AsteronAsteron

    EU AI Act readiness for European healthtech

    Asteron helps healthtech companies determine how the EU AI Act applies to each AI system, product and market role. We map provider and deployer responsibilities, prohibited practices, high-risk classification, transparency duties and the evidence needed across the AI lifecycle. The service is designed for organisations developing, supplying or using AI in the Netherlands, Germany and the wider European market.

    View AI Act pricing
    • Provider and deployer roles mapped
    • AI systems classified by regulatory risk
    • MDR, IVDR and GDPR overlaps identified
    • Prioritised compliance roadmap created

    EU AI Act readiness from €9,900

    What is the EU AI Act?

    Regulation (EU) 2024/1689 creates a common European regulatory framework for artificial intelligence. It applies different requirements according to the system’s intended purpose, risk category and the organisation’s role in the AI value chain.

    The Act does not regulate every AI system in the same way. Some practices are prohibited. Certain systems are classified as high-risk and require extensive lifecycle evidence. Other systems have specific transparency obligations, while many lower-risk uses remain subject primarily to voluntary governance and existing laws.

    Healthtech companies must also consider medical-device regulation, privacy, cybersecurity, product safety and professional obligations. AI Act readiness should therefore be integrated into the wider product and compliance system rather than treated as an isolated legal memo.

    The AI Act applies to individual AI systems and market roles. A company cannot classify itself once as “low risk” and reuse that answer across every product, feature and deployment.

    Does the AI Act apply to your organisation?

    The AI Act may apply to:

    • providers placing an AI system or general-purpose AI model on the EU market;
    • providers putting an AI system into service in the EU under their own name;
    • deployers using AI systems within the EU;
    • importers and distributors making third-country AI systems available in Europe;
    • providers or deployers outside the EU where the system’s output is used in the EU;
    • product manufacturers incorporating AI into a regulated product;
    • organisations that substantially modify an AI system or change its intended purpose.

    A healthtech company may hold several roles. It can be a provider of an AI-enabled clinical product, a deployer of an internal recruitment tool and an integrator of a third-party general-purpose model. Each role needs its own obligations, evidence and accountable owner.

    How the AI Act classifies systems

    Prohibited practices
    The AI system or use is not permitted in the prohibited form.
    Classification must consider manipulation, exploitation, social scoring and prohibited biometric or emotion-related uses.
    High-risk AI
    Extensive requirements apply across risk management, data, documentation, human oversight, conformity and monitoring.
    May include AI used as a safety component of a regulated medical product or AI that is itself such a product and requires third-party conformity assessment.
    Transparency-risk AI
    Defined disclosure or information duties apply.
    May affect patient-facing chatbots, synthetic content and systems interacting directly with individuals.
    Other AI systems
    No full high-risk regime, but other AI Act, GDPR, product, security and contractual obligations may remain.
    Includes many administrative, analytical and internal tools, depending on their actual intended use.

    Risk classification must be based on the system’s intended purpose and real deployment context. Marketing language, internal labels or a supplier’s generic classification are not sufficient evidence.

    When healthtech AI becomes high-risk

    An AI system may be high-risk under Article 6(1) when:

    1. it is intended to be used as a safety component of a product, or is itself a product, covered by relevant EU product legislation; and
    2. the product is required to undergo third-party conformity assessment.

    This route is particularly relevant to AI-enabled medical devices and IVDs under MDR or IVDR. However, the presence of AI or a healthcare use case does not automatically make every system high-risk. Other healthtech uses may fall under high-risk categories because they affect employment, access to essential services, insurance, biometric identification or other areas listed in the AI Act.

    The intended purpose used for AI Act classification must remain consistent with the product claims, MDR or IVDR documentation, user instructions and actual deployment.

    What high-risk AI providers need to establish

    Product and lifecycle requirements

    • Continuous risk-management system
    • Data and data-governance controls
    • Technical documentation
    • Automatic record-keeping and logs
    • Instructions and transparency for deployers
    • Effective human-oversight design
    • Accuracy, robustness and cybersecurity
    • Verification and validation evidence

    Market and operational requirements

    • Quality-management system
    • Applicable conformity assessment
    • EU declaration of conformity and CE marking
    • Registration where required
    • Post-market monitoring
    • Serious-incident reporting
    • Corrective actions and authority cooperation
    • Controlled change and substantial-modification assessment

    The evidence must reflect the system actually placed on the market. A policy or risk register cannot compensate for missing product validation, data provenance, monitoring or human-oversight evidence.

    Provider, deployer and supplier responsibilities

    Provider
    Defines the intended purpose, classification, product controls, technical evidence, conformity route and post-market monitoring.
    Deployer
    Uses the system according to instructions, assigns human oversight, monitors operation and acts on risks and incidents.
    Importer
    Checks that a non-EU provider has completed the required conformity steps before the system enters the EU market.
    Distributor
    Verifies required marking and documentation and avoids making a system available when non-compliance is suspected.
    Product manufacturer
    May become responsible for the AI system when integrating it into a regulated product under its own name.
    GPAI integrator
    Must understand the model provider’s information and manage the intended purpose, integration and resulting system risks.

