Dentistry is where practice AI has come furthest: caries and lesion detection on radiographs has become routine. That is exactly where the strictest rules sit — medical-device law for the tool, secrecy law for the data. And for the smile simulation on Instagram, three questions apply, of which the AI label is the last.
By Patrick de Kathen, Founder of KlarComply · Reviewed on
| What you do | What applies | Order of magnitude |
|---|---|---|
| X-ray AI for caries/lesion detection | Medical-device law (MDR) + possibly Annex I AI Act | manufacturer's CE duty |
| Drafting findings or referral letters in a general-purpose AI tool | Professional secrecy + Art. 9 GDPR | criminal/professional law · up to €20m or 4 % |
| Dictation/transcription via a cloud service | Professional secrecy + Art. 9 GDPR | criminal/professional law · up to €20m or 4 % |
| Showing smile simulations as advertising | Advertising law + Art. 50 AI Act + consent | injunctions · labelling |
| Booking bot on your website or Instagram | Art. 50 AI Act — disclosure | up to €15m or 3 % |
| Your team uses AI tools | Art. 4 AI Act — literacy | no standalone fine |
For small and medium-sized enterprises, the lower of the two AI Act values applies (Art. 99(6)). Under the GDPR, the higher one does.
Systems that mark caries, apical lesions or bone loss on radiographs support a diagnosis. Such software is generally a medical device under the Medical Device Regulation — CE marking, intended purpose and conformity assessment are the manufacturer's duty. The AI Act can additionally classify such systems as high-risk via Annex I where the product must undergo third-party conformity assessment; those AI-specific duties were postponed to 2 August 2028 — the medical-device duties were not.
For you as the operator, this does not mean certifying anything yourself. It means having two things in writing:
Dentists are bound by professional secrecy in every member state — under criminal law, professional regulation, or both, with the exact scope set by national law. The operative point for AI is the same everywhere:
Secrecy can be breached the moment patient data sits on a server that the provider's staff could access. It does not depend on whether a human ever reads the text. It is not the reading that constitutes the disclosure — the possibility of it does. A referral letter pasted into a general-purpose AI tool for drafting can cross that line even if the output never leaves your practice.
If your practice is in Germany: dentists are named expressly in § 203(1) of the Criminal Code — up to one year's imprisonment for unauthorised disclosure — and since 2017, § 203(3)–(4) permits involving IT and AI providers only where they are contractually bound to secrecy; a data processing agreement alone is not enough, because it covers data protection, not criminal law. Outside Germany, check your national rules — the safe baseline is the same everywhere: patient data goes into no tool whose provider is not contractually bound.
No patient reference in the prompt. "Draft a friendly reminder about professional tooth cleaning" is unproblematic. "Write the referral letter for Mr K., born 1961, post extraction of 36" is not. Strip names, dates of birth and findings before the input and re-insert them in your own system.
AI tools that simulate the treatment result — whiter teeth, a closed gap, a new front — are advertising with an implied promise. The order of review will be familiar to readers of our beauty salon article:
Health-advertising law is regulated nationally and often strict. In Germany, § 11 of the Heilmittelwerbegesetz prohibits comparative before-and-after depictions for operative aesthetic procedures without medical necessity — and the Federal Court of Justice reads "operative" broadly, so purely aesthetic instrumental treatments such as veneers without medical indication can fall under the ban, while medically indicated restorations do not. That boundary is case-specific: clarify it before the campaign runs. Misleading claims of results are prohibited everywhere — a simulation presented as a guaranteed outcome is an easy target.
A treatment photo shows a specific person's state of health. Publishing it requires its own explicit consent under Article 9(2)(a) GDPR — revocable at any time, specific as to channel and context. Consent to treatment is not consent to publication.
Since 2 August 2026, Article 50 of the AI Act requires AI-generated or materially AI-edited images to be identifiable. For a simulation, one honest sentence is enough: "Simulation, AI-generated — not a treatment result." That line replaces neither answer 1 nor answer 2.
The booking bot must identify itself — one sentence is enough: "You are chatting with an automated assistant." Dictation, transcription and AI-assisted billing tools, by contrast, see patient data and belong in the same review as every tool with a patient reference: a data processing agreement under Article 28 GDPR and, where your national law requires it, a contractual secrecy undertaking. A provider unwilling to sign the latter is telling you something.
Since 2 February 2025, Article 4 of the AI Act has obliged you to take measures to foster AI literacy among your staff — since the Digital Omnibus a duty of effort, not of result, and without a standalone fine (Article 99(4) lists the sanctioned duties exhaustively; Article 4 is not among them). Why the record still matters: if a referral letter ends up in the wrong tool or a simulation goes online unlabelled, the first question — from the regulator, the professional body, the other side's lawyer — is always: did your staff know what they were doing? A dated training record answers it.
If it is placed on the market as a CE-marked medical device for exactly that purpose: yes — conformity is the manufacturer's duty. Get the intended purpose and CE status in writing, and record that final clinical responsibility stays with the dentist. A system that is officially documentation-only but in practice shapes your findings shifts the risk to you.
Not with a patient reference in a general-purpose tool: professional secrecy can be breached the moment the provider's staff could access the data — actual reading is not required. It becomes workable with a provider that signs a secrecy undertaking and a data processing agreement, or with no patient reference in the prompt at all.
Three questions, in this order: first — does national health-advertising law restrict before-and-after depictions for the treatment in question? Clarify before the campaign. Second — is there specific, explicit consent to publication? Third — is the simulation labelled as AI-generated (Art. 50 AI Act) and free of guaranteed-result claims? Only when all three are answered is the post clean.
Yes. Article 50 of the AI Act requires that people can tell when they are interacting with an AI system, unless it is obvious. One sentence is enough: “You are chatting with an automated assistant. For a personal conversation, call us.”
The free quick check walks through ten points — AI inventory, training status, transparency duties, responsibilities. Two minutes, no sign-up, an honest result and your concrete gaps.
Start the quick check — free