Physician AI Liability and Regulatory Compliance

No universal rule assigns clinical AI liability to the physician, hospital, or vendor in every case. Legal responsibility depends on jurisdiction, parties, claims, facts, contracts, regulatory status, evidence, causation, and the applicable standard of care. The same AI-assisted event may implicate professional negligence, institutional duties, product liability, contract, privacy, insurance, and medical-device law.

This chapter is educational and is not legal advice. Health systems and clinicians should obtain advice from qualified counsel and insurers for the specific jurisdiction, product, use, and contract.

Learning Objectives

After completing this chapter, clinicians should be able to:

  • Separate professional-negligence, institutional, product, contract, privacy, and regulatory issues
  • Explain why FDA authorization does not determine the standard of care
  • Identify current U.S. state health-AI requirements without generalizing them nationwide
  • Distinguish enacted law from guidance, proposed policy, mock-juror research, and legal scholarship
  • Ask insurers and vendors precise questions about coverage, notice, indemnity, and control
  • Design clinically useful documentation and traceability without indiscriminate copying of AI output

Liability begins with the exact jurisdiction, parties, product, version, intended use, workflow, evidence, and alleged harm. Existing doctrines still apply, but their application to clinical AI is not settled by a universal physician-hospital-vendor hierarchy.

Actor Potential issues Questions that matter
Clinician Professional negligence, informed decision-making, documentation What information was available, what was reasonably assessed, and what standard applies in the jurisdiction?
Health system Procurement, integration, training, monitoring, privacy, incident response What did the organization control, promise, test, monitor, and correct?
Developer or vendor Product, warning, warranty, contract, privacy, cybersecurity, regulatory claims Was the product defective, misleading, outside its intended use, or changed without adequate notice?
Data and integration partners Data quality, identity matching, latency, hosting, interfaces Which party controlled the failure point and what did the contracts allocate?

Four Critical Liability Scenarios:

Scenario Fact-specific legal questions
Following harmful AI advice Was reliance reasonable under the intended use, available information, training, workflow, and applicable standard?
Disregarding a correct alert Was the alert material, reliable, available, and reasonably interpreted, and did the response cause the alleged harm?
Using nondevice, internal, investigational, or unauthorized software Which regulatory category and institutional controls actually applied? Was the use research, quality improvement, or clinical care?
Software malfunction or undisclosed update Which party controlled the defect, update, warning, validation, monitoring, and corrective action?

FDA Clearance and Liability:

  • 510(k): Generally addresses substantial equivalence to a legally marketed predicate
  • De Novo: Classifies certain novel low- to moderate-risk devices without a predicate
  • PMA: Applies to Class III devices and requires reasonable assurance of safety and effectiveness
  • Legal boundary: FDA authorization is not a malpractice safe harbor, does not establish local clinical benefit, and does not decide civil liability

Key Documentation Practices:

  1. Maintain institutional traceability: System identity, version, intended use, labeling, validation, and material changes
  2. Document clinically material reasoning: Information considered, independent assessment, decision, and rationale when relevant
  3. Record discordance and incidents: Use approved escalation and retention processes that also protect privacy and security

Insurance Questions to Ask: - Does policy cover AI-assisted decisions? - Exclusions for non-FDA-cleared AI? - Notice requirements for AI-related adverse events?

The Dual Liability Risk:

Legal scholarship describes potential exposure from both directions (Mello and Guha, 2024): - Using AI incorrectly (automation bias, accepting hallucinations) - Failing to use a sufficiently established AI in a setting where the applicable standard arguably required it

These are analytical possibilities, not universal holdings. Availability, FDA status, reimbursement, or market adoption alone does not create a legal duty.

Generative AI Reproducibility Problem:

LLMs can produce different outputs for identical prompts (Maddox et al., 2025). This creates governance questions about: - record accuracy and provenance - reproducibility of clinically material output - version, prompt, and retention controls - quality assurance for variable output

Mock-juror evidence (2025–2026): Randomized vignette studies found that scripted information about AI error rates and a before-and-after image review changed mock-juror perceptions (Bernstein et al., 2025; Bernstein et al., 2026). These studies measure perceptions under hypothetical facts. They do not establish binding law, predict a court outcome, or create documentation or double-review requirements.

