weeklyAI · Week of 27 September 2026weeklyAI · Semana del 27 de septiembre de 2026

← Your rights← Sus derechos

survey · Bulletin of the World Health Organization · la publicación, 1 jun 2026 · gratis

Una encuesta de la OMS Europa halló que menos de 10% de 50 países tiene normas sobre quién responde por la IA en salud.

Una encuesta de la OMS Europa encontró que casi ningún gobierno tiene reglas sobre quién responde cuando una herramienta de IA daña a un paciente.

Versión breve · la versión detallada sigue, unos 4 min

Pregunte a weeklyAI

Pregúnteme por este estudio: a quiénes se estudió, qué encontró y qué no dice.

Las conversaciones se guardan mientras exista weeklyAI, para mejorar la publicación. Se responde en el idioma en que usted escribe.

El estudio, de un vistazo
Quiénes
Estados Miembros de la Región Europea de la OMS
Cuántos
50 de 53 Estados Miembros respondieron
Dónde
Región Europea de la OMS
Cuándo
entre junio de 2024 y marzo de 2025
Tipo de estudio
encuesta
Quién lo hizo
Oficina Regional de la OMS para Europa
El límite que importa
Las definiciones de los términos eran flexibles y cada país las interpretó a su manera.
Países de la Región Europea de la OMS según sus reglas sobre inteligencia artificial en salud
Tienen una estrategia de IA específica para salud8%
Han emitido medidas legislativas específicas para IA en salud8%
Han creado estándares de responsabilidad para IA10%
Tienen procesos para que una persona afectada presente una queja por IA10%
Han adoptado marcos éticos intersectoriales20%
No han publicado ninguna guía ética38%
No tienen políticas sobre IA en salud o no están seguros64%

Porcentaje de los 50 países que respondieron a la encuesta de la OMS Europa. Los números no son derechos exigibles y no dicen nada sobre las leyes de América Latina, Estados Unidos o Canadá.

Ninguna de esas prioridades es ley en su país por aparecer en este estudio.
Lectura de weeklyAI
Así podría verse · ilustración generada por weeklyAI.watch, no es una fotografía

Usted entrega su rostro, su voz, sus datos y su trabajo a herramientas de inteligencia artificial (IA). Si una de esas herramientas le hace daño, ¿quién responde? Hoy, en la mayoría de los países, no existe una respuesta clara.

Eso es lo que muestra una encuesta de la Oficina Regional para Europa de la Organización Mundial de la Salud (OMS). Entre junio de 2024 y marzo de 2025, invitó a los 53 Estados Miembros de su región. Respondieron 50: una tasa del 94%.

El resultado: la gobernanza de la IA en salud está poco desarrollada. Solo 4 de 50 países tienen una estrategia de IA específica para la salud; 7 más la están elaborando. Unos 33 tienen estrategias de IA que abarcan varios sectores. Solo 10 han creado leyes nuevas de IA para la salud. Y solo 4 de cada 50 han definido normas de responsabilidad para la IA, o guías sobre cómo aplicar las normas que ya existen.

En materia de datos, 33 de 50 países (66%) tienen una estrategia nacional de datos de salud y 33 tienen centros de datos de salud. Un 68% cuenta con una autoridad de datos de salud, es decir, un organismo que decide quién accede a los datos y cómo se usan.

Esto es solo un retrato de Europa. La encuesta no dice nada sobre lo que la ley dice hoy en América Latina, Estados Unidos ni Canadá. No puede usarla como prueba de las reglas de su propio país.

Tampoco es una medida exacta. Los propios gobiernos reportaron sus respuestas, y el artículo señala que las definiciones de los términos eran flexibles y cada país las interpretó a su manera. Un número aquí no equivale a un derecho exigible.

Y es una foto que se mueve: los autores dicen que la gobernanza de la IA cambia rápido y que algunos hallazgos pueden quedar desactualizados pronto.

El artículo propone prioridades para las políticas. ¿Qué agencia vigila la IA en salud en su país? ¿Qué puede presentar una persona afectada y ante quién? ¿Quién debe responder cuando un sistema causa un daño?

El artículo propone prioridades: institucionalizar la vigilancia en agencias existentes, definir responsabilidades para desarrolladores, personal clínico, proveedores de datos e instituciones, y convertir los principios éticos en reglas aplicables.

Ninguna de esas prioridades es ley en su país por aparecer en este estudio. Pero cada una es una pregunta que usted puede hacer hoy.

Pregunte: ¿quién responde si esta herramienta me daña?

Qué significa para usted

Usted no encontrará en este estudio ninguna norma que su país deba cumplir, porque la encuesta solo retrató a Europa y no evaluó si la IA daña o mejora la salud. Lo que sí puede hacer hoy es preguntar en su país qué autoridad vigila estas herramientas y ante quién se reclama si un sistema causa un daño. Anote también si su gobierno prepara una ley o una estrategia sobre inteligencia artificial en salud.