    Contract terms help allocate work, but they do not override the statutory role created by the product, branding, modification and market activity.

    General-purpose AI in healthtech products

    General-purpose AI models can support clinical documentation, patient communication, coding, research, decision support and product features. Their flexibility does not remove the integrator’s responsibility for the resulting AI system.

    A healthtech company should document:

    • which model and version are used;
    • the provider and contractual dependencies;
    • intended and prohibited uses;
    • training or adaptation performed by the company;
    • health and personal data sent to the model;
    • evaluation against the actual use case;
    • human review and fallback arrangements;
    • monitoring for model, supplier and policy changes.

    A supplier’s model card or compliance statement is useful input, but it is not a complete assessment of the healthtech product built around the model.

    Requirements already in application

    Do not frame the AI Act solely as a future obligation.

    Prohibited AI practices

    The prohibition rules have applied since 2 February 2025. Organisations need a process for detecting and stopping prohibited use cases before procurement or deployment.

    AI literacy

    Providers and deployers must take measures to ensure an appropriate level of AI literacy among staff and other people operating AI systems on their behalf. Training should reflect the system, role, user knowledge and affected individuals.

    General-purpose AI models

    GPAI governance and provider obligations began applying on 2 August 2025. Companies using or integrating GPAI should confirm which obligations belong to the model provider and which remain with the resulting system provider or deployer.

    AI literacy is not satisfied by one generic awareness presentation. Personnel need enough knowledge to perform their actual oversight, approval, monitoring and escalation responsibilities.

    Application timeline

    1 August 2024
    The EU AI Act entered into force.
    2 February 2025
    Prohibited-practice and AI-literacy requirements began applying.
    2 August 2025
    Governance rules and obligations for general-purpose AI models began applying.
    2 August 2026
    Under the enacted AI Act, most remaining provisions are scheduled to apply, subject to specific exceptions and any final legislative amendments.
    High-risk rules under legislative revision
    As of July 2026, a political agreement on the AI Omnibus proposes application from December 2027 for certain Annex III high-risk systems and August 2028 for AI embedded in regulated products.
    The revised high-risk dates must not be presented as final law until the amending legislation has completed adoption and publication. The roadmap should track the final legal text, harmonised standards, common specifications and Commission guidance.

    From applicability to a compliance roadmap

    1. AI inventory and intended purpose

      Identify systems in development, production, procurement and internal use. Record users, affected people, outputs, data, models, suppliers and target markets.

    2. Value-chain role mapping

      Determine provider, deployer, importer, distributor, product-manufacturer and GPAI relationships for each system.

    3. Regulatory classification

      Assess prohibited practices, high-risk criteria, transparency duties, exemptions and interaction with MDR, IVDR, GDPR and other product legislation.

    4. Evidence and control mapping

      Map applicable requirements to current quality, risk, data, software, security, monitoring and incident processes.

    5. Gap prioritisation

      Separate requirements already applicable from future product evidence and dependencies awaiting standards, guidance or legislative completion.

    6. Implementation roadmap

      Assign actions, owners, decision gates and evidence milestones. Update the roadmap when intended purpose, suppliers, models or legislation change.

    What Asteron delivers

    Applicability and classification

    • AI system inventory structure
    • Intended-purpose baseline
    • Provider and deployer role map
    • Prohibited-practice screening
    • High-risk classification rationale
    • Transparency-obligation assessment
    • MDR, IVDR and GDPR interface map
    • Regulatory dependency register

    Readiness and evidence plan

    • Applicable-requirement matrix
    • Current control and evidence mapping
    • AI-literacy responsibility plan
    • Quality and risk-process gaps
    • Data and model governance gaps
    • Human-oversight and monitoring gaps
    • Supplier and GPAI dependencies
    • Prioritised implementation roadmap

    This project establishes the regulatory position and readiness plan. Full ISO 42001 implementation, product validation, conformity assessment, legal opinions and technical remediation are included only when expressly stated in the proposal.

    Netherlands, Germany and wider European deployment

    The AI Act creates a shared EU framework, while competent-authority structures, market surveillance and sector coordination are implemented nationally.

    For the Netherlands, healthtech companies should connect AI Act readiness with Dutch privacy, medical-device, healthcare and information-security requirements, including NEN 7510 where applicable.

    For Germany, the roadmap may also need to account for federal and state data-protection supervision, medical-device authorities, employment requirements and local healthcare regulation.

    A company serving both markets should maintain one controlled AI Act classification and evidence base. National requirements should be handled as traceable market extensions rather than contradictory product files.