The Bottom Line: Every legal claim in an AI governance document should identify its jurisdiction, effective date, scope, and source. Documentation should support care and traceability, not defensive boilerplate. Insurance and indemnity depend on actual policy and contract language.

Introduction

Liability Framework for Medical AI

Current law did not develop around adaptive models, probabilistic output, hidden training data, model updates, or complex EHR integrations. That does not create a legal vacuum. Professional negligence, institutional or vicarious liability, product liability, contract, privacy, consumer protection, medical-device law, and licensing rules remain relevant. AI complicates proof because output can depend on data quality, interface design, user behavior, version changes, and the controls held by different organizations.

The central inquiry is therefore not simply “who is liable when AI fails?” It is a sequence of narrower questions:

  • Which jurisdiction and causes of action apply?
  • Which actor controlled the clinical decision, product design, data, integration, warning, update, monitoring, or incident response?
  • What did each party know or reasonably need to know at the time?
  • What standard of care or statutory duty applied to that actor and use?
  • Did an alleged breach cause a legally compensable injury?

The same adverse event can support different claims against different actors, and responsibility need not follow a fixed hierarchy.

Traditional Medical Malpractice Standard

  • Duty: Physician owes duty of care to patient
  • Breach: Deviation from standard of care
  • Causation: Breach directly caused harm
  • Damages: Patient suffered compensable injury

AI adds complexity to each element. The standard of care is jurisdiction- and fact-specific. Product labeling, FDA status, professional guidance, local policy, adoption, validation, and expert testimony may be relevant evidence, but none alone determines breach or causation.


Physician Liability Scenarios

The following are hypothetical fact patterns for legal and governance analysis. They do not predict a verdict or allocate liability without the missing jurisdictional, evidentiary, contractual, and causal facts.

Hypothetical Scenario 1: Following an AI Recommendation That Harms a Patient - Physician used FDA-cleared AI - AI suggested inappropriate treatment - Physician followed recommendation without independent verification - Questions to investigate: Was the product used within its intended use? What warnings and uncertainty were shown? Was independent verification clinically feasible and reasonably expected? Did the clinician’s conduct breach the applicable standard and cause the harm? - Evidence boundary: Ethical scholarship supports preserving professional judgment, but it is not a court holding and does not decide a malpractice claim (Char et al., 2018).

Hypothetical Scenario 2: Disregarding a Correct AI Recommendation - AI correctly identifies critical finding (e.g., pulmonary embolism on CT) - Physician dismisses or overlooks AI alert - Patient suffers harm from missed diagnosis - Questions to investigate: Was the alert visible, reliable, material, and within scope? What competing clinical information existed? Did policy or professional guidance address the workflow? Was the response reasonable, and did it cause the alleged injury? - Evidence boundary: A correct retrospective output does not itself prove that disregarding the alert was negligent. Standard-of-care analysis requires the contemporaneous facts and law.

Hypothetical Scenario 3: Using Nondevice, Internal, Investigational, or Unauthorized Software - Physician uses experimental or internally-developed AI - AI produces erroneous result - Patient harmed - Questions to investigate: Did the function meet the statutory definition of a device? If so, what pathway and authorization applied? Was the activity research, quality improvement, or clinical care? What local validation, review, consent, and oversight were required? - Evidence boundary: Lack of 510(k) clearance does not by itself prove unlawful use or negligence. Some software is not a device, some falls within enforcement discretion, and some may require a different pathway.

Hypothetical Scenario 4: AI System Malfunction or Undisclosed Change - FDA-cleared AI produces error due to software bug - Physician reasonably relied on system - Patient harmed - Questions to investigate: Was there a design, manufacturing, integration, data, warning, or update defect? Which party controlled testing, monitoring, notification, rollback, and corrective action? Was reliance reasonable under the interface and labeling? - Evidence boundary: A software defect does not automatically establish vendor, clinician, or shared liability. Product treatment, defenses, causation, and allocation vary by claim and jurisdiction.

