AI and Healthcare / Reading the WHO European Region's Report on AI Readiness in Healthcare: Reflections on the Six Pillars and the Greatest Barrier of 'Legal Uncertainty'
0 Introduction
I have read the report published by the WHO Regional Office for Europe in 2025 titled "Artificial intelligence is reshaping health systems: state of readiness across the WHO European Region" (hereinafter referred to as the WHO European AI Report). This report systematically measures, for the first time, the "readiness" for integrating AI into healthcare systems, based on responses obtained from 50 out of 53 countries in the European region between 2024 and 2025.
World Health Organization Regional Office for Europe, Artificial intelligence is reshaping health systems: state of readiness across the WHO European Region (WHO Regional Office for Europe, 2025).
*Please note that this article is merely a collection of personal reflections, and since my own reading may not be perfectly translated, please refer to the original source for detailed confirmation.
Europe is a region that resembles a "jungle" of dense rule-making surrounding AI and healthcare, including the AI Act, the European Health Data Space (EHDS) regulation, and the Council of Europe's Framework Convention on AI. In terms of observing AI law and governance, this report is a valuable resource because it visualizes the actual steps taken by countries currently navigating through this jungle, as compiled by the WHO.
This time, I would like to take notes on points that caught my attention, particularly from the perspective of legal systems and governance, using the six pillars presented in the report (Navigators, Change-makers, Guardrails, Backbones, Catalysts, and Gatekeepers) as a guide. This is a reflection at the level of "where Europe is now and where it is stalling," without delving into detailed discussions of individual civil law, medical jurisprudence, or insurance law.
1 Healthcare AI in Europe through the Six Pillars
First, the pillar named "Navigators" indicates the status of AI strategy development in each country. Only 4 out of 50 countries (8%) have already published a healthcare-specific national AI strategy, and even including those currently in development, the figure is only 22%. On the other hand, 66% of countries already have a cross-sectoral national AI strategy, and another 16% are in the process of developing one.
In other words, the structure is that many countries are prioritizing cross-sectoral AI strategies first and positioning healthcare AI as a part of them, while countries that have drilled down to a healthcare-specific strategy remain in the minority. This balance can be said to quite frankly reflect the classic trade-off of "whether to gain speed with a vertical healthcare AI strategy or to gain consistency with a cross-sectoral strategy."
The next pillar, "Change-makers," focuses on stakeholder participation and human resource development. While 72% of countries engage in some form of dialogue with stakeholders, the most frequent participants are government officials (81%), healthcare providers (75%), and AI developers (75%), while patient organizations (42%) and the general public (22%) are clearly underrepresented.
Furthermore, countries that conduct in-hospital or academic training on AI are limited to 24% for incumbent staff and 20% for integration into training curricula. Only 42% of countries have newly established professional positions for AI and data science, highlighting the fact that "on-site skills and positions" are not keeping pace.
"Guardrails" is the pillar that measures the status of legal systems and guidelines. While 46% of countries have conducted gap analyses with existing legislation and 54% have established regulatory bodies responsible for the evaluation and approval of AI systems, only 4 countries (8%) have developed liability rules or guidance specific to healthcare AI, and only 3 countries (6%) have introduced legal requirements for generative AI in the healthcare sector.
"Backbones" is the pillar for data governance, where 66% of countries have formulated dedicated national health data strategies, and 76% have governance frameworks for health data. In 66% of countries, regional or national health data hubs have been established, many of which are said to be intended for participation in the European Health Data Space (EHDS) ecosystem.
However, only 30% of countries have published guidance on the secondary use of health data, 30% have rules for cross-border data sharing for research purposes, and 40% have established rules for data sharing with private companies. Additionally, in 82% of countries, data anonymization is a primary requirement for secondary use, but detailed guidelines regarding its operation cannot be said to be sufficient.
"Catalysts" indicates priority areas for AI utilization and the actual state of usage. As for the main objectives expected of AI, 98% of countries cite "improving patient care and health outcomes," followed by "reducing the burden on healthcare workers" at 92%, and "improving efficiency" at 90%. On the other hand, only about half of these countries have actually secured dedicated budgets for these priority areas.
Regarding specific forms of use, approximately two-thirds of countries have introduced AI-assisted diagnostics such as diagnostic imaging, and half of the countries use chatbots for patients. The adoption of AI to support continuous patient observation, such as remote monitoring, remains relatively low.
The final 'gatekeeper' addresses the barriers to AI adoption and the policy measures to overcome them. The greatest barrier cited was 'legal uncertainty,' with 24 out of 50 countries (48%) identifying it as a 'major barrier,' and an additional 19 countries (38%) rating it as having 'moderate importance.' The next most significant barrier mentioned was 'financial affordability,' with 46% identifying it as a major barrier and 32% as a moderate barrier.
