The EU AI Act in the medical practice: AI literacy under Art. 4 and what applies to documentation software
A practice that uses an AI system professionally is a deployer within the meaning of the AI Act, Regulation (EU) 2024/1689. For tools that are not classified as high-risk, one duty follows from that role above all: Art. 4 requires measures so that the people operating the system have a sufficient level of AI literacy. That rule has applied since 2 February 2025.

Reviewed editorially against product behaviour and the stated primary sources; not individual medical or legal advice.
This overview is general information, not legal advice. Which content, deadlines and forms apply to a specific practice should be clarified with the practice's own legal or data protection advisers.
Which role the practice has in the Regulation
Regulation (EU) 2024/1689 draws its main distinction between providers and deployers. Under Art. 3(4) a deployer is anyone using an AI system under their own responsibility, except where it is used in the course of a personal, non-professional activity. A practice using a tool in the consulting room is therefore a deployer — even if it only bought the tool.
The provider role stays with the manufacturer. It carries the heavier duties, on conformity and technical documentation among others. For the practice the decisive question is therefore not what duties exist in total, but which of them attach to the deployer role.
Art. 4: AI literacy, and what is meant by it
Art. 4 obliges providers and deployers to take measures to ensure, to their best extent, that their staff and other persons dealing with the operation and use on their behalf have a sufficient level of AI literacy. The provision names knowledge and experience, education and training, the context in which the systems are used, and the persons on whom they are used.
Art. 3(56) defines AI literacy as the skills, knowledge and understanding that allow systems to be deployed knowledgeably. That is deliberately not a certificate and not a number of training days, but an outcome: whoever operates the tool should know what it does, where it errs, and when an output has to be checked.
For a practice this is more a question of induction than of continuing education. Whoever records should be able to explain what is being captured; whoever reviews the draft should know that the review is the point at which a draft becomes documentation.
What applies since when
The Regulation was published in the Official Journal in July 2024 and entered into force in August 2024. Its application is staged, and the stages are set out in Art. 113.
- 2 February 2025: Chapters I and II — general provisions, prohibited practices and Art. 4.
- 2 August 2025: among others the rules on general-purpose AI models and the governance chapters.
- 2 August 2026: the rest of the Regulation.
- 2 August 2027: Art. 6(1) and the high-risk duties attached to it for regulated products.
When a tool counts as a high-risk system
Art. 6(1) ties classification to product law: a system is high-risk if it is a safety component of, or itself is, a product covered by the Union legislation listed in Annex I, and a third-party conformity assessment is required for that product. Annex I, Section A, point 11 names the Medical Devices Regulation (EU) 2017/745.
Alongside that stands Annex III with independently classified use cases. Its point 5 concerns access to essential services and names, under (d), certain systems used in emergency care. Documenting a consultation is not what is meant.
In practice this means classification runs through the intended purpose. A tool that makes no diagnosis and claims no medical purpose does not become a high-risk system by the Annex I route. Whether an application is a medical device is still decided under the Medical Devices Regulation, not under the AI Act.
What a practice can actually put on file
Art. 4 requires measures, not forms. A practice that still wants something in hand when asked is best served by collecting what arises anyway: who was inducted, on what, and what the tool does and does not do according to its provider.
- A short note on which people were inducted and when.
- The workflow the practice agreed on: consent, recording, review, carry-over.
- The limits of the tool as the provider describes them.
- Who decides, in case of doubt, that a draft is discarded.
- Where the data protection files sit that the GDPR requires in any case.
What the AI Act does not replace
The Regulation sits beside the existing rules. The data protection assessment still follows the GDPR, professional secrecy follows § 203 StGB, the documentation duty follows § 630f BGB. None of those assessments is settled by the AI Act, and none of them settles it.
Conversely, the AI Act does not turn a documentation tool into a medical device, nor a medical device into a harmless text tool. It adds a layer on which the practice mainly has to show one thing: that the people operating the system understand what they are working with.
Frequently asked questions
Does a medical practice have to register anything because of the AI Act?
For a tool that is not classified as high-risk, the Regulation provides no registration for deployers. The duty that follows from the deployer role is above all Art. 4: measures for a sufficient level of AI literacy.
Since when does Art. 4 apply?
Since 2 February 2025. Chapters I and II of the Regulation have applied from that date; the rest of the Regulation since 2 August 2026, and the duties under Art. 6(1) from 2 August 2027.
Is a documentation application a high-risk system?
Not simply because it runs in a practice. Art. 6(1) attaches to products under Annex I for which a third-party conformity assessment is required; Annex III lists its own use cases, and documenting a consultation is not among them.
Is a training session enough to satisfy Art. 4?
The provision requires measures that fit the context, and names knowledge, experience, education and training as factors. A documented induction into the practice's workflow is the obvious start; what is enough in a given case belongs with the practice's own legal advisers.
Does the AI Act apply if the model runs locally?
Yes. The Regulation attaches to the use of an AI system, not to where it computes. Where processing happens is a data protection question and is answered separately.