Empirical evidence on AI use and liability perceptions: Randomized vignette studies examine how AI recommendations, performance information, and review workflows affect judgments under hypothetical facts:

  • A study of 1,334 U.S. adults evaluated scripted malpractice vignettes involving missed findings on radiologic images. Participants were more likely to find for the plaintiff when the AI flagged a finding that the radiologist missed than when both missed it. Providing false-discovery and false-omission information attenuated this mock-juror “AI penalty” (Bernstein et al., 2025). The measured endpoint was participant judgment under hypothetical facts, not an actual court outcome or a test of medical-record documentation.

  • A follow-up randomized vignette study of 282 participants varied whether the radiologist reviewed the image once or reviewed it again after AI feedback. Under the scripted facts, 74.7% of participants in the single-review condition and 52.9% in the double-review condition concluded that the duty of care was not met (Bernstein et al., 2026). The experiment supports studying workflow design and perception. It does not make double review a legal standard, prove that double review improves diagnostic outcomes, or require that workflow in every setting.

  • A randomized oncology-vignette study of U.S. and German adults and German physicians found higher reasonableness ratings for accepting standard-care AI advice than for rejecting it (Tacconelli et al., 2026). Acceptance and rejection of nonstandard-care advice met the study’s prespecified equivalence criterion, which did not exclude smaller differences. Harm and causation were fixed in the vignette; the study did not measure court outcomes, patient safety, or whether hospitals should adopt AI.

Together, these studies show that AI recommendations, performance information, and the sequence of human review can change participant judgments in controlled vignettes. Institutions may use that finding to formulate research questions and consult counsel, but should not convert it into a claimed defense, documentation mandate, or standard of care.


The Dual Liability Risk

Legal scholarship identifies a possible dual risk: unreasonable reliance on AI and failure to use a sufficiently established tool could each support a claim under some future facts (Mello and Guha, 2024). These are competing theories for case-specific analysis, not a settled rule that every physician must both use and distrust AI.

Liability from Using AI

Traditional liability concerns focus on AI errors:

  • AI hallucinations: Large language models can produce confident but false output. Uncritical reliance may become relevant to breach and causation, but liability still requires the governing jurisdiction and facts.
  • Automation bias: Over-reliance can contribute to unreasonable care when contrary information was available. It is a human-factors hazard, not automatic proof of negligence.
  • Opaque output: Limited explainability can affect reasonable reliance, warnings, informed discussion, procurement, and expert testimony. It does not create one universal legal result.

Liability from NOT Using AI

As evidence and practice evolve, a plaintiff could argue that reasonable care required access to or use of a particular tool. That argument would still need to establish the applicable standard, availability, clinical fit, breach, and causation:

  • Autonomous diabetic-retinopathy screening: FDA authorization and a prospective pivotal study establish a marketed intended use and performance evidence, not a national legal duty to offer the product in every community (Abràmoff et al., 2018).
  • Medication interaction and radiology support: Availability and adoption can be evidence, but alert quality, workflow, local resources, and professional guidance affect what reasonable care required.
  • Retrospective scrutiny: A litigant may ask whether a tool could have changed an outcome. That counterfactual is not self-proving and must be tied to admissible evidence and causation.

Published commentary continues to discuss failure-to-use theories, but commentary is not case law (Chew, 2025). No adoption percentage, reimbursement decision, product availability, or FDA authorization automatically converts AI use into a legal duty.

Generative AI: The Reproducibility Problem

Generative AI introduces a liability and governance dimension that is less prominent in fixed-output diagnostic software: output can vary with the model version, system instructions, prompt, context, tools, retrieval corpus, and sampling configuration. The same apparent request can therefore produce different text over time (Maddox et al., 2025).

Why Reproducibility Matters for Liability

Record accuracy and provenance: Variation that is unrelated to the clinical facts can produce inconsistent drafts. The legal significance depends on whether a draft entered the record, influenced care, misrepresented reasoning, or was retained under applicable policy.

