Only four WHO European region countries (8%) have standards for determining who is responsible if an artificial intelligence (AI) tool makes a mistake or causes harm in healthcare settings, according to a new report published by the World Health Organization (WHO) Regional Office for Europe.
Of these countries, just one, Russia, has complete liability standards according to WHO criteria. Liability standards exist but are incomplete in Spain, Belgium, and Sweden.
This lack of legal infrastructure comes at a time when two thirds of the region’s countries report using AI for diagnostics and half use AI chatbots for patient support, wrote the authors of the report.
“AI is sprinting ahead, while our literacy and laws are still tying their shoelaces,” Charlotte Blease, PhD, associate professor of digital health at Uppsala Universitet, Uppsala, Sweden, and author of Dr Bot: Why Doctors Can Fail Us — and How AI Could Save Lives, told Medscape News Europe. “Most countries still don’t have a proper AI-in-health plan: lots of strategy documents but very little actual investment. We’re bolting 21st-century tools onto 20th-century law.”
Of the countries surveyed by WHO Europe, 92% said that liability rules would facilitate widespread adoption of AI in healthcare. Nine in 10 countries said that guidance on transparency, verifiability, and explainability would also help.
“This lack of clear standards, especially around liability, creates real-world challenges. Clinicians may become hesitant to rely on AI, fearing legal repercussions, or overly reliant, assuming the system carries responsibility. Both scenarios increase patient safety risks,” Hans Kluge, MD, WHO regional director for Europe, told Medscape News Europe.
The WHO Europe’s report is based on survey data collected between June 2024 and March 2025 from 50 of the WHO European Region’s 53 member states.
How to Decide Who Is Accountable?
The key problem for developing liability standards for AI in healthcare lies in the responsibility gap, Mihály Héder, PhD, associate professor of the Department of Philosophy and History of Science at Budapest University of Technology and Economics, told Medscape News Europe.
“A system making a decision is not a legally accountable agent as society does not think it is a moral agent, a position which could remain for a long time. Responsibility thus needs to be assigned elsewhere, and this redistribution is far from trivial,” he said.
Blease said that AI mistakes in healthcare will not produce a single culprit but rather shared liability between the systems developer, the hospital that deployed it, and the clinician who used it. The challenge lies in determining the degree to which each is accountable.
Kluge added that neural networks and deep learning models adapt over time, making it difficult to apply traditional product-liability frameworks that could hold their original developer to account. The “many hands problem” adds to the complexity, he said. AI development involves numerous contributors making it difficult to trace harm to a specific actor.
Beyond this, many advanced algorithms work as “black boxes,” meaning clinicians and regulators do not understand how input data leads to clinical decisions, something which Kluge said complicates accountability, obscures detection of harm, and limits compensation for affected individuals.
He added that hospitals could face liability if they don’t act carefully when choosing or managing AI tools. And if manufacturers provide clear warnings and require that a trained clinician operates the system, responsibility for safe operation may shift to clinicians.
In Practice
On July 12, 2024, the EU published the AI Act, the world’s first legal framework for AI. It defines AI health applications as being “high risk,” meaning they must meet strict standards on safety, data quality, human oversight, and transparency. The exact rules for such high-risk AI applications will only come into effect in August 2026 and August 2027, however.
“Standards may be edging closer across Europe, at least on paper, but for patients the reality remains highly local; that is, the experience in Stockholm, Dublin, or Bucharest still looks very different,” said Blease.
Given most countries do not yet have AI-specific liability rules for healthcare, legal bodies may choose to address AI-driven mistakes with current infrastructure. In Sweden, for example, AI-related cases are handled through its “no-fault patient-injury system,” which compensates patients first and deals with responsibility later, said Blease.
“Something that I believe needs to be emphasized: This black box of liability isn’t much better in medicine without AI. There is very little accountability or admission when mistakes happen in healthcare, and they frequently do due to human error,” she said.
Blease added a hint of optimism. She noted that one upside of working with AI is that it is easier to interrogate than human doctors thanks to digital footprints and explicit technical standards. This, she noted, means that AI applications may be used to hold humans to account, highlighting when a clinician ignored guidance or failed to use a tool properly.
“In some ways, AI may make accountability clearer on both sides,” she said.
The WHO Europe is currently in discussion with member states about the best way forward for a regional AI roadmap in healthcare, said Kluge.
Blease and Kluge reported having no relevant financial relationships.
Annie Lennon is a medical journalist. Her writing appears on Medscape Medical News, WebMD, and Medical News Today, among other outlets.
Admin_Adham