Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Term of the Day

Natural history study

A natural history study is a preplanned observational study intended to track the course of a disease over time, identifying demographic, genetic, environmental and other variables that correlate with its development and outcomes in the absence of intervention, or under standard of care. Designs may be retrospective (chart review of existing records) or prospective (longitudinal follow-up of a cohort or registry).

Natural history data is particularly important in rare and paediatric diseases, where randomised placebo-controlled trials may be infeasible or unethical. The FDA (guidance on rare disease natural history studies, 2019) and the EMA accept well-designed natural history studies to define endpoints and biomarkers, identify patient subgroups, estimate sample sizes and, in some cases, serve as external or historical control arms for single-arm trials supporting orphan products.

Because they are non-interventional, natural history studies fall outside the CTR and are governed by national law (for example France's MR-003 or MR-004 reference methodologies) and by the GDPR. They typically involve secondary use of medical records, long-term follow-up, genetic data and small populations in which anonymisation is rarely achievable, so pseudonymisation, a DPIA and a robust research legal basis under Art. 9(2)(j) are essential. Registries maintained by patient organisations or academic consortia raise additional questions of joint controllership and data access governance.

H

High-risk AI system

A high-risk AI system is an AI system that falls within one of the two categories of Art. 6 of the EU AI Act. Under Art. 6(1) and Annex I, an AI system is high-risk if it is intended to be used as a safety component of a product, or is itself a product, covered by listed Union harmonisation legislation and required to undergo third-party conformity assessment; the Medical Device Regulation and the IVDR are on that list, so AI-enabled medical devices and diagnostics above Class I are high-risk. Under Art. 6(2) and Annex III, stand-alone AI systems used in listed areas are high-risk: biometrics, critical infrastructure, education, employment, access to essential private and public services (including systems evaluating eligibility for public healthcare benefits and emergency triage of patients), law enforcement, migration and justice. Art. 6(3) allows a derogation where the system does not pose a significant risk because it performs a narrow procedural task or merely supports human assessment, subject to documentation.

Providers of high-risk systems must implement a risk management system across the lifecycle (Art. 9), apply data governance and quality criteria to training, validation and testing data including examination for bias (Art. 10), draw up technical documentation (Art. 11) and enable automatic logging (Art. 12), provide instructions for use and transparency to deployers (Art. 13), design for effective human oversight (Art. 14), ensure accuracy, robustness and cybersecurity (Art. 15), operate a quality management system, undergo conformity assessment, register the system in the EU database, affix the CE marking and carry out post-market monitoring and serious incident reporting. Deployers must use the system according to instructions, ensure human oversight by competent staff, monitor operation, keep logs, inform affected persons and, where they are public bodies or provide essential services, carry out a fundamental rights impact assessment. Most obligations apply from 2 August 2026 for Annex III systems and from 2 August 2027 for Annex I products, subject to the adjustments proposed in the Commission's digital omnibus.

For life sciences, AI software as a medical device (imaging analysis, diagnostic algorithms, dosing and monitoring tools) is the main high-risk category, with conformity assessment integrated into the notified body's MDR or IVDR review. AI used purely for scientific research and development, or in clinical trials before placing on the market, is largely exempt under Art. 2(6) and 2(8), but the same systems become high-risk when marketed. Where a high-risk system processes personal data, the GDPR applies cumulatively, and the DPIA and the AI Act risk documentation should be prepared together. iliomad's AI compliance services cover classification, gap analysis and documentation.