Forgotten Dairies
Europe’s AI Law Has Teeth But Medicine Must Wait -By Fransiscus Nanga Roka
This is the world’s most significant experiment in regulating AI, and Europe is doing it. The success of that initiative will not in any way be quantified by the number of compliance forms companies fill out.
Europe has entered the regulatory Rubicon Now that August 2, 2026 has come and gone, the EU Artificial Intelligence Act is no longer primarily a legislative promise. It is also implementing its transparency regime, enforced relevant clauses and is empowering Brussels to fight back against an industry that has long distanced itself from the democratic process with its technological reach.
True, but there is a painful contradiction in this view: when it comes to healthcare Europe has unleashed the sheriff while delaying parts of the law.
Article 50 Transparency Obligations: now requires disclosure, in certain scenarios, when individuals are engaging with an AI application or come across AI-generated or manipulated content. In August 2025, governance and obligations for general-purpose AI models entered into force; However, the Digital Omnibus proposed to apply application of the high-risk regime to Annex III systems until December 2027 at the latest for those systems and especially importantly under Annex I, through to August 2, 2028 with regard to high risk AI embedded within regulated products.
AIs: Developers, Providers, Purchasers and much more: GPAs are a necessary collaboration between AI devs, GPA providers producers/ sellers/ procurers of every type (med-device producers and hospitals suing those med-devices), clinicians that deploy (and potentially profit from) the AIs and ultimately people who receive care. AI contained within computer systems or devices that meet the statutory classification conditions under the Act may be classified as high risk. In cases where an algorithmic decision errored because software impacted diagnosis, imaging interpretation or clinical decisions, it is not just bad software. It can become defective medicine.
The current applicable provisions come into force on August 2 meaning enforcement across the EU single market. However, product-embedded high-risk obligations now become due in August 2028, having been postponed until after the AI Omnibus came into force in July 2026. Brussels contends that a delay allows standards, guidance and compliance infrastructure to develop.
Healthcare cannot endure a two-year accountability vacuum in substance, merely because compliance is delayed in law. AI is able to generate clinically persuasive, machine-speed outputs which are never produced in a vacuum; they reproduce biased datasets, hidden assumptions and poorly generalizable correlations. A doctor can question another doctor. It is a much tougher task to interrogate an opaque model.
This creates a perilous temptation for the EU: to confuse postponement of statutory deadlines with a license to postpone patient safety.
First, hospitals should voluntary treat the 2028 requirements today as the procurement standard: proof of risk management, data governance, technical traceability and human over sight >> performance validation and after market surveillance contractually deemed mandatory for purchase of clinical AI.
Second, for MDR/IVDR compliance process to be an enabler of AI governance without uncertainty, regulatory by design must be built in by medical device manufacturers, not using parallel safety compliance bureaucracies.
Third, an algorithmic clinical governance board is needed within the hospital whose purpose includes auditing model performance by sex, age, ethnicity and comorbidity subgroups; when real-world performance worsens they should suspend systems.
Fourth, patients deserve meaningful disclosures rather than a meaningless AI-assisted lingo. They should understand the AI’s role, if a clinician reviewed its recommendation independently and where ultimate clinical accountability lies.
Last but not least, regulators will have to be clear cut with the penalties. The headline cap of €35 million or 7% of worldwide annual turnover, relates to breaches of AI provisions prohibited under Article 5; the vast majority of operators will face a maximum fine of €15 million or 3%. The regulatory credibility begins with the regulatory accuracy.
This is the world’s most significant experiment in regulating AI, and Europe is doing it. The success of that initiative will not in any way be quantified by the number of compliance forms companies fill out.
In medicine there is only one real test: when the algorithm is wrong, does the law find out before the patient pays?
Fransiscus Nanga Roka
Faculty of Law University 17 August 1945 Surabaya and Managing Partner Law Firm Victorious Indonesia