    How EU AI Act readiness connects to other frameworks

    ISO 42001
    Provides a certifiable management system for organisational AI governance.
    ISO 27001
    Supports information-security risk, supplier and incident processes.
    ISO 27701
    Supports privacy governance for personal data processed by AI.
    ISO 13485
    Provides the quality-management foundation for AI-enabled medical devices.
    ISO 14971
    Structures medical-device product-risk management.
    IEC 62304
    Supports controlled software development and maintenance.
    MDR and IVDR
    Determine the product conformity route that may trigger high-risk AI classification.

    Pricing

    EU AI Act readiness
    from €9,900

    The starting project covers the AI inventory structure, role mapping, regulatory classification, priority evidence gaps and implementation roadmap.

    Final scope depends on:

    • number and complexity of AI systems;
    • provider, deployer and value-chain roles;
    • regulated medical-device or IVD products;
    • number of markets and legal entities;
    • use of third-party and general-purpose models;
    • existing quality, privacy and security systems;
    • volume of high-risk evidence requiring review.

    This is an AI Act readiness project, not an ISO certification or legal opinion.

    Payment terms (fixed-scope)
    • 40% at signing
    • 40% when the agreed classification and gap baseline is delivered
    • 20% after the contracted readiness roadmap is completed

    Prices exclude VAT where applicable.

    View all pricing

    Independent assessment and external costs

    Asteron provides the applicability assessment, evidence mapping and implementation roadmap. Asteron does not issue an AI Act certificate or make a binding classification decision on behalf of a court, authority or notified body.

    There is no general organisational “AI Act certification.” High-risk products may require a conformity-assessment route, and AI embedded in medical devices or IVDs may be assessed through the relevant product-regulatory process.

    Notified-body fees, product testing, clinical or performance studies, external legal opinions and specialist validation are quoted and paid separately to the relevant independent organisation unless expressly included in the proposal.

    If the contracted readiness outcome is not reached because an Asteron deliverable is incomplete or deficient, Asteron corrects that work at no additional professional fee within the agreed scope. This does not cover legislative changes, new AI systems, changed intended purposes or decisions by independent authorities.

    Responsibilities

    Asteron

    • Structures the AI system inventory
    • Maps value-chain roles and classification
    • Identifies applicable AI Act requirements
    • Connects requirements with existing frameworks
    • Reviews current evidence and governance gaps
    • Produces the prioritised implementation roadmap

    Your organisation

    • Provides accurate product, model and supplier information
    • Owns intended-purpose and market decisions
    • Assigns accountable AI and product owners
    • Approves classification and risk decisions
    • Implements product, technical and contractual changes
    • Operates human oversight and monitoring
    • Tracks regulatory and product changes after delivery

    Frequently asked questions

    What is the EU AI Act?

    The EU AI Act is the European regulation establishing rules for artificial intelligence according to system risk, intended purpose and the organisation’s role.

    Does the AI Act apply to companies outside the EU?

    It may apply when an AI system is placed on the EU market, used in the EU or produces output used in the EU.

    Is every medical or health AI system high-risk?

    No. Classification depends on the intended purpose and Article 6 criteria. AI in a regulated product may be high-risk when third-party conformity assessment is required.

    What is the difference between a provider and deployer?

    A provider places an AI system on the market or puts it into service under its name. A deployer uses the AI system under its authority.

    Can using a third-party model make us a provider?

    Yes, depending on how the model is integrated, branded, modified and used within the resulting AI system.

    What AI Act requirements already apply?

    Prohibited-practice and AI-literacy rules have applied since February 2025. GPAI-related rules began applying in August 2025.

    What does AI literacy require?

    Organisations must take measures appropriate to their staff, AI systems, use context and affected people. The programme should enable personnel to perform real oversight and escalation responsibilities.

    Does ISO 42001 certification prove AI Act compliance?

    No. ISO 42001 supports organisational governance but does not replace system-specific legal classification and product evidence.

    Is there an EU AI Act certificate?

    There is no general organisational certificate. Certain high-risk products follow the applicable conformity-assessment route.

    How much does AI Act readiness cost?

    The service starts from €9,900. Final scope depends on the AI portfolio, roles, product regulation, suppliers and existing evidence.

    Official references

    • – Regulation (EU) 2024/1689 — EUR-Lex
    • – European Commission AI Act overview
    • – European Commission AI Act Service Desk
    • – AI Act Single Information Platform
    • – Current Commission guidance on high-risk classification
    • – Final AI Omnibus amendment when adopted and published
    • – MDR and IVDR guidance for AI-enabled regulated products

    Last reviewed: July 2026

    Asteron is not endorsed by or partnered with the European Commission, any national competent authority or certification body.

    Know which AI Act obligations apply before product decisions become difficult to reverse

    We will assess your AI systems, market roles, intended purposes and existing evidence, then create a practical compliance roadmap.

    View AI Act pricing