Adib, K., Letchford, N., Dunning, H. E. et al. (2026). Governance of artificial intelligence for health systems, WHO European Region. Bulletin of the World Health Organization. https://doi.org/10.2471/blt.25.294978

Quién pagó: La Comisión Europea apoyó este trabajo en el marco del proyecto titulado Supporting Member States in strengthening health information systems and boosting health data governance; el artículo no declara intereses en conflicto y no indica que el financiador tuviera participación alguna en el diseño, el análisis o la redacción.

No tome esto como consejo médico profesional.

Versión detalladaLos pasajes copiados del artículo, las ilustraciones y cada fuente con cuánto leímos de ella · 801 palabras · unos 4 minLeerla →Cerrar

Encuesta de la OMS Europea: 50 países, solo 4 con reglas de responsabilidad para IA en salud

Una encuesta de la OMS Europea a 50 países encontró que apenas 4 tienen reglas de responsabilidad para la IA en salud.

Así podría verse · ilustración generada por weeklyAI.watch, no es una fotografía

La inteligencia artificial se está integrando en los sistemas de salud, pero las reglas que dirían quién responde cuando esa herramienta se equivoca casi no existen. Pero las reglas que dirían quién responde cuando esa herramienta se equivoca casi no existen. Eso es lo que midió una encuesta del Buró Regional para Europa de la Organización Mundial de la Salud (OMS), aplicada a las 53 naciones que forman esa región entre junio de 2024 y marzo de 2025. Respondieron 50 países y el análisis fue descriptivo: no buscó comparar ni probar hipótesis, sino fotografiar qué tan preparados están esos sistemas de salud para gobernar la IA.

Los números son elocuentes. Solo 8% (4 de 50) tiene una estrategia de IA específica para salud, y 14% (7) la está redactando. Solo 4 países han emitido medidas o disposiciones legislativas específicas para la gobernanza y la vigilancia de la IA en el sector sanitario, y 18 las están elaborando. Menos de 10% (4 de 50) ha creado estándares de responsabilidad para IA o guías para aplicar los que ya existían. Solo 5 de 50 países han puesto en marcha procesos para que una persona afectada presente una queja relacionada con IA. Y 19 de 50 todavía no han publicado ninguna guía ética, ni sanitaria ni intersectorial.

El estudio tiene límites que el propio artículo reconoce. Las definiciones de los términos variaban y cada país las interpretó a su manera; la validez dependió del experto que cada gobierno designó; tres países no respondieron (Bosnia y Herzegovina, Mónaco y Turkmenistán), así que los totales regionales descansan en 50 de 53. Además, la gobernanza de la IA cambia rápido y estos hallazgos pueden quedar desactualizados pronto.

¿Qué incluye la palabra "gobernanza"? No es solo una ley. Es el conjunto de estrategias, normas, marcos de responsabilidad y reglas que buscan proteger a las personas y hacer que las instituciones rindan cuentas. Puede ser vertical, enfocada en un sector como la salud, u horizontal, atravesando muchos sectores. Puede concentrarse en una sola autoridad o repartirse entre varias. Y puede tener distintos grados de exigibilidad: desde instrumentos vinculantes hasta guías sin poder de obligar.

El problema de la responsabilidad es el más delicado. La pregunta de fondo es esta: si un sistema de IA recomienda algo y un paciente sale dañado, ¿responde el médico que siguió la recomendación, el que la ignoró, el fabricante del software o el hospital que lo compró?1. Cuando no hay estándares claros, quien sufre el daño tiene pocos caminos para reclamar2. El propio artículo pide marcos legales más claros y mayor capacidad institucional para manejar los riesgos de la IA3.

La misma lógica aparece en salud mental.

Así lo leemos nosotros. El patrón que se repite en estos documentos es el de una tecnología que llega antes que la regla que la vigila. Cuando no existe una norma clara de responsabilidad, lo probable es que los pacientes ni siquiera pregunten quién responde si un sistema automatizado causa daño, porque darán por sentado que no hay a quién reclamar. Sabríamos que nos equivocamos si, en un país sin esa ley, una asociación de pacientes o una defensoría exigiera públicamente explicaciones tras un daño causado por una herramienta de IA.

También cabe esperar que clínicas, aseguradoras y proveedores de software se escuden en que "el sistema lo recomendó" para no asumir culpa. Veríamos lo contrario si, ante un daño, la institución reconociera de inmediato su responsabilidad y ofreciera reparación sin necesidad de una ley específica. Como el estudio no midió resultados en pacientes, no puede decirnos si la IA en salud hace daño con frecuencia ni si mejora la atención. Solo describe las reglas.

