Artificial intelligence (AI) offers opportunities to improve care, but it also raises important questions. How do we ensure that AI remains clinically relevant, is organisationally feasible, is applied correctly in legal terms and remains ethically responsible? The interdisciplinary team of UGent Delta developed a guide for this purpose.
This guide builds on existing quality principles in care and uses the Quintuple Aim model as its framework. It helps care organisations to discuss and evaluate AI applications and to make well-founded choices.
The checklist is not a tick-box exercise, but a tool for reflection and dialogue.
The document is a work in progress and can be adapted on the basis of new insights
and practical experience.
This checklist focuses on general AI policy within care organisations. Are you looking for a checklist to evaluate specific AI applications in care? Then use the checklist for specific AI applications.
Economic Without a clear objective, AI increases the risk of unsuccessful implementation and resource waste.
Ethical AI must solve a real care need. When technology starts from a concrete need identified by patients or care providers, it is more likely to genuinely contribute to better care.
Organisational If you have no clear objective, you do not know why you are deploying AI. You then risk wasting money, choosing the wrong KPIs and using technology that does not fit your mission. AI should solve a real care need and align with your strategy rather than driving the strategy itself.
Ethical Clear involvement in decision-making makes it possible to take responsibility and to properly justify decisions afterwards.
Clinical Care providers on the ground recognise risks that board members miss.
Organisational AI changes work processes. If decisions are taken purely top-down without alignment between levels, resistance arises and implementations fail. Good alignment ensures that the strategy actually works on the ground.
Psychosocial When care providers are involved in the choice and introduction of new tools, support grows and the work remains motivating.
Legal When AI has an impact on the processing of personal data, it may be necessary to seek the advice of a DPO, where appropriate, after carrying out a Data Protection Impact Assessment.
Ethical Care providers remain responsible towards patients. Without critical thinking and shared responsibility, privacy problems, errors and moral stress can arise. Care providers may then feel uncomfortable using AI applications.
Legal Failing to ensure that AI use remains subject to appropriate human supervision can lead to AI systems operating without appropriate human control and oversight.
Clinical Critical thinking about AI-generated outputs prevents automation bias and improves patient safety.
Organisational The corporate culture is a translation of the organisation's broader mission and vision. It determines how people deal with AI. Values must become visible in concrete behaviour, otherwise innovations will not be supported.
Economic Having training delivered solely by external parties can carry a high cost. Training costs must be factored in, but ideally the benefits of that training are taken into account as well. This will lead to a more efficient application of AI.
Ethical Care providers must understand AI well in order to act responsibly towards patients. Insufficient knowledge can also lead to moral stress among staff.
Clinical There is sufficient scientific evidence that non-experts may use AI applications as if they were automated decision-making systems. This use also leads to unexpected consequences. Negative consequences are often only noticed late. In addition, AI literacy among managers is a precondition for responsible AI governance.
Organisational Without training and other supporting facilities, such as a helpdesk, the risk of errors and exclusion increases. Managers and staff need both skills and support in order to keep up with digital change.
Psychosocial Knowledge about the systems should make it possible to resolve conflicts among staff about the use of AI.
Legal Failing to train people about the limitations can result in the institution being held responsible for clinical errors.
Ethical If AI is used in evaluations without transparency and human oversight, this can be unfair and damage trust.
Organisational If the use of AI is not well aligned with how people are assessed and rewarded, this can lead to undesirable behaviour. The organisation's values must therefore be clearly reflected in organisational policies, evaluations and incentives. HR plays a key role here: it provides the right training and assesses, for each member of staff, which digital skills are needed to use AI responsibly.
Psychosocial The use of AI in evaluations can cause uncertainty or distrust among staff and therefore calls for extra care, or even restraint in using AI.
Legal If AI is used for the evaluation of staff, account must be taken of the ban on AI-driven emotion recognition in the workplace (except where necessary for medical reasons or to ensure safety). Monitoring staff performance with AI is not prohibited, but must comply with the safeguards applicable to high-risk AI applications.
Economic Excessive use of AI tools can have an impact on care costs.
