sales pitch. Preparing makes sense because of how many systems are involved, not because a deadline is looming.

What is already in force, regardless of classification

The same as for any other organisation: Article 4 on AI literacy and Article 5 on prohibited practices, since 2 February 2025. The first changed wording with the Digital Omnibus without ceasing to bind; the second admits no exception by sector or by size.

With one note that isn't theoretical in healthcare: Article 5 prohibits inferring emotions in the areas of workplace and education institutions, except where the use of the system is intended to be put in place or into the market for medical or safety reasons. A system that analyses the state of staff — not the patient — enters prohibited territory, not high-risk territory. These are different things, and the second one isn't documented: it's discontinued.

Content in accordance with Articles 4, 5 and 6, and Annexes I and III, of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (Official Journal of the EU, 24 July 2026).

This article is for informational purposes only and does not constitute legal advice.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (CIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es). More information in the privacy policy.