Capability stopped being the question
Ambient documentation now has randomized-trial evidence, and foundation models are being validated in clinical trials. In health AI, “can it?” is largely settled.
For a decade the constraint in clinical AI was capability. That question is closing. A pragmatic randomized trial in NEJM AI found an ambient scribe cut documentation time and reduced burnout; multimodal foundation models such as EyeFM are now validated in double-masked randomized trials. The technology has crossed from demo to evidence.
Which means the interesting question has moved. It is no longer whether a model can read a scan or draft a note, but whether a health system can deploy it in a way a clinician trusts, a regulator accepts, and a patient is safe within. That is a problem of data and governance, not of model size, and it is a patient-experience problem too: care that feels personal only works when the patient can trust where their data went.
The bottleneck moved to trust
The WEF and BCG argue the real constraint is now trust, evaluation, and data lineage, not model capability.
The WEF and BCG's flagship study, “Earning Trust for AI in Health,” reframes the bottleneck precisely: from building AI to governing it. The priorities it names are technical and unglamorous, meticulous management of data sources, systematic data lineage, metadata completeness, and post-market surveillance that fits probabilistic systems rather than static drugs. In other words, trustworthy health AI is a data-management discipline before it is a modelling one.
Read against the chart, the lesson is stark: raw model capability is the least of the gating factors now. Governed data, evaluation, residency, and clinician adoption are what decide whether a deployment survives contact with a hospital. An AI that is built safe but not felt safe simply does not get used.
Modelled importance of each factor in whether a health-AI deployment succeeds, capability is no longer the constraint. Directional, not survey data; informed by WEF+BCG 'Earning Trust for AI in Health' (2025).
And Europe made the data foundation governable
The European Health Data Space turns health-data governance from a cost centre into a structured, funded, EU-resident regime.
The European Health Data Space entered into force in March 2025, with primary- and secondary-use rules phasing in to 2029 and 2031. Crucially, Member States may require health data to be stored and processed within the EU, and patient records are special-category data under GDPR. This makes Europe the most structured health-data jurisdiction on earth, and it makes residency a first-class design constraint.
Here too, residency is not the same as sovereignty: health data in an EU region of a US-headquartered provider remains reachable under the US CLOUD Act, which is why France already mandates certified health-data-sovereignty infrastructure. The lineage, evaluation, and oversight the WEF calls for are far easier to deliver, and to prove, when the data and the model live inside a sovereign perimeter. Figures here are Rindogatan models; the EHDS timeline is the Commission's.
“In health, an AI that is built safe but not felt safe does not get used. Trust is earned in the data lineage and the evaluation, not in the model card.”
Build trust into the foundation
Four moves to make health AI that is felt safe, not just built safe.
Start with lineage, not models: can you trace every input, version, and human sign-off behind an AI-assisted clinical output? If not, that gap, not the model, is your roadmap. Build the governed, EU-resident data foundation first.
Pilot the workload clinicians already want, ambient documentation is the cleanest first win, on sovereign infrastructure, and instrument it for evaluation and post-market surveillance from day one. Keep the frontier to de-identified research, and be honest about ROI: the firms that measure it (and most do not yet) are the ones that earn the next deployment.
- 1. Headline figures are Rindogatan models, directional benchmarks to be calibrated to a specific institution, not survey statistics.
- 2. Partner data points are drawn from publicly published research (e.g. Snowflake's Modern Marketing Data Stack, Databricks' State of Data + AI) and cited for direction only.
- 3. Regulatory references: EU AI Act, Reg. (EU) 2024/1689; GDPR, Reg. (EU) 2016/679; DORA, Reg. (EU) 2022/2554; NIS2, Dir. (EU) 2022/2555.
- 4. Sovereign deployment modelled on European sovereign infrastructure.