AI system and health: how to meet your information obligations? (GDPR, IA Act, CSP)
The use of artificial intelligence systems (AIS) in health imposes on professionals a triple obligation to provide information: the Public Health Code (CSP) for care, the GDPR for personal data, and the IA Act for the transparency of systems. To ensure their compliance, institutions must adopt graded (general, specific and comprehensive) and pedagogical communication. The objective is to guarantee transparency, to respect the right to explanation and to maintain patient-practitioner trust throughout the care journey.
.png)
Health professionals have More and more use of artificial intelligence systems (in fact, the “SIA”) as part of their practices and care.
However, as deployers of these systems (under the AI Act) and responsible for the processing of their patients' personal data (under the GDPR), health professionals are subject to several information obligations. The latter are also accompanied by the information obligations applicable to care, resulting from the Public Health Code.
The aim of the article is to provide keys to professionals in order to help them. To identify and to ensure their various information obligations with their patients.
The legal framework for the use of an AIS in the care system
Communication with the patient is governed by several texts. The Public Health Code requires in particular to inform the patient about his state of health and the treatments offered (article L.1111-2 of the CSP).
The requirements of the Public Health Code and the right to algorithmic information
Since 2021, article L.4001‑3 of the CSP also provides A specific right to information When the doctor uses a medical device With an “algorithmic” function As part of a preventive, diagnostic or care act (definition which may correspond to an AIS).
Transparency according to the GDPR and the EDPS guidelines
The GDPR requires any data controller (here the health institution or the practitioner) to inform the person of the characteristics of the processing of their personal data, in accordance with articles 12 to 14 of the GDPR (purpose of the treatment, categories of data collected, categories of data collected, categories of data collected, categories of data collected, categories of data collected, categories of data collected, recipients, storage period, rights, etc.). The EDPS (formerly W29) also published Guidelines on Transparency Measures to be Adopted with respect to persons concerned by data processing.
The draft guide recently published by the HAS and the CNIL (currently in public consultation) on the use of SIA in the field of care includes A sheet dedicated to the information of individuals and to consent. This Last Guide Recognizes The multiplicity of information obligations Relying on the health professional.
What's new in the AI Act: right to explanation and transparency of chatbots
The Artificial Intelligence Regulation (“RIA”, “IA Act”) recognizes A Right to Explanation for any individual decision based on an AIS (article 86 RIA), as well as the possibility for the patient to File a Complaint with the Supervisory Authority (Article 85 RIA).
These rights Are in addition to the rights provided by the RGPD (access, rectification, deletion, limitation, limitation, limitation, opposition, complaint to the CNIL). If the patient interacts directly with the AIS (e.g. chatbot for medical information), he must also be clearly Informed of the Generation of Responses by an AIS (article 50 of the RIA).
Beyond these obligations, the HAS and the CNIL emphasize that Transparency is essential to demystify AIS and maintain patient-professional trust. French European and national texts have thus provided for a detailed catalog of rules concerning information to individuals in the context of the use of an AIS in the field of care. Transparency is thus achieved at various levels.
Typology and levels of information to be provided to the patient
It is necessary To differentiate and deliver in an appropriate manner information at various levels. The aforesaid draft guide of the HAS and the CNIL provides in particular for the following information obligations:
General information on the use of AIS and secondary uses
- General information on the use of AI in healthcare: The aim is to inform all patients that AIS can be used in their career (radiological diagnosis, decision support, etc.). For example, a simple message can be broadcast in the welcome booklet or displayed in the waiting room: “As part of your care, artificial intelligence systems can be used to improve your diagnosis. For more information, consult our website or contact the reception” (recommendation 7.2 of the guide)
- Information on secondary data re-uses: If the data collected as part of the care is reused (improvement of the AIS model, health research, etc.), the patient must be informed accordingly, as soon as the data is collected. Secondary use refers to secondary treatments that are considered distinct and subject in themselves to compliance with all applicable obligations under the GDPR.
Specific Information on Personal Data and the Exercise of Rights
- Information on the use of personal data: In accordance with the RGPD, the patient must know the identity of the data controller, the purpose of the treatment, the categories of data used (clinical data, imaging, biological information, etc.), the recipients of the data (AIS provider, health organizations), the storage periods, the health organizations), the storage periods, the storage periods, their rights and the contact details of the DPO. This information must be provided before any data is processed. It should be understandable and easily accessible.
- Information on patients' rights: patients must be informed of their rights to health data (right of access, modification, modification, deletion, opposition, limitation, etc.) and the procedures for exercising them (transparency portal, DPO contact, CNIL appeal). The HAS and CNIL guide also mentions the right to complain (CNIL, market authority) and the right to explanation if they find that an individual decision has been taken with the help of an SIA (article 86 of the RIA), applicable within the framework of the RIA
This information, which is distinct in its substance, must be formalized in various media in order to ensure the effectiveness of the transparency obligation.
Good practices and modalities for the dissemination of medical information
The HAS and CNIL Guide focuses on the need to carry out educational communication, By Avoiding Technical Vocabulary Everything With an Emphasis on Benefits That the person concerned can derive from it (guarantee of efficiency, security, assistance, speed, etc.).
Gradation of Information: From the Welcome Booklet to the Medical Report
In addition, the guide proposes a gradation of information into three levels:
- General information: Information messages must be distributed to all patients in waiting rooms, on the website, on posters or other supports in order to indicate the possible presence of AI as part of the care process
- Specific information for the person concerned: When an AIS has been used as part of the care process, the report or any other medical documentation must include a statement detailing the use of an AIS, the purpose of the system, its name and version, as well as the doctor who validated the tool. Other measures can also be considered, such as videos or explanatory booklets.
- Extensive prior information: In the case of using a high-risk AIS as defined by the RIA, complete information must be given before using the system if the use of the system may involve a risk to the rights of individuals
Traceability and proof of information in the patient file
The traceability of information measures, in particular for the purposes of proof of the fulfilment of their obligations by the health professional or his institution, can in particular be traced within the patient's medical file. Healthcare personnel are also involved in providing information, adapting to the characteristics of the patient and his expectations.
In addition, consideration should be given toThe multiplicity of shapes and supports To the information of people in the context of the use of SIA in care. Delivering information in several formats and at different points in the care journey can allow patients To better integrate and understand how the AIS works and the processing carried out of his personal data.
Practical aspects such as the choice of supports, the training of healthcare personnel and procedures Ensuring Effectiveness of Rights Are measures Strictly necessary to be implemented by health institutions concerned. These aspects will be the subject of a dedicated webinar, co-hosted by Aumans Avocats and Adequacy April 16, 2026, in order to help institutions to develop their SIA projects and to support them in their regulatory compliance process. Sign up now.
FAQ - AI system and information requirements (health sector)
Why inform patients about the use of AI in health?
Information is a legal obligation that combines compliance with the GDPR, the IA Act and the Public Health Code. It ensures the transparency of care, maintains patient-practitioner trust and ensures respect for fundamental rights to health data.
What are the obligations of the IA Act for Health Professionals?
The IA Act imposes a right to explanation for any individual decision based on an AIS (section 86) and the obligation to clearly inform the patient if he interacts with an AI, such as a medical chatbot (section 50).
How to prove that the patient has been informed of the use of an AIS?
The traceability of information can be ensured by specific mentions in the patient's medical file, the inclusion of clauses in the welcome booklets or the delivery of reports detailing the tool used and the doctor who validated the results.


