AI governance in personal health — what the WHO report and the EU AI Act actually ask of you.
Two big documents landed on health-AI this year: a WHO readiness report and the EU’s AI Act starting to bite. Between them they hand back a question most people have been outsourcing: who is accountable when a chat tool helps you decide something about your own body. This is what changes for a careful individual, and what changes for a solo practitioner.
Two documents did the quiet work this year. The WHO published a readiness assessment on how governments and health systems should adopt AI without importing its harms. The EU’s AI Act stopped being a paper and started being a deadline. Neither is written for you personally. Both, if you read them side by side, are describing the same question in different registers: who is accountable when an AI tool helps someone decide something about their own body.
That question has been comfortably unowned for a while. The vendor says the tool is a general-purpose assistant. The doctor says they never saw the chat. The user says the model told them. Nobody in that triangle is holding the pen. What these two documents do — carefully, in different ways — is put the pen back on the table and ask which hand should be picking it up. Once you see it, you cannot un-see it. And it changes what a defensible personal AI health practice actually looks like.
what the WHO report actually says (in plain english)
Strip away the diplomatic hedging and the WHO’s message is small and firm. First: AI in health is not automatically safe just because it looks helpful, and it is not automatically dangerous just because it is fast. Second: the safety property does not live inside the model — it lives in the surrounding system of consent, oversight, logging and monitoring. Third: countries that adopt AI without those surrounds will not get better care, they will get faster errors.
Translated to a person: a chat tool used for your own health is safer when there is a written intent (‘this is what I use it for’), a written limit (‘this is what I never use it for’), a written record (‘this is what it drafted, and this is what I decided’), and a real human review path (‘this is the clinician I bring the draft to’). None of those four are technical. All four are governance. Nobody was going to write them for you.
what the eu ai act adds — and to whom
The AI Act sorts systems into buckets by how much damage a failure could do. Most consumer chat tools sit in the ‘limited-risk’ bucket, which basically means: the vendor must be honest that it is AI and must not pretend to be a doctor. Useful, but modest. The interesting bucket is high-risk. The moment an AI system materially informs a medical decision — triage, diagnosis, treatment planning, interpreting a scan — it is treated as high-risk, and the law puts the duties on whoever deploys it in that setting. Documentation, human oversight, data-quality controls, post-market monitoring, a log you can hand to a regulator.
The regulator has been polite about this so far. That is the phase we are in. But the words in the Act do not need an update to catch a solo practitioner who used a general-purpose model to draft a plan for a real client and kept no record of it. They already do. ‘I only use it for admin’ is a governance claim — and unless there is a written scope somewhere behind that sentence, it is a claim that will not hold up the first time a client asks the question in a room with a lawyer in it.
“The old defence — ‘the AI told me’ — is not a defence, it is a confession. The new defence is a piece of paper you wrote before you turned the tool on.”
the two-page personal policy (for the careful individual)
For a person using AI on their own body, defensible does not mean bureaucratic. It means two pages you actually wrote and can find again. Page one is intent and limit. What you use the tool for — sourced-search on research questions, long-context reading of your own notes, drafting questions for your GP. What you never use it for — dose decisions, symptom triage during an active problem, mental-health crisis material, anything that would move you off a prescribed treatment without a clinician in the loop.
Page two is review and record. Which clinician you bring the drafts to, how often, and what you keep — a running note of what the model suggested, what you asked about it, and what got decided. Not a legal document. A habit written down so it survives the moment you get tired. That habit, more than any single prompt technique, is the thing that turns AI use in your own health from a private gamble into something a careful person is doing on purpose.
the solo practitioner version (higher stakes, same shape)
For a solo clinician, coach or health professional, the policy is the same shape and does more work. Intent and limit becomes a written scope-of-use: which tools are on the list, what client data may be pasted into them, what may not, and which decisions the AI is allowed to draft rather than decide. Review and record becomes a session log: which drafts touched a client’s case, what the human clinician overrode, what got sent. A consent line on your intake form — short, honest, plain-English — that says AI is used in preparation and never in place of your judgement.
Two things stop a working clinician from writing that policy: the fear that acknowledging AI is used will spook clients, and the fear that a written scope will look like a confession. Both fears invert once the policy exists. Clients who are told plainly what a tool is for and where the human judgement lives trust more, not less. And a written scope, applied honestly, is exactly the artifact that turns ‘I only use it for admin’ from a hopeful sentence into a defensible one.
where this fits in the stack
The 3-Layer Method has always assumed a human at the end of it: the Protocol layer produces a better question, not a prescription. Governance is the layer that makes that assumption enforceable. Research is what the model can read; Ledger is what it can remember; Protocol is what it can draft; Governance is what says which of those drafts is allowed to leave the room, and under whose signature. Skip it and the stack still works — until the day someone asks who decided. Add it and the same tools do the same work with none of the exposure.
what to do this week
Open a blank document. Write four sentences: what your AI tools are for, what they are never for, who reviews the outputs before they change anything, and where the record of that review lives. If you are an individual, that is your personal policy. If you are a solo practitioner, that is the first draft of your clinic’s AI scope-of-use. Print it, stick it above your desk, revisit it in ninety days. That single artifact, more than any prompt, is the thing the WHO report and the AI Act are quietly asking every serious user of AI in health to produce.
Common Questions
Does the EU AI Act apply to me if I am an individual using ChatGPT on my own health? Not directly — the Act sits on providers and deployers, not on you as a private person. But your GP, your clinic, and any practitioner you work with are deployers the moment they use AI in your care, and their obligations become your paper trail.
Is ChatGPT high-risk under the Act? The general-purpose model itself is not automatically high-risk. The use is. The moment it materially informs a medical decision in a professional setting, the deployment is high-risk and the duties attach to whoever deployed it there.
Am I breaking a rule by pasting my own labs into an AI chat for my own understanding? No. Personal use of your own data on a general-purpose tool is not what the Act is aimed at. The governance question is whether you would want that chat surfaced in a room with your clinician — and whether you have a written line about what you do next with what it says.
If a solo practitioner uses AI only for admin, do the AI Act obligations still apply? Genuine admin (scheduling, note formatting, marketing copy) is limited-risk. The rub is that ‘admin’ quietly slides into ‘summarising a client’s intake’ and then into ‘drafting their plan’. A written scope-of-use is what keeps that slide honest.
TL;DR
- The WHO report and the EU AI Act converge on one question: who is accountable when AI touches a health decision.
- For an individual: a two-page personal policy — intent + limit, review + record — is the whole personal governance stack.
- For a solo practitioner: a written scope-of-use, a client consent line, and a session log turn AI use from a liability into a defensible practice.
- The 3-Layer Method needs a governance layer on top: it is what says which drafts are allowed to leave the room.
- Write four sentences this week. That single artifact is what both documents are quietly asking of every serious user of AI in health.
Sources
- WHO Europe — Readiness assessment for the use of artificial intelligence in health (2026 update)
- European Parliament and Council — Regulation on Artificial Intelligence (the AI Act), high-risk system provisions (Annex III)
- The Lancet — commentary on governance of AI in clinical practice (2026)
Recommended next