Skip to main content An official website of the United States government Here's how you know Here's how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock Locked padlock icon ) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites. Search Log in Dashboard Publications Account settings Log out Search… Search NCBI Primary site navigation Search Logged in as: Dashboard Publications Account settings Log in Search PMC Full-Text Archive Search in PMC Journal List User Guide PERMALINK Copy As a library, NLM provides access to scientific literature. Inclusion in an NLM database does not imply endorsement of, or agreement with, the contents by NLM or the National Institutes of Health. Learn more: PMC Disclaimer | PMC Copyright Notice Virchows Arch . 2025 Oct 17;488(4):789–799. doi: 10.1007/s00428-025-04291-3 Search in PMC Search in PubMed View in NLM Catalog Add to search Practical consequences of the European union-AI act for anatomic pathology laboratories a European society of pathology and European society of digital and integrative pathology commissioned expert opinion paper Frederik Deman Frederik Deman 1 PA2, Dept. of Pathology, Ziekenhuis aan de Stroom (ZAS), Antwerp, Belgium 2 Department of Diagnostic Sciences, Faculty of Medicine and Health Sciences, University of Ghent, Ghent, Belgium Find articles by Frederik Deman 1, 2, ✉, # , Sofia Palmieri Sofia Palmieri 3 Metamedica, University of Ghent, Ghent, Belgium Find articles by Sofia Palmieri 3, # , Glenn Broeckx Glenn Broeckx 1 PA2, Dept. of Pathology, Ziekenhuis aan de Stroom (ZAS), Antwerp, Belgium 4 Centre for Oncological Research (CORE), MIPPRO, Faculty of Medicine, Antwerp University, Antwerp, Belgium Find articles by Glenn Broeckx 1, 4 , Thomas Van Den Berghe Thomas Van Den Berghe 2 Department of Diagnostic Sciences, Faculty of Medicine and Health Sciences, University of Ghent, Ghent, Belgium 5 Department of Radiology and Medical Imaging, University Hospital Ghent, Ghent, Belgium 8 RheumaFinder BV, Ghent, Belgium Find articles by Thomas Van Den Berghe 2, 5, 8 , Inti Zlobec Inti Zlobec 9 Faculty of Medicine, Department Digital Medicine, University of Bern, Bern, Switzerland 10 Institute of Tissue Medicine and Pathology Murtenstrasse 31, University of Bern, Bern, CH-3008 Switzerland 19 European Society of Pathology (ESP), Bruxelles, Belgium 20 European Society of Digital and Integrative Pathology (ESDIP), Lisboa, Portugal Find articles by Inti Zlobec 9, 10, 19, 20 , Peter Schirmacher Peter Schirmacher 11 Institute of Pathology Heidelberg, Heidelberg University, Heidelberg, Germany 19 European Society of Pathology (ESP), Bruxelles, Belgium Find articles by Peter Schirmacher 11, 19 , Sara P Oliveira Sara P Oliveira 12 Computational Pathology Group, The Netherlands Cancer Institute, Amsterdam, The Netherlands 19 European Society of Pathology (ESP), Bruxelles, Belgium 20 European Society of Digital and Integrative Pathology (ESDIP), Lisboa, Portugal Find articles by Sara P Oliveira 12, 19, 20 , Luca Di Tommaso Luca Di Tommaso 13 Pathology Unit, IRCCS Humanitas Research Hospital, Rozzano, Milan, Italy 14 Department of Biomedical Sciences, Humanitas University, Pieve Emanuele, Milan, Italy 19 European Society of Pathology (ESP), Bruxelles, Belgium Find articles by Luca Di Tommaso 13, 14, 19 , Norman Zerbe Norman Zerbe 15 Institute of Pathology, RWTH Aachen University Hospital, Aachen, Germany 16 Institute of Medical Informatics, Charité - Universitätsmedizin Berlin, corporate member of Freie Universität Berlin and Humboldt Universität zu Berlin, Berlin, Germany 20 European Society of Digital and Integrative Pathology (ESDIP), Lisboa, Portugal Find articles by Norman Zerbe 15, 16, 20 , Vincenzo L’Imperio Vincenzo L’Imperio 17 School of Medicine and Surgery, University of Milano-Bicocca, Milan, Italy 18 Department of Pathology, Fondazione IRCCS San Gerardo dei Tintori, Monza, Italy 20 European Society of Digital and Integrative Pathology (ESDIP), Lisboa, Portugal Find articles by Vincenzo L’Imperio 17, 18, 20 , Sabine Declercq Sabine Declercq 1 PA2, Dept. of Pathology, Ziekenhuis aan de Stroom (ZAS), Antwerp, Belgium Find articles by Sabine Declercq 1 , Marc Van Den Bulcke Marc Van Den Bulcke 21 Belgian Cancer Centre, Sciensano, Brussels, Belgium Find articles by Marc Van Den Bulcke 21 , Anouk Waeytens Anouk Waeytens 21 Belgian Cancer Centre, Sciensano, Brussels, Belgium Find articles by Anouk Waeytens 21 , Roberto Salgado Roberto Salgado 1 PA2, Dept. of Pathology, Ziekenhuis aan de Stroom (ZAS), Antwerp, Belgium 6 Division of Research, Peter Mac Callum Cancer Centre, Melbourne, Australia Find articles by Roberto Salgado 1, 6 , Amélie Dendooven Amélie Dendooven 2 Department of Diagnostic Sciences, Faculty of Medicine and Health Sciences, University of Ghent, Ghent, Belgium 4 Centre for Oncological Research (CORE), MIPPRO, Faculty of Medicine, Antwerp University, Antwerp, Belgium 7 Dept. of Pathology, University Hospital Ghent, Ghent, Belgium Find articles by Amélie Dendooven 2, 4, 7 Author information Article notes Copyright and License information 1 PA2, Dept. of Pathology, Ziekenhuis aan de Stroom (ZAS), Antwerp, Belgium 2 Department of Diagnostic Sciences, Faculty of Medicine and Health Sciences, University of Ghent, Ghent, Belgium 3 Metamedica, University of Ghent, Ghent, Belgium 4 Centre for Oncological Research (CORE), MIPPRO, Faculty of Medicine, Antwerp University, Antwerp, Belgium 5 Department of Radiology and Medical Imaging, University Hospital Ghent, Ghent, Belgium 6 Division of Research, Peter Mac Callum Cancer Centre, Melbourne, Australia 7 Dept. of Pathology, University Hospital Ghent, Ghent, Belgium 8 RheumaFinder BV, Ghent, Belgium 9 Faculty of Medicine, Department Digital Medicine, University of Bern, Bern, Switzerland 10 Institute of Tissue Medicine and Pathology Murtenstrasse 31, University of Bern, Bern, CH-3008 Switzerland 11 Institute of Pathology Heidelberg, Heidelberg University, Heidelberg, Germany 12 Computational Pathology Group, The Netherlands Cancer Institute, Amsterdam, The Netherlands 13 Pathology Unit, IRCCS Humanitas Research Hospital, Rozzano, Milan, Italy 14 Department of Biomedical Sciences, Humanitas University, Pieve Emanuele, Milan, Italy 15 Institute of Pathology, RWTH Aachen University Hospital, Aachen, Germany 16 Institute of Medical Informatics, Charité - Universitätsmedizin