Services · How does it end up in use, and stay there?

Production use requires six things at once. If one is missing, the solution stays an experiment.

The pilot works, and the project ends. The solution waits for a stage that has no named owner and no written criteria. In the interviews for three studies the same pattern repeated almost without exception.

When this becomes relevant

  • Several pilots are running, and taking them into use is nobody's job.
  • The pilot works, but nobody knows what taking it into production would require.
  • There is no single place that shows which models are in use and who is responsible for them.
  • The same solution is being built in parallel in different units or regions.
  • Some obligations of the EU AI Act already apply and the rest are approaching, and it is not clear which of them concern you.

Six preconditions

PreconditionWhat it means
1. Understanding the regulationWhat applies to this particular solution, when and with which obligations: the EU AI Act, MDR and IVDR, GDPR and the regulation of the sector itself.
2. Data protection and rolesPurposes of use, legal bases for processing and roles are clear before the model handles production data.
3. Production environmentThe environment withstands production load, monitoring and regular releases.
4. Lifecycle ownerSomeone is responsible for the model in production as well: updates, drift monitoring and retirement.
5. SecurityAccess control, logging and the protection of the models. The permissions of a language model are limited on the assumption that it will become the target of prompt injection.
6. Procurement and governance modelThe solution fits the procurement model and the decision-making of the organisation.

A single hospital or wellbeing services county rarely has the resources to keep all six standing at the same time.

What we offer

A repeatable structure with five parts. So far we have carried out studies and AI readiness assessments. We build the parts of the structure with you.

PartTask
Experimentation environmentModels are tested with real data without any effect on production. The environment has an agreed route into production, so that it does not turn into a permanent experiment.
Model registryOne place that shows which models are in use and in development, who is responsible for them and what stage they are at. The registry is used for prioritisation and approval.
Reference architectureHow AI is connected to the environment: data flows, access rights, logging, monitoring and the lifecycle of the models. Without it every project builds the same foundation again.
Decision points and a decision rhythmThe criteria for continuing and for stopping are agreed in advance. At regular intervals it is decided whether to continue, to redirect or to stop.
Lifecycle operationsModel drift, updates, version control and service level. This is the part that is forgotten most often.

When a pilot is evaluated, the work that moved out of sight is measured too: manual checks and workarounds. The reasoning is in the article.

Experiment and production use side by side

ExperimentProduction use
An isolated pilot, data fetched by handControlled inputs and an agreed way of releasing
Monitoring is occasionalMonitoring and drift tracking are continuous
Dependent on one specialistA named owner and shared responsibility
No maintenance planThe lifecycle and the maintenance are agreed

The timeline of the EU AI Act

The EU AI Act is risk-based. It works alongside GDPR, MDR and the regulation of the sector, and it does not replace them. Not all AI in healthcare is a high-risk AI system in the meaning of the regulation. The classification depends on the intended purpose and on whether the system is a medical device that a notified body has to assess.

Some of the obligations already apply. The prohibited practices and Article 4 on AI literacy have applied since February 2025, the rules on general-purpose models since August 2025 and the transparency obligations since August 2026.

The timeline for high-risk systems changed in July 2026. The obligations for the standalone high-risk systems of Annex III start to apply on 2 December 2027. For high-risk AI embedded in products, such as medical devices assessed by a notified body, they apply from 2 August 2028.

The extra time does not change what production use requires. An owner, a lifecycle and quality are needed in any case. The regulation makes them visible and auditable.

Evidence

The observations on this page come from three studies we have taken part in. They have surveyed the use of AI in Finnish health and social care, and in them we have interviewed dozens of researchers, clinicians, information management specialists and executives.

A named assignment: the AI Lab of Istekki

The survey identifies and assesses AI models developed in university hospitals and wellbeing services counties, and Invinite is responsible for carrying it out. On the basis of the survey Istekki has started a continuous workshop together with its customers, and a scientific article is being prepared from the results.

How to buy this

An assessment of readiness for AI in production, carried out as part of a definition, is a good way to start. Building the structure is bought as a project or a continuous allocation.