Traceability: If model output materially influenced care, an organization may need a proportionate record of the output, version, or decision pathway. What must be preserved depends on clinical-record, privacy, discovery, retention, and institutional requirements.

Quality assurance: Non-determinism does not make audit impossible. It requires test sets, repeated runs where relevant, version control, sampling controls, human review, and monitoring designed for variable output.

Mitigation Strategies

  1. Treat LLM outputs as drafts requiring verification, not final products
  2. Require an accountable reviewer for patient-facing or clinically material output
  3. Preserve output through approved systems when policy or law requires it, while avoiding indiscriminate retention of protected or misleading drafts
  4. Restrict use by risk: Do not use a general-purpose LLM as an unvalidated diagnostic authority
  5. Define version, prompt, privacy, review, correction, and incident controls before deployment

Standard of Care Transition: When “Optional” Becomes “Required”

The legal standard of care can evolve as evidence, professional practice, technology, and law change, but the process is not a five-stage adoption ladder. Its content and proof vary by jurisdiction (Mello and Guha, 2024).

Indicators That AI Is Becoming Standard of Care

Potential evidence What it can establish What it does not establish alone
Professional guidance Recommended practices, conditions, and cautions A binding legal standard in every jurisdiction
FDA authorization and labeling Regulatory status and intended use for a specific product version Clinical benefit, local transportability, or immunity from civil liability
Coverage and reimbursement Payment eligibility and conditions Medical necessity or negligent nonuse
Peer and local practice How comparable clinicians or systems work A numerical adoption threshold that decides breach
Training and institutional policy Expected competence and local workflow The complete legal standard or causation
Case law and statutes Binding or persuasive rules within their jurisdiction and scope A national rule beyond that authority

The Transition Timeline

Institutions can still use a maturity framework for governance, but it must not be presented as law. A practical sequence is: investigational evidence, external validation, prospective workflow evaluation, comparative clinical utility, guideline consideration, monitored local adoption, and continuing reassessment. Each step answers a different evidentiary question. Failure to use a marketed AI is not presumptive negligence.


FDA Regulation and Liability

FDA Device Classification and Marketing Pathways

Device status is function-specific. Some clinical software is excluded from the device definition, some is subject to enforcement-discretion policies, and some is a regulated device. Classification depends on intended use, indications, risk, and statutory controls, not on a simple assistive-versus-autonomous label. The FDA Clinical Decision Support Software guidance was revised in January 2026 and should be read with other applicable digital-health policies.

  • 510(k): Generally demonstrates substantial equivalence to a legally marketed predicate.
  • De Novo: Provides a classification route for certain novel low- to moderate-risk devices without a predicate.
  • PMA: Applies to Class III devices and requires reasonable assurance of safety and effectiveness.

The exact product, version, classification, decision date, labeling, and authorization number should be verified in the FDA device databases.

What FDA Clearance Does and Does Not Mean

FDA authorization can establish: - that FDA permitted marketing through a specified pathway for a defined intended use - the product version, indications, labeling, performance evidence, and controls described in the decision record - for a 510(k), FDA’s substantial-equivalence determination

FDA authorization does not by itself establish: - Complete protection from liability - AI is infallible or perfect - Physician can abdicate clinical judgment - that the local standard of care is met or that a civil-liability burden shifts - Freedom from recall: a 2025 study of 950 FDA-authorized AI devices found 60 experienced 182 recall events, with 43% of recalls occurring within the first 12 months of authorization (Lee et al., JAMA Health Forum, 2025)


Documentation to Minimize Liability

Essential Documentation Practices

1. Document AI Use in Clinical Note:

Assessment and Plan:
[Clinical reasoning]

AI Decision Support Used:
- System: [Name, version] (FDA 510(k) cleared)
- AI Output: [Summary of AI recommendation]
- Clinical Judgment: [How physician integrated/modified AI recommendation]
- Rationale: [Why physician agreed/disagreed with AI]

2. Document Deviations from AI Recommendations:

AI Recommendation: [Treatment A]
Clinical Decision: Selected [Treatment B] instead
Rationale: [Patient-specific factors: comorbidities, preferences, contraindications]

