Industry guide
Healthcare & wellbeing
Clinical decision support, triage bots, scribing tools, mental-health chatbots and eligibility decisions sit at the sharp end of AI regulation. Medical-device rules already apply to diagnostic software; the EU AI Act adds high-risk duties for AI in regulated medical devices (Annex I, from August 2028) and for access to healthcare services (Annex III, December 2027). Texas requires providers to disclose AI used in treatment; Utah requires AI disclosure in medical and mental-health interactions and regulates mental-health chatbots. Health data is special-category data everywhere.
Regulated uses
- Diagnostic and clinical decision-support software (often a medical device)
- Patient-facing triage, symptom-checker and mental-health chatbots
- Ambient scribing and note generation from consultations
- Eligibility, prior-authorisation and benefits decisions
- Emotion recognition or monitoring of patients or staff
Laws by region
| Region | Law | Status |
|---|---|---|
| EU | EU AI ActEU Artificial Intelligence Act (Regulation (EU) 2024/1689) | In force |
| EU | EU AI Omnibus 2026Digital Omnibus on AI (Regulation (EU) 2026/1744) | In force |
| US | Texas TRAIGATexas Responsible Artificial Intelligence Governance Act (HB 149) | In force |
| US | Utah AI Policy ActUtah Artificial Intelligence Policy Act (SB 149, as amended by SB 226 and SB 332 in 2025) | In force |
| US | Colorado ADMT ActColorado Automated Decision-Making Technology Act (SB 26-189, replacing SB 24-205) | Upcoming |
| US | EO 14365 (federal preemption push)Executive Order 14365 — Ensuring a National Policy Framework for Artificial Intelligence | In force |
| Canada | PIPEDA (Canada)Personal Information Protection and Electronic Documents Act (PIPEDA) | In force |
| Canada | Quebec Law 25Quebec Law 25 — Act respecting the protection of personal information in the private sector (automated decision provisions) | In force |
| Canada | Canada GenAI Code of ConductVoluntary Code of Conduct on the Responsible Development and Management of Advanced Generative AI Systems | Voluntary |
| Standards | NIST AI RMFNIST AI Risk Management Framework 1.0 and Generative AI Profile (NIST AI 600-1) | Voluntary |
| Standards | ISO/IEC 42001ISO/IEC 42001:2023 — Artificial intelligence management system | Voluntary |
Obligations checklist
- Check whether each tool is a medical device under FDA, Health Canada or EU MDR rules before any AI-law analysis.
- Tell patients when AI is used in their care, no later than when the service is provided (Texas) and at the start of health or mental-health interactions (Utah).
- Keep a clinician in the loop with authority to override, and log overrides.
- Run a privacy/data-protection impact assessment for any tool processing health data.
- Validate accuracy and bias across patient groups and monitor drift after deployment.
- Set retention and confidentiality rules for prompts, recordings and generated notes.
- For mental-health chatbots, document clinician involvement in design and testing and avoid advertising inside sessions.
Real cases
- Ban2023 · US-federalFTC v. Rite Aid — five-year ban on facial recognition surveillance
Settlement announced 19 December 2023. Rite Aid is banned from using facial recognition for surveillance for five years, must delete the images and any models built from them, must notify consumers before enrolling them in any future biometric system, run a comprehensive security programme with independent assessments for 20 years, and have its CEO certify compliance annually.
- Ruling2024 · CA-BCMoffatt v. Air Canada — airline liable for its chatbot's wrong answer
Decision 2024 BCCRT 149 (February 2024). Air Canada was ordered to pay C$812.02 in total: C$650.88 in damages (the fare difference) plus pre-judgment interest and tribunal fees. Small money, but the first widely reported ruling that a company answers for what its customer-facing AI says.
Where do you stand in healthcare & wellbeing?
The screener is pre-filled for this sector — ten minutes to your level and gaps.
Sources
- The Texas Responsible AI Governance Act — Norton Rose Fulbright ↗
- Chatbots in Check: Utah's Latest AI Legislation — Future of Privacy Forum ↗
Last reviewed Sep 25, 2026.