Ethical The wellbeing of care providers must be safeguarded when several AI systems are used at the same time.
Clinical Using several AI systems at once increases cognitive load and the risk of interference. AI applications may, for example, pass information to one another without taking action (and telling this to the user). It can also lead to unnecessary costs because all patients follow the same automated care pathway, in which all examinations are scheduled and carried out for all patients. The fear of “missed cases” will lead to a tendency to avoid false negatives, and will therefore push doctors to work in a highly sensitive and poorly specific way. That leads to an increase in examinations.
Organisational The impact of a single AI tool is usually visible, but the combination of several tools can cause extra workload, errors or inefficiency that go unnoticed. A clear overview of all AI applications is therefore needed. Strong IT governance, a well-considered IT architecture and a central AI team that coordinates help to avoid fragmentation and to safeguard coherence.
Psychosocial The social aspect of the job may be compromised, which makes the job less attractive.
Ethical Clear agreements about conflicting AI recommendations are needed in order to be able to take responsibility and to avoid harm to patients.
Clinical AI may support, but people must always remain ultimately responsible. Care providers must have the final say and be able to overrule AI when necessary. If AI systems contradict one another or are followed blindly, clinical decision-making and patient safety are put at risk.
Organisational There must be clear agreements about what to do in the event of doubt or conflicting AI advice. A clear AI policy sets out how staff deal with AI advice and when they may or must overrule it. In this way people remain ultimately responsible, professional expertise is respected and AI remains a tool rather than a decision-maker.
Economic Conflicting recommendations can lead to inefficiencies.
Economic Strategic embedding increases the return on investment of AI implementation projects.
Ethical AI must not be introduced merely because the technology exists. It must have a clear added value for care.
Organisational Stand-alone AI projects often cause fragmentation, duplicated work and waste of resources. AI works better when it fits within the organisation's mission, vision and strategy. A clear AI vision, AI vision, embedded in a broader digital strategy, provides coherence, better coordination and more clarity for staff about what AI does and why.
Economic Digital transformation requires a coherent vision in order to prevent fragmentation.
Ethical A clear digital strategy prevents technology from steering policy instead of the other way around.
Organisational Deploying AI without a clear digital strategy leads to technical problems and to systems that work together poorly. Technology must support and improve work processes, not disrupt them. If AI is well embedded in a broader digital vision, it can help to improve services, work processes and even the organisational model, step by step or thoroughly.
Psychosocial The use of AI must contribute to workable care and to time for patient contact.
Clinical The use of AI must not be aimed solely at cost saving, but can also give rise to better clinical outcomes.
Economic By opting for a flexible IT architecture, you avoid being locked into one technology or supplier. That makes it easier and more cost-efficient to make adjustments later. It is also important to make clear agreements about how long the AI software will be maintained, so that you are not unexpectedly left without updates or support.
Ethical New AI applications must continue to be tested against basic values such as patient safety, fairness and trust in care.
Clinical AI models age quickly; without an update policy, clinical risk increases.
Organisational AI evolves rapidly, and care organisations work in a constantly changing environment. An agile way of working is therefore needed, with flexible processes that can move along with new technology and expectations. The organisational culture must also be open to change, so that staff can adapt and keep learning.
Psychosocial Staff need basic knowledge about AI in order to keep working with new applications.
Legal When AI-driven processes become part of a standard of care (for example from an evidence-based medicine approach), the institution must be ready to respond quickly to that development in order to avoid liability on the basis of best-efforts obligations.
Ethical If you select AI without an ethical assessment, you run the risk of discriminatory or unfair systems. Transparency about how a system works and takes decisions is therefore essential in order to keep acting ethically and to retain trust.
Legal Transparency about how an AI system arrives at decisions remains important in health care. In addition, the continuity of care must be guaranteed. Interoperability and mapping out exit strategies in advance are therefore crucial.
Organisational For a safe integration of AI, systems must be transparent and able to work well with other applications. It is therefore important to carry out a thorough market analysis before procurement, and to compare different options critically. This avoids technical problems and leads to a well-considered choice.
