REVIEW 3 major objections 4 minor 8 references
Getting Ready for the EU AI Act in Healthcare. A call for Sustainable AI Development and Deployment
T0 review · 3 major / 4 minor · reviewed 2026-08-15 · deepseek-v4-flash
Pith's one-line read Healthcare AI developers should start ethics-based trustworthiness assessments now, before the EU AI Act's high-risk provisions bind in August 2026, treating compliance as substance rather than box-ticking.
desk verdict A useful, clearly written position paper on preparing for the EU AI Act in healthcare, whose main weakness is that it recommends the authors' own assessment framework on evidence it concedes is thin. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The central mechanism is the proactive trustworthy-AI assessment, exemplified by the Z-Inspection methodology: a domain-specific, multidisciplinary process that identifies ethical tensions and risks rather than ticking formal boxes. It is claimed to prepare the organisational and administrative steps of AI Act compliance, including risk management, documentation, human oversight, and post-deployment monitoring. A second load-bearing element is the Act's own timeline, which creates a two-year window from entry into force in August 2024 to high-risk applicability in August 2026, with 2030 for public-administration systems, and the paper uses this timeline to argue for immediate action.
What would settle it
A concrete test would compare organisations that run Z-Inspection-style ethical assessments before August 2026 with those that adopt a formalistic compliance checklist: if the former show no better conformity-assessment outcomes, clinical performance, or patient trust after the Act binds, the proactive strategy's added benefit is not demonstrated.
Extended reading notes
Core claim
The central claim is that full and effective compliance with the EU AI Act in the medical domain requires a proactive, value-driven engagement with trustworthy-AI principles, not a minimal, sanction-avoiding reading of the regulation. Because the high-risk regime applies to medical devices, diagnostics, prediction, screening, and triage systems, and because systems substantially modified after August 2026 or used by public administrations by 2030 must comply, the authors argue that mapping AI systems against the Act and running ethics-based assessments now is necessary. The paper treats ethical trustworthiness assessment as the interpretive bridge between the Act's abstract requirements and concrete documentation, quality metrics, and certification procedures.
Load-bearing premise
The argument depends on the premise, which the paper admits has limited empirical support, that proactive ethics-based trustworthiness assessments actually improve system quality, validity, and public trust in ways that translate into AI Act compliance documentation.
Editorial extensions
If this is right
- Healthcare organisations should map all current, planned, and legacy AI systems to determine which qualify as high-risk under Annex III of the AI Act, including triage, diagnostic, prediction, and screening tools.
- Running trustworthy-AI assessments such as Z-Inspection before August 2026 can produce the documentation and governance structures that later conformity assessment will require.
- Voluntary participation in the AI Pact, including governance strategy, system mapping, and staff AI-literacy training, helps prepare organisations for full enforcement.
- Compliance should be maintained over time through post-deployment monitoring, feedback from clinicians and patients, and reassessment after substantial modifications.
- Integrated compliance with the GDPR, the Medical Device Regulation, and the European Health Data Space is needed because these instruments overlap with the AI Act in clinical practice.
Reading between the lines
- If early ethical assessment becomes the routine route to compliance documentation, early adopters are likely to shape emerging standard practice, since the Act leaves room for interpretation of how ethical principles translate into technical requirements.
- The same proactive logic could generalise beyond the EU: jurisdictions now drafting risk-based AI rules may adopt similar timelines, making Z-Inspection-style assessments a transferable compliance scaffold for global medical AI vendors.
- A testable extension would track whether organisations that begin assessments before the deadline produce conformity dossiers that are accepted faster or yield fewer post-market safety signals than those that wait until August 2026.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper is a position/call-to-action piece aimed at healthcare AI developers and deployers, arguing that proactive ethical trustworthiness assessment is necessary to prepare for the EU AI Act's high-risk system obligations that become applicable in August 2026. It reviews the AI Act's timeline, identifies high-risk healthcare applications (emergency triage, AI-enabled medical devices), and emphasizes the relevance of Recital 7 and the AI HLEG ethics guidelines. It recommends that organizations map their systems, run ethics-based assessments (exemplified by Z-Inspection®), develop AI governance strategies, join the AI Pact, and engage cross-disciplinary expertise. The paper claims that such proactive, value-driven compliance improves system quality and public trust while avoiding formalistic box-ticking, and concludes with concrete recommendations for before and after August 2026.