Berlin, corporate member of Freie Universität Berlin and Humboldt Universität zu Berlin, Berlin, Germany 17 School of Medicine and Surgery, University of Milano-Bicocca, Milan, Italy 18 Department of Pathology, Fondazione IRCCS San Gerardo dei Tintori, Monza, Italy 19 European Society of Pathology (ESP), Bruxelles, Belgium 20 European Society of Digital and Integrative Pathology (ESDIP), Lisboa, Portugal 21 Belgian Cancer Centre, Sciensano, Brussels, Belgium ✉ Corresponding author. # Contributed equally. Received 2025 May 2; Revised 2025 Sep 19; Accepted 2025 Sep 27; Issue date 2026. © The Author(s) 2025 Open Access This article is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License, which permits any non-commercial use, sharing, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons licence, and indicate if you modified the licensed material. You do not have permission under this licence to share adapted material derived from this article or parts of it. The images or other third party material in this article are included in the article’s Creative Commons licence, unless indicated otherwise in a credit line to the material. If material is not included in the article’s Creative Commons licence and your intended use is not permitted by statutory regulation or exceeds the permitted use, you will need to obtain permission directly from the copyright holder. To view a copy of this licence, visit http://creativecommons.org/licenses/by-nc-nd/4.0/ . PMC Copyright notice PMCID: PMC13053491 PMID: 41102487 Abstract The European Union Artificial Intelligence Act (AI Act) introduces a landmark regulatory framework governing the development, deployment, and post-marketing requirements and maintenance of AI systems, with growing relevance for the field of digital pathology. This paper explores the practical implications of the AI Act for pathology laboratories, particularly in relation to high-risk AI tools used in diagnostic workflows. We outline the Act’s risk-based classification approach and highlight key obligations for both AI developers and users, including requirements for transparency, explainability, risk management, data governance, human oversight, and staff training. Special attention is given to how these regulatory demands relate to existing healthcare standards and implemented quality systems in anatomic pathology laboratories. By translating the AI Act’s legal language into concrete, pathology-specific recommendations, this work provides guidance supporting safe and effective AI integration in clinical practice. While the legislation introduces operational and administrative challenges, it also presents an opportunity to enhance accountability, trust, and innovation in pathology. This paper aims to equip anatomic pathology laboratories with the tools and insights needed to responsibly navigate the evolving regulatory landscape of AI in healthcare. Keywords: AI, Legislation, Pathology, Guidance Introduction Artificial intelligence (AI) is already commonly used in everyday life. In the next years, its use will dramatically increase in any professional fields; however, despite the great interest in so-called artificial general intelligence, which should match or surpass human capabilities, the most likely scenario is that of widespread use of artificial narrow intelligence whose competence is confined to well-defined tasks. Many jobs will thus change significantly, and the demand for AI-literate skills for professionals will be higher. AI in digital pathology refers to the application of advanced computational algorithms and machine-learning techniques on digitalized slides. The scope of AI in digital pathology encompasses various tasks, including automated tissue classification for diagnostics, quantitative analysis of biomarkers, prognostic or therapeutic predictions based on image analysis, quality control, workflow management, and generative AI chatbots providing assistance during the diagnostic process [ 1 – 4 ]. These AI-driven approaches aim to augment human capabilities, reduce interobserver variability, and expedite large-scale pathology dataset analysis. AI algorithms may identify patterns in tissue not apparent so far and/or link histological features to other patient data (including medical history, laboratory tests, and radiology images) leading to earlier disease detection and personalized improved diagnostics and treatment strategies. As the field evolves, AI in digital pathology is expected to play a role in supporting clinical decision-making, facilitating research, and advancing precision medicine. Beyond opportunities, the application of AI in digital pathology will face major challenges, such as ethical and legal issues—including concerns about accountability and informed consent; privacy and data security—particularly in relation to the use of whole-slide images and sensitive patient information in model training and deployment; cultural and organizational barriers—such as resistance to change and lack of AI literacy among pathologists; regulatory and clinical validation—involving the need for rigorous clinical trials, standardization, and regulatory approval to ensure safety. The main risk is that these challenges are addressed too slowly compared to the tumultuous speed with which AI in pathology is developing. The recent EU act on AI offers an excellent starting point for addressing the regulatory aspects through an “ESP and ESDIP commissioned expert opinion” paper. Because large-scale deployment is only beginning and technologies continue to evolve, robust safeguards remain essential, for example through quality control measures that pathology laboratories are progressively becoming familiar with (e.g., external validation on representative data, assessment of bias and generalizability, transparent documentation, human oversight, monitoring for performance drift, incident handling, disciplined change management for updates, interoperability, and audit trails). Pathology laboratories generally operate under comprehensive quality assurance and control measures outlined by ISO standards. Within this regulatory framework, any algorithm used in pathology must be rigorously validated to ensure compliance and diagnostic accuracy. In addition to existing standards, the new EU AI Act—Entering into full force as of mid-2027—introduces further