EU AI Act readiness for European healthtech
Asteron helps healthtech companies determine how the EU AI Act applies to each AI system, product and market role. We map provider and deployer responsibilities, prohibited practices, high-risk classification, transparency duties and the evidence needed across the AI lifecycle. The service is designed for organisations developing, supplying or using AI in the Netherlands, Germany and the wider European market.
- Provider and deployer roles mapped
- AI systems classified by regulatory risk
- MDR, IVDR and GDPR overlaps identified
- Prioritised compliance roadmap created
EU AI Act readiness from €9,900
What is the EU AI Act?
Regulation (EU) 2024/1689 creates a common European regulatory framework for artificial intelligence. It applies different requirements according to the system’s intended purpose, risk category and the organisation’s role in the AI value chain.
The Act does not regulate every AI system in the same way. Some practices are prohibited. Certain systems are classified as high-risk and require extensive lifecycle evidence. Other systems have specific transparency obligations, while many lower-risk uses remain subject primarily to voluntary governance and existing laws.
Healthtech companies must also consider medical-device regulation, privacy, cybersecurity, product safety and professional obligations. AI Act readiness should therefore be integrated into the wider product and compliance system rather than treated as an isolated legal memo.
The AI Act applies to individual AI systems and market roles. A company cannot classify itself once as “low risk” and reuse that answer across every product, feature and deployment.
Does the AI Act apply to your organisation?
The AI Act may apply to:
- – providers placing an AI system or general-purpose AI model on the EU market;
- – providers putting an AI system into service in the EU under their own name;
- – deployers using AI systems within the EU;
- – importers and distributors making third-country AI systems available in Europe;
- – providers or deployers outside the EU where the system’s output is used in the EU;
- – product manufacturers incorporating AI into a regulated product;
- – organisations that substantially modify an AI system or change its intended purpose.
A healthtech company may hold several roles. It can be a provider of an AI-enabled clinical product, a deployer of an internal recruitment tool and an integrator of a third-party general-purpose model. Each role needs its own obligations, evidence and accountable owner.
How the AI Act classifies systems
Risk classification must be based on the system’s intended purpose and real deployment context. Marketing language, internal labels or a supplier’s generic classification are not sufficient evidence.
When healthtech AI becomes high-risk
An AI system may be high-risk under Article 6(1) when:
- it is intended to be used as a safety component of a product, or is itself a product, covered by relevant EU product legislation; and
- the product is required to undergo third-party conformity assessment.
This route is particularly relevant to AI-enabled medical devices and IVDs under MDR or IVDR. However, the presence of AI or a healthcare use case does not automatically make every system high-risk. Other healthtech uses may fall under high-risk categories because they affect employment, access to essential services, insurance, biometric identification or other areas listed in the AI Act.
The intended purpose used for AI Act classification must remain consistent with the product claims, MDR or IVDR documentation, user instructions and actual deployment.
What high-risk AI providers need to establish
Product and lifecycle requirements
- – Continuous risk-management system
- – Data and data-governance controls
- – Technical documentation
- – Automatic record-keeping and logs
- – Instructions and transparency for deployers
- – Effective human-oversight design
- – Accuracy, robustness and cybersecurity
- – Verification and validation evidence
Market and operational requirements
- – Quality-management system
- – Applicable conformity assessment
- – EU declaration of conformity and CE marking
- – Registration where required
- – Post-market monitoring
- – Serious-incident reporting
- – Corrective actions and authority cooperation
- – Controlled change and substantial-modification assessment
The evidence must reflect the system actually placed on the market. A policy or risk register cannot compensate for missing product validation, data provenance, monitoring or human-oversight evidence.
Provider, deployer and supplier responsibilities
Contract terms help allocate work, but they do not override the statutory role created by the product, branding, modification and market activity.
General-purpose AI in healthtech products
General-purpose AI models can support clinical documentation, patient communication, coding, research, decision support and product features. Their flexibility does not remove the integrator’s responsibility for the resulting AI system.
A healthtech company should document:
- – which model and version are used;
- – the provider and contractual dependencies;
- – intended and prohibited uses;
- – training or adaptation performed by the company;
- – health and personal data sent to the model;
- – evaluation against the actual use case;
- – human review and fallback arrangements;
- – monitoring for model, supplier and policy changes.
A supplier’s model card or compliance statement is useful input, but it is not a complete assessment of the healthtech product built around the model.
Requirements already in application
Do not frame the AI Act solely as a future obligation.
Prohibited AI practices
The prohibition rules have applied since 2 February 2025. Organisations need a process for detecting and stopping prohibited use cases before procurement or deployment.
AI literacy
Providers and deployers must take measures to ensure an appropriate level of AI literacy among staff and other people operating AI systems on their behalf. Training should reflect the system, role, user knowledge and affected individuals.
General-purpose AI models
GPAI governance and provider obligations began applying on 2 August 2025. Companies using or integrating GPAI should confirm which obligations belong to the model provider and which remain with the resulting system provider or deployer.
AI literacy is not satisfied by one generic awareness presentation. Personnel need enough knowledge to perform their actual oversight, approval, monitoring and escalation responsibilities.
Application timeline
From applicability to a compliance roadmap
AI inventory and intended purpose
Identify systems in development, production, procurement and internal use. Record users, affected people, outputs, data, models, suppliers and target markets.
Value-chain role mapping
Determine provider, deployer, importer, distributor, product-manufacturer and GPAI relationships for each system.
Regulatory classification
Assess prohibited practices, high-risk criteria, transparency duties, exemptions and interaction with MDR, IVDR, GDPR and other product legislation.
Evidence and control mapping
Map applicable requirements to current quality, risk, data, software, security, monitoring and incident processes.
