Artificial intelligence in healthcare: between clinical promise and legal dizzying heights. A regulatory turning point in digital health.

By Charles Cardine
Published on 02/05/2025
Artificial intelligence in healthcare: between clinical promise and legal dizzying heights. A regulatory turning point in digital health.

But its interaction with the GDPR, already complex in theory, becomes dizzying in practice.

A Dual Framework, Two Logics of Compliance

In practice, DPOs must contend with a dual regulatory framework: on the one hand, the GDPR, based on the protection of individuals; on the other, the AI Act, structured by the management of technological risk. While the two frameworks share certain tools—impact assessment, documentation, transparency—they remain built on distinct rationales. And healthcare, a field that is both sensitive and highly regulated, crystallizes all these tensions.

Data Minimization vs. Performance Logic

The principle of data minimization, a pillar of the GDPR, clashes head-on with the performance requirements of AI. The more an AI is fed, the more it learns—but the more it learns, the more it exposes itself to legal risks if the purpose is not clearly defined or if the processing is not proportionate. The temptation is strong, on the industry side, to collect large amounts of data “to train others later.” This is precisely what regulators want to control.

Consent: Beware of the “mirror clause” effect

Another pitfall: the explosion of legal bases. Consent, public interest, legal obligation, legitimate interest… These foundations can coexist, or even overlap. The risk? Creating an incomprehensible contractual maze, where the patient no longer knows what they are agreeing to, or for what purpose. To avoid this pitfall, the collection of consent must be rethought within a process framework, rather than a fixed moment. This is a real challenge in legal design and the ethics of clarity.

Liability: A worrying legal vacuum

Who is responsible if a medical AI makes a mistake? The professional who used it? The software developer who designed it? The healthcare facility that deployed it? Today, there is no clear answer. French positive law remains attached to traditional legal frameworks—liability for things, product liability, contractual or tortious liability—which are poorly suited to algorithmic decision-making processes. This legal deficiency, coupled with the opacity of certain models, fuels legitimate concerns among healthcare professionals.

Synthetic Data: Legal False Friends

Faced with the constraints of the GDPR, some are relying on synthetic data to circumvent certain obligations. But beware: if the generated data retains a structure too similar to the original data, the risk of re-identification remains. The EDPB reiterated in December 2024 that anonymization is a contextual assessment, never an automatic label. In healthcare, where data is scarce, sensitive, and highly correlated, vigilance must be paramount.

A CNIL in Action but Overwhelmed

The CNIL established an AI task force in 2023. It supports projects (such as Dalvia Santé), produces soft law (fact sheets, guidelines), and attempts to anticipate emerging uses. However, it operates in a constantly evolving legal landscape. Generative AI, for example, raises new challenges: pre-trained models on uncontrolled data, and the difficulty of tracing the source data. The legal framework must now address these gray areas.

Generative AI: Questions Abound, Answers Slow to Arrive

In healthcare, generative AI raises particular concerns: it is capable of producing credible medical content… but sometimes erroneous content. The line between decision support and substitution is becoming blurred. If a healthcare professional acts based on an AI-generated summary, and that summary is inaccurate, who will bear the responsibility? And how do you audit a “black box” model trained abroad? Here again, the law struggles to keep up.

A Strategic Role for DPOs

In this context, the role of healthcare-specialized DPOs takes on a new dimension. It’s no longer about “tickling boxes,” but about articulating law, technology, and strategy. This requires dialogue with lawyers, CISOs, business units, and sometimes even data scientists. It’s a job of building bridges, anticipating, and constantly negotiating with uncertainty.

An Ethical Imperative: Protecting the Body… Even the Digital Body

Ultimately, the real question is this: What kind of digital health society do we want? If we allow technical logic to dominate without a framework, the risk is that we will dehumanize healthcare. If we over-regulate, we will stifle useful innovation. Between these two extremes, a path must be forged: that of a right to digital integrity, capable of guaranteeing that even in the world of data, the human body remains protected. Because it’s not enough to process data: the person must be cared for.

Join us in September for a webinar dedicated to these issues! Find all the latest news and registration details soon on our LinkedIn page: THE HEALTH DPOs

www.lesdpodelasante.com