Lo que esto significa para quien vive en América Latina, Estados Unidos o Canadá es concreto. La encuesta cubre solo la región europea de la OMS: no dice nada sobre lo que la ley de su país permite o prohíbe hoy. No puede usarse como prueba de que su gobierno tenga o no tenga reglas. Pero sí muestra qué preguntas hacer. Cuando reciba una decisión médica o administrativa tomada con ayuda de un sistema automático, pida por escrito quién la revisó y quién asume la responsabilidad si algo sale mal. Guarde ese documento. Pregunte ante su centro de salud o su autoridad de protección de datos si existe algún procedimiento para reclamar por decisiones automatizadas que lo afecten. Si no lo hay, pida que quede registrada su consulta. Comparta esa pregunta con otras personas: la resignación silenciosa es lo único que garantiza que nadie responda nunca. ¿Sabe usted, hoy, a quién le reclamaría?

De dónde sale cada dato de contexto, y cuánto leímos de cada documento

  1. Adib, K., Letchford, N., Dunning, H. E. et al. (2026). Governance of artificial intelligence for health systems, WHO European Region. Bulletin of the World Health Organization. https://doi.org/10.2471/blt.25.294978 - el artículo del que trata esta nota — el artículo completo — el pasaje: "Concerns include whether clinicians should be held responsible for following or ignoring AI recommendations that lead to harm, and how liability rules influence their reliance on such tools."
  2. Adib, K., Letchford, N., Dunning, H. E. et al. (2026). Governance of artificial intelligence for health systems, WHO European Region. Bulletin of the World Health Organization. https://doi.org/10.2471/blt.25.294978 - el artículo del que trata esta nota — el artículo completo — el pasaje: "In parallel, liability remains a challenge in the use of AI in health care, especially as clear legal standards exist in only a few Member States, limiting avenues for redress."
  3. Adib, K., Letchford, N., Dunning, H. E. et al. (2026). Governance of artificial intelligence for health systems, WHO European Region. Bulletin of the World Health Organization. https://doi.org/10.2471/blt.25.294978 - el artículo del que trata esta nota — el artículo completo — el pasaje: "Addressing these issues requires clearer legal frameworks and stronger institutional capacity to manage AI-related risks."
  4. Hashimoto DA, Marwaha JS, Lee SA, Schwaitzberg S, Duffourc MN. (2026). Risk and liability in the deployment of AI systems for surgery: a SAGES white paper. Surgical Endoscopy. 10.1007/s00464-026-12881-8 — solo el resumen - no se pudo obtener el texto completo — el pasaje: "Risks associated with surgical AI can be understood through a tripartite framework: risks inherent to the AI system, risks introduced by the clinician-user, and risks arising from institutional deployment."
  5. Hashimoto DA, Marwaha JS, Lee SA, Schwaitzberg S, Duffourc MN. (2026). Risk and liability in the deployment of AI systems for surgery: a SAGES white paper. Surgical Endoscopy. 10.1007/s00464-026-12881-8 — solo el resumen - no se pudo obtener el texto completo — el pasaje: "Although surgeons remain the ultimate clinical decision-makers, liability may also extend to developers for defective design or failure to warn, and to institutions for negligent implementation or oversight."
  6. Sawesi S, Sabbineni H, Shagamreddy R, Rashrash B. (2026). Cybersecurity and Privacy Risks of Generative AI Mental-Health Chatbots: A Systematic Review and Regulatory Framework. Journal of Multidisciplinary Healthcare. 10.2147/jmdh.s581251 — solo el resumen - no se pudo obtener el texto completo — el pasaje: "Most systems relied on general-purpose LLMs (21/33, 63.6%) and were deployed via consumer-facing platforms (16/33, 48.5%)."
  7. Sawesi S, Sabbineni H, Shagamreddy R, Rashrash B. (2026). Cybersecurity and Privacy Risks of Generative AI Mental-Health Chatbots: A Systematic Review and Regulatory Framework. Journal of Multidisciplinary Healthcare. 10.2147/jmdh.s581251 — solo el resumen - no se pudo obtener el texto completo — el pasaje: "Critically, 78.8% of studies (26/33) were rated high risk for cybersecurity evaluation rigor, indicating that formal adversarial testing and structured threat modeling remain rare."
  8. Sawesi S, Sabbineni H, Shagamreddy R, Rashrash B. (2026). Cybersecurity and Privacy Risks of Generative AI Mental-Health Chatbots: A Systematic Review and Regulatory Framework. Journal of Multidisciplinary Healthcare. 10.2147/jmdh.s581251 — solo el resumen - no se pudo obtener el texto completo — el pasaje: "Key risks included harmful or unsafe outputs, failures in crisis response, exposure of sensitive personal information, and limited transparency."
  9. Zhang Z, Lu X, Zhang Y, Zhang H, Zhang M. (2026). Privacy assurances and professional-boundary warnings in generative AI mental health chatbots: a randomized vignette experiment on calibrated trust, overreliance risk, and professional help-seeking intentions. Frontiers in Psychology. 10.3389/fpsyg.2026.1934264 — solo el resumen - no se pudo obtener el texto completo — el pasaje: "We conducted a 2 × 2 randomized vignette experiment with 768 college students. Participants were assigned to one of four chatbot scenarios that either included or omitted privacy assurance and professional-boundary warning."
  10. Zhang Z, Lu X, Zhang Y, Zhang H, Zhang M. (2026). Privacy assurances and professional-boundary warnings in generative AI mental health chatbots: a randomized vignette experiment on calibrated trust, overreliance risk, and professional help-seeking intentions. Frontiers in Psychology. 10.3389/fpsyg.2026.1934264 — solo el resumen - no se pudo obtener el texto completo — el pasaje: "Calibrated trust was highest when both messages were present."
  11. Zhang Z, Lu X, Zhang Y, Zhang H, Zhang M. (2026). Privacy assurances and professional-boundary warnings in generative AI mental health chatbots: a randomized vignette experiment on calibrated trust, overreliance risk, and professional help-seeking intentions. Frontiers in Psychology. 10.3389/fpsyg.2026.1934264 — solo el resumen - no se pudo obtener el texto completo — el pasaje: "Such messages should not be understood as prompts for greater use. Rather, they may help users treat chatbots as limited tools for information and support navigation and recognize when professional help is needed."

