AI Act audit for hospitals
AI in a hospital falls into three tracks, each governed by its own framework.
Software that contributes to a diagnostic or treatment decision is generally a medical device. The Medical Devices Regulation applies, with a conformity assessment carried out by a notified body. The EU AI Act applies on top of that, since 2 august 2028.
Systems that prioritise patients for emergency care are listed directly in Annex III. Those obligations apply from 2 december 2027.
Administration, logistics and capacity planning generally fall outside both. What applies there is primarily the AI literacy obligation, in force since 2 February 2025.
The difficulty is that in practice all three tracks sit inside the same electronic patient record.
Clinical or administrative
We establish which applications use data relating to an individual patient to support a care decision, and which only organise the process. That distinction determines whether you fall within the medical devices regime.
We establish the position; we do not assess conformity. That is reserved to a notified body.
Triage and prioritisation
Systems that determine who is seen first warrant separate examination.
We review the basis on which prioritisation is carried out, and whether the clinician in practice has the time and the information to depart from it.
Your role in procured systems
Your electronic patient record, and the AI modules within it, come from suppliers. We determine who is the provider and who is the deployer.
An organisation that puts a system on the market under its own name, or changes its intended purpose, becomes a provider itself — whatever the contract may suggest.
Interaction with existing frameworks
Your institution already works with the GDPR, with patients' rights and with information security standards.
We map where these already providefor what the AI Act requires and where they diverge, so that you do not document the same thing twice
What you receive
An inventory of the AI systems within scope, a qualification for each system, and a prioritised list of the gaps identified. The qualification is the work of the affiliated lawyers, acting in their own name and under their own professional indemnity insurance.
We carry out the audit and compile the report. We do not assess conformity and we do not issue certificates.
After the audit,
Automation
The remediation plan is yours. You can carry it out in-house, with your existing supplier, or with us.
If the audit shows that your AI systems run on US infrastructure and you want that to change, that is a separate question.
That is what we are developing Thor for: a self-hosted environment in which your business data does not leave Europe. Development starts on 1 November 2026 and runs for six months, against thresholds set in advance. It is a separate engagement, not a follow-on from the audit.