Innovation is possible — and strategically necessary — despite strict regulation. IT leaders in healthcare — whether in hospitals, pharma, or medical devices — have to drive innovations like AI while staying compliant with strict regulations such as Good Practice (GxP), the Medical Device Regulation (MDR), and the GDPR.
For a long time, public cloud was seen as a risk in this space. In my view, it is now the foundation of modern digital strategies. The question is no longer if but how to use it securely and compliantly. The Bitkom Cloud Report 20251 also shows: 90% of companies in Germany use cloud applications, and 46% plan to invest more in cloud than in the previous year. Cloud is becoming the standard operating model for new digital capabilities and AI services.
Public cloud and regulation – do they go together?
In short: yes. Despite stringent demands — for example through EU Good Manufacturing Practice (GMP) Annex 112 — healthcare organizations continue to push cloud adoption3 forward. Back in 2021, Gartner4 predicted that by 2025 more than 85% of companies would embrace a cloud-first strategy and would not be able to fully execute their digital strategies without cloud-native architectures and technologies. A Gartner forecast from November 20235 expects 70% of workloads to run in a cloud environment by 2028, up from 25% in 2023.
The key is “compliance by design.” In my view, earlier concerns about multi-tenancy have been put into perspective: shared cloud environments today often even offer a security advantage, as standardized protection mechanisms reduce cyber risk. European cloud regions address data residency; encryption with customer-managed keys reduces the risk of unauthorized access. In my view, the legal question remains open whether authorities outside the EU — for example via the US CLOUD Act — can access data held by providers with a US parent company. When health data is processed in the cloud, GDPR’s strict requirements naturally apply; for medical devices, MDR requirements come on top. Using established best practices (e.g. Good Automated Manufacturing Practice, the GAMP5 guide6), companies validate cloud systems in a GxP-conformant way. The compliance hurdle is shrinking, especially with experienced partners who implement GxP, data protection, and security from day one.
Cloud as the foundation for AI innovation
In my view, scalable AI is hardly feasible without cloud: large data volumes and compute-intensive algorithms demand cloud elasticity. According to Forrester (June 2025)3, an average of 20% of the healthcare industry’s x86 server OS instances already run in the public cloud — a different metric from the Gartner forecast above, which refers to cloud environments in general. Organizations use cloud primarily for agility, scalability, and pace of innovation. According to the Bitkom Cloud Report 20247, 17% of companies across all sectors used AI from the cloud, a share expected to double to 34% within five years. In the Bitkom Cloud Report 20251, it had already reached 26%.
In 2024, Bitkom7 president Dr. Ralf Wintergerst said that IT security and artificial intelligence will give cloud computing a strong boost, and that the cloud in turn promotes the use of AI and strengthens security.
The EU AI Act8 defines the regulatory framework — especially where AI acts as part of a medical device or delivers clinically relevant results. Risk management, high-quality datasets, transparency, and human oversight are key. In practice, organizations combine these requirements with GxP validation and audit trails. For AI in GMP/GxP processes outside of products (e.g. for evaluating research data), differentiated obligations apply — but the technical implementation stays the same: cloud-based governance, versioned pipelines, monitoring, and traceable approvals.
Outlook: agent-based AI – the next evolutionary step
AI workloads keep evolving. In agent-based AI, models act as autonomous agents that flexibly access distributed data and act on their own. Examples include real-time patient monitoring and intelligent assistance in diagnostics and therapy. For agents to operate safely in regulated environments, standardized and auditable tool and data integrations are required. This is where the Model Context Protocol (MCP)9 comes in — an open standard often described as “USB-C for AI.”
MCP enables bidirectional, finely controlled connections between AI applications and external systems (Document Management System DMS, Laboratory Information Management System LIMS, Manufacturing Execution System MES, Quality Management System QMS). This reduces development effort and enables precisely controlled least-privilege access. Thanks to growing ecosystem support, MCP can become a central building block for agent-based architectures in GxP contexts.
Shaping the transition
Cloud technologies give healthcare organizations the option to combine innovation and compliance. A systematic approach is decisive — from secure migration through building robust governance structures to integrating AI strategies into existing processes. In my view, public cloud infrastructures can be designed to reliably meet technical and regulatory requirements while also forming the foundation for new digital services.
Sources
- Bitkom: “Wirtschaft ruft nach einer deutschen Cloud” (Business calls for a German cloud), press release on the Cloud Report 2025, 11 June 2025. Telephone survey of 604 companies with 20+ employees in Germany (Bitkom Research, calendar weeks 12–19 2025), representative. bitkom.org
- European Commission: “EudraLex – Volume 4 – Annex 11: Computerised Systems”, GMP guideline, in operation since 30 June 2011. health.ec.europa.eu
- Forrester (Tracy Woo, Shannon Germain Farraher): “The Future Of Healthcare Is In The Cloud”, blog post, 24 June 2025. forrester.com
- Gartner: “Gartner Says Cloud Will Be the Centerpiece of New Digital Experiences”, press release, 10 November 2021. gartner.com
- Gartner: “Gartner IT Infrastructure, Operations & Cloud Strategies Conference 2023 London: Day 1 Highlights”, press release, London, 20 November 2023. webwire.com
- ISPE: “GAMP® 5: A Risk-Based Approach to Compliant GxP Computerized Systems (Second Edition)”, guidance document, 2022. ispe.org
- Bitkom: “Unternehmen treiben mit der Cloud ihre Digitalisierung voran” (Companies drive their digitalisation with the cloud), press release on the Cloud Report 2024, 3 July 2024. Telephone survey of 603 companies with 20+ employees in Germany across all sectors (Bitkom Research, calendar weeks 12–19 2024), representative. bitkom.org
- European Parliament and Council: “Regulation (EU) 2024/1689 of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)”, OJ L, 2024/1689, 12 July 2024. eur-lex.europa.eu
- Model Context Protocol: “What is the Model Context Protocol (MCP)?”, project documentation, accessed 27 September 2026. modelcontextprotocol.io