Adib, K., Letchford, N., Dunning, H. E. et al. (2026). Governance of artificial intelligence for health systems, WHO European Region. Bulletin of the World Health Organization. https://doi.org/10.2471/blt.25.294978

Quién pagó: La Comisión Europea apoyó este trabajo en el marco del proyecto titulado Supporting Member States in strengthening health information systems and boosting health data governance; el artículo no declara intereses en conflicto y no indica que el financiador tuviera participación alguna en el diseño, el análisis o la redacción.

No tome esto como consejo médico profesional.

survey · Bulletin of the World Health Organization · the paper, 1 Jun 2026 · free

Few European Countries Have Rules for Who Pays When Health AI Harms a Patient

The WHO surveyed 50 countries on how they govern AI in health care. Most are still writing the rulebook — and none of it covers the Americas.

Short version · the longer version follows, about 7 min

Ask weeklyAI

Ask me about this study: who was studied, what it found, and what it does not say.

Conversations are saved for as long as weeklyAI exists, to improve the publication. Answers come in the language you write in.

The study at a glance
Who
Member States of the WHO European Region
How many
50
Where
WHO European Region
When
June 2024 to March 2025
Kind of study
survey
Who did it
WHO Regional Office for Europe and European Commission
The limit that matters
Definitions were flexible and interpreted differently by each country.
Share of surveyed countries with each AI health rule
Health-specific AI strategy8%
Health-specific AI guidelines on ethics8%
Cross-sectoral ethical frameworks20%
No ethical guidance at all38%
No policies or unsure of AI health policies64%

These are shares of the 50 responding countries, based on government self-reports with flexible definitions.

Ask who is responsible before you are asked to trust the tool.
weeklyAI's reading
How it could look · illustration generated by weeklyAI.watch, not a photograph

If a hospital uses an AI tool and something goes wrong, who answers for it? In most of the 50 countries the World Health Organization surveyed, there is no clear legal answer.

The WHO Regional Office for Europe asked all 53 of its Member States about their plans, laws and data systems for artificial intelligence in health care. The survey ran from June 2024 to March 2025. Fifty countries replied — a 94% response rate.

The results describe governance that is still being built. Only 4 of the 50 countries have a strategy aimed specifically at AI in health, while 7 are writing one. Thirty-three have a broader AI strategy that covers many sectors, and 8 are developing one.

Ten countries have passed new laws written specifically for AI in health. Nearly half — 23 — are reviewing their existing laws and policies on AI systems. Fourteen have issued guidelines on the ethical questions raised by using AI in health or across sectors.

Four of the 50 countries have set liability standards for AI, or guidance on how existing liability rules apply. That is the part that decides who a harmed patient could pursue. Twenty-three countries require data accountability practices — the most common minimum standard found.

On health data, 33 countries have a national health data strategy, 33 have a health data hub, and 68% have an authority handling data access and control.

This is a European snapshot. It says nothing about what the law in Latin America, the United States or Canada currently requires of a company using your face, voice or health data. No reader there can point to this survey as their own country's rule.

The numbers are also self-reported by governments. The article notes that the definitions in the survey's questions were flexible and understood differently by each country.

Nor is this a verdict on whether AI helps or harms patients. The survey asked what strategies, laws and data systems exist — not whether any tool works or has injured anyone.