It is interesting to note that the policies evaluated as having the greatest positive impact as countermeasures were 'guidance on AI transparency, verifiability, and explainability' (90%) and 'clear liability rules for manufacturers, implementers, and users' (92%). Countries seem to be more strongly aware of the need for frameworks of responsibility and accountability than for the technology itself.
2 The fact that 'legal uncertainty' is the greatest barrier
In discussions about AI, the phrase 'regulations are not keeping up' tends to become a cliché (I often use this phrase myself...), but the WHO European AI report has visualized with data just how much countries actually consider this a problem. At least within the European region, legal uncertainty has clearly emerged as the biggest bottleneck for the adoption of AI in the medical field.
The content of this 'legal uncertainty' needs to be considered in at least three layers. First is the relationship between cross-cutting AI regulation at the EU level (the AI Act) and medical device regulations. The AI Act classifies AI systems into four levels based on risk and imposes obligations such as data governance, transparency, and human oversight on high-risk AI. This includes AI-equipped medical devices and some AI systems used for health purposes.
Second is the issue of overlap and discrepancies between national medical laws and personal data protection laws, and the AI Act and EHDS regulations. The EHDS regulation comprehensively governs the primary and secondary use of health data within the EU and sets out detailed procedures for data access for research and innovation. However, coordination with national medical confidentiality obligations and data subject consent requirements is still in progress, making it difficult to judge where 'legitimate secondary use for research' ends and where a violation begins.
Third is the design of liability regarding who bears responsibility—the doctor, the hospital, or the vendor—and to what extent for medical results produced by AI. According to the report, only 4 out of 50 countries have established liability rules or guidance specifically for medical AI. On the other hand, 92% of respondents in each country evaluate 'clear liability rules' as an important enabler for AI adoption. In other words, there is a rather profound gap where the rules do not yet exist, but all stakeholders are strongly aware that they are necessary.
When applying this situation to Japan, although there is not as complex a 'multi-layered' structure as in Europe at present, similar uncertainties seem to be gradually emerging regarding the division of responsibility for clinical support tools incorporating AI and the positioning of explanations and record creation using generative AI. The European figures can be read as a signal that warns us a little early that we will not be able to avoid similar discussions in Japan in the future.
3 Data governance and the EHDS: The future of the 'backbone'
In the report, a considerable amount of space is devoted to the chapter on data governance. The recognition that the reuse of high-quality, diverse health data is a prerequisite for algorithmic validation and fair AI is almost universally shared among member states.
Looking at the development status of national-level health data hubs, 66% of countries have already established hubs, and many are designed to participate in the EHDS ecosystem. The EHDS regulation itself is positioned as a framework that treats the interoperability of electronic medical records within the region and secondary use for research purposes as two wheels of the same vehicle.
On the other hand, the rules regarding the secondary use of health data still seem to lean heavily on 'anonymization as the sole method.' While anonymization is a primary requirement for secondary use in 82% of countries, only 30% of countries have specific guidance for secondary use, and rules regarding cross-border data sharing and data sharing with private companies are also limited. Over-reliance on anonymization may lead to the loss of data from minority groups, making bias correction and fairness evaluation even more difficult.
The situation in Europe, where data protection law (GDPR), the EHDS, and national medical laws are intertwined, is in a sense an experimental ground showing 'what the landscape looks like when AI regulation is built on the starting point of personal data protection.' When discussing the development of foundations such as Japan's My Number system and the NDB, it seems possible to derive from the European experience the direction of 'designing access rights and purposes of use precisely, rather than relying solely on anonymization.'
4 How medical AI is used: The era of diagnostics and chatbots
The most widely adopted medical AI applications at present are, as expected, AI-assisted diagnostics centered on diagnostic imaging and the like. According to the WHO European AI report, nearly two-thirds of countries use AI-assisted diagnostics, and half have introduced conversational chatbots for patients. On the other hand, the adoption rate of remote patient monitoring using AI is relatively low at 32%, and the use of medical AI remains concentrated on diagnosis and communication within medical institutions.
While the report appreciates that AI-assisted diagnostics contribute to reducing the burden on doctors and that chatbots can enhance patient engagement and autonomy, it also points out risks such as automation bias, the erosion of clinical skills, the dilution of face-to-face relationships between doctors and patients, and disproportionate impacts on marginalized groups. These are points that will also directly apply to new use cases such as medical consultation services using generative AI and the automatic summarization of medical records.
Personally, I found it somewhat surprising that AI for remote monitoring remains limited. Considering the aging population and the increase in chronic diseases, the impact on the healthcare system as a whole could be greater with remote monitoring than with diagnostic imaging AI. Despite this, the reason for the slow adoption likely stems from uncertainties regarding accountability and the division of roles with primary care, in addition to issues with infrastructure development and insurance reimbursement. Here, too, 'legal uncertainty' and 'economic burden' seem to be casting a shadow.