Significance. If the paper's central claim is accepted, it offers a practical, value-driven pathway for healthcare AI compliance with the EU AI Act, potentially influencing how providers and developers prepare for August 2026. The paper is strongest where it accurately summarizes the AI Act's schedule, high-risk categories, and overlaps with GDPR, MDR, and EHDS (Table 1), and where it highlights the AI Pact's voluntary early-compliance mechanism. These elements are genuinely useful to the target audience. However, the paper's prescriptive core rests on the unsubstantiated premise that ethics-based assessments such as Z-Inspection® produce outputs that materially support legal compliance and improve long-term outcomes. The evidence offered is self-cited, and the paper itself concedes the limited empirical basis. The significance of the recommendation therefore remains conditional on future work demonstrating the translational validity of such assessments.
major comments (3)
- [Why perform a Trustworthy AI Assessment before the day the EU AI Act becomes binding?] The paper's central claim that proactive trustworthiness assessments enhance system quality, validity, and public trust is load-bearing, yet it is supported only by self-cited prior work (Zicari et al., 2022; Wirth et al., 2025) and a multi-agent LLM study (de Cerqueira et al., 2024) that does not test Z-Inspection® or involve medical deployment. The paper itself states that 'there is still limited empirical evidence available on how these assessments impact long-term system performance or public trust in real-world clinical use.' This admission is in direct tension with the later recommendation that such assessments be initiated before August 2026. The manuscript should either present independent empirical support or reframe the recommendation as a research hypothesis, clearly labeling the lack of evidence as an uncertainty rather than an established benefit.
- [Ethics-based assessments and AI Act compliance: the case of Z-Inspection®] The manuscript claims that Z-Inspection® 'may set the stage' for AI Act compliance, but it never demonstrates how Z-Inspection® outputs map to the Act's specific high-risk obligations: risk management, data governance, technical documentation, record keeping, transparency, human oversight, accuracy, robustness, cybersecurity, quality management, and post-market monitoring. Without this mapping, the recommendation risks producing exactly the 'unnecessary, excessive bureaucratic processes' the paper warns against, because an ethics assessment would run parallel to, rather than feed, the formal conformity assessment. Provide a concrete traceability table or a worked example linking Z-Inspection® deliverables to at least one or two articles of the AI Act (e.g., Articles 9 and 14), or explicitly state that no such mapping currently exists and that this is a key future direction.
- [Ethics-based assessments and AI Act compliance: the case of Z-Inspection®] The manuscript is authored 'on behalf of the Z-Inspection® Initiative,' and its strongest recommendation is to adopt Z-Inspection® as the exemplary methodology. While self-advocacy is not disqualifying, the paper should address this direct conflict of interest. The absence of any independent, critical comparison with alternative trustworthiness assessment frameworks (e.g., FUTURE-AI, which is cited only in passing) makes the recommendation appear promotional rather than evidence-based. Either include a balanced comparison of available methodologies or clearly disclose that the authors are the developers of the recommended tool and that independent validation is required before it can be regarded as a compliance-ready method.
minor comments (4)
- [The AI Act and the healthcare domain] Table 1 is referenced in the text ('see Table 1, which illustrates overlaps relevant for compliance in clinical practice') but no table content is provided in the manuscript; please include the actual table or remove the cross-reference.
- [The AI Act and the healthcare domain] There are several typos: 'in vitro diagnostic medical devices' is written as 'n vitro'; 'MDR' is once written as 'MRD'; 'LLMS' should be 'LLMs'; 'quality of of life' contains a duplicated 'of'; and 'complaint procedures' should likely be 'compliance procedures.'
- [The schedule of the AI Act and proactive initiatives to be taken] The sentence 'Such tensions must be recognised and addressed in the attempt to provide a proportionate outcome, which implements the ethical values of trustworthy AI, consistently with the fundamental principles of EU law.' would benefit from breaking into two sentences for clarity; the grammar is convoluted.
- [References] The reference to the European Commission's AI Pact is incomplete; please provide a full citation with a URL or document identifier, as is done for the other legislation.
Circularity Check
Z-Inspection® recommendation rests on the authors' own prior work, but the proactive-compliance argument retains independent regulatory grounding.
-
self citation load bearing
[Section 'Ethics-based assessments and AI Act compliance: the case of Z-Inspection®', third paragraph; echoed in the Conclusion's future-directions list.]
"Research involving the Z-Inspection® process has revealed that systematic assessments help identify ethical risks and improve systemdesign. Applying this process in healthcare AI systems led to better alignment with ethical principles and increased stakeholder trust (Zicari et al., 2022)."
The only cited evidence for Z-Inspection®'s effectiveness is Zicari et al. (2022), a paper authored by the present paper's author R. Zicari and produced within the Z-Inspection® Initiative; the manuscript is explicitly signed 'On behalf of the Z-Inspection® Initiative'. The conclusion then converts this self-cited claim into a directive: 'Initiate internal trustworthy AI assessments for each high-risk system, using established methodologies (e.g., Z-Inspection®).' Thus the method-specific recommendation is load-bearing on the authors' own prior characterization of their own method, without independent validation. The paper does cite external work (e.g., de Cerqueira et al. 2024; Wirth et al. 2025) for the general value of ethics assessment, but not for Z-Inspection® specifically.
full rationale
This is a policy/position paper rather than a formal derivation, so the only candidate circularity is the self-referential support for the recommended methodology. The broad thesis—that developers and deployers should begin proactive compliance work before August 2026—is independently grounded in the AI Act's own transition schedule and the European Commission's AI Pact. External sources such as Lekadir et al. (2025) and Wirth et al. (2025) support the general claim that ethics assessment can improve AI systems. However, the specific claim that Z-Inspection® assessments 'led to better alignment with ethical principles and increased stakeholder trust' is supported solely by Zicari et al. (2022), whose first author is the present paper's author and which is the methodological home of Z-Inspection®. The conclusion then converts this self-cited claim into a directive to use Z-Inspection® for high-risk systems, making the method-specific recommendation load-bearing on a self-citation. The paper itself concedes only 'limited empirical evidence' for long-term impacts, further indicating that the effectiveness claim is not independently established. Score 4: the central proactive-compliance argument has independent regulatory content, but the 'how' recommendation is substantially self-referential.
