RISKLINE

EU AI Act · Healthcare AI

When a hospital asks, “Is your AI still doing what you approved?” — what do you hand them?

Not last year’s PDF. This week’s evidence.

RiskLine verifies your defined EU AI Act controls as your models, prompts and vendors change, and keeps timestamped proof ready before anyone asks.

Verification sequence

Illustrative
  1. 01

    Verified

  2. 02

    Change detected

  3. 03

    Exception

  4. 04

    Remediation

  5. 05

    Verified

What hospitals ask

Three questions. Three things you should be able to hand over.

Is it still the AI you approved?

What you hand over

Change log against the approved version, with each material change reviewed and timestamped.

Who is accountable if it gets a case wrong?

What you hand over

Named control owner, oversight step status, and an exception trail when human review was skipped or overridden.

How would you know if it drifted?

What you hand over

Threshold checks, timestamps, and an incident record — not a narrative assembled the week before an audit.

Why now

Snapshot assurance does not survive a live clinical system.

Systems change

A model update, prompt revision, new vendor API, or tooling change can invalidate last quarter’s approval pack overnight.

Buyers ask again

Procurement and clinical governance do not stop at contract signature. They ask what the AI is doing now.

Evidence goes stale

A PDF from March answers a March question. Hospitals need timestamped proof tied to the live system.

What we verify

Selected EU AI Act obligations → controls → evidence

Starting mapping for healthcare AI vendors. Not a complete legal inventory.

Art. 9

Risk management

Control. Documented risk process for the AI system; re-run when the system or use context materially changes.

Evidence. Versioned risk record, change trigger log, last review timestamp.

Art. 12

Record-keeping / logging

Control. Logs that show what the system did, when, and under which configuration.

Evidence. Log presence/format checks, retention window, sample event IDs.

Art. 14

Human oversight

Control. Named oversight step before high-impact clinical or triage actions; kill-switch path.

Evidence. Oversight status, owner identity, exception trail when skipped or overridden.

Art. 15

Accuracy, robustness, cybersecurity

Control. Agreed performance and security thresholds for the approved model version.

Evidence. Threshold check results, model/version hash, drift or failure incidents.

Art. 72

Post-market monitoring

Control. Ongoing collection and review of how the system behaves after placement.

Evidence. Monitoring schedule, findings, remediation status — not a one-time assessment PDF.

Illustrative mapping of selected obligations to example controls and evidence. Starting set pending expert review. Not legal advice. Does not certify compliance.

30-day pilot

Start with one meaningful clinical AI system.

1–3 AI applications or workflows · 5–15 agreed controls · one framework or internal policy set · continuous verification · exception and evidence review · executive findings. No promised legal outcome.

Week 1

Scope & controls

Agree the systems, the control set, and what “verified” means for each.

Week 2

Wire verification

Connect classification context and verification checks to the live estate.

Week 3

Run & exceptions

Continuous checks surface exceptions; owners review and remediate.

Week 4

Evidence pack

Hand over timestamped findings your hospital buyers can actually read.

Book a 30-day pilot

Advisory tool only. Not legal advice. RiskLine does not certify regulatory compliance. We will not publish your organisation without written permission.

FAQ

Straight answers

Is RiskLine a certification or legal-compliance product?

No. It is an advisory verification layer. It helps you operationalise and continuously check defined controls. It does not certify EU AI Act compliance and is not legal advice.

Does classification or verification use an LLM for the verdict?

No. Classification and verification verdicts are deterministic and driven by a versioned ruleset. Optional document helpers elsewhere may use an LLM and are labelled as such.

Who is this one-pager for?

EU healthcare AI vendors whose hospital and health-system customers ask for ongoing assurance. Other sectors and regulations can be added later without rewriting the product story.

What does a 30-day pilot include?

Typically 1–3 AI applications or workflows, 5–15 agreed controls, one framework or internal policy set, continuous verification, exception review, and executive findings. No promised legal outcome.

Do you replace our GRC or quality system?

No. RiskLine sits alongside GRC, security and observability. Keep those systems. Add continuous verification where you need evidence that controls still hold.

Will you name us as a customer?

Only with written marketing permission covering name, relationship and intended use. Until then, proof stays anonymised or labelled illustrative.

If a hospital can ask again next month, the evidence should already be there.

Book a 30-day pilot

Another sector or regulation?

This page is healthcare × EU AI Act on purpose. Tell us what you need — demand shapes what we open next.

Interest capture

Advisory tool only. Not legal advice. RiskLine does not certify regulatory compliance. We will not publish your organisation without written permission.