Professional Liability Insurance

Key Policy Questions to Ask the Insurer or Broker

  1. Does the policy cover the exact AI-assisted activity and role?
    • Do not infer coverage because AI is described as a “tool”
    • Obtain written confirmation tied to the policy, endorsement, use, and jurisdiction
  2. Are there exclusions for specific AI technologies?
    • Experimental AI, non-FDA-cleared AI?
    • Autonomous vs. assistive AI?
  3. What are notice requirements if AI-related adverse event occurs?
    • Immediate reporting?
    • Documentation standards?
  4. Does policy cover defense costs for regulatory investigations (FDA, CMS)?
    • Not all policies include regulatory defense

Policy Language to Request

When reviewing or negotiating coverage, examine the actual policy, endorsements, definitions, exclusions, conditions, and notice provisions. The following are discussion points, not specimen language guaranteed to be available or sufficient:

Coverage affirmations: - “Clinical decision support tools, including AI-based systems, are covered as instruments of medical practice” - “Use of FDA-cleared AI systems within their intended use does not constitute policy exclusion” - “AI-assisted documentation, including ambient clinical documentation, is covered under standard professional liability”

Exclusions to watch for: - “Experimental or investigational technology” (may exclude non-FDA-cleared AI) - “Autonomous decision-making systems” (ambiguous, could exclude AI you thought was covered) - “Computer-generated diagnoses” (overly broad)

When Insurance May Deny Coverage

Coverage disputes depend on policy language and law. The table identifies questions to resolve, not universal grounds for denial:

Scenario Insurer Argument Mitigation
Used nondevice, internal, investigational, or unauthorized software How do experimental, investigational, software, and professional-services terms apply? Obtain a written, use-specific coverage position before deployment
Used a device outside labeled indications Does the policy restrict off-label use or require notice? Review labeling, evidence, policy, and local governance before use
AI-related incident occurred What event triggers notice, to whom, and by what deadline? Follow the actual notice clause and counsel’s advice, not a generic “immediate” rule
Generated documentation contained an error Which professional, cyber, institutional, or technology policy responds? Require review, correction, provenance, and incident processes appropriate to the workflow

Coordinating Multiple Policies

AI-related claims may implicate multiple insurance types: - Professional liability (malpractice) - Cyber liability (if data breach involved) - Hospital/institutional coverage (if using hospital-provided AI)

Confirm with your broker that there are no coverage gaps between policies for AI-related incidents.

Legal Duties in the Age of AI

The Physician’s Core Duty Remains Unchanged

Despite technological change, professional-negligence analysis generally asks whether a clinician owed a duty, breached the applicable standard of care, caused the alleged harm, and produced legally compensable damages. The content and proof of each element vary by jurisdiction. AI can change the facts considered, but it does not create a single national rule.

Relevant facts can include intended use, clinical context, information available at the time, training, institutional policy, reasonable reliance, independent assessment, communication, and response to discordant information. Scholarship can identify issues, but it is not a substitute for governing law or expert evidence (Char et al., 2018).

Allocation of Liability

The “Liability Gap” Problem

AI can diffuse information and control across a clinician, health system, developer, host, EHR vendor, data supplier, and integration partner. That complexity can make proof and allocation harder:

  • Physician claims: “I relied on FDA-cleared AI; the AI was wrong.”
  • Vendor claims: “We provided accurate risk information; the physician misused our system.”
  • Hospital claims: “We implemented AI per vendor specifications; the physician didn’t follow protocols.”

Legal scholarship calls this potential mismatch a “liability gap,” although available claims and recovery depend on the jurisdiction and actual parties (Char et al., 2018). Contracts should map responsibility for data quality, identity matching, latency, updates, monitoring, support, notification, and corrective action before an incident occurs.

Physician Liability Scenarios in Detail

Hypothetical Scenario A: Inadequate Review of AI-Assisted Imaging

A radiologist uses an AI chest X-ray system for pneumonia detection. The AI flags a nodule as benign. The radiologist does not independently review the image and misses a lung cancer.

