Home › Articles ›  Choosing GDPR-compliant medical AI in 2026: the practitioner's guide
Medical AI

Choosing GDPR-compliant medical AI in 2026: the practitioner's guide

13 May 2026 8 min read Clinovus AI Team

On 12 July 2024, the EU AI Act was published in the Official Journal of the European Union. The countdown has begun: on 2 August 2026, Annex III high-risk AI systems must be fully compliant.[1] AI that is, or is a safety component of, a medical device under the MDR is also high-risk (Art. 6(1)), with obligations from August 2027. A documentation tool that does not diagnose is not automatically high-risk. For the physician, this date is not abstract — it means that using a non-compliant tool engages their professional and potentially criminal liability.

Why ChatGPT is not an option for patient data

GDPR Article 9 classifies health data as a special category of personal data, requiring a reinforced legal basis for any processing.[2] OpenAI is an American company, and the CLOUD Act can compel any American operator to hand over data to federal authorities — including data from European patients. In addition, the consumer version may use conversations for training (unless you opt out) and offers no DPA suited to health data.

What GDPR Art. 9 says

Processing health data is prohibited by default. It is only permitted in limited cases — including "for the purposes of preventive or occupational medicine, for the assessment of the working capacity of an employee, medical diagnosis, the provision of health or social care" — and only by a professional bound by medical secrecy.

The 6 non-negotiable criteria

6 non-negotiable criteria for choosing GDPR-compliant medical AI 1 Hosting in the EU or GDPR adequacy zoneData hosted in the EU, EEA or adequatecountry (Switzerland, UK…) 2 GDPR Art. 9 — health dataLawful processing of sensitive data, legaldocumented basis 3 EU AI Act — risk classificationAI medical device = high risk;human oversight always required 4 DPA signed (Data Processing Agreement)Data processing contract signed with theprovider 5 Encryption in transit and at restCheck what is encrypted (transit, at rest)and who holds the keys 6 No reuse to train the AIYour patient data never serves to improvethe model
6 non-negotiable GDPR criteria for evaluating a medical AI tool in 2026

The CLOUD Act trap: why hosting matters

The CLOUD Act (USA, 2018) allows US federal authorities to demand from any American company the disclosure of data stored abroad — even if servers are physically located in Italy. This covers AWS, Azure, Google Cloud, OpenAI.

A medical AI tool hosted on American infrastructure therefore offers no real GDPR guarantee, even with a DPA. This is why European data protection authorities recommend hosting in the EU, EEA, or countries with an adequacy decision — including Switzerland.[4]

Medical AI hosting: GDPR comparison by provider type ProviderHostingGDPRArt. 9 healthNote ChatGPT / Gemini (consumer)🇺🇸 USA❌ GDPR❌ Art. 9⚠ CLOUD ActEU SaaS (EU servers)🇪🇺 EU✓ GDPR✓ Art. 9✓ MDR readySwiss SaaS (adequacy)🇨🇭 CH✓ GDPR✓ Art. 9✓ nFADP + EU adequacyLocal on-premise🏥 Local✓ GDPR✓ Art. 9⚠ High cost
Medical AI hosting comparison by provider type — GDPR 2026

EU AI Act: what physicians must verify before 2 August 2026

As a deployer under the AI Act — a professional user of an AI system — the physician has specific obligations[6]:

AI Act fines for non-compliance with data governance obligations can reach EUR 15 million. For prohibited practices: EUR 35 million or 7% of global turnover.[3] These amounts primarily target providers — but the deployer's liability is also engaged.

How to verify a tool's compliance in 10 minutes

See also our articles on medical AI liability and on what AI changes for physicians in 2026.

Frequently asked questions

Can a physician use ChatGPT to write medical notes?

No, not with real patient data. ChatGPT (OpenAI) is subject to the American CLOUD Act and its consumer version offers no DPA suited to health data. Health data is sensitive data under GDPR Article 9 — processing it through a non-compliant tool exposes the physician to sanctions from the Italian data protection authority (Garante). The maximum fine for violating Article 9 is EUR 20 million or 4% of global turnover.

What does the EU AI Act concretely change for physicians in 2026?

High-risk AI systems — Annex III systems from 2 August 2026 and AI medical devices (Art. 6(1)) from 2 August 2027; a tool that structures the physician's dictation is not one in itself — must meet strict requirements: transparency on algorithm functioning, mandatory human supervision, decision traceability, and the ability for the physician to override AI recommendations. As a deployer (professional user), the physician is responsible for verifying that the tool they use meets these requirements.

Is Switzerland a GDPR adequacy zone?

Yes. The European Commission has recognised Switzerland as a country providing an adequate level of personal data protection. This means that transferring personal data to Switzerland is permitted without additional safeguards — the same as an intra-EU transfer (Decision 2000/518/EC). The processing itself must still comply with the GDPR and, in Switzerland, with the FADP.

What should a DPA contain for medical AI?

A DPA under Art. 28 GDPR must specify: the nature and purpose of processing, the categories of data processed (including Art. 9 health data), retention periods, technical and organisational security measures, authorised sub-processors, and a commitment not to reuse data for purposes other than the service. For medical AI, the DPA must also specify whether data is used to train or improve the model — which requires specific consent.

What fines does a physician risk for GDPR violations with medical AI?

In Italy, GDPR fines are imposed by the Garante. For violation of Article 9 (health data): up to EUR 20 million or 4% of global turnover. For general obligation breaches: up to EUR 10 million or 2% of turnover. In practice, authorities primarily target companies rather than individual physicians — but the practitioner's liability as 'deployer' under the AI Act is engaged if they knowingly use a non-compliant tool.

Sources and references

  1. Regulation (EU) 2024/1689 (EU AI Act), Art. 6 and Annexes I and III. High-risk application: 2 August 2026 (Annex III), 2 August 2027 (medical devices, Art. 6(1)). eur-lex.europa.eu
  2. Regulation (EU) 2016/679 (GDPR), Art. 9 — Processing of special categories of personal data. eur-lex.europa.eu
  3. Inquira Health (Feb. 2026). The EU AI Regulation and AI in healthcare. Fines up to €35M or 7% of turnover. inquira.health
  4. European Commission. Adequacy decision — Switzerland. Adequate protection level recognised. commission.europa.eu
  5. Garante per la protezione dei dati personali. Decalogue for the implementation of national health services through AI systems. October 2023. garanteprivacy.it
  6. Houdart & Associés (Oct. 2025). AI in healthcare: regulatory framework and practical guides. AI Act Art. 14 — human oversight. houdart.org
Note: this article is for informational purposes. For a legal assessment of your specific situation, consult a lawyer specialising in digital health law.

Clinovus AI: designed around these criteria

Servers in Switzerland (a country with an EU adequacy decision), encryption in transit (TLS 1.3) and at rest, encrypted backups, DPA available; the model provider is contractually committed not to use the data for training. Designed in line with the GDPR and the Swiss FADP.

Try free →
A question about GDPR compliance? Our team replies within 24h.
support@clinovusai.com