Health data is not ordinary personal data. It sits in GDPR's special categories, which means the processing needs a specific legal basis rather than a legitimate-interest argument, and a breach is judged against that standard. Everything downstream inherits the constraint — where a system may run, which supplier may host it, what a model may be shown — and no amount of enthusiasm about a use case changes it.
The regulatory floor moved this summer. The Dutch Cyberbeveiligingswet came into force on 15 August 2026, with no transition period and roughly eight thousand organisations in scope, healthcare among them. In practice that means a duty of care you can be asked to evidence, an incident clock that starts at twenty-four hours, and — the part that changes the tone of a board meeting — accountability that sits with the management body personally, including a knowledge requirement with a deadline attached.
Then there is the validated estate. A GxP-validated system is deliberately hard to change, because the validation *is* the assurance. Put a model inside a validated workflow and you have acquired a component that changes behaviour without a change request — a real conflict rather than a paperwork problem. It is solvable, usually by keeping the model outside the validated boundary and having a person carry the output across, but it has to be designed rather than discovered.
Meanwhile AI arrives from two directions at once. Commercially — medical affairs, market access, field force, pharmacovigilance triage — where the value is large and the data is mostly not patient data. And clinically, where it is, and where the EU AI Act's high-risk rules meet the medical device rules. The first is where almost every organisation should start. The second is what almost every organisation starts talking about.
We work in both and we are blunt about the boundary. Where a workload cannot legitimately leave a jurisdiction or a tenancy, that shapes the architecture on day one rather than at deployment. Where a supplier's contract does not say what happens to your data, we read the contract before anyone signs off a use case.