AUSTRIA Law and Practice Contributed by: Harald Strahberger and Florian Sesztak, Kinstellar
sion-support software), it must undergo a conformity assessment, involving a Notified Body, particularly for Class IIa or higher. Pre-market requirements include: • preparation of technical documentation in accord - ance with Annexes II and III of the MDR, covering design, software architecture, usability, and perfor - mance; • a clinical evaluation pursuant to Article 61 MDR, demonstrating safety and performance through literature, clinical data, or new studies; • a risk management file, addressing hazards, miti - gation measures, and residual risks; and • evidence of a Quality Management System. While algorithmic transparency and bias testing are not currently mandatory under the MDR and MPG, they are increasingly expected by the regulatory authorities overseeing medical device regulations and are explicitly required under the AI Act. That legislation will also impose obligations for explainability, human oversight, and documentation of training data quality (see also 2.4 Software as a Medical Device (SaMD) ). 3.3 Post-Market Surveillance Once an AI system is on the Austrian market, manu - facturers must fulfil post-market surveillance obliga - tions under the MDR and MPG. These include: • maintaining a post-market surveillance plan and regularly updating it based on real-world perfor - mance data; • submitting periodic safety update reports for class IIa and higher devices, summarising benefit-risk assessments and performance data; and • operating a vigilance system to detect and report serious incidents, field safety corrective actions, and device-related deaths or injuries to BASG within defined timelines. Any modifications to the AI algorithm, especially those affecting its intended use or safety, may require re- certification or, at the very least, documented change management under the MDR’s significant change rules. Additionally, the MPG requires healthcare insti - tutions utilising AI to collaborate with the authority in
post-market surveillance by reporting adverse events and ensuring clinician training and the traceability of AI-assisted decisions. The AI Act also stipulates structured documentation of significant changes, ver - sion control and continuous monitoring, especially for adaptive or continuously learning systems. 3.4 Enforcement Actions As of now, Austria has not seen high-profile enforce - ment actions or recalls involving AI-based medical devices specifically. However, the BASG has broad powers under the MPG to: • suspend or prohibit the use of non-compliant devices; • require corrective actions or safety updates; and • impose administrative fines. The DSB, in turn, has the authority (under the GDPR rules) to conduct investigations, audits, and impose fines of up to EUR20 million or 4% of the company’s global turnover for data breaches or unlawful process - ing, which could arise from improperly configured AI systems. In practice, Austrian regulators have so far taken a cautious and cooperative approach to digital health enforcement, prioritising guidance over punishment. However, with the AI Act and growing use of AI in patient care, increased scrutiny and formal enforce - ment actions are expected, particularly regarding transparency, risk controls, and bias. 4. Liability and Risk in Healthcare AI 4.1 Liability Framework In Austria, the liability framework for healthcare AI sys - tems is not governed by a standalone AI liability stat - ute; instead, it applies a combination of traditional tort, medical, and product liability principles, along with specific rules for medical devices and data protection. Healthcare AI systems that qualify as medical devices under the MPG are subject to strict liability for defec - tive products under the Austrian Product Liability Act ( Produkthaftungsgesetz – “PHG”). Manufacturers and developers may be held liable if their AI software caus -
22
CHAMBERS.COM
Powered by FlippingBook