
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
Doctolib, a major French healthcare platform, is under scrutiny for its AI-powered consultation assistant, which uses technologies from Google, Microsoft, and Anthropic. Allegations suggest patient data may be exposed to US tech giants, raising privacy concerns. Doctolib denies misuse, but risks of future data breaches and regulatory investigation persist.[AI generated]
Why's our monitor labelling this an incident or hazard?
The event involves the use of AI systems (AI-powered consultation assistant) processing sensitive health data. Although Doctolib asserts strict contractual and technical measures to prevent misuse, the article emphasizes the plausible risk of data being used improperly or accessed under legal compulsion (e.g., Cloud Act), which could lead to violations of data protection laws and harm to individuals' privacy rights. No actual harm has been reported yet, but the credible risk of future harm due to potential data misuse or loss of control qualifies this as an AI Hazard rather than an AI Incident. The article does not describe a realized incident but focuses on the plausible risks and regulatory concerns, so it is not Complementary Information or Unrelated.[AI generated]