Economic The AI application must offer sufficient value for money.
Economic Dependence on a single vendor (vendor lock-in) limits future flexibility and increases long-term costs.
Ethical Be aware that by purchasing AI applications you almost always become dependent on one or more parties, even for seemingly simple applications. Attention to this is important in terms of safeguarding quality, self-direction and independence.
Legal Open standards and exit clauses are legally and strategically necessary.
Organisational In order not to be locked into one supplier, it is important to build up sufficient in-house knowledge. By also continuing to explore the market regularly and comparing alternatives, the organisation retains its independence and negotiating power. The question is, however, whether dependency can still be avoided when only a handful of players worldwide have enough clout to build genuinely working base platforms.
Ethical Agreements about data and models protect the privacy of patients and prevent important knowledge from being lost. However, this requires additional effort. Deliberately keeping data in-house is often the most expensive solution. It takes work and it requires leadership.
Legal Agreements about data, models and knowledge must be clearly established before the start of the collaboration, and must also be arranged during its term. Without clear agreements on data portability (transferability) and intellectual property rights, an organisation can lose valuable clinical knowledge. Rights and responsibilities must therefore be properly laid down contractually.
Ethical Without clear safeguards, AI can put important care values, such as autonomy and humanity, under pressure. That affects not only the relationship with the patient, but also the integrity of the care institution itself. It is therefore essential to think carefully in advance about which values you want to protect and how you will do so concretely.
Organisational For a responsible deployment of AI, an organisation must first clearly map out which values it wants to protect and strengthen. A critical analysis of strengths, weaknesses, opportunities and threats (SWOT analysis) helps to make realistic choices. It is also important to keep assessing the sustainability of AI, both ecologically and socially, for example in terms of inclusion and digital skills.
Psychosocial AI must not crowd out the human care relationship and must contribute to sufficient time for patient contact.
Ethical Explicit preconditions prevent technological advantages from concealing ethical harm.
Organisational AI only works well if it responds to a real need and is supported by its users. That requires not only technical security, but also clear organisational agreements. Staff must experience its usefulness and ease of use, and the organisation must support them in this. Starting small with visible success stories can help to build trust and to facilitate the further implementation.
Legal Clear preconditions help to prevent applications qualified as prohibited AI from nevertheless being introduced within the organisation. The categories of prohibited applications are exhaustively listed in the European AI Act and are typically interpreted rather restrictively (see the Commission Guidelines on Prohibited AI).
Economic Sustainable AI implementation requires long-term budgeting, not just project funding.
Organisational AI projects often fail because organisations underestimate how much time, knowledge and resources a good implementation requires. It is therefore important to build up sufficient internal expertise. At the same time, innovation usually happens together with external partners, such as suppliers or knowledge institutions, which makes good collaboration essential.
Legal Unlike the GDPR, the AI Act does not provide for an obligation to appoint an independent officer for AI. The AI Act therefore does not introduce a new equivalent of the DPO role. Nor are any additional tasks described that are expressly assigned to the DPO. It is the case, however, that the organisation is made responsible for putting a range of processes in place, including a risk management system, data governance and data management. This requires time, expertise, resources and possibly the appointment of specifically assigned staff, whether or not at management level.
Organisational The existing workload has a major influence on the success of digital changes. In the beginning, AI can even create extra pressure, because staff still have to learn to work with the system and errors are possible. It is important to take this into account and to allow room for learning, so that temporary difficulties do not lead to lasting resistance or drop-out. AI systems' preference for algorithms that produce false positive rather than false negative alerts can also create an additional workload.
Psychosocial AI can raise expectations towards staff, which increases the workload. If AI is introduced into an already busy care environment without first examining the available capacity, the risk of stress and burnout increases. It is therefore important to plan realistically in advance and to take the team's capacity into account.
Economic When AI leads to better quality of care but that gain is not rewarded within the funding model, this can hamper the valorisation of meaningful applications. Organisations must therefore explicitly consider how they deal with innovations that do create societal or clinical added value but do not immediately translate into extra income or savings.
