On 7 April 2026, Medscape asked directly: "Medical errors involving AI: who is responsible?" That same week, the French Académie nationale de médecine published a reference report on the subject.[1] The legal answer is becoming clearer — and it directly concerns every physician using AI software.
Signed on 13 June 2024, the EU AI Act is the world's first dedicated AI legal framework.[2] It introduces two key actors:
The EU AI Act does not create liability for AI as an autonomous entity. Liability remains human — shared between provider and deployer depending on the nature of the failure.[2]
Position of the Académie nationale de médecine (2026)
The healthcare professional is the last link in the chain. Their liability can only be engaged if they made an error in using the AI — particularly by not validating outputs or by using an inappropriate tool. The duty of care remains the standard and now includes verifying AI recommendations.[1]
The AI provider is liable if the harm arises from an intrinsic system defect: biased algorithm, inadequate training data, software bug, absent clinical validation.
A microeconomic study published in February 2026 demonstrates that full physician liability is the most effective regime for incentivising providers to improve tool quality: a fully exposed physician is willing to pay more for a more reliable AI, creating positive pressure on the industry.[3]
Validating an AI output does not mean simply reading it. It means:
See also our articles on GDPR and medical AI in Italy.
Can a physician be held liable for an error made by AI?
Yes. Under Italian law (Law 24/2017, Gelli-Bianco) and EU law, the physician remains responsible for the final medical act, regardless of the technology used. The EU AI Act distinguishes between the provider (developer) and the deployer (physician/institution), but clinical responsibility always falls on the practitioner. Using AI outputs without validation exposes the physician to negligence liability.
Does the EU AI Act apply to physicians in Italy?
Yes, directly: a physician using an AI system professionally is a "deployer" under the Act, whatever the provider's country.
What is a class IIa or IIb medical device?
MDR classification of medical devices determines the risk level. Software supporting diagnostic or therapeutic decisions is a medical device (MDR, Rule 11, at least Class IIa; Class IIb if a wrong decision could cause a serious deterioration of health) and requires CE marking before being placed on the market in Italy. A tool that only supports documentation or administration is not a medical device.
How can a physician protect themselves legally when using AI?
Four concrete measures: (1) systematically validate every AI output before any clinical use — never copy-paste without review; (2) use only tools with a clear data processing agreement; (3) document AI use in the patient record if it influenced a decision; (4) choose tools designed for medical validation, not consumer products.
Every document is structured from your dictation, for you to review and sign. The physician decides. Hosted in Switzerland.
Try free →