The use of Artificial Intelligence (AI) in medical diagnosis has significantly increased in Indonesian hospitals, including RSU Cahaya Medika Makassar which has integrated AI for radiology and pathology since 2024 (with a capacity of 500 beds and 20+ AI tools). Law No. 17/2023 on Health (Article 220) and Permenkes 75/2020 on AI in Health require accuracy >90%, algorithm transparency, and liability sharing between doctors-AI-vendors. However, legal risks emerge: AI diagnosis errors (15% false positive, Kemenkes 2025), malpractice claims (Article 29 Law 29/2004), and data responsibility (UU PDP 27/2022). A case at a Jakarta hospital (2024) lost a Rp2 billion lawsuit over AI breast cancer misdiagnosis; RSCM Makassar recorded 3 AI error incidents in 2025. Without risk management (policy, training, insurance), RSU Cahaya Medika is vulnerable to litigation, reputational damage, and costs. This study aims to identify main legal risks of AI diagnosis use and design an effective legal risk management framework according to ISO 31000 and Indonesian regulations. This research uses a qualitative case study with a normative-empirical juridical approach, involving in-depth interviews with 25 key informants, AI system observations, and document analysis. The results show that the main legal risks include criminal and civil malpractice due to AI errors, non-compliance with UU Health and Permenkes AI regulations, and complex liability sharing between doctors-vendor-AI-hospitals. The effective legal risk management framework must include risk identification, risk assessment, risk treatment, and continuous risk monitoring according to ISO 31000 standards.