Ethical A thorough ethical assessment in advance helps to prevent harmful or irresponsible applications. It makes clear who bears responsibility and how accountability is given. In this way you protect the wellbeing, the safety and the privacy of patients as well as the reputation of the organisation.
Legal The AI Act does not affect the applicability of other regulations on good, high-quality practice in health care. For the development of AI as part of diagnosis or therapy, for example, the Belgian law on medical experiments will apply – also when it concerns research into AI applications and use is made of regulatory sandboxes (Article 60(3) AI Act). In addition, the AI Act does introduce, for a limited number of very specific AI applications, an obligation to carry out a “FRIA” (fundamental rights impact assessment). In making that assessment, it may be useful to draw on the ethical frameworks the organisation has at its disposal. For AI applications within health care, two categories are relevant. The FRIA must be carried out for (a) applications used to assess whether persons are eligible for public benefits and services, including health services, and (b) AI systems intended to evaluate and classify emergency calls by natural persons or to be used for dispatching, or for establishing priority in the dispatching of, emergency services, including police, fire brigade and ambulance, as well as systems for the triage of patients in need of urgent medical care.
Economic A knowledge hub facilitates faster and better evaluation of new AI applications.
Organisational If knowledge about AI is scattered, isolated decisions and duplicated work arise. By centralising expertise, for example in an AI Centre of Excellence, the organisation can coordinate better, provide advice and develop a clear and coherent AI policy.
Ethical Centralised supervision by an independent body allows several people to build up expertise in the ethical aspects of AI use, and also gives them the time to carry out those assessments. Such an approach also results in greater trust among users, and can therefore avoid, address and/or investigate unnecessary unrest.
Legal The legal assessment of (contracts for) the use of AI also benefits from a body in which knowledge about the functioning, the impact and the quality of AI is brought together.
Ethical Patient representation in AI governance strengthens trust and inclusiveness. Although representation may not be strictly necessary, there does at least need to be a point of contact for patients in order to pick up their concerns.
Organisational Good AI policy requires different perspectives. A multidisciplinary team is therefore needed, including for example IT and process experts. When such an AI Centre of Excellence sits close to top management and reports directly to it, it can advise better and ensure balanced and well-considered decisions.
Psychosocial Involve users in the choice and adoption of new tools. This will generate support and job satisfaction. Moreover, it is important that people on the ground know that an independent committee is looking on, will represent their interests, and can be approached in order to raise any problems.
Organisational A knowledge body has little impact if its advice does not genuinely feed through into policy. Clear agreements on how expertise is translated into decisions strengthen AI governance. By advising top management and coordinating AI projects, the organisation can ensure a consistent policy and clear priorities.
Ethical Clear no-go zones for AI protect the autonomy and dignity of patients. They make visible where the organisation draws lines as a matter of principle. In this way the core values and the integrity of the care institution are maintained even amid technological innovation.
Organisational Whether you refrain as a matter of principle from deploying AI in certain care situations depends on your mission, vision and core values. Some decisions touch so strongly on humanity, trust or autonomy that you deliberately choose not to use AI there. Social sustainability also plays a role: if AI leads to exclusion or inequality because of limited digital skills, you must dare to draw clear lines.
Ethical Non-negotiable human decision-making space is at the core of ethically responsible care.
Legal The AI Act prohibits the use of fully automated decision-making procedures for applications qualified as high risk. Removing all human decision-making space is therefore not permitted when using these applications. What is more: the care provider must maintain oversight, monitor and intervene in the functioning of the AI application when necessary. The care institution is responsible for assigning this oversight to care providers with the necessary competence, training and authority. Supporting the persons with “oversight authority” is also a responsibility of the institution. This means, among other things, that time must be made available for training.
Organisational Care providers must always be able to overrule AI, because they ultimately remain responsible for the decisions taken. But then these people must indeed be properly trained. Without training, it is difficult for doctors to dare to contradict an AI.
Ethical Making clear agreements in advance about who is responsible in the event of errors involving AI is ethically necessary. It protects all parties involved. This is important, among other things, in the context of the right of patients to proper compensation for harm or additional costs.