5 The Inclusivity Gap—Whose Voices Are Reflected in Healthcare AI?
The question posed by the 'Change-makers' chapter is simple: Who is invited to the table when discussing the introduction of AI into clinical settings? Reading the report's figures at face value, the three groups of government, healthcare providers, and AI developers are overwhelmingly represented, while patient organizations and the general public remain peripheral participants.
This composition is very similar to the tendency seen in AI governance in general, where 'discussions revolve only around engineers, regulators, and a few experts.' In the case of healthcare AI, there should be a richer accumulation of dialogue with ethics committees and patient groups than in other fields, but as soon as it becomes about AI, they are immediately pushed off the table because 'it's a difficult technical topic.' The WHO European AI report also points out that this inclusivity gap carries the risk that AI tools may deviate from real-world needs or reinforce inequalities.
In Japan, too, channels for patient and citizen involvement in policy formation are gradually increasing, such as patient participation in the clinical practice guideline formulation process and public comments on reforms to the public health insurance system. However, when asked to what extent patients and citizens are involved in a meaningful way in the design and implementation of AI, it seems likely that many would still say it is insufficient. It seems more fruitful to view the figures in the WHO European AI report as a mirror image—suggesting that 'if things continue as they are, Japan could end up with the same graph'—rather than simply reading them as a story about Europe.
6 Implications for Japan and Future Discussion Points
What emerges from the WHO European AI report is a reality that is, in a sense, obvious but carries weight when presented with numbers: healthcare AI will not truly begin to function in earnest unless the 'legal system, data infrastructure, human resources, funding, and inclusivity' are all in place. Even with progress in European-level systems such as the AI Act, the EHDS, and the AI Framework Convention, at the individual country level, strategies specialized for healthcare, liability rules, human resource development, and inclusive governance are still halfway there.
Roughly summarizing the implications for Japan, there are at least the following three points. First, when considering cross-cutting regulations on AI (for example, regulations on generative AI services in general), the 'legal uncertainty' in the field will not be resolved unless the liability structure and data usage methods specific to the high-risk domain of healthcare are designed simultaneously. Second, when developing data infrastructure, it is important to combine access rights, prohibitions on secondary use, and audit mechanisms, rather than relying solely on anonymization. Third, the design of inclusivity—who is invited to the table for discussions surrounding AI—becomes just as important as the legal system itself.
I believe that AI governance is not a topic that can be completed by scholars alone. That said, when looking at materials that calmly quantify the 'readiness' of each country, such as the WHO European AI report, I feel that we need to more carefully distinguish between the aspects of legal system design as a deceleration device and as an acceleration device. If legal uncertainty is left unaddressed, AI will not advance, but if it is enclosed by overly rigid rules, AI will not advance either. The task of finding the right combination of deceleration and acceleration in between is surely a modest but rewarding job assigned to researchers and practitioners.
7 Conclusion
The WHO European AI report is not a flashy report introducing the latest technological trends in healthcare AI. If anything, it is a rather steady read that calmly lists the lack of preparation and gaps in each country. However, that is precisely why I believe it should be valued when thinking about AI and the law. This is because 'missing pieces'—such as the absence of strategy, lack of human resources, lack of liability rules, and ambiguity in data governance—rather than spectacular success stories, become the starting point for legal system design.
The situation in Europe is by no means someone else's problem for Japan. Rather, it is a welcome precedent in the sense that we can observe 'where the region that is running ahead is stumbling.' While reading the WHO European AI report, when advancing discussions on AI governance in Japan, it will be necessary to similarly re-examine which of the six pillars—Navigators, Change-makers, Guardrails, Backbones, Catalysts, and Gatekeepers—are weak.
◾️References
World Health Organization Regional Office for Europe, Artificial intelligence is reshaping health systems: state of readiness across the WHO European Region (WHO Regional Office for Europe, 2025).
Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2016/798 (Artificial Intelligence Act) OJ L, 12 July 2024.
Regulation (EU) 2025/327 of the European Parliament and of the Council of 13 March 2025 on the European Health Data Space and amending Regulations (EU) 2016/679, (EU) 2018/1725 and (EU) 2021/241 and Regulations (EC) No 851/2004, (EC) No 1920/2006, (EU) No 282/2014 and (EU) No 536/2014 (European Health Data Space Regulation) OJ L, 19 March 2025.
Council of Europe, Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, CETS No. 225, opened for signature 5 September 2024.
European Commission, “Artificial Intelligence Act: the world’s first comprehensive AI law”, European Commission website, 2024.
European Commission, “European Health Data Space (EHDS)”, European Commission website.
8 Materials for Thought
(Magazine) 'AI and Law - Random Thoughts'
※ Please refer to the following for the table of contents
note General Terms of Service Article 3, Paragraph 2, First Sentence
3.2 The copyright of digital content produced by the creator belongs to the creator.
