The Pipeline Gap: Why the EU AI Act, the Product Liability Directive and the Medical Device Regulation Do Not Reach Multi-Tool Clinical-AI Pipelines

17 August 2026, Version 1
This content is an early or alternative research output and has not been peer-reviewed by Cambridge University Press at the time of posting.

Abstract

Administrative artificial intelligence (AI) reaches primary care not as one tool but as a pipeline of interacting tools: scheduling, documentation, coding, billing, and referral, often with feedback loops between them. The regulatory timetable sharpens the question. Most of the EU AI Act applies from 2 August 2026, but the high-risk obligations that would reach clinical AI are deferred by the 2026 Digital Omnibus to 2 December 2027 for stand-alone Annex III systems and to 2 August 2028 for AI embedded in regulated products. An existing literature argues that the EU framework leaves gaps for medical AI. The contribution here is more specific: the gap sits at the level of the pipeline as a unit, and it is structural rather than incidental, because each principal instrument regulates a narrower unit. The AI Act regulates the individual system (Article 3(1)) and gates high-risk duties through Article 6 and Annex III, so most administrative clinical AI, being neither a device safety component nor an enumerated high-risk use, falls outside Articles 8 to 15. The recast Product Liability Directive (2024/2853) treats software as a product and considers interconnection, but still requires an identifiable defective product (Article 10(1)) and knows no correlated or systemic risk. The Medical Device Regulation gates on medical purpose (Article 2(1)), leaving administrative AI outside its scope. Four pipeline-level risks therefore fall between the three instruments: the pipeline as a regulated unit, cascade amplification, the ontological attack surface, and correlated systemic risk. We set out what a pipeline-level regime would require.

Keywords

AI governance
EU AI Act
Digital Omnibus
Product Liability Directive
Medical Device Regulation
clinical AI
regulatory gap
systemic risk
pipeline
ontological integrity
primary care

Comments

Comments are not moderated before they are posted, but they can be removed by the site moderators if they are found to be in contravention of our Commenting and Discussion Policy [opens in a new tab] - please read this policy before you post. Comments should be used for scholarly discussion of the content in question. You can find more information about how to use the commenting feature here [opens in a new tab] .
This site is protected by reCAPTCHA and the Google Privacy Policy [opens in a new tab] and Terms of Service [opens in a new tab] apply.