The EU AI Act risks producing trust paperwork, not trust outcomes. Healthcare will feel it first
A new wave of analysis around the EU AI Act is landing on the same uncomfortable conclusion: the law can generate process without generating control. In healthcare, that gap becomes dangerous because ‘trust’ is not a branding exercise. It is a question of evidence when systems shape diagnosis, triage, and care pathways.
The failure mode is familiar. Add another code, another assessment, another set of principles, and call it governance. Meanwhile, the operational questions remain unanswered: what was the model asked to do, what data shaped the output, what changed since last validation, and who has the authority to stop it?
Voluntary codes and high-level rights language do not solve that. They can even slow real accountability by creating the impression that something meaningful has been implemented. A system can be ‘compliant’ on paper while still being impossible to audit, explain, or contest when it matters.
If trust is the goal, the route is boring. Make claims testable. Make logs reproducible. Make oversight real. Without that, the EU AI Act risks becoming a factory for documentation, not a scaffold for safer outcomes.
We'd like your views:
- What evidence should be required before AI influences clinical decisions or pathways?
- Are voluntary codes ever sufficient for high-stakes AI, or do they always become theatre?
- Who should be accountable when a hospital deploys a third-party model that later fails?
- What is a realistic ‘right to contest’ for patients in AI-mediated care?
- How can regulators avoid slowing beneficial innovation while still demanding proof?

