Artificial intelligence (AI) is scanning breasts in Turkey, reading X-rays in Portugal and phoning elderly patients at home. The technology has arrived. The rules to govern it are being drafted elsewhere, and health is not at the table.

37 countries gathered in Lisbon on 15 and 16 July, at a conference hosted by WHO and the government of Portugal, to talk about AI in health. The message from WHO was not about the promise of the technology. It was about who controls it. “The question is not whether AI will transform health, but whether we will shape that transformation or simply react to it,” said WHO Regional Director for Europe, Dr Hans Kluge.

A machine that already works

The examples are real and already running. In Turkey, Dr Kluge said, AI is built into national breast cancer screening for women aged 40 to 69, “supporting detection, reducing radiologist workload and accelerating diagnosis.” In Portugal, the Coimbra local health unit uses AI image analysis to support radiology in primary care and emergency rooms, cutting waiting times while clinicians keep the final decision. The United Kingdom trains new diagnostic tools with a national database of more than 81,000 COVID-19 chest scans.

One story showed what this looks like for a patient. Ricardo Baptista Leite, chief executive of the non-profit agency HealthAI, described an elderly woman in rural Portugal. After she left hospital, an AI assistant phoned her every day to remind her to take her medicine. When she visited her cardiologist, she asked to meet the assistant in person. Told it was a virtual one, she said it did not matter, “as long as she continues to call me, because she’s so kind.” The fear that AI makes care less human, Mr Baptista Leite argued, misses what the technology can do.

The rules are being written elsewhere

The governance is not keeping pace. Alain Labrique, who leads data, digital health, analytics and AI at WHO headquarters, pointed to a document published the day before the conference. Demis Hassabis, then chief executive of Google DeepMind and a Nobel laureate, had proposed a standards body to test the most advanced AI models before release. It would be funded by industry, answerable to one government, and modelled on financial regulation.

Mr Labrique’s objection was direct. “There is no Ministry of Health represented in this governing body,” he said. The most consequential technology of our time, he warned, is being designed “in rooms where health is not represented”.

You might be interested

Government belongs in the driver’s seat.
— Alain Labrique, Data, Digital Health, Analytics and AI Lead, World Health Organization

His conclusion set the tone. A ministry that cannot inspect, audit or withdraw a model, he said, “does not own that system. It rents it. It inherits it.” Government, he added, belongs “in the driver’s seat, not the vendor, not the platform, not the funder”.

A trust gap, in numbers

WHO’s own data shows how far governance lags. Only 8 per cent of countries in the pan-European region have a health-specific AI strategy, Dr Kluge said. Only one in five trains health professionals before they enter practice. Almost 40 per cent lack any operational guidance on the ethical use of AI. “These numbers represent doctors, nurses and patients being asked to embrace AI, but without the policies,” he said.

Mr Labrique named the risk in one line. Generative AI can deliver “a wrong answer delivered fluently, confidently”. Medicine spent a century building systems to catch bad drugs and devices, he said, and has “barely begun” to build the same for AI.

Europe’s answer, and a cyber warning

The European Union (EU) came with a regulatory answer. Marco Marsella, a director at the European Commission’s health department (DG SANTE), argued that the problem is rarely the technology itself. “The bottleneck is in everything around that model,” he said: fragmented data, unclear rules, funding gaps and workforce doubts. Two reviews, one by the Commission and one by WHO, reached the same conclusion.

He described the EU’s response as three legs that only work together. Rules come first: data protection law, the Medical Device Regulation, the European Health Data Space and the AI Act, which Mr Marsella called “one interlocking system”. Then collaboration. Then money. “Regulations without funding is aspirations,” he said, “and funding without collaborations may lead to fragmentation.”

Mr Marsella also named a gap no rulebook can close. The Commission surveyed clinicians, hospitals and AI developers. They agreed AI could ease workload. They split on whether it works at the bedside. Developers “are much more confident than the clinicians,” he said. Building a system is not the same as being trusted to use it. “Adoption per se is not a model, it’s a system.”

Trust also means security. Dr Kluge noted that leading cyber security agencies from five countries had just warned that AI is transforming cyber risks “in months, not years”. Health data, Mr Marsella had said earlier, is “intensely personal”, and the stakes are life or death.

What comes next

The plan is a roadmap. Dr Kluge said WHO’s European Roadmap for Action on Artificial Intelligence in Health, covering 2026–2033, goes to member states in October. He called it “not just another strategy” but a practical plan for implementation.

This is not an aspiration. This is a deadline.
— Marco Marsella, Director, DG SANTE, European Commission

Mr Marsella left the room with a date. Under the EU’s digital targets, every citizen should be able to reach their own electronic health record by 2030. “This is not an aspiration,” he said. “This is a deadline.” The clock is the easy part. The harder question is whether the systems reading that record will be ones a health minister can inspect, audit and switch off.