Case studies

    Pharma & healthcare

    Patient and trial data in the strictest category European law defines, validated systems built not to change, a cybersecurity law that has applied since August, and AI arriving in clinical and commercial workflows at the same time. We work inside those constraints rather than around them.

    Book a 30-minute executive briefing
    Relevant regulation or standard
    GDPR Article 9 special category data
    Relevant regulation or standard
    NIS2 / Cyberbeveiligingswet
    Relevant regulation or standard
    EU GMP Annex 11 and GxP validation
    Relevant regulation or standard
    EU AI Act
    Relevant regulation or standard
    ISO/IEC 27001 and ISO/IEC 42001

    Who we work with

    • Quality and compliance lead

      Owns validated systems and is being asked to approve tools that change monthly.

    • CISO or IT director

      Is now in scope of a law that puts duties on the board personally.

    • Clinical or medical affairs lead

      Holds data that cannot move, and questions that need answering from it.

    • Commercial director

      Wants the AI advantage without going anywhere near patient data.

    The hardest data in Europe, and the deadlines are real

    Health data is not ordinary personal data. It sits in GDPR's special categories, which means the processing needs a specific legal basis rather than a legitimate-interest argument, and a breach is judged against that standard. Everything downstream inherits the constraint — where a system may run, which supplier may host it, what a model may be shown — and no amount of enthusiasm about a use case changes it.

    The regulatory floor moved this summer. The Dutch Cyberbeveiligingswet came into force on 15 August 2026, with no transition period and roughly eight thousand organisations in scope, healthcare among them. In practice that means a duty of care you can be asked to evidence, an incident clock that starts at twenty-four hours, and — the part that changes the tone of a board meeting — accountability that sits with the management body personally, including a knowledge requirement with a deadline attached.

    Then there is the validated estate. A GxP-validated system is deliberately hard to change, because the validation *is* the assurance. Put a model inside a validated workflow and you have acquired a component that changes behaviour without a change request — a real conflict rather than a paperwork problem. It is solvable, usually by keeping the model outside the validated boundary and having a person carry the output across, but it has to be designed rather than discovered.

    Meanwhile AI arrives from two directions at once. Commercially — medical affairs, market access, field force, pharmacovigilance triage — where the value is large and the data is mostly not patient data. And clinically, where it is, and where the EU AI Act's high-risk rules meet the medical device rules. The first is where almost every organisation should start. The second is what almost every organisation starts talking about.

    We work in both and we are blunt about the boundary. Where a workload cannot legitimately leave a jurisdiction or a tenancy, that shapes the architecture on day one rather than at deployment. Where a supplier's contract does not say what happens to your data, we read the contract before anyone signs off a use case.

    What bites here

    Special category data, everywhere

    Patient, trial and occupational health data all fall in GDPR's Article 9 categories. The legal basis has to be specific, the retention justified, and 'we anonymised it' is a claim that gets tested rather than accepted.

    NIS2 in force, with personal accountability

    The Cyberbeveiligingswet has applied since 15 August 2026 with no transition period. Healthcare providers are in scope, early warning of a significant incident runs on a 24-hour clock, and the management body carries duties it cannot delegate away.

    Validation against iteration

    A validated system is built not to change; AI is built to change. Keeping both true means designing the boundary deliberately, before an auditor finds it for you.

    Suppliers inside the perimeter

    CROs, laboratories, logistics partners and software vendors all touch the data. Your obligations do not stop at your own perimeter, and neither do the questionnaires you are asked to complete.

    Shadow AI among highly qualified people

    Clinicians, scientists and medical writers under time pressure will use whatever helps. The workable response is an approved route with a fast approval, not a prohibition that moves the usage onto personal accounts where you cannot see it.

    What we do here

    01

    Evaluate

    Establish the position before committing to anything: where the data actually is, what the law now requires of this entity, and whether an AI use case is worth attempting at all.

    02

    Plan

    Decide the target state and sequence it against the calendar you actually have.

    03

    Enable

    Move the people who will have to work differently, and evidence it.

    04

    Build

    Implement inside the constraints rather than alongside them.

    05

    Operate

    Keep it defensible once it is live.

    Where this usually starts

    Two entry points, depending on which conversation is louder in your organisation. If it is the regulator — the Cyberbeveiligingswet, an ISO 27001 clause in a tender, a client questionnaire nobody can answer — start with the readiness assessment, because it produces the written position that everything afterwards references. If it is AI, start commercially rather than clinically. The highest-value early use cases in this sector sit in market access, medical information, pharmacovigilance triage and business development, where the data is not special category and the approval path runs in weeks rather than quarters. The clinical use cases are worth doing. They are not worth doing first.

    Questions

    Can we use AI on patient data at all?

    Yes, within a specific legal basis and with the processing located where your obligations allow. The more useful answer is that a first use case usually does not need patient data, and starting where it is not involved buys the organisational learning without the regulatory exposure.

    Does the Cyberbeveiligingswet apply to us?

    It is assessed per legal entity against sector, size and the criteria in the law, and healthcare is in scope. The determination should be written down with its reasoning, because the question will be asked again — by a regulator, an insurer or a client. That is day one of the readiness engagement.

    What about AI inside a validated system?

    Our default is to keep the model outside the validated boundary and have a person carry the output across, with the decision and its reasoning recorded. Where that is not possible, the change control and the revalidation trigger have to be designed with your quality function before anything is built.

    We supply pharma rather than being pharma. Does this reach us?

    Through the contract, almost certainly. Supplier questionnaires in this sector have become the de facto regulator: ISO 27001, an incident process, and increasingly a stated AI position. The work is the same, the driver is commercial rather than legal, and it usually arrives with a deadline attached to a renewal.

    Our data cannot leave the country. Is that workable?

    Yes, and it belongs in the architecture session rather than the deployment meeting. Where residency or tenancy is a hard constraint, it determines the model choice and the hosting — which is what the sovereign hosting engagement exists for.

    Leave with your top three risks documented

    Thirty minutes with a senior practitioner. No slideware, no sales engineer.