Gap prioritisation
Separate requirements already applicable from future product evidence and dependencies awaiting standards, guidance or legislative completion.
Implementation roadmap
Assign actions, owners, decision gates and evidence milestones. Update the roadmap when intended purpose, suppliers, models or legislation change.
What Asteron delivers
Applicability and classification
- – AI system inventory structure
- – Intended-purpose baseline
- – Provider and deployer role map
- – Prohibited-practice screening
- – High-risk classification rationale
- – Transparency-obligation assessment
- – MDR, IVDR and GDPR interface map
- – Regulatory dependency register
Readiness and evidence plan
- – Applicable-requirement matrix
- – Current control and evidence mapping
- – AI-literacy responsibility plan
- – Quality and risk-process gaps
- – Data and model governance gaps
- – Human-oversight and monitoring gaps
- – Supplier and GPAI dependencies
- – Prioritised implementation roadmap
This project establishes the regulatory position and readiness plan. Full ISO 42001 implementation, product validation, conformity assessment, legal opinions and technical remediation are included only when expressly stated in the proposal.
Netherlands, Germany and wider European deployment
The AI Act creates a shared EU framework, while competent-authority structures, market surveillance and sector coordination are implemented nationally.
For the Netherlands, healthtech companies should connect AI Act readiness with Dutch privacy, medical-device, healthcare and information-security requirements, including NEN 7510 where applicable.
For Germany, the roadmap may also need to account for federal and state data-protection supervision, medical-device authorities, employment requirements and local healthcare regulation.
A company serving both markets should maintain one controlled AI Act classification and evidence base. National requirements should be handled as traceable market extensions rather than contradictory product files.
How EU AI Act readiness connects to other frameworks
Pricing
The starting project covers the AI inventory structure, role mapping, regulatory classification, priority evidence gaps and implementation roadmap.
Final scope depends on:
- – number and complexity of AI systems;
- – provider, deployer and value-chain roles;
- – regulated medical-device or IVD products;
- – number of markets and legal entities;
- – use of third-party and general-purpose models;
- – existing quality, privacy and security systems;
- – volume of high-risk evidence requiring review.
This is an AI Act readiness project, not an ISO certification or legal opinion.
- – 40% at signing
- – 40% when the agreed classification and gap baseline is delivered
- – 20% after the contracted readiness roadmap is completed
Prices exclude VAT where applicable.
Independent assessment and external costs
Asteron provides the applicability assessment, evidence mapping and implementation roadmap. Asteron does not issue an AI Act certificate or make a binding classification decision on behalf of a court, authority or notified body.
There is no general organisational “AI Act certification.” High-risk products may require a conformity-assessment route, and AI embedded in medical devices or IVDs may be assessed through the relevant product-regulatory process.
Notified-body fees, product testing, clinical or performance studies, external legal opinions and specialist validation are quoted and paid separately to the relevant independent organisation unless expressly included in the proposal.
If the contracted readiness outcome is not reached because an Asteron deliverable is incomplete or deficient, Asteron corrects that work at no additional professional fee within the agreed scope. This does not cover legislative changes, new AI systems, changed intended purposes or decisions by independent authorities.
Responsibilities
Asteron
- – Structures the AI system inventory
- – Maps value-chain roles and classification
- – Identifies applicable AI Act requirements
- – Connects requirements with existing frameworks
- – Reviews current evidence and governance gaps
- – Produces the prioritised implementation roadmap
Your organisation
- – Provides accurate product, model and supplier information
- – Owns intended-purpose and market decisions
- – Assigns accountable AI and product owners
- – Approves classification and risk decisions
- – Implements product, technical and contractual changes
- – Operates human oversight and monitoring
- – Tracks regulatory and product changes after delivery
Frequently asked questions
What is the EU AI Act?
The EU AI Act is the European regulation establishing rules for artificial intelligence according to system risk, intended purpose and the organisation’s role.
Does the AI Act apply to companies outside the EU?
It may apply when an AI system is placed on the EU market, used in the EU or produces output used in the EU.
Is every medical or health AI system high-risk?
No. Classification depends on the intended purpose and Article 6 criteria. AI in a regulated product may be high-risk when third-party conformity assessment is required.
What is the difference between a provider and deployer?
A provider places an AI system on the market or puts it into service under its name. A deployer uses the AI system under its authority.
Can using a third-party model make us a provider?
Yes, depending on how the model is integrated, branded, modified and used within the resulting AI system.
What AI Act requirements already apply?
Prohibited-practice and AI-literacy rules have applied since February 2025. GPAI-related rules began applying in August 2025.
What does AI literacy require?
Organisations must take measures appropriate to their staff, AI systems, use context and affected people. The programme should enable personnel to perform real oversight and escalation responsibilities.
Does ISO 42001 certification prove AI Act compliance?
No. ISO 42001 supports organisational governance but does not replace system-specific legal classification and product evidence.
Is there an EU AI Act certificate?
There is no general organisational certificate. Certain high-risk products follow the applicable conformity-assessment route.
How much does AI Act readiness cost?
The service starts from €9,900. Final scope depends on the AI portfolio, roles, product regulation, suppliers and existing evidence.
Official references
- – Regulation (EU) 2024/1689 — EUR-Lex
- – European Commission AI Act overview
- – European Commission AI Act Service Desk
- – AI Act Single Information Platform
- – Current Commission guidance on high-risk classification
- – Final AI Omnibus amendment when adopted and published
- – MDR and IVDR guidance for AI-enabled regulated products
Last reviewed: July 2026
Asteron is not endorsed by or partnered with the European Commission, any national competent authority or certification body.
Related services and frameworks
Know which AI Act obligations apply before product decisions become difficult to reverse
We will assess your AI systems, market roles, intended purposes and existing evidence, then create a practical compliance roadmap.