legal obligations that must be integrated into laboratory operations. On the other hand, regulation should avoid becoming so restrictive that patients are delayed or prevented from benefiting from clinically validated technologies but guarantee timely access to innovation. To maintain compliance without compromising efficiency, it is essential to align these new AI regulations with established quality workflows. This creates a pressing need for a practical, specific interpretation of the AI Act tailored to the pathology community. In this article, we provide an overview of the AI Act, its relevance to pathology laboratories, and guidance for its practical implementation. Methods This article was authored by a multidisciplinary panel comprising expert academic pathologists, a scientist with a legal background, and healthcare professionals with regulatory expertise [ 5 – 7 ]. The panel engaged in a formal, expert consensus-driven process, involving regular correspondence via mail and teleconferences conducted by the writing committee (FD, SP, AD). Draft versions of the manuscript were circulated by email to all co-authors for review. The writing committee held the final responsibility for approving the definitive version of the manuscript. Furthermore, the definitive version was submitted for legal review to an external legal expert (see Acknowledgements). None of the authors has any conflict of interest with respect to the topic. Overview of the AI Act The European Union Artificial Intelligence Act (AI Act; Regulation (EU) 2024/1689) establishes a harmonized legal framework for the development, deployment, post-market surveillance, and oversight of AI systems within the European Economic Area. It adopts a model, categorizing AI systems into four risk levels: minimal, limited, high-risk, and unacceptable [ 8 ]. Minimal-risk systems—such as spam filters or AI-enabled video games—fall under existing EU law without added requirements. Limited-risk applications, like AI chatbots or emotion detection systems used outside sensitive contexts, must meet basic transparency obligations, including user notification when interacting with AI (Article 50). High-risk systems, which include AI systems for safety-critical sectors such as healthcare (Article 6; Annex I and III), face strict requirements, such as conformity assessments prior to market placement, compliance with post-market monitoring and incident reporting, and ensuring the establishment of a risk management system, as specified in Chapter 2 (Articles 8–15) [ 6 ]. Systems classified as unacceptable—such as those using subliminal techniques or real-time biometric surveillance in public spaces—are banned outright due to ethical, safety, or livelihoods concerns (Article 5). A separate risk classification was introduced for General Purpose AI models (Articles 51–54). AI Act interaction with other regulations The AI Act is designed to complement, not replace, sector-specific EU legislation. In the healthcare domain, it intersects directly with the Medical Devices Regulation (MDR; Regulation (EU) 2017/745) and In Vitro Diagnostic Medical Devices Regulation (IVDR; Regulation (EU) 2017/746) [ 7 , 9 , 10 ]. AI systems that qualify as medical devices are by default considered high-risk and must comply with both frameworks (Annex I AI Act). Additionally, any AI system that processes personal data must meet the General Data Protection Regulation (GDPR; Regulation (EU) 2016/679), especially concerning data minimization, lawful processing, and automated decision-making rights (GDPR Articles 5, 6, and 22). High-risk systems must comply with detailed technical, procedural, and organizational requirements. These include the establishment and maintenance of a risk management system (Article 9), robust data governance (Article 10), comprehensive documentation (Article 11), record-keeping (Article 12), transparency (Article 13), human oversight (Article 14), and cybersecurity measures (Article 15). Providers must ensure that the training, validation, and testing datasets are relevant, representative, error-free, and sufficiently complete to minimize risks and discriminatory outcomes. Systems influencing medical decisions require embedded human oversight mechanisms to ensure clinical judgment is not undermined. AI Act application in the health sector As an EU Regulation, the AI Act applies uniformly across all Member States, avoiding the need for national transposition and reducing regulatory fragmentation. Still, the implications for the healthcare sector at the national level and AI-driven medical technologies are profound. Within the regulatory framework of the EU Artificial Intelligence Act, AI systems used in healthcare are mainly categorized as high-risk because of their potential to significantly impact patient safety, clinical outcomes, and care delivery. In healthcare, the implications are significant. Most AI systems used in clinical care are classified as high-risk due to their potential influence on diagnoses, treatments, and patient outcomes, and their access to sensitive data like personal health information. Before these systems can be placed on the market, they must pass a conformity assessment (Article 43) that verifies compliance with essential safety and performance requirements through rigorous technical documentation, testing, and, in many cases, third-party evaluation. A robust quality management system (Article 17) must be in place to address data lifecycle management, risk controls, and system maintenance. In the context of healthcare, where decisions often carry life-or-death consequences, the integrity of training, validation, and testing data is especially critical. Article 10 mandates that datasets used to develop these systems be relevant, representative, generalizable, and free from bias, thereby mitigating the risk of systemic errors or discriminatory effects with regard to age, ethnicity, race, or other demographic factors. Transparency (Article 13) is also essential—providers must deliver clear documentation of the AI system’s intended use, limitations, and performance characteristics. This allows healthcare professionals (acting as deployers) to understand and responsibly use AI in clinical workflows. Human oversight, as stipulated in Article 14, must be built into the design and use of the system, ensuring that