magine a piece of software designed to do something clinically simple and legally impossible. It reads a patient’s whole-genome sequence, cross-references their electronic health records, identifies a pathogenic variant with a known targeted therapy, orders a confirmatory laboratory test, updates the treatment plan, and writes a prescription that lands in the pharmacy back-end. No human in the loop. Every step is technically feasible today. And every step, in Europe, is blocked by a different regulatory instrument.
This is not the story of Europe’s genomic infrastructure. That story, the one about the Genome of Europe, the 1+ Million Genomes framework, and the slow orchestration of federated data across twenty-seven health systems, has already been told. This is the story of what happens when you try to place an autonomous agent on top of that infrastructure and ask it to act.
Step one: reading the genome
The agent’s first act is variant calling and interpretation on a whole-genome sequence. Under the AI Act, any AI system embedded in a medical device that requires third-party conformity assessment inherits high-risk status automatically. The reading software, if it influences a clinical decision, falls under the Medical Device Regulation as a Class IIa device or higher, depending on the intended purpose. The sequencer itself is governed by the In Vitro Diagnostic Regulation on the assay side. Before the agent has done anything clinically meaningful, it already needs a Notified Body, a quality management system, and a technical documentation file that satisfies both the MDR and the AI Act’s requirements for high-risk systems.
Step two: accessing the health record
The agent needs the patient’s electronic health record to contextualize the variant. Here it hits the European Health Data Space regulation, which began to apply in March 2026. The secondary-use framework for genomic data, however, will not be operational until March 2031, according to the staggered timeline set by the Commission. Even primary use, in a clinical setting, requires explicit consent management under the GDPR unless the member state has legislated an alternative legal basis. The agent cannot simply query the record; it must be granted access through a national health data access body, under conditions that vary from Stockholm to Seville.
Step three: ordering a confirmatory test
With the variant identified and the health record consulted, the agent determines that a confirmatory laboratory test is required before prescribing. Ordering that test means interfacing with a laboratory information system, which in most European hospitals is a protected medical device in its own right. The interface must be certified under the MDR if it influences patient management. The agent is now not just a piece of software; it is a medical device orchestrating another medical device, and the liability chain has no clear owner.
Step four: updating the therapy plan
This step triggers Article 22 of the GDPR, which gives the patient the right not to be subject to a fully automated decision with legal or similarly significant effect. A therapy plan update is precisely that: a decision that affects the patient’s health and legal rights. The agent can recommend, but it cannot decide. The moment it decides, the deployer must demonstrate either explicit consent, a legal authorization, or a human override that is meaningful, not cosmetic. The proposed AI Liability Directive adds another layer, shifting part of the evidentiary burden onto the deployer when harm plausibly originates from an opaque model.
Step five: writing the prescription
Prescribing is a reserved act in every European jurisdiction. The agent must authenticate against a national e-prescription system, hold a digital certificate, and act under the delegated authority of a licensed physician. In France, that means navigating the Carte de Professionnel de Santé. In Germany, the gematik infrastructure. In Spain, each autonomous community has its own prescription module. The agent is now subject to sectoral rules that were written for human professionals, and the mismatch is not accidental. It is the product of legal systems that equate clinical judgment with human judgment.
What the Digital Omnibus changes, and what it does not
The European Commission’s Digital Omnibus on AI, announced in late 2025, is widely expected to push the compliance deadline for high-risk product-embedded systems to August 2028. That buys developers two extra years. But it does not change the architecture of the problem. The agent is still blocked not by a single law but by a stack of laws that were not designed to interoperate. The Omnibus adjusts the timeline; it does not harmonize the MDR, the IVDR, the GDPR, the EHDS, and the AI Act into a single coherent pathway for autonomous clinical software.
The compliance layer is the product
A practical consequence follows. A startup building an autonomous variant-calling agent is more likely to win a hospital contract by having a credible answer for the Notified Body than by having the best F1 score on a benchmark. The RegTech tier, the layer of software that proves compliance across multiple regulatory regimes, is where a real share of the value probably accrues over the next five years. The model tier is necessary but not sufficient. The agent that reaches the clinic first will be the one whose compliance architecture is more convincing than its model architecture.
The runway, not the ceiling
Europe will not deploy a fully autonomous prescribing agent in 2026, nor in 2028. The regulatory stack is too tall, and the harmonization too slow. But the infrastructure being built, the federated data spaces, the Notified Body capacity, the compliance tooling, can function as a runway for a different kind of agent: one that is auditable, certifiable, and trusted across borders. If the AI Act, the MDR, and the EHDS end up functioning as the compliance passport for autonomous genomic care, the delay will look, in retrospect, like the necessary preparation for something that the rest of the world will eventually need to adopt. If they do not, Europe will have built a very expensive platform on which no one is allowed to run.
Sources
- European Health Data Space Regulation (EHDS), Regulation (EU) 2025/327: https://eur-lex.europa.eu/eli/reg/2025/327/oj
- EU AI Act, Regulation (EU) 2024/1689, Annex III on high-risk AI systems: https://eur-lex.europa.eu/eli/reg/2024/1689/oj
- Medical Device Regulation (MDR), Regulation (EU) 2017/745: https://eur-lex.europa.eu/eli/reg/2017/745/oj
- In Vitro Diagnostic Medical Devices Regulation (IVDR), Regulation (EU) 2017/746: https://eur-lex.europa.eu/eli/reg/2017/746/oj
- General Data Protection Regulation (GDPR), Article 22 on automated individual decision-making: https://gdpr-info.eu/art-22-gdpr/
- Proposed AI Liability Directive, COM(2022) 496 final: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52022PC0496
- Updated Product Liability Directive, Directive (EU) 2024/2853: https://eur-lex.europa.eu/eli/dir/2024/2853/oj
- European Commission, Digital Omnibus on AI, announced November 2025: https://digital-strategy.ec.europa.eu/en/policies/ai-omnibus
- 1+ Million Genomes initiative, European Commission: https://digital-strategy.ec.europa.eu/en/policies/1-million-genomes
- Genome of Europe project, European Commission: https://digital-strategy.ec.europa.eu/en/policies/genome-europe
- IMPaCT-GENóMICA program, ISCIII: https://www.isciii.es/QueHacemos/Financiacion/IMPaCT/Paginas/Genomica.aspx