Legal It must be clear that the care provider remains at the wheel and has the final say, but beyond that, liability for harm caused by faulty AI output will not be divided any differently than is the case today for harm caused by other (medical) software applications. AI applications, too, follow the rules on product liability and medical devices.
Psychosocial In AI-supported decisions, credit and blame are unequally distributed: a correct outcome is attributed to the system, whereas an incorrect outcome remains with the care provider, regardless of whether they followed the advice or departed from it. This asymmetry can undermine the motivation and the professional self-confidence of staff and calls for explicit attention in policy on liability.
Economic The substitution myth leads to an underestimation of retraining and restructuring costs.
Ethical Preventing bias is important in order to guarantee high-quality and fair care for all patients.
Organisational AI does not fully replace a member of staff; task shifts require an active redistribution policy.
Organisational Staff need training in order to work well with AI and to develop their expertise further.
Ethical Preventing bias is important in order to guarantee high-quality and fair care for all patients.
Clinical Blindly relying on AI reduces clinical vigilance and increases the risk of error.
Organisational Knowledge among staff about the basic concepts of AI systems will be needed in order to assess the possibilities and the limitations.
Organisational Training in critical use of AI is essential in order to counteract automation complacency.
Ethical Preventing bias is important in order to guarantee high-quality and fair care for all patients. Care provision must also be free of discrimination.
Clinical Automation bias has been empirically demonstrated in clinical settings with diagnostic AI.
Organisational Explicit warning protocols for AI output reduce bias-driven errors.
Organisational Training must teach staff to assess AI advice critically and to recognise errors in time.
Legal AI literacy requires combined efforts from providers, deployers and the persons concerned. Measures must relate both to the use of the system itself and to the interpretation of the output of the system.
Ethical Preventing bias is important in order to guarantee high-quality and fair care for all patients.
Clinical Passively receiving AI suggestions worsens clinical reasoning skills in the longer term.
Organisational Training courses must integrate active practice alongside AI in order to prevent deskilling.
Organisational Targeted training helps staff to maintain their expertise and to use AI as a supporting tool.
Ethical Clear procedures on data management, consent and transparency are essential in order to protect the privacy of patients. They strengthen the relationship of trust between care provider and patient and also increase the confidence of staff in the use of AI within the organisation.
Legal Procedures on data management and consent are not optional. They are legally required under the GDPR and the EU AI Act. By complying with these correctly, the organisation avoids legal risks and shows that it handles personal data carefully and responsibly. For AI applications that qualify as high-risk AI, specific obligations are imposed with regard to the datasets used for training, validation and testing. In this respect, the AI Act provides a specific exception to the general prohibition on processing sensitive personal data established by the GDPR. The processing of health data is lawful where this is necessary in order to detect and correct bias in high-risk AI applications. This is of course subject to compliance with all other GDPR safeguards. In this case, consent from the patient is not legally required.
Organisational A clear and central AI policy makes expectations around data use clear and helps staff to apply these rules correctly.
Ethical Including patients and care providers in data policy increases support and quality.
Organisational For AI applications that operate across organisational boundaries, external care partners must also be involved in data procedures. The policy is usually developed by IT and process managers and top management, with input from other stakeholders. After that, it is important that all staff know these agreements and comply with them.
Legal The procedures are submitted to the DPO for advice.
Legal It is part of the DPO's remit to monitor the follow-up of all procedures that contribute to the protection of personal data. This therefore also includes those relating to privacy and data in AI applications.
Organisational Regular checks on the use of AI and data are needed in order to comply with the rules and to safeguard quality. This monitoring is usually carried out by the IT department or an AI Centre of Excellence, and is best linked to targeted training via HR. In this way the policy does not merely remain on paper, but is also complied with in practice.
Ethical Transparent communication about data use builds trust among all stakeholders.
Legal Uninformed staff can unintentionally cause GDPR breaches.
Organisational Staff must be informed through clear internal communication and training, for example via policy documents, campaigns and HR training.