healthcare practitioners retain control over AI tools, can override automated outputs when necessary, and can identify instances of malfunction, drift, or misuse. This technical safeguard is reinforced by the broader organizational obligation to ensure adequate AI literacy among users, recognizing that the competence of clinical staff in understanding and managing AI is essential for its safe and effective application (Article 4). Following distribution, high-risk healthcare AI systems are subject to continuous post-market monitoring (Article 72). Providers must collect real-world performance data, assess ongoing system performance across confounding variables (e.g., age, sex, BMI, race, ethnicity), investigate adverse outcomes, and notify national authorities of serious incidents. All high-risk AI systems must be registered in a centralized EU database (Article 49), which promotes transparency, facilitates regulatory scrutiny, and enables regulatory review and public access to key system information. This approach mirrors and complements the lifecycle principles of the MDR, embedding long-term accountability into AI oversight. In summary, the AI Act introduces a rigorous framework for the safe use of AI in healthcare, while trying to balance the promotion of innovation with essential safeguards around patient safety, ethical standards, and clinical accountability. For healthcare professionals and developers alike, the Act sets clear expectations and accountabilities for the responsible integration of AI into medical practice. Practical consequences for clinical digital pathology labs Classification of AI-based pathology tools Regarding pathology, AI systems used in the field vary from minimal risk AI to high-risk AI. As previously expressed, high-risk AI tools, such as those used for primary diagnosis or cancer detection, would face more stringent requirements. However, according to the Act, some other solutions would be classified as low-risk AI applications because they do not directly influence diagnosis. These include quality assessment tools for digitized slides, workflow optimization systems for laboratory processes, and AI assistants for purely administrative tasks. Such lower-risk tools face less stringent regulations, requiring only transparency in their functionality and performance. Below, we focus on how the AI Act applies to high-risk AI systems used in pathology potentially affecting clinical outcomes, and examine what the requirements outlined in the previous paragraph imply in practice within this field. Regulatory compliance and implementation challenges Provider obligations Under the EU AI Act, a provider is defined as the entity that develops or commissions the development of an AI system for placement on the market or for use under its own name or trademark. In pathology, providers may include commercial vendors or clinical laboratories that develop high-risk AI tools in-house. Providers of AI systems bear a range of responsibilities, beginning with the obligation to promote AI literacy among users (Article 4). This includes ensuring that end users—such as pathologists—are equipped with the knowledge needed to understand how the AI systems function, their limitations, potential risks, and ethical implications. These considerations should be incorporated into the earliest stages of system design, with the aim of facilitating safe and informed use. Providers must anticipate how end users will interact with AI and build in safeguards and educational resources accordingly. Moreover, they should test the AI systems during formative and summative usability studies in a relevant intended use environment, where informed and trained intended users interact with the AI system to perform the intended task. Maintaining data quality and governance is another key requirement, particularly in accordance with GDPR principles. This involves implementing robust data protection measures, safeguarding user privacy, and maintaining rigorous control over data collection, storage, and processing (Article 10). Providers must conduct and document a formal bias assessment to reduce risks of discriminatory or skewed outputs (Articles 9 and 10). Measures such as anonymizing sensitive data and offering transparent user controls are central to these efforts. Additionally, providers must establish and enforce clear policies on data retention and secure data transfers to protect against breaches or unauthorized access (Article 10). In healthcare—and in pathology in particular—these requirements are especially critical. AI systems in this field must be trained and validated on relevant, high-quality datasets that accurately reflect the diverse and complex nature of real-world clinical data (Articles 9–10). The success and safety of AI applications in medical diagnostics relies heavily on responsible data governance and on the ability of users to interpret AI outputs knowledgeably and ethically. Under the AI Act, providers of high-risk AI systems are required to maintain transparency across all stages of the system’s development and lifecycle. This means clearly specifying the datasets used for training, validation, and testing—including information on where the data came from, how it was compiled, and what pre- and postprocessing steps were taken (Articles 10 and 13). Transparency also extends to any clinical trials, validation studies, and model-specific evaluations, which must be documented and made comprehensible to deployers. The goal of these measures is to support responsible use in practice, enhance decision-making, and help build confidence in AI-assisted tools within the healthcare setting (Article 13). Alongside transparency, the AI Act requires providers to establish and maintain a structured risk management system (Article 9). This system must actively monitor and address risks that may emerge throughout the lifecycle of the AI tool. This requirement aligns with the risk management principles outlined in the IVDR and MDR legislation, which also mandate similar systems for medical devices and in vitro diagnostic medical devices. In practice, this means that providers must document and communicate known risks, usage limitations, and recommended precautions clearly to those implementing the system in a clinical setting. Providers must also supply deployers with comprehensive