Skip to content
A working laboratory seen through a glazed wall from a corridor, staff in white coats at the benches inside.

THE MODEL YOU ALREADY VALIDATED

You can get a validated model into daily use.

What stops a validated model is rarely the rulebooks: it is unsettled data, a workflow nobody redesigned, and no named owner on your side. That is the work, for private care providers and life-science companies that decide for themselves.

THE SEQUENCE FOUND IN TWENTY REGIONS

Why AI projects stall in healthcare. Documented.

When the Swedish Association of Local Authorities and Regions (Sveriges Kommuner och Regioner, SKR) interviewed 20 of 21 regions about AI in healthcare, the same sequence appeared again and again.

Identify the initiative. Collect the data. Validate the model. Then, at deployment, it surfaces: the data doesn't exist in real time, manual processing is required, and nobody owns the operation. The project pauses.

AI Sweden's 2025 mapping of AI in healthcare, covering 17 of the 21 regions, found 179 initiatives, of which 13 percent were fully implemented.

The model was never the problem. The journal system, the data flow and the ownership were.

The sequence is identical inside a pharma or medtech group's Nordic unit. The difference is that there, someone can decide.

THE REGULATORY READ

The EU AI Act and medical devices. Read together, not in operation.

01

The device track is doubled, on purpose.

CE-marked AI in a medical device remains under both the device rules and the AI rules; a single assessment covering both was rejected, so the regimes run in parallel. For AI built into devices, Annex I, the high-risk requirements apply from 2 August 2028. Being integrated in a device does not automatically make an AI function high-risk. The intended safety purpose decides, and drawing that line is part of our job.

02

The surprise sits outside the device.

The new duties land mostly on what is not a medical device: journal assistants, capacity planning, administrative AI, patient-facing generative tools. These duties are EU law. In Sweden, the sector authority is the Swedish Medical Products Agency (Läkemedelsverket), whose guidance urges that healthcare control the AI systems, not the other way around.

03

The data reality is stricter than the ambition.

The Swedish Authority for Privacy Protection (IMY) has assessed that reusing journal data for training is likely incompatible with the purposes it was collected for, absent an opt-out, and merging regional registers for validation is blocked. European data access is years away. We build for the data reality you have, not the promised one.

04

The care side has its own list and its own clock.

Triage, referral prioritisation and needs assessment sit on the care-side high-risk list, Annex III, with requirements from 2 December 2027, ahead of the device track. The fundamental rights impact assessment duty follows the type of deployer instead: a region or a publicly run care provider is covered as a public body, a private care company normally is not. Our EU AI Act page carries the calendar.

THE ACCOUNTABILITY BLOCKER

Who monitors, who stops, who documents.

No court ruling and no supervisory decision has yet clarified who is liable when an AI decision support gets it wrong. In Sweden, personal clinical accountability is technology-neutral, and it sits uneasily with models whose reasoning is hard to inspect. Swedish regions name this, explicitly, as a blocker for deployment.

Our answer is operational, because that is where the question can actually be settled today: who monitors performance, who holds the authority to stop the system, what gets documented, and how the clinician stays in command.

We build that structure into the deployment and hand it over with the system. Unresolved in case law does not mean unmanageable in operation.

FOUR STEPS, IN THAT ORDER

What to do, in order.

01

Inventory across all tracks.

Devices, care-side systems, and the administrative layer where the new duties actually land. The AI Readiness Assessment settles what you run, which track each system sits in, and what that triggers.

02

Close the transparency gaps.

Patient-facing chatbots and generated content carry disclosure duties that apply broadly. A small, fast, fixed-price review: the gap list and the fix plan. Weeks, not months.

03

Start the runway where the care list applies.

Triage, prioritisation, needs assessment: risk management, the impact assessment as a working process, and the accountability structure that unblocks deployment. The head start, never the panic.

04

Lift the leadership first.

Executive sessions and masterclasses delivered by Ampliro, in the leadership team and among chief physicians. Role-specific programmes for the wider organisation run through AIUC, our education arm, built for effect, not attendance.

Delivered where evidence is the culture.

PROOF

In this sector we have worked with leadership teams, chief physicians and teams in the business, at Getinge, Sachsska Children's Hospital at Södersjukhuset, and Angelini Pharma Nordics. The consultant who leads your engagement is the person who delivered that work.

QUESTIONS

Before you put the model into daily use.

No, CE marking under the medical device rules is not conformity with the EU AI Act. A single combined assessment covering both regimes was rejected, so the two tracks run in parallel: for AI built into devices, Annex I, the high-risk requirements apply from 2 August 2028. The sharper question usually sits outside the device, in journal assistants, planning tools and patient-facing generative AI, where the inventory is thinnest.

High-risk status under the EU AI Act follows the intended use of a system, not how advanced the technology is. On the care side, triage, referral prioritisation and needs assessment sit in Annex III, with requirements from 2 December 2027. AI built into medical devices sits in Annex I, from 2 August 2028. The fundamental rights impact assessment in Article 27 also applies from 2 December 2027, and it binds public bodies and private providers delivering public services.

Training AI models on your own patient records is in most cases not possible as the data protection rules stand today. The Swedish Authority for Privacy Protection (IMY) has assessed that reuse of record data for training is likely incompatible with the purposes the data was collected for, absent an opt-out. Since May 2026 IMY has also had an open supervisory case on a region's AI transcription service in primary care, and that case rests on data protection law, not on the EU AI Act. What works instead is assistive tools with the clinician in command.

Liability for a faulty AI decision support tool in healthcare has not been tested: no court ruling and no supervisory decision has settled it, and anyone claiming otherwise is guessing. Guidance from the Swedish Medical Products Agency (Läkemedelsverket) points the direction, that healthcare should control the AI systems rather than the other way round. What you can control today is the structure: who monitors performance, who holds the authority to stop the system, what gets documented, and how clinical judgement stays decisive.

A region is a public body under the EU AI Act and has a back stop of its own: existing high-risk systems must meet the requirements by 2 August 2030 under Article 111(2). That deadline holds whether or not the systems are significantly changed, because the legacy relief tied to leaving a system substantially unchanged applies to other deployers. New systems follow the ordinary calendar, so 2 December 2027 for Annex III.

The EU AI Act's transparency duties in Article 50 apply from 2 August 2026 and cover patient-facing chatbots in healthcare. People must be told when they are interacting with an AI system, and generated content must be recognisable as synthetic. The AI literacy duty in Article 4 and the prohibited practices have applied since 2 February 2025, so a chatbot already in service is worth reviewing now rather than closer to the date.

A single clinic or care provider can start on the EU AI Act on its own, and that is deliberately where we work: engagements scoped to one clinic or one business unit, defined and fixed-price, where a decision can actually be made. The inventory and the classification can be done at that level. The AI Readiness Assessment is sized to start without waiting for anyone else's programme.

Start where a decision can be made.

One conversation settles which track your AI actually sits in, what the data reality allows, and what it takes to get from validated to deployed. If the honest answer is that your device programme already covers you, we will say so.