Privacy AI
Regulatory

Health data compliance, handled.

Tell us what you need. We'll tell you what it takes and how long, before you commit.

Contact us

Summary

The EU Digital Omnibus (Regulation 2026/1744) simplifies AI Act compliance, easing the burden for healthcare and AI systems. Concurrently, Rhode Island has enacted three laws regulating AI in healthcare, emphasizing transparency and accountability, impacting biotech and healthtech sectors in compliance and patient engagement.

Contact us

EU Digital Omnibus on AI: Simplification of the AI Act

Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amends Regulation (EU) 2024/1689 (the EU AI Act), Regulation (EU) 2018/1139 (aviation safety) and Regulation (EU) 2023/1230 (machinery) with the stated aim of simplifying harmonised AI rules. The European Parliament and Council acknowledged that the original AI Act's implementation requirements created disproportionate complexity for smaller operators and certain regulated sectors, and the Digital Omnibus seeks to address that by streamlining specific obligations. Healthtech and medtech developers should map the revised provisions against their existing AI governance frameworks to identify where updated procedures or documentation may be required.

Read more

United States: Rhode Island Regulates AI in Healthcare and Companion Tools

Rhode Island enacted three AI-focused statutes in June 2026, including the Use of Artificial Intelligence by Healthcare Providers Notification Act (S 2570), which imposes disclosure requirements on healthcare providers using AI tools in clinical settings. Additional statutes address AI companion tools and the use of AI in the provision of mental health services, reflecting legislative concern about patient vulnerability and the potential for AI-generated interactions to influence clinical or emotional outcomes. Organisations offering AI-assisted care-coordination, patient-engagement or mental-health platforms in the United States should review these statutes alongside existing federal frameworks to ensure notification and safeguard obligations are met.

Read more

Contact us

FAQs

Our frequently questions

What does the EU's Digital Omnibus on AI (Regulation (EU) 2026/1744) actually change?

t amends the EU AI Act (Regulation (EU) 2024/1689) — along with the Machinery Regulation (EU) 2023/1230 and the aviation safety regulation (EU) 2018/1139 — to simplify certain implementation obligations that were seen as disproportionately burdensome, particularly for smaller operators. It doesn't dismantle the AI Act's risk-based framework; it revises specific procedural and documentation requirements, including aspects of conformity-assessment pathways relevant to high-risk systems.

Does this affect biotech and healthtech companies using AI in clinical decision support or diagnostics?

Potentially, yes. If a company deploys or develops high-risk AI systems in these areas, the revised conformity-assessment and documentation rules under the amended regulations could change what's required on their product roadmap. Compliance teams should map the updated provisions against their existing AI governance framework to confirm which specific obligations shifted.

What do Rhode Island's new AI healthcare laws require?

Rhode Island enacted three statutes in June 2026. The centerpiece, the Use of Artificial Intelligence by Healthcare Providers Notification Act (S 2570), requires healthcare providers to disclose their use of AI tools in clinical settings. The other two address AI companion tools and AI use in mental health service delivery, reflecting concern about patient vulnerability in these contexts.

Do these Rhode Island laws matter for a company already compliant with GDPR in Europe?

They're a useful signal rather than a compliance shortcut. The transparency and accountability expectations echo principles familiar from European data protection law, but Rhode Island's requirements are distinct state statutes with their own notification and safeguard obligations. Any organization offering AI-assisted patient engagement, care coordination, or mental health tools to Rhode Island residents needs to review these specific statutes against its US compliance posture — GDPR alignment alone won't cover them.

Seamus Larroque

CDPO / CPIM / ISO 27005 Certified

Find out how iliomad can help your company.

[Map placeholder]
Only visible in production
38.709099
-39.182035
1.6
6d17042a3425c5b3
Your message has been received!
We'll get back to you as soon as possible.
Something went wrong, please try again.
Home

Discover our latest articles

View All Blog Posts
A data protection officer reviewing adverse event safety reports and GDPR compliance documentation for a multinational clinical trial
August 10, 2026
Clinical Trials
Biotech & Healthtech

Safety Reporting Personal Data in Clinical Trials: GDPR Obligations and Cross-Border Risks

Understand GDPR obligations for safety reporting personal data in clinical trials, including adverse event disclosure timelines, cross-border transfer rules and sponsor duties.

Abstract digital network over a hospital building silhouette, representing healthcare cybersecurity and data protection threats in the biotech sector
August 5, 2026
Healthtech
Data Breach & Cybersecurity
Regulations & Guidelines
GDPR
AI

Weekly Digest: Healthcare Cyber Breaches, AI Regulation Advances and Genetic Data Enforcement | iliomad

Ransomware mortality data, the FDA-EMA AI framework, Germany's KI-MIG, the EU-US DPF under review and a wave of US healthcare breaches: this week's digest for biotech and healthtech.

Diagram illustrating the EDPB three-criteria anonymisation test applied to clinical trial datasets under GDPR, with icons for record isolation, linkage and inference
July 13, 2026
DPIA
AI
Testimonial
EU Privacy Law
Regulations & Guidelines

EDPB Anonymisation Guidelines 2026 and Clinical Trial Data: What Life Sciences Organisations Must Know

EDPB Guidelines 02/2026 on anonymisation set new standards for clinical trial data. Learn the three-criteria test, enforcement lessons and compliance steps. iliomad.