details about the AI system’s capabilities, intended uses, performance indicators, and any known limitations or issues. These steps aim to improve accountability, build trust, and support informed decision-making by pathologists (Article 13). Additionally, providers are required to log AI system activities and retain these records for a minimum of 6 months (Article 19). A comprehensive quality management system (QMS) must also be implemented (Article 17). This must encompass all phases of AI development and deployment, including design, testing, validation, continuous improvement processes, and post-market surveillance. The QMS may include appointing an authorized representative, creating a governance structure (e.g., a dedicated AI compliance team), conducting conformity assessments for CE marking (Article 43), managing serious incident reporting (Article 73), and maintaining post-market monitoring procedures (Article 72). For applications in pathology, this requirement is reinforced by overlapping QMS provisions under MDR and IVDR. Notably, the AI Act expands the QMS scope to include areas such as data governance, algorithmic transparency, stakeholder communication, and bias mitigation (Articles 10, 13, and 17). Additionally, when developing an AI system, it is essential for providers to consider that high-risk AI tools should be equipped with automated logging throughout their lifecycle. This ensures the capture of events for system traceability, risk identification, and post-market monitoring (Article 12). Apart from that, AI providers for pathology must incorporate human oversight into high-risk AI systems to ensure accuracy, reliability, and ethical compliance. This oversight can include mechanisms such as human-in-the-loop validation, continuous monitoring, and clinician intervention when AI outputs are uncertain or potentially erroneous. Human oversight helps mitigate risks associated with AI decision-making, ensuring that patient safety and diagnostic integrity remain the top priority. Robust cybersecurity measures, including encryption, access controls, and secure infrastructure, are essential components of high-risk AI solutions. Furthermore, AI providers must ensure resilience against attacks and implement regular system updates to address vulnerabilities and security risks. Deployer obligations Deployers—those who use AI systems in practice—are typically pathology labs or healthcare institutions integrating these tools into diagnostic workflows. For labs acting as both providers and deployers of AI systems mentioned in Annex III of the AI Act, a fundamental requirement is the registration of the AI system and the laboratory itself in the EU high-risk AI database prior to deployment (Article 49). This measure is designed to establish a centralized inventory of high-risk AI systems in use across the EU, facilitating regulatory oversight, tracking of adverse events, and assurance that all systems adhere to the strict safety, performance, and transparency standards demanded for clinical use in pathology. From a quality management standpoint, it is essential that pathology laboratories verify and document their compliance with provider and deployer obligations outlined in the AI Act, particularly when developed internally (Article 17) (summarized in Table 1 ). This verification process should cover key areas such as data governance, risk management, human oversight, and transparency obligations (Table 2 ). Implementing a structured approach to compliance assessment helps labs identify gaps, mitigate regulatory risk, and demonstrate due diligence to competent authorities. Table 4 is a non-exhaustive checklist to guide pathology labs through the complex landscape of AI provider and deployer responsibilities under the Act. Table 1. Provider obligations for high-risk AI systems following the AI Act Provider obligations AI literacy measures Introduction of a risk management system Transparency and information duties Guard data quality and data governance for training or testing Technical documentation • Intended use(s), user(s), use environment(s) • Performance indicators • Known limitations or issues Record keeping: maintain logs of AI systems for min. 6 months Human oversight measures Accuracy and robustness Quality management system: • Creation of an AI office • Appoint representative • Undergo conformity assessment (CE marking and registration) • Serious incident reporting • Post-market surveillance • Take corrective actions in case of non-conformity Cybersecurity Open in a new tab Table 2. Deployer obligations for high-risk AI systems following the AI Act Deployer obligations Registration of in-house developed high-risk tool AI literacy measures Ensuring human oversight • Use according to instructions • Use by qualified lab personnel • Guarantee relevant and sufficient input data • Pathologist validation before clinical use • AI outputs clearly identifiable as AI-generated Transparency measures • Inform stakeholders about AI implementation • Serious incident policy Fundamental rights assessment Open in a new tab Table 4. Non-exhaustive checklist to guide pathology labs through the complex landscape of AI provider and deployer responsibilities under the act Open in a new tab An additional obligation for pathology labs deploying AI tools is to ensure sufficient AI literacy among all employees interacting with these systems, directly or indirectly, applying to pathologists, lab technicians, and other staff involved in the pathology diagnostic workflow. Comprehensive AI literacy training enables staff to understand the capabilities, limitations, and potential biases of AI systems, fostering informed decision-making and effective oversight. Fostering this level of competence ensures meaningful human oversight, enhances the reliability of AI-assisted diagnostics, and supports ethical standards in patient care. The AI Act places significant emphasis on human oversight as a crucial responsibility for deployers. In pathology labs, this includes ensuring that AI systems are used strictly in accordance with provided instructions for use, that qualified personnel remain responsible for supervising the AI’s clinical application, and that input data used for using the AI model is relevant and representative. Crucially, AI-generated outputs must be validated by a pathologist