Home health device market grows without a named responsible party
In July 2024, Kohler Health and Throne introduced smart toilet devices in the United States equipped with cameras and AI algorithms designed to analyze urine and feces, returning hydration and gut health scores through a connected app, as documented by Wired[1]. The Kohler Health device costs $449, plus $130 for an annual family subscription; Throne, which raised $10 million in funding that same month, offers a product at $399 with a $70 subscription. The global gut health market, according to the same source, is expected to reach nearly $106 billion by 2029.
The two companies keep confidential the methodology by which the algorithm classifies collected biometric data.
No public communication identifies which corporate function bears formal responsibility for processing, in writing, before commercial launch. This documentary gap precedes any clinical evaluation of the product.
AI transparency obligations remain poorly defined for consumer devices
The EU AI Act, Regulation (EU) 2024/1689, imposes transparency obligations under Article 50 for artificial intelligence systems that interact with people or generate outputs intended to inform decisions. The implementation timeline is staggered: provisions on high-risk systems listed in Annex III enter force progressively, with a deadline set for August 2, 2026 for most remaining obligations. This deadline defines the European jurisdiction exclusively.
The devices launched by Kohler Health and Throne operate outside the immediate European scope, as they are marketed primarily in the United States. The United States jurisdiction, absent a comprehensive federal artificial intelligence law, proceeds with fragmented state-level regulations.
The Colorado case SB 26-189, which replaces SB 24-205 before it even takes effect, illustrates this trajectory.
Who is accountable for classifying biometric data
The central question for the General Counsel concerns identifying the named role responsible for classifying data collected by the device, in writing, before commercial deployment.
Frameworks that assign responsibility to a generic team, rather than to an identified individual, produce documentation rather than effective governance. This distinction recurs in analysis of artificial intelligence regulatory regimes, including the EU AI Act, where the absence of a specific named responsible party constitutes a structural gap replicated by most corporate implementations observed so far.
The audit trail remains the minimum perimeter of legal defense
Audit remains required even absent direct legal obligation in the United States; what changes is the scope breadth. A device that collects sensitive health data via imaging and processes it with a proprietary algorithm requires traceability of model versions, changes to classification criteria, and connected product decisions.
A compliance posture calibrated to generic data protection proves today undersized for devices processing health, biometric, and behavioral data categories simultaneously. The Chief Compliance Officer verifies whether the existing register covers this combination, or remains limited to a single category.
Three decisions for the board
Three decisions define the operational perimeter for General Counsel and Board Audit & Risk Committee.
- Map which internal function receives, classifies, and retains biometric data collected by the device, with name and role documented before any product expansion.
- Verify whether public disclosure of the classification algorithm meets standards equivalent to those required by Article 50 of the EU AI Act, even absent direct legal obligation in the United States.
- Define an audit trail protocol that documents every modification to the health data classification algorithm, with retention of previous versions.
What changes for Chief Risk Officer and CEO
The Chief Risk Officer updates the risk framework to include exposure from health data collected via consumer devices, a category previously underpinned by traditional risk management systems. Risk includes, beyond direct regulatory violation, reputation, civil litigation, and investor assessment should health data misclassification incidents emerge. This combination requires an update to the risk register within short review cycles.
For the CEO, the constrained strategic decision concerns the timing of international product expansion. Should the company plan entry into the European market, anticipatory alignment with Article 50 requirements reduces subsequent compliance costs, rather than chasing already-set regulatory deadlines.
The governance signal: home health precedes regulators
The governance signal emerging from this case is clear: consumer devices collecting health data through AI algorithms systematically anticipate the regulators' capacity to classify them.
Research on enterprise adoption of agentic AI systems, published by MIT Technology Review, observes that organizations building structured governance before enforcement achieve a measurable time advantage over competitors chasing compliance (MIT Technology Review[2]). The same principle applies to home health devices. Companies that define named responsibility and transparent classification now reduce exposure when enforcement becomes effective.
Clinical doubt reinforces disclosure urgency
Gastroenterologists consulted by Wired[1] express skepticism about the added clinical value of smart toilets for healthy individuals, defining the product as excessive compared to visual self-assessment. A methodological contribution on transparency of outputs generated by artificial intelligence models, published on arXiv, underscores how unclear communication of classification criteria reduces the possibility of independent third-party verification (arXiv[3]).
Should clinical utility remain uncertain while biometric data collection proceeds at scale, the absence of methodology disclosure amplifies regulatory risk rather than reducing it. This scenario makes AI transparency obligations for companies a governance topic, before it becomes a marketing one.
Regulatory horizon
The current state sees the EU AI Act in staggered implementation, with Article 50 obligations set to complete by August 2, 2026 in the European jurisdiction.
In the United States, state-level regulatory fragmentation continues, absent a comprehensive federal law expected before 2028-2030, according to the trajectory observed in recent state legislative patterns. Producers of home health devices thus operate in a time window where voluntary disclosure represents the available mitigation measure, rather than direct legal obligation. The Board that initiates this mapping by 2025 anticipates the regulatory window, rather than submitting to it.
This article was written by an AI editorial author with human oversight, in compliance with transparency obligations under Regulation (EU) 2024/1689 (AI Act, Art. 50). Sources are linked in the text.
Article by ATLAS
Sources
- Wired 3 Sep 2026 (wired.com)
- MIT Technology Review (technologyreview.com)
- arXiv (arxiv.org)