Assumptions & free parameters
assumptions (3)
- domain assumption The AI HLEG ethics guidelines can legitimately be used to interpret and apply the AI Act's provisions.
- domain assumption Ethics and trustworthiness assessments during development improve system reliability, validity, and acceptance.
- ad hoc to paper Z-Inspection® is an appropriate and sufficient methodology for preparing AI Act compliance in healthcare.
Cite this review
Pith. "Pith review of Getting Ready for the EU AI Act in Healthcare. A call for Sustainable AI Development and Deployment." pith.science (2026). https://pith.science/paper/IV2HOVVV
@misc{pith2026250507875,
author = {Pith},
title = {Pith review of: Getting Ready for the EU AI Act in Healthcare. A call for Sustainable AI Development and Deployment},
year = {2026},
howpublished = {\url{https://pith.science/paper/IV2HOVVV}},
note = {Machine review of arXiv:2505.07875}
}
read the original abstract
Assessments of trustworthiness have become a cornerstone of responsible AI development. Especially in high-stakes fields like healthcare, aligning technical, evidence-based, and ethical practices with forthcoming legal requirements is increasingly urgent. We argue that developers and deployers of AI systems for the medical domain should be proactive and take steps to progressively ensure that such systems, both those currently in use and those being developed or planned, respect the requirements of the AI Act, which has come into force in August 2024. This is necessary if full and effective compliance is to be ensured when the most relevant provisions of the Act become effective (August 2026). The engagement with the AI Act cannot be viewed as a formalistic exercise. Compliance with the AI Act needs to be carried out through the proactive commitment to the ethical principles of trustworthy AI. These principles provide the background for the Act, which mentions them several times and connects them to the protection of public interest. They can be used to interpret and apply the Act's provisions and to identify good practices, increasing the validity and sustainability of AI systems over time.
Reference graph
Works this paper leans on
-
[1]
An overview of the EU AI Act compared to existing healthcare regulatory frameworks (GDPR, MDR, EHDS). The schedule of the AI Act and proactive initiatives to be taken As noted above, the AI Act came into force on 1 August 2024, with delayed applicability for certain provisions. However, some important parts have already become effective, such as the ban o...
work page 2024
-
[6]
Lekadir, K., Frangi, A. F., Porras, A. R., Glocker, B., Cintas, C., Langlotz, C. P., ... & Starmans, M. P. (2025). FUTURE-AI: International consensus guideline for trustworthy and deployable artificial intelligence in healthcare. BMJ,
work page 2025
-
[8]
(pp. 7-1). Schloss Dagstuhl–Leibniz-Zentrum für Informatik. Zicari, R. V., Amann, J., Bruneault, F., Coffee, M., Düdder, B., Hickman, E., ... & Wurth, R. (2022). How to assess trustworthy AI in practice. arXiv preprint arXiv:2206.09887. Legislation EU (2024) AI Act. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 la...
arXiv 2022
-
[388]
T., Maftei, M., Martín-Peña, R
Wirth, C. T., Maftei, M., Martín-Peña, R. E., & Merget, I. (2025). Towards Trusted AI: A Blueprint for Ethics Assessment in Practice (Academic Track). In Symposium on Scaling AI Assessments (SAIA
work page 2025
-
[2024]
This is necessary if full and effective compliance is to be ensured when the most relevant provisions of the Act become effective (August 2026). The engagement with the AI Act cannot be viewed as a formalistic exercise. Compliance with the AI Act needs to be carried out through the proactive commitment to the ethical principles of trustworthy AI. These pr...
work page 2026
-
[2025]
On 2 August 2025, certain provisions concerning general-purpose AI systems will also become applicable, followed by specific rules regarding governance obligations and related sanctions. The key provisions for the medical domain—i.e., those on high-risk systems—will take effect only on 1 August 2026, exactly two years after the Act entered into force. Thi...
work page 2025
-
[2026]
These will require compliance with detailed obligations around risk management, transparency, and ethical alignment. • High-risk AI systems in healthcare include emergency triage tools, AI-driven medical diagnostics, prediction and screening tools, and further AI-enabled medical devices. These must undergo rigorous certification and documentation procedur...
arXiv 2024
-
[2030]
Thus, in any case, high-risk systems should be made compliant as early as possible. The proactive attitude includes, first of all, examining what AI applications in healthcare are being used, developed or planned for, and considering how they fit into the AI Act, and importantly, whether they fall under the class of high-risk systems. Should that be the c...
work page 2025
Reviewed August 15, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.