Hilbi IQ · one question, answered
Who is responsible when AI touches a patient case?
Under the AI Act, whoever puts an AI system to work in a professional process carries the duties. Paste a case into a general assistant and the practice owns that. IQ arrives the other way round, as a processor under a written agreement.
- Deployer duties, explained
- Signature gate before filing
- Architecture not published

Deployer duties
carried by the processor, not by you
Art. 50(4)
transparency recorded on every output
Two ways of working, side by side
The comparison is between two situations, never between named products.
| A general-purpose assistant used outside the clinical system | Hilbi IQ | |
|---|---|---|
| Who is the deployer under the AI Act | ||
| Contractual relationship for the data | ||
| Where the data is processed | ||
| Use for model training | ||
| Transparency toward the patient | ||
| Human oversight | ||
| Record of what happened | ||
| What reaches the clinical record |
In force: applies today and can be evidenced. In progress: under way and dated. Readiness: the position is prepared and the market opens next.
What is published, and what is not
Enough to assess responsibility. Not enough to rebuild the system.
- Processing location
- Stated per market and contractual.
- Legal roles
- Provider as controller, Hilbi as processor under Art. 28 GDPR, with the AI Act deployer duties allocated in writing.
- Transparency mechanism
- Machine-generated clinical text is disclosed under AI Act Art. 50(4) and carries the clinician who signed it.
- Oversight mechanism
- A signature gate before filing, not a review recommendation.
- Intended purpose
- Generates a structured draft report for clinician review and suggests service codes. It does not diagnose and it does not decide.
- Classification
- Assessed against MDCG 2019-11 and AI Act Art. 6(1) on the stated intended purpose, so a reviewer can re-run the assessment.
- Audit evidence
- What was generated, what was edited, who signed, when: immutable and exportable.
- What is not published
- Model routing, prompt construction, retrieval design and the vendor mix are not published. Responsibility can be assessed without them, and publishing them would not make the answer more checkable.
- Independent verification
- Under agreement a reviewer receives the audit report, the penetration test summary and the sub-processor list.
The follow-up questions
Is it actually forbidden to use a general assistant on a patient case?
What changes if the assistant is used with data that is not identifiable?
Who is liable if the draft contains an error?
Does the AI Act make IQ a high-risk system?
Why will you not publish the architecture?
Monthly briefing
The signal, once a month.
What changed in European health data, what we shipped, and what it means for a provider. Nothing else.