It is a moving picture. The authors say AI governance is changing quickly and some findings may soon be out of date.

What it does offer is a set of questions to bring to your own officials: Which agency, if any, monitors AI used in health care? If a tool leads to harm, what can a patient file, and against whom? Does your country have a health data authority you can ask about how your records are used?

The article's own priority list is a checklist you could put to them: oversight run by permanent agencies, not temporary bodies; liability defined for developers, clinicians, data providers and institutions; and ethical principles written into enforceable rules rather than left voluntary.

Ask who is responsible before you are asked to trust the tool.

What this means for you

For your own country, this survey settles nothing about what a company may do with your face, voice or health data, and no one there can cite it as local law. Watch instead for what your officials publish: who monitors AI used in health care, what a harmed patient can file and against whom, and whether any health data authority exists to answer how your records are used.

Adib, K., Letchford, N., Dunning, H. E. et al. (2026). Governance of artificial intelligence for health systems, WHO European Region. Bulletin of the World Health Organization. https://doi.org/10.2471/blt.25.294978

Who paid: The European Commission supported this work under the project entitled Supporting Member States in strengthening health information systems and boosting health data governance; the article states no competing interests and does not say the funder had any role in the design, analysis or writing.

Do not take this as professional medical advice.

The longer versionThe passages copied from the paper, the pictures, and every source with how much of it we read · 1462 words · about 7 minRead it →Close

Most Countries in Europe Have No Rule Saying Who Answers When a Health AI Harms a Patient

The World Health Organization surveyed its European member states and found that the paperwork for artificial intelligence in medicine — strategies, laws, ethics codes, liability rules — is mostly missing.

How it could look · illustration generated by weeklyAI.watch, not a photograph

Fewer than one in ten of the governments surveyed have written a rule saying who is responsible when an artificial intelligence tool used in health care causes harm. The finding comes from a survey by the World Health Organization's Regional Office for Europe, which asked all 53 member states about their plans, laws and data systems for AI in health. Fifty responded. The survey ran from June 2024 to March 2025, and the results were published in the Bulletin of the World Health Organization. The authors are affiliated with the WHO Regional Office for Europe and the European Commission. The European Commission supported the work under the project entitled Supporting Member States in strengthening health information systems and boosting health data governance. No competing interests were declared.12

The numbers are stark in every category the survey asked about. Eight per cent of the responding countries — four out of fifty — have a health-specific AI strategy, and another seven are developing one. Thirty-three have a cross-sector AI strategy, and eight more are developing one. Twenty-three reported ongoing assessments of their laws and policies on AI systems. Ten have written new health-specific AI laws. Fourteen have issued guidelines on the ethical implications of using AI in health or across sectors. Only four have developed liability standards for AI or guidance on how to apply existing liability standards.123

To picture what "liability standard" means here, start with the everyday question. A hospital buys an AI tool that reads scans and flags possible tumours. The tool misses one. The patient's cancer goes untreated for months. Who pays? The doctor who trusted the flag? The hospital that bought the software? The company that built it? In most of the surveyed countries, no rule answers that question clearly. The article puts it plainly: clear legal standards exist in only a few member states, and that limits the avenues for redress.4

The survey also asked countries whether they had set up any process for a patient to file an AI-related complaint. Only five out of fifty had. That is ten per cent of the region. In the same survey, nearly two-thirds of countries — thirty-two out of fifty — reported having no policies at all focused on AI in health, or said they were unsure whether such policies existed.56

The article raises a specific worry about how liability rules affect medical practice. If a clinician follows an AI recommendation that leads to harm, should the clinician be held responsible? If the clinician ignores an AI recommendation that turns out to be right, should the clinician be held responsible then too? The article asks these questions directly and notes that the answers shape how much doctors trust and rely on these tools. Without clear rules, the effect runs both ways: doctors may over-rely on the machine to avoid second-guessing it, or under-rely on it to avoid legal exposure.7

8910

The WHO article describes the governance problem as a gap between what exists and what is needed. It points out that the EU's AI Act — a cross-sector regulation with four risk categories — is designed to work alongside health-specific rules like the Medical Devices Regulation and the proposed European Health Data Space. When those pieces are not in place, the framework has holes. The article's authors call for liability frameworks that clearly define responsibilities for developers, clinicians, data providers and institutions, with mechanisms for timely redress when AI systems cause harm.11

The survey also looked at data governance. Two-thirds of the responding countries — thirty-three out of fifty — have a national health data strategy. The same number have a health data hub. Thirty-four have a health data authority responsible for approving access to data or creating new datasets. Of the countries with data hubs, almost all collect inpatient data, but only five collect genomic data. The authors say this finding is likely due to the complexity of genomic data, ethical considerations and high costs.12