Ethical Even when working with external AI providers, the organisation remains responsible for its own values and standards. By monitoring suppliers ethically, you protect the integrity of the institution and prevent reputational damage. Keeping control yourself is essential in order to stay true to your mission.
Legal When AI applications are used to process personal data, the various roles of the parties involved must also be qualified under the GDPR, and this on the basis of the factual characteristics of the collaboration. AI providers may act as a processor for the institution (or self-employed care provider). That will be the case when the AI provider works under the control and instructions of the institution: the institution decides what the AI application is used for and gives instructions on elements that are important for the data processing (consider, for example, the retention period of the data, the minimum security level, the categories of data that may be entered). If the AI providers act as processors, a data processing agreement must be provided that meets all the conditions of Article 28 GDPR. Sometimes the collaboration with an AI provider will be more of a partnership. When the AI provider co-decides on the purpose of the processing and on the essential elements, both parties will be qualified as joint controllers. In that case they must set out their respective responsibilities regarding the processing of personal data in writing and also make this information available to patients (Article 26 GDPR).
Ethical Open and clear communication about AI is a sign of being a good and ethical employer. When staff understand how and why AI is deployed, they can continue to provide high-quality care and the risk of moral stress or uncertainty decreases.
Organisational If staff are not well informed, they use AI in varying and sometimes unsafe ways. Clear communication is therefore needed, for example via internal campaigns and policy documents, together with targeted training via HR. In this way everyone knows what is expected and how AI must be used correctly.
Psychosocial When staff are involved in decisions about AI, trust and support grow.
Legal Keeping a register of all AI applications used within the organisation is not an obligation imposed by the AI Act. Such a register can, however, help to comply with the high-risk AI obligations that rest on care organisations, including the obligations to have quality management and to keep (technical) documentation, to retain automatically generated logs, and so on. In addition, having an overview of the AI applications that process personal data will be necessary in order to keep an accurate record of processing activities.
Organisational If staff have no view of which AI applications are used, they find it difficult to assess the impact on their work. Because AI often works in the background, not everyone needs to know everything, but every member of staff must learn in their role-specific training which AI is relevant. That comes on top of a general introductory course on AI.
Psychosocial Staff must know which AI applications are used, so that they can be transparent about this towards patients.
Organisational Without central coordination, confusion arises and people contradict one another about the use of AI. When one clear person in charge is designated, for example an AI Centre of Excellence or the IT department, the policy becomes more consistent and clearer. This provides clear direction, better alignment and stronger oversight of the use of AI.
Psychosocial A clear person responsible for AI communication prevents extra workload and ensures clear information.
© 2026 Ghent University – UGent Delta.
This work is made available under the
Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International
(CC BY-NC-SA 4.0)
licence.
You may share, remix, adapt and build upon this material, for non-commercial purposes only, provided that you give appropriate credit and distribute any derivative works under the same licence terms.
Bourgonjon, J., Annemans, L., Gesquière, N., Goffin, T., Mertes, H., Neutens, T., Van de Weghe, N., Van Biesen, W., Van Looy, A., & Verhenneman, G. (2026). AI Quality Label for Care. UGent Delta, Ghent University.
This quality label is a work in progress. Various people connected to Ghent University contributed to it, through conversations, workshops or individual contributions.
Lieven Annemans, Jeroen Bourgonjon, Tom Goffin, Wim Van Biesen, Griet Verhenneman.
Jeroen Bourgonjon, Lieven Annemans, Natacha Gesquière, Tom Goffin, Heidi Mertes, Tom Neutens, Nico Van de Weghe, Wim Van Biesen, Amy Van Looy, Griet Verhenneman.
Laetitia Aerts, Lieven Annemans, Sofie Bekaert, Jeroen Bourgonjon, Femke De Backere, Thomas Demeester, Joni Dambre, Natacha Gesquière, Tom Goffin, Veronique Hoste, Teodora Lalova-Spinks, Erik Mannens, Heidi Mertes, Tom Neutens, Paloma Rabaey, Sigrid Sterckx, Sylvie Tack, Nico Van de Weghe, Wim Van Biesen, Amy Van Looy, Marthe Van Overbeke, Griet Verhenneman.