SWEDEN Law and Practice Contributed by: Anders Bergsten and Victoria Nordenberg, Mannheimer Swartling Advokatbyrå AB
Security by Design High-risk AI systems must be designed and devel - oped to achieve an appropriate level of accuracy, robustness and cybersecurity and perform consist - ently throughout their life cycle, including resilience to faults and external interference. In addition, provid - ers must operate a documented quality management system covering design and development controls, testing/validation, risk management, post-market monitoring and incident reporting procedures. Supply-Chain and Model Component Security The AI Act allocates responsibility along the AI sup - ply chain and contemplates written arrangements with suppliers of tools, services, components or processes used or integrated into high-risk AI systems, including sharing necessary information/capabilities/technical access to enable compliance. The quality manage - ment system requirements also include resource man - agement and security-of-supply related measures, which in practice supports supply-chain controls for AI development and deployment. For GPAI models with systemic risk, providers must ensure an adequate level of cybersecurity protection for the model and its physical infrastructure (alongside systemic-risk assessment/mitigation and adversarial testing). Incident Reporting Providers of high-risk AI systems must report serious incidents to the competent market surveillance author - ity in the member state where the incident occurred, with the AI Act setting deadlines and follow-on steps; the Commission has also issued draft guidance and a reporting template (noting these rules apply from August 2026). Separately, providers of GPAI models with systemic risk must track, document and report relevant information about serious incidents and cor - rective measures without undue delay to the AI Office (and, as appropriate, national competent authorities). Parallel Regimes AI Act requirements apply in parallel with other regimes. For example, where personal data is used in training or operation, GDPR security and breach-han - dling obligations continue to apply. For organisations in Sweden that are in scope of the Swedish Cyber - security Act, AI-related incidents may also trigger incident reporting (eg, initial notice within 24 hours,
then further reporting steps) and broader risk-based security duties. In addition, where AI is embedded in “products with digital elements”, the CRA may impose product cybersecurity/vulnerability-handling require - ments alongside the AI Act. 6.3 Cybersecurity in the Healthcare Sector Cybersecurity and the Healthcare Sector Cybersecurity in healthcare focuses on safeguarding electronic information and assets against unauthor - ised access, use and disclosure. The healthcare sec - tor must systematically address the security of health - care information management. The Patient Data Act contains explicit provisions to prevent unauthorised dissemination by electronic means of data relating to patients undergoing treat - ment. It contains the provisions specifically needed for the processing of patient data by healthcare pro - viders in relation to other personal data processing. Otherwise, the provisions of the GDPR apply to the processing of patient data and other personal data by healthcare providers. The Patient Data Act governs several aspects, including: • the ability of healthcare personnel involved in a patient’s care to access necessary medical records, even if those records were created by a different healthcare organisation; • the regulations determining which individuals are permitted to access patient data as part of their duties within the healthcare system; and • the patient’s right to restrict access to informa - tion in their medical records within an electronic records system. Further, the Swedish Cybersecurity Act applies to in- scope entities in the health sector (which is treated as an essential sector under the NIS2 framework). Accordingly, healthcare providers and other covered organisations must comply with the cybersecurity-law requirements described above. Under NIS2, the health sector belongs to the category of highly critical enti - ties, which is identified as a high-criticality (“essen - tial”) sector under the NIS2 framework. However, whether a particular healthcare organisation is classi - fied as a essential or important operator depends on the entity’s status and size under the Swedish imple - mentation.
367 CHAMBERS.COM
Powered by FlippingBook