The survey has limits that matter for how you read it. The authors say the main limitation is that the definitions of the terms used in the questions were flexible, and each country interpreted them differently. The validity of the responses depended on the expertise of each country's survey coordinator and the national experts they consulted, and the number and expertise of those contributors varied by country. Three member states — Bosnia and Herzegovina, Monaco and Turkmenistan — did not respond and were excluded, so the regional totals rest on fifty of fifty-three states. The authors also note that AI governance is changing rapidly, and some findings may be out of date soon. The analysis was descriptive only; no statistical comparisons between subregions were tested.1314

Here is how we read it. When a machine makes a decision — or helps a person make one — the first thing people ask is who is responsible if something goes wrong. But the machine's decision is often too fast to intervene in, and its history runs through many hands: the company that trained it, the hospital that bought it, the doctor who used it, the data it learned from. Responsibility gets spread so thin that no single person can be pointed to. That is the pattern this survey describes. In the countries surveyed, even where AI is used in hospitals, the law may not name anyone who answers when a patient is harmed. If you ask, you may be sent from one agency to another, and no one will take the file. We would expect that to hold until a health ministry, a regulator or a court publicly names a responsible party and orders compensation or discipline after an AI-related harm. If that happens in one of these countries, we are wrong.

There is a second pattern worth naming. New technology usually arrives because it is useful or profitable, and its long-term effects are noticed only after the fact. The people who bear the costs are rarely the ones who made the decision to adopt it. We would expect health AI to spread through procurement and vendor contracts before any liability rule exists. When harm occurs, the cost may fall on patients and public budgets, while the companies that supplied the tool face no specific penalty. What would show we are wrong? A country in the survey passing a binding rule that makes AI vendors or hospitals financially answerable for patient harm before the tool is widely deployed. Until then, if you hear about an AI tool in a clinic, ask who is named as answerable if it harms someone. If no name or office is given, treat that as the current state of the law — not as a promise that someone will step forward later.

1516171819

2021222324

The survey covers only the WHO European Region, so it says nothing about what the law in Latin America, the United States or Canada now says. You cannot use it as a statement of your own country's rules. The findings are self-reported by governments, and the article notes that the definitions were flexible and interpreted differently by each country. Do not treat any number as a precise measure of enforceable rights. The article says AI governance is rapidly evolving and findings may change soon. Check your own country's current law and regulator rather than relying on this snapshot. Three member states did not respond, and no statistical comparisons between subregions were tested, so no difference between one group of countries and another can be treated as a tested finding.

What this makes possible for you is a specific question to ask, wherever you live. The next time you hear that a clinic, a hospital or a health insurer is using an AI tool — for reading scans, for triaging symptoms, for scheduling, for anything — ask who is named as answerable if it harms a patient. Ask whether the contract that brought the tool in says who pays if something goes wrong. Ask what complaint or court procedure exists in your country for harm from a health AI tool, and whether any group is already using it. If no name, no clause and no procedure exist, that absence is itself the answer. The first real rule about who answers for AI harm may come not from a legislature but from a patient or a worker who files a complaint and refuses to let it go. Until someone does that, the gap stays open. What would you ask for, and from whom?