prior to clinical application, with systems providing interpretable decision pathways to support this process. Moreover, any synthetic or AI-generated content must be clearly identified as such, and systems must support manual override mechanisms to allow human intervention where needed. These provisions reinforce the central role of clinical judgment and expertise in maintaining patient safety while integrating AI into routine diagnostic workflows. Transparency remains a cornerstone of the AI Act also for deployers (Article 13). Pathology laboratories must proactively inform stakeholders—including clinicians and patients—about the use of AI systems in diagnostic processes. This can be achieved through public-facing channels such as hospital or laboratory websites, direct statements in pathology reports, or disclosures within informed consent materials, depending on the clinical context. Deployers must also record, report, and communicate any serious incidents to the relevant authorities and affected parties (Article 73). These obligations aim to promote transparency, support post-market monitoring, and provide stakeholders with critical information about system performance, limitations, and potential risks. Lastly, the AI Act imposes additional administrative responsibilities on pathology labs deploying AI tools. Specifically, read together with the GDPR, it is arguable that the performance and documentation of a Data Protection Impact Assessment (DPIA) are necessary; furthermore, a fundamental rights assessment prior to AI implementation is required (Article 27). These requirements aim to ensure that AI systems in pathology labs are deployed responsibly, with due consideration for data protection and fundamental rights. By conducting these assessments, labs can identify potential risks, implement necessary safeguards, and demonstrate compliance with the Act’s provisions. This proactive approach not only meets regulatory requirements but also fosters the indispensable trust and transparency in the use of AI within pathology practice. Example templates of these assessments are provided in the supplementary checklist accompanying this paper. Discussion Implementing the AI Act brings new challenges for pathology laboratories and AI developers. In this new panorama, ESP and ESDIP welcome the EU AI Act as a constructive step toward trustworthy AI amid rapid innovation in pathology. The implementation should be thoughtful and risk-proportionate, aligned with existing quality systems, and supported by clear guidance and transition periods that allow time for learning and adjustment. The effective adoption depends on a close and structured expert dialogue among all stakeholders (e.g., pathologists, laboratory technologists, biologists, computer scientists, data engineers, patient representatives, and the AI industry) together with regulators and policy makers. A key concern is the added regulatory load, which comes on top of existing complex requirements from frameworks like the MDR/IVDR. Many aspects of the AI Act overlap with MDR/IVDR obligations—such as maintaining thorough documentation, managing risks, and monitoring performance—all areas that pathology labs are already working within. Harmonizing the documentation and procedural requirements of both regulations is essential to reduce redundancy and streamline the overall compliance process. Such alignment would ease regulatory obligations for both providers and pathology labs, potentially reducing costs and accelerating the safe adoption of AI technologies in healthcare. However, the AI Act also raises several open questions that require urgent clarification. For example, the expected content, structure, and storage format of log files that AI system deployers are required to maintain remain undefined. Resolving such ambiguities will be critical for consistent and effective implementation of the AI Act across member states. The recent Frequently Asked Questions (FAQ) of the Directorate-General for Health and Food Safety of the European Commission confirms that the AI Act complements—rather than replaces—the rules of the MDR/IVDR [ 11 ]. Remarkably, this FAQ stresses that in-house developed tests have no notified body involvement and therefore do not fulfil the conditions in the AI Act for designation as a high-risk AI system. For pathology laboratories, this means that in-house developed tests continue to operate under the familiar IVDR in-house exemption: they must be justified by specific patient needs, produced within a certified quality management system, and kept off the commercial market, but they do not trigger the AI Act’s full suite of high-risk obligations [ 9 ]. By folding the residual baseline AI Act duties (such as the ban on prohibited practices and basic transparency for generated reports) into quality systems, pathology labs can achieve compliance without duplicative paperwork. To navigate the complexity of the regulatory landscape, transparency and accessibility of information are essential—particularly for those working on the frontlines of healthcare. Like many legal texts, the AI Act is highly technical and difficult to translate into day-to-day practice for pathologists and laboratory personnel. This makes it all the more important to translate legal and regulatory requirements into clear, practical guidance that clinicians, lab technicians, and quality officers can easily interpret and apply. This manuscript and other ongoing activities endorsed by ESP and ESDIP (e.g., expert forums, scientific lectures, guidelines and recommendations) are meant to offer multiple trajectories to contribute to shaping AI Act implementation, serving as a neutral community hub, linking all the stakeholders involved in the process. Moreover, to show how this can be done, we applied the AI Act to a real-world case: an AI tool used for Ki-67 quantification in breast cancer. We looked at how the tool would need to be documented, overseen, and potentially adjusted under the Act. Table 3 summarizes this analysis, offering a concrete view of what compliance might look like in a working pathology setting, and how the AI Act impacts product development, validation, and deployment in a clinical setting. Table 3. Practical example of the application of the AI Act to the deployment of a commercially available Ki-67 quantification AI