FRANCE Law and Practice Contributed by: Liliana Eskenazi, Julie Ernewein and Pauline Lecrenais, Fréget Glaser et Associés
3. Regulatory Oversight of Healthcare AI 3.1 Regulatory Authorities French key bodies are as follows: • HAS (Authority for Health) (a) assesses clinical utility and added value of medical devices, AI-based diagnostic and decision-support tools; and (b) issues guidelines and best practices for evalu - ating digital health technologies. • ANSM (Medicine Agency) (a) regulates and ensures the safety, performance, and conformity of medical devices, including SaMD; and (b) authorises clinical investigations for AI-driven devices when required. • CNIL (Data Protection Authority) (a) oversees compliance with data protection rules under the GDPR and French Data Protection Act; and (b) issues guidance specific to health data pro - cessing and the use of AI in healthcare. • ANS (Digital Health Agency) (a) develops digital infrastructure, interoperability standards, and cybersecurity frameworks for health IT systems, including AI tools; and (b) manages the national health identifier system and supports the Mon espace santé platform. • Ministry of Health (a) defines national strategies and policies for digital health and AI regulation; and (b) co-ordinates public funding and innovation programmes (eg, the Health Innovation Plan). Coordination between regulatory and data protection authorities in France occurs through several mecha - nisms, as follows. • Joint guidance and frameworks – regulatory and data protection authorities have already collabo - rated through working groups, notably to develop guidance documents on AI in healthcare, such as the Implementation Guide for Ethical AI Systems in Healthcare (2025). • National strategy alignment – France 2030 Stra - tégie d’accélération santé numérique aligns the
2.5 Data Protection and Privacy France applies GDPR rules – emphasising informed patient consent, proportional data use, and cyberse - curity – and the French Data Protection Act (see 6. Data Governance in Healthcare AI ). 2.6 Interoperability and Standards Applicable Technical Standards for Healthcare AI Systems ISO and IEC have developed the ISO/IEC 42001 standard to support manufacturers in aligning their AI- enabled products with the requirements of the AI Act. The standard promotes the responsible development of AI, emphasising safety, transparency, and ethics. It thus provides a normative framework for manufac - turers of devices incorporating AI, to implement an AI management system. The implementation of such a system should be aligned with the processes required for ISO 13485 certification, such as management responsibility, risk management, audits, and continu - ous improvement. ISO/IEC 42001 introduces some additional require - ments concerning: • the needs and expectations of interested parties; • the development and deployment of AI; • the AI lifecycle; • data management; and • technical documentation for AI. In practice, manufacturers must comply with both ISO 13485 and ISO/IEC 42001. While the two share over - lapping requirements, these must be consolidated into a unified quality management system. Interoperability and Data Protection Requirements Since February 2023, an Interoperability and Secu - rity Framework for Digital Medical Devices has been applicable to all medical devices reimbursed by the French National Health Insurance that involve the pro - cessing of personal data as defined by the GDPR. Certification of compliance is issued by ANS.
71
CHAMBERS.COM
Powered by FlippingBook