Where each piece of context comes from, and how much of it we read

  1. Adib, K., Letchford, N., Dunning, H. E. et al. (2026). Governance of artificial intelligence for health systems, WHO European Region. Bulletin of the World Health Organization. https://doi.org/10.2471/blt.25.294978 - the article this story is about — the whole article — the passage: "Less than 10% (4) of Member States have developed liability standards for AI or guidance on the application of existing liability standards."
  2. Adib, K., Letchford, N., Dunning, H. E. et al. (2026). Governance of artificial intelligence for health systems, WHO European Region. Bulletin of the World Health Organization. https://doi.org/10.2471/blt.25.294978 - the article this story is about — the whole article — the passage: "Less than 10% (4/50) of Member States had developed liability standards or guidance for manufacturers and users on the application of existing liability standards ( Fig. 7 )."
  3. Adib, K., Letchford, N., Dunning, H. E. et al. (2026). Governance of artificial intelligence for health systems, WHO European Region. Bulletin of the World Health Organization. https://doi.org/10.2471/blt.25.294978 - the article this story is about — the whole article — the passage: "Few Member States (4/50; 8%) have issued specific legislative measures or provisions for governance and oversight of AI in the health sector, with 36% (18/50) currently developing legislation."
  4. Adib, K., Letchford, N., Dunning, H. E. et al. (2026). Governance of artificial intelligence for health systems, WHO European Region. Bulletin of the World Health Organization. https://doi.org/10.2471/blt.25.294978 - the article this story is about — the whole article — the passage: "In parallel, liability remains a challenge in the use of AI in health care, especially as clear legal standards exist in only a few Member States, limiting avenues for redress."
  5. Adib, K., Letchford, N., Dunning, H. E. et al. (2026). Governance of artificial intelligence for health systems, WHO European Region. Bulletin of the World Health Organization. https://doi.org/10.2471/blt.25.294978 - the article this story is about — the whole article — the passage: "Only 10% (5/50) of Member States focused on processes for affected individuals to file AI-related complaints."
  6. Adib, K., Letchford, N., Dunning, H. E. et al. (2026). Governance of artificial intelligence for health systems, WHO European Region. Bulletin of the World Health Organization. https://doi.org/10.2471/blt.25.294978 - the article this story is about — the whole article — the passage: "In contrast, 64% (32/50) of Member States reported having either no policies or being unsure of policies focused on AI in the health sector."
  7. Adib, K., Letchford, N., Dunning, H. E. et al. (2026). Governance of artificial intelligence for health systems, WHO European Region. Bulletin of the World Health Organization. https://doi.org/10.2471/blt.25.294978 - the article this story is about — the whole article — the passage: "Concerns include whether clinicians should be held responsible for following or ignoring AI recommendations that lead to harm, and how liability rules influence their reliance on such tools."
  8. Hashimoto DA, Marwaha JS, Lee SA, Schwaitzberg S, Duffourc MN. (2026). Risk and liability in the deployment of AI systems for surgery: a SAGES white paper. Surgical Endoscopy. 10.1007/s00464-026-12881-8 — only the abstract - the full text could not be fetched — the passage: "Current regulatory and legal frameworks are not fully equipped to address the challenges of AI-assisted surgery."
  9. Hashimoto DA, Marwaha JS, Lee SA, Schwaitzberg S, Duffourc MN. (2026). Risk and liability in the deployment of AI systems for surgery: a SAGES white paper. Surgical Endoscopy. 10.1007/s00464-026-12881-8 — only the abstract - the full text could not be fetched — the passage: "Risks associated with surgical AI can be understood through a tripartite framework: risks inherent to the AI system, risks introduced by the clinician-user, and risks arising from institutional deployment."
  10. Hashimoto DA, Marwaha JS, Lee SA, Schwaitzberg S, Duffourc MN. (2026). Risk and liability in the deployment of AI systems for surgery: a SAGES white paper. Surgical Endoscopy. 10.1007/s00464-026-12881-8 — only the abstract - the full text could not be fetched — the passage: "Although surgeons remain the ultimate clinical decision-makers, liability may also extend to developers for defective design or failure to warn, and to institutions for negligent implementation or oversight."
  11. Adib, K., Letchford, N., Dunning, H. E. et al. (2026). Governance of artificial intelligence for health systems, WHO European Region. Bulletin of the World Health Organization. https://doi.org/10.2471/blt.25.294978 - the article this story is about — the whole article — the passage: "Third, liability frameworks should be established and clearly define responsibilities for developers, clinicians, data providers and institutions, with mechanisms for timely redress and accountability when AI systems cause harm."
  12. Adib, K., Letchford, N., Dunning, H. E. et al. (2026). Governance of artificial intelligence for health systems, WHO European Region. Bulletin of the World Health Organization. https://doi.org/10.2471/blt.25.294978 - the article this story is about — the whole article — the passage: "In the WHO European Region, governance of AI in health care is underdeveloped. Adaptive legal and policy mechanisms are needed to respond effectively to the complex and evolving challenges of AI integration in health systems."
  13. Adib, K., Letchford, N., Dunning, H. E. et al. (2026). Governance of artificial intelligence for health systems, WHO European Region. Bulletin of the World Health Organization. https://doi.org/10.2471/blt.25.294978 - the article this story is about — the whole article — the passage: "The main limitation of the survey is the relative flexibility of the definitions of terms used in the questions and the interpretation by each of the participating Member States."