tool for breast tumors AI Act role Obligations and best practices Risk classification • The Ki-67 AI tool qualifies as a high-risk AI system since it is a medical device regulated by the IVDR (IVDR listed in the AI Act, Annex I) Provider • Appoint a designated contact person for the deploying laboratory • Implement a robust risk management system • Provide clear and comprehensive Instructions for Use detailing the intended purpose, intended use, intended user and intended use environment: The tool can only be used in breast cancer with the vendor dedicated viewer, no restrictions on the antibody clone • Share performance metrics publicly (e.g., sensitivity, specificity) and specify environmental dependencies (e.g., scanner type, antibody clone) • Obtain and document CE-IVDR conformity for this Ki-67 AI assay • Provide a system architecture diagram (data flow from WSI ingestion to output delivery, including the visual points of interest and/or a general proliferation index score) • Document cybersecurity measures, including site-specific deployment details • Maintain detailed usage logs, including timestamps of Ki-67 analysis, to who or which system the results of the Ki-67-AI-assessment were sent, recipients of results, and access audits. These logs need to be shared with the labs that installed the Ki-67-AI-assay • Establish a post-market surveillance program (e.g., ISO-accreditation) with an AI office. Deviations between AI Ki-67 results and pathologist findings should trigger risk analysis and corrective action with transparent communication to stakeholders Joint responsibilities (provider and deployer) • Promote AI literacy among end users (e.g., via certified courses by local scientific committees) ◦ Deliver tool-specific training ◦ Disclose AI development methods and technologies ◦ Provide transparent information on the training, validation and test datasets (size, origin, bias considerations) ◦ Report dataset quality (e.g., carcinoma subtype diversity, class balance) ◦ Explain performance metrics and their clinical implications (e.g., false-positive rate) ◦ Describe the user interface, for example the control of AI overlays ◦ Identify known limitations and pitfalls (e.g., misclassification of in situ carcinoma which can influence the overall result) Deployer • Evaluate completeness and clarity of the provider’s documentation (transparency on data, cybersecurity, model performance, documentation on quality management, etc.) • Conduct a Fundamental Rights Impact Assessment • Create a local verification set with at least 20 cases (10 with < 30% Ki-67, 10 with ≥ 30%), requiring ≥ 95% concordance for clinical validation • Re-validate if significant changes are made to the workflow (e.g., staining protocol updates, AI software upgrades) • Develop a competency matrix for staff trained in the AI tool • Inform stakeholders (e.g., lab website, reports, referring physicians, by a general informative mailing to requestion physicians, in the lab manual, a statement in the report of the sample that a clinical decision support AI tool for Ki-67 assessment was used) about the use of the AI tool • Retain AI usage records for at least 6 months. Integration into the laboratory information system (LIS) can be used for this record • Ensure human oversight: ◦ Enforce adherence to the intended use via record audits ◦ Ensure only appropriate input data is used (e.g., selection of most relevant slide for the Ki-67 analysis). If needed, use the appropriate validated antibody and scanner) ◦ Make AI-generated outputs visibly distinct from human assessments, using viewer annotations, color codes, or specific LIS fields ◦ Avoid implementation where the AI output could be mistaken for a pathologist’s assessment without clear differentiation ◦ Allow pathologist override AI results prior to clinical reporting ◦ Report significant discrepancies to the provider’s AI office and document in the lab’s quality system, with follow-up risk assessment and stakeholder notification Open in a new tab From a practical perspective, the financial and administrative demands placed on compliance are significant. Complying with the abovementioned requirements involves allocating substantial resources for testing, certification, documentation, and post-market monitoring. These demands may disproportionately affect smaller pathology labs and emerging AI startups, for whom regulatory navigation can be both resource-intensive and cost-prohibitive. This could delay or even prevent the clinical introduction of new AI tools in clinical practice, potentially slowing progress in digital pathology and precision medicine. Nonetheless, there are mechanisms within the AI Act designed to ease the path to compliance. Article 57 of the legislation provides a legal framework for the creation and encourages the establishment of AI regulatory sandboxes in each EU member state. These sandboxes offer controlled environments for the development, training, testing, and validation of AI systems before they are introduced to the market. Beyond fostering innovation, these platforms provide crucial opportunities to identify risks, improve safety, and demonstrate regulatory readiness. Importantly, evidence generated within sandboxes can support future certification efforts, helping to streamline the approval process. By enabling cross-border cooperation and sharing of best practices, these initiatives could accelerate AI adoption in pathology while upholding ethical and safety standards. To fully comply with the AI Act, pathology laboratories must not only implement technical and procedural changes but also build the internal capacity to understand and manage these requirements. The AI Act introduces complex obligations—ranging from documentation and performance monitoring to transparency and risk management—that can be difficult to interpret without a regulatory background. To bridge this gap, it is essential to translate regulatory language into accessible, practice-oriented guidance. We developed a checklist to overcome this problem (Table 4 ). However, making the requirements more accessible is only part of the solution. Pathology laboratories must also invest in AI literacy among their staff to ensure these resources are effectively understood and applied in practice. Understanding how AI systems function, what their limitations are, and