AUSTRIA Law and Practice Contributed by: Harald Strahberger and Florian Sesztak, Kinstellar
5.4 Human Oversight Human oversight is a core principle in Austrian health - care AI governance, anchored in both regulatory requirements and medical ethics. The AI Act requires all high-risk AI systems, including those in healthcare, to be designed and implemented with meaningful human oversight to prevent automation bias or over- reliance on algorithmic recommendations. This aligns with the restriction that medical services may only be provided by physicians according to Sec - tion 3 (4) ÄrzteG (“ Arztvorbehalt ”). As a result, AI tools cannot act autonomously in clinical care settings. Even highly sophisticated AI systems must serve in a decision-support role, with the final judgment always made by a medical professional. Under MDR, manufacturers must include human-fac - tor testing and clear instructions for use, ensuring that healthcare professionals can correctly interpret and override AI outputs. The level of oversight depends on the type of system: for example, triage-support AI may require passive monitoring, while diagnostic tools demand active physician validation. In short, in Austria, AI may assist, but never replace the healthcare professional. 6. Data Governance in Healthcare AI 6.1 Training Data Requirements Training data is central to the performance and reli - ability of healthcare AI systems. In Austria, the use of health-related datasets is governed primarily by the GDPR and the Austrian DSG. These laws require that personal data, particularly sensitive categories such as health data, be processed lawfully, fairly, and trans - parently. For AI systems regulated as medical devices under the MDR, the training dataset forms part of the tech - nical documentation and must be described in terms of representativeness, inclusion and exclusion crite - ria, and data quality. Developers are expected to use datasets that are complete, clinically relevant, and statistically representative of the patient population in which the system will be used. Particular atten -
tion must be paid to avoiding historical biases, which could lead to discriminatory outcomes. The AI Act additionally requires that: • training data of high-risk AI systems is relevant, representative, free of errors, and complete; • the dataset’s characteristics, origin, and preproc - essing methods are comprehensively and auditably documented; and • measures to detect, prevent, and mitigate bias in data and algorithms are in place. To mitigate bias, developers are required to: • conduct bias impact assessments during dataset development and model training; • include diverse and representative samples in the training data to reduce demographic imbalances; • regularly test and validate AI systems across sub - populations to detect differential performance; and • document mitigation strategies transparently and make them available to regulators and clinical users. The AI Act further reinforces this by requiring high- risk AI systems to undergo post-market monitoring to identify and correct emerging biases once they are deployed. 6.2 Secondary Use of Health Data The secondary use of health data – ie, using data originally collected for clinical care for research or AI training – is subject to strict rules under Articles 5, 6, and 9 of the GDPR and the DSG. The usage requires explicit, informed consent from the data subject, par - ticularly for identifiable data. Alternatively, processing may be permitted under the research exemption in Article 9 (2)(j) GDPR, provided adequate safeguards are in place. In Austria, ethics committee approval is generally required for research projects using personal health data. This includes AI development in academic set - tings or collaborations with healthcare providers. Projects must be registered with local ethics boards (eg, at university hospitals) and often require a Data
25
CHAMBERS.COM
Powered by FlippingBook