  14. Adib, K., Letchford, N., Dunning, H. E. et al. (2026). Governance of artificial intelligence for health systems, WHO European Region. Bulletin of the World Health Organization. https://doi.org/10.2471/blt.25.294978 - the article this story is about — the whole article — the passage: "Another limitation is that AI governance is rapidly evolving, meaning some findings may change in the near future."
  15. Sawesi S, Sabbineni H, Shagamreddy R, Rashrash B. (2026). Cybersecurity and Privacy Risks of Generative AI Mental-Health Chatbots: A Systematic Review and Regulatory Framework. Journal of Multidisciplinary Healthcare. 10.2147/jmdh.s581251 — only the abstract - the full text could not be fetched — the passage: "Generative AI chatbots were most frequently used for therapy or emotional support (13/33, 39.4%), followed by safety evaluation or benchmarking (9/33, 27.3%) and psychoeducation or advice (6/33, 18.2%)."
  16. Sawesi S, Sabbineni H, Shagamreddy R, Rashrash B. (2026). Cybersecurity and Privacy Risks of Generative AI Mental-Health Chatbots: A Systematic Review and Regulatory Framework. Journal of Multidisciplinary Healthcare. 10.2147/jmdh.s581251 — only the abstract - the full text could not be fetched — the passage: "Suicide prevention or crisis detection was the most common domain (10/33, 30.3%)."
  17. Sawesi S, Sabbineni H, Shagamreddy R, Rashrash B. (2026). Cybersecurity and Privacy Risks of Generative AI Mental-Health Chatbots: A Systematic Review and Regulatory Framework. Journal of Multidisciplinary Healthcare. 10.2147/jmdh.s581251 — only the abstract - the full text could not be fetched — the passage: "Most systems relied on general-purpose LLMs (21/33, 63.6%) and were deployed via consumer-facing platforms (16/33, 48.5%)."
  18. Sawesi S, Sabbineni H, Shagamreddy R, Rashrash B. (2026). Cybersecurity and Privacy Risks of Generative AI Mental-Health Chatbots: A Systematic Review and Regulatory Framework. Journal of Multidisciplinary Healthcare. 10.2147/jmdh.s581251 — only the abstract - the full text could not be fetched — the passage: "Key risks included harmful or unsafe outputs, failures in crisis response, exposure of sensitive personal information, and limited transparency."
  19. Sawesi S, Sabbineni H, Shagamreddy R, Rashrash B. (2026). Cybersecurity and Privacy Risks of Generative AI Mental-Health Chatbots: A Systematic Review and Regulatory Framework. Journal of Multidisciplinary Healthcare. 10.2147/jmdh.s581251 — only the abstract - the full text could not be fetched — the passage: "Current governance frameworks have not fully adapted to generative conversational AI in mental health contexts."
  20. Zhang Z, Lu X, Zhang Y, Zhang H, Zhang M. (2026). Privacy assurances and professional-boundary warnings in generative AI mental health chatbots: a randomized vignette experiment on calibrated trust, overreliance risk, and professional help-seeking intentions. Frontiers in Psychology. 10.3389/fpsyg.2026.1934264 — only the abstract - the full text could not be fetched — the passage: "We conducted a 2 × 2 randomized vignette experiment with 768 college students. Participants were assigned to one of four chatbot scenarios that either included or omitted privacy assurance and professional-boundary warning."
  21. Zhang Z, Lu X, Zhang Y, Zhang H, Zhang M. (2026). Privacy assurances and professional-boundary warnings in generative AI mental health chatbots: a randomized vignette experiment on calibrated trust, overreliance risk, and professional help-seeking intentions. Frontiers in Psychology. 10.3389/fpsyg.2026.1934264 — only the abstract - the full text could not be fetched — the passage: "Privacy assurance increased perceived privacy protection, F (1, 764) = 159.30, p 2 = 0.172, d = 0.91."
  22. Zhang Z, Lu X, Zhang Y, Zhang H, Zhang M. (2026). Privacy assurances and professional-boundary warnings in generative AI mental health chatbots: a randomized vignette experiment on calibrated trust, overreliance risk, and professional help-seeking intentions. Frontiers in Psychology. 10.3389/fpsyg.2026.1934264 — only the abstract - the full text could not be fetched — the passage: "Professional-boundary warning increased boundary awareness, F (1, 764) = 176.40, p 2 = 0.188, d = 0.96."
  23. Zhang Z, Lu X, Zhang Y, Zhang H, Zhang M. (2026). Privacy assurances and professional-boundary warnings in generative AI mental health chatbots: a randomized vignette experiment on calibrated trust, overreliance risk, and professional help-seeking intentions. Frontiers in Psychology. 10.3389/fpsyg.2026.1934264 — only the abstract - the full text could not be fetched — the passage: "Calibrated trust was highest when both messages were present."
  24. Zhang Z, Lu X, Zhang Y, Zhang H, Zhang M. (2026). Privacy assurances and professional-boundary warnings in generative AI mental health chatbots: a randomized vignette experiment on calibrated trust, overreliance risk, and professional help-seeking intentions. Frontiers in Psychology. 10.3389/fpsyg.2026.1934264 — only the abstract - the full text could not be fetched — the passage: "Such messages should not be understood as prompts for greater use. Rather, they may help users treat chatbots as limited tools for information and support navigation and recognize when professional help is needed."

Adib, K., Letchford, N., Dunning, H. E. et al. (2026). Governance of artificial intelligence for health systems, WHO European Region. Bulletin of the World Health Organization. https://doi.org/10.2471/blt.25.294978

Who paid: The European Commission supported this work under the project entitled Supporting Member States in strengthening health information systems and boosting health data governance; the article states no competing interests and does not say the funder had any role in the design, analysis or writing.

Do not take this as professional medical advice.

The findings of other studies mentioned here are known to us through this document, which is the one we read; we did not open each of those studies.