how to critically evaluate their outputs is key to safe and responsible implementation. In this sense, AI literacy becomes a foundational competency—not only for using AI tools effectively, but also for ensuring regulatory compliance and maintaining trust in clinical workflows. Professional bodies play a pivotal role in developing training programs that go beyond operational use and address broader topics such as data governance, ethics, explainability, and compliance frameworks. Equipping healthcare professionals with these skills will ensure that they are not just passive users, but informed actors in the evolving AI-driven landscape of pathology. Recently, it has been a topic of debate if AI tools need to be fully explainable on how they come to their output. The AI Act does not explicitly mandate “explainability” in those exact terms, though its stringent requirements for high-risk systems make compliance for non-explainable, or “black box,” models exceedingly challenging. Nevertheless, obligations such as justifying model decisions during conformity assessments, maintaining detailed audit trails that track decision-making processes, and enabling effective human oversight over AI outputs inherently demand a high degree of transparency and interpretability [ 6 , 12 ]. Conclusion The AI Act marks a significant step in the regulation of artificial intelligence across the European Union, with profound implications for pathology laboratories. As these labs increasingly adopt AI-driven tools for diagnostics and workflow optimization, understanding and adhering to the requirements of the AI Act is essential. This paper highlights the classification of AI systems under the Act, the specific obligations for high-risk systems, and the practical consequences for compliance within pathology workflows. While the Act presents challenges in terms of documentation, transparency, and ongoing monitoring, it also offers an opportunity to foster trust, accountability, and innovation in medical diagnostics. Proactive engagement with regulatory guidelines and close collaboration with AI developers will be key for pathology labs to successfully navigate this evolving landscape and continue to deliver high-quality patient care. Acknowledgements The authors would like to express their sincere gratitude to Dr. Jacopo Dirutigliano for his invaluable contribution to this work, evaluating the correctness of the legal premises of the manuscript. Dr. Dirutigliano holds a Ph.D. in Law, Science and Technology (LAST-JD-RIoE) through a co-tutelle program involving the University of Bologna, the University of Turin, and the University of Luxembourg, and he is currently a member of the AI commission of the Turin Bar Association. His expertise is in the intersection of law, science, and emerging technologies, and he has therefore been fundamental in ensuring the accuracy and correctness of the messages of this manuscript. Author contribution Conceptualizing: FD, SP, AD. Writing: FD, SP, AD, IZ, VLI. Proofreading: FD, SP, GB, TVDB, IZ, PS, SO, LDT, NZ, VLI, SD, MVDB, AW, RS, AD Declarations Ethics approval and consent to participate This article is based on the authors’ expert opinion and a review of existing literature. No new studies with human participants or animals were conducted by the authors for this work. Conflict of interest The authors declare no competing interests. Footnotes Publisher’s Note Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations. Frederik Deman and Sofia Palmieri contributed equally to this work. References 1. Weng Z, Seper A, Pryalukhin A et al (2024) Grandqc: a comprehensive solution to quality control problem in digital pathology. Nat Commun 15:10685. 10.1038/s41467-024-54769-y [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 2. Lu MY, Chen B, Williamson DFK et al (2024) A multimodal generative AI copilot for human pathology. Nature 634:466–473. 10.1038/s41586-024-07618-3 [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 3. Yousif M, van Diest PJ, Laurinavicius A et al (2022) Artificial intelligence applied to breast pathology. Virchows Arch 480:191–209. 10.1007/s00428-021-03213-3 [ DOI ] [ PubMed ] [ Google Scholar ] 4. Eloy C, Fragetta F, Van Diest PJ et al (2025) Digital transformation of pathology - the European Society of Pathology expert opinion paper. Virchows Arch. 10.1007/s00428-025-04090-w [ DOI ] [ PMC free article ] [ PubMed ] [ Google Scholar ] 5. Deman F, Broeckx G, Declercq S et al. Practical implementation of AI in a non-academic, non-commercial Pathology laboratory: real world experience and lessons learned. Histopathology n/a: 10.1111/his.15481 [ DOI ] [ PMC free article ] [ PubMed ] 6. Palmieri S (2024) The renewed EU legal framework for medical AI. Eur J Law Technol 15 7. Palmieri S, Walraet P, Goffin T (2021) Inevitable influences: AI-based medical devices at the intersection of medical devices regulation and the proposal for AI regulation. Eur J Health Law. 10.1163/15718093-bja10053 [ DOI ] [ PubMed ] [ Google Scholar ] 8. European Artificial Intelligence Act 9. European Medical Device Regulation 10. European in-vitro diagnostics regulation 11. (2025) MDCG 2025-6 FAQ on interplay between the medical devices regulation & in vitro diagnostic medical devices regulation and the Artificial Intelligence Act 12. Busch F, Kather JN, Johner C et al (2024) Navigating the European union artificial intelligence act for healthcare. npj Digit Med 7:1–6. 10.1038/s41746-024-01213-6 [ DOI ] [ PMC free article ] [ PubMed ] Articles from Virchows Archiv are provided here courtesy of Springer ACTIONS View on publisher site PDF (1.5 MB) Cite Collections Permalink PERMALINK Copy RESOURCES Similar articles Cited by other articles Links to NCBI Databases Cite Copy Download .nbib .nbib Format: AMA APA MLA NLM Add to Collections Create a new collection Add to an existing collection Name your collection * Choose a collection Unable to load your collection due to an error Please try again Add Cancel Follow NCBI NCBI on X (formerly known as Twitter) NCBI on Facebook NCBI on LinkedIn NCBI on GitHub NCBI RSS feed Connect with NLM NLM on X (formerly known as Twitter) NLM on Facebook NLM on YouTube National Library of Medicine 8600 Rockville Pike Bethesda, MD 20894 Web Policies FOIA HHS Vulnerability Disclosure Help Accessibility Careers NLM NIH HHS USA.gov Back to Top