Artificial Intelligence and healthcare Bill: the new data sovereignty, between risk and innovation

The approval of the Artificial Intelligence Bill (Bill No. 1146-B) marks a turning point in the Italian legislative debate, a moment of necessary strategic reflection in the face of an inexorable technological transformation. The wave of the digital revolution, and AI in particular, is not a reality that allows for simple choices. For the healthcare sector—an area defined by data sensitivity and the criticality of its functions—the text under discussion, acting in close synergy with the European AI Act, is not a mere regulatory framework. Rather, it constitutes an articulated roadmap aimed at redefining the concepts of innovation, risk, and sovereignty, with a direct impact on the decision-making processes of every operator.

Far from representing a mere liberalization, the Bill introduces a strategic dilemma: greater technological freedom of choice is met with a dramatic increase in legal and operational liability. Through a sophisticated architecture, the current draft clearly differentiates obligations between the private sector and public healthcare. We analyze the key points that every decision-maker in the healthcare world should consider in the current discussion phase, in order to fully understand the scope of the change and prepare adequately.

The legislative shift: from “Fortress Italy” to calculated risk

The trajectory of the Bill has been emblematic and revealing of the underlying tensions. The initial version, approved by the Senate, contained a provision (formerly Art. 8, para. 2) requiring the use of servers located within the national territory for all AI systems in the public sector. This was the “Fortress Italy” approach: maximum security guaranteed by geographical and jurisdictional control. The advantage of such an approach was a drastic simplification of GDPR compliance, eliminating at the root the complex and burdensome issues related to the transfer of personal data to third countries.

The Chamber of Deputies subsequently suppressed this provision, a precise strategic choice seemingly dictated by a profound legal and market realism. Firstly, such a rigid national localization rule could have created profiles of incompatibility with the principle of free movement of data, one of the pillars of the European Digital Single Market. Secondly, it would have risked isolating Italian healthcare and research, precluding access to the most advanced and high-performing global AI platforms, resulting in a competitive gap that would be difficult to bridge. Finally, there is a consideration of economic sustainability: the global cloud model offers efficiency, scalability, and innovation speed that a purely national approach would struggle to replicate. If the text were approved in this form, the legislator would have effectively replaced a rigid geographical boundary with a more flexible, yet more complex, legal boundary.

The new burden of proof: the complex compliance “toolbox”

With the potential removal of the geographical barrier, the responsibility for protecting health data would shift entirely onto the shoulders of the healthcare organization. To legitimately use a non-EU provider, a hospital or local health authority (ASL) would need to build a robust “legal bridge” based on a precise compliance “toolbox,” the management of which requires highly specialized legal and technical expertise.

This would include reliance on mechanisms such as the Data Privacy Framework (DPF) for transfers to the United States, the legal standing of which remains under constant scrutiny following previous invalidations by the CJEU. To this would be added Standard Contractual Clauses (SCCs), which jurisprudence has clarified are no longer sufficient on their own unless supported by a concrete analysis. The core of the new obligation would become the Transfer Impact Assessment (TIA). This is not a mere formal fulfillment, but a complex substantive assessment in which the data exporter must analyze the legislation of the third country (for example, the pervasive government surveillance laws in the US) and demonstrate, with concrete evidence, the ability to guarantee, through supplementary measures, a level of protection “essentially equivalent” to that of Europe.

Given the extreme sensitivity of health data, passing a TIA for a transfer to the US, where regulations such as FISA 702 allow for extensive government surveillance, would constitute a high-risk legal exercise, exposing the entity to potential sanctions and significant reputational damage.

The fast track for public healthcare: Article 5

Here, the Bill reveals its dual-track strategy. While a freedom of choice emerges for private entities (albeit with the described burdens), the path indicated for public healthcare is different. Art. 5 of the current text establishes that public administrations are “directed” to “prioritize” AI solutions in public tenders that guarantee the localization of strategic data and disaster recovery within the national territory.

This “preference” is not a mere recommendation, but a guiding criterion with specific weight in public procurement procedures. It combines synergistically with the “Italian Cloud Strategy” of the National Cybersecurity Agency (ACN), which classifies health data almost universally as “Critical” or “Strategic” and mandates its hosting on infrastructures that have obtained specific ACN qualification, such as the Polo Strategico Nazionale (PSN). The combined effect of these provisions would create a quasi-obligation: for public healthcare, the main road to compliance and contract award would remain that of a sovereign cloud ecosystem.

Already defined boundaries: the role of jurisprudence

The regulatory framework outlined by the Bill does not operate in a vacuum but is part of a legal context already densely populated by the interpretations of the Data Protection Authority (Garante) and national and European courts. The activity of these institutions has already defined an extremely high standard of diligence for the processing of health data.

For example, the Garante has previously sanctioned healthcare companies for insufficient legal bases in algorithmic profiling. These orientations have been reinforced by the Supreme Court of Cassation (Order No. 28417/2023) and the European Court of Human Rights (Cracò v. Italy), clarifying that data protection is a widespread responsibility where even procedural negligence can constitute a serious violation.

The future horizon: preparing for the European Health Data Space (EHDS)

Every technological and contractual choice made today must take into account the regulatory future. The European Health Data Space (EHDS) will revolutionize the ecosystem through mandatory interoperability standards and European certification for medical software. Choosing a technological partner today that is not designed to be compatible with future EHDS requirements would mean making an investment at high risk of obsolescence.

Conclusions: compliance as a strategic function

The AI Bill, in its current form, does not simplify the framework for healthcare but makes it more mature, shifting the focus from rigid rules to conscious risk management. The “freedom” of choice is a real option only for those who have the structure and expertise to manage extremely high legal and reputational risk. For public healthcare, the path of national sovereignty remains the safest and, effectively, the one favored by the legislator.

For healthcare management, this scenario requires a change of pace: mapping data according to ACN criteria, verifying supplier qualifications, and treating legal risk management as a structural component of innovation.