Term of the Day

Natural history study

A natural history study is a preplanned observational study intended to track the course of a disease over time, identifying demographic, genetic, environmental and other variables that correlate with its development and outcomes in the absence of intervention, or under standard of care. Designs may be retrospective (chart review of existing records) or prospective (longitudinal follow-up of a cohort or registry).

Natural history data is particularly important in rare and paediatric diseases, where randomised placebo-controlled trials may be infeasible or unethical. The FDA (guidance on rare disease natural history studies, 2019) and the EMA accept well-designed natural history studies to define endpoints and biomarkers, identify patient subgroups, estimate sample sizes and, in some cases, serve as external or historical control arms for single-arm trials supporting orphan products.

Because they are non-interventional, natural history studies fall outside the CTR and are governed by national law (for example France's MR-003 or MR-004 reference methodologies) and by the GDPR. They typically involve secondary use of medical records, long-term follow-up, genetic data and small populations in which anonymisation is rarely achievable, so pseudonymisation, a DPIA and a robust research legal basis under Art. 9(2)(j) are essential. Registries maintained by patient organisations or academic consortia raise additional questions of joint controllership and data access governance.

H

Human oversight (AI Act)

Human oversight is the requirement in Art. 14 of the EU AI Act that high-risk AI systems be designed and developed, including with appropriate human-machine interface tools, so that they can be effectively overseen by natural persons during the period in which they are in use, with the aim of preventing or minimising risks to health, safety or fundamental rights. Providers must build in oversight measures, either integrated into the system or identified for implementation by the deployer, that enable the persons assigned to oversight to understand the system's capacities and limitations, remain aware of automation bias (the tendency to over-rely on outputs), correctly interpret outputs, decide not to use the system or to disregard, override or reverse an output, and intervene or interrupt the system through a "stop" button or similar procedure. For remote biometric identification systems, verification by at least two competent persons is required.

Deployers, under Art. 26, must assign human oversight to natural persons who have the necessary competence, training, authority and support, ensure that input data is relevant and sufficiently representative, monitor the system's operation according to the instructions for use, and inform the provider and authorities of risks and serious incidents. Art. 4 additionally requires providers and deployers to ensure a sufficient level of AI literacy among their staff. The Commission and standardisation bodies (CEN-CENELEC JTC 21) are developing harmonised standards that specify oversight measures in more detail.

Human oversight in the AI Act complements, but is broader than, the protections against solely automated decisions in Art. 22 GDPR: GDPR safeguards apply to decisions with legal or similarly significant effects on individuals, whereas AI Act oversight applies to the operation of the system as a whole, whether or not individual decisions are involved. In healthcare, effective oversight means that a radiologist reviewing AI-flagged images, a clinician using a decision-support tool or a pharmacovigilance scientist validating AI-coded cases must have the time, training and interface design to disagree with the system, and that these arrangements are documented; a nominal "human in the loop" who rubber-stamps outputs satisfies neither the AI Act nor the GDPR. iliomad's AI Officer service designs and monitors these governance arrangements.