Questions for analysis: What was the AI’s intended role? Did the radiologist have a professional duty to interpret the image independently? What did the interface display, and what review occurred? Did the missed finding cause the alleged harm? An AI review article can inform the technology context but does not prove breach (Rajkomar et al., 2019).

Hypothetical Scenario B: Possible Product or Integration Defect

A dermatologist uses an FDA-cleared AI skin lesion analyzer. The AI has a systematic defect: it misclassifies melanomas in darker skin tones due to training data bias. The dermatologist reasonably relies on the AI and misses a melanoma in a Black patient.

Questions for analysis: Was the tool actually authorized for this use and population? Was the performance problem known, warned about, or detectable through reasonable local validation? Did design, data, integration, deployment, or use cause the error? Daneshjou and colleagues documented performance disparities in dermatology AI, but that research does not establish a defect or liability for the hypothetical product (Daneshjou et al., 2022). FDA authorization does not decide reasonable reliance or product liability.

Hypothetical Scenario C: Disregarding an AI-Enabled ECG Alert

An emergency physician evaluates a patient with chest pain. An AI-enabled ECG system flags high-risk features of acute coronary syndrome. The physician dismisses the alert without documentation, diagnoses anxiety, and discharges the patient. The patient suffers a myocardial infarction.

Questions for analysis: Was the alert authorized, available, visible, validated, and clinically material? What evidence contradicted or supported it? What was documented under ordinary standards, and did the response cause the injury? Attia and colleagues evaluated an AI-enabled ECG model; the paper does not establish that an alert was legally required, shift a burden of proof, or decide negligence (Attia et al., 2019).

Hospital and Health System Liability

Hospitals face distinct liability theories:

1. Vicarious Liability (Respondeat Superior): - An organization may face vicarious liability for conduct within an employment or agency relationship, subject to jurisdiction-specific rules. - AI does not erase those doctrines, but employment status, scope, control, and claim still matter.

2. Corporate Negligence: - Hospital’s independent duty to ensure quality care - Includes: credentialing, equipment maintenance, policy development - AI-Specific Duties: - Selecting appropriate AI systems (due diligence) - Training staff on AI use - Monitoring AI performance post-deployment - Maintaining AI system updates/patches - Establishing AI governance Kelly et al., 2019

Hypothetical example: A hospital deploys a sepsis prediction system without adequate training or workflow testing, clinicians do not respond as intended, and patients are allegedly harmed. Potential institutional issues include procurement, integration, training, alert design, monitoring, and incident response. Sendak and colleagues describe implementation experience, not a legal verdict or a finding of negligent implementation (Sendak et al., 2020).

3. Failure to Adopt AI (Emerging Theory): - As AI becomes standard, not adopting it may be corporate negligence - Analogous to failure to adopt other safety technologies - Not yet legally established, but plausible future claim Topol, 2019

Vendor Liability

Vendor exposure depends on product status, claim, jurisdiction, contract, warnings, control, and causation. It should not be described as categorically limited:

Traditional Product Liability Theories:

1. Design Defect: - AI system systematically produces errors due to design (e.g., biased training data, inappropriate algorithm) - Plaintiff must show: (a) alternative safer design was feasible, (b) defect caused harm - Challenge: Defining “defect” for probabilistic AI is difficult (all AI has error rates) Beam and Kohane, 2018

2. Manufacturing Defect: - Software bug or deployment error causes AI to malfunction - Differs from design: specific instance departed from intended design - Example: Software update introduces bug causing misclassification

3. Failure to Warn: - Vendor did not adequately warn users about AI limitations, failure modes, or misuse risks - Examples: - Insufficient information about validation population - Inadequate guidance on when not to use AI - Failure to disclose known error patterns Nagendran et al., 2020

Challenges in Applying Product Liability to AI:

  • “Learned intermediary” doctrine: A vendor may argue that warnings properly ran through a clinician, but the doctrine’s availability and effect vary by product, jurisdiction, and claim.

  • Software and product status: Courts do not treat all software identically, and whether strict product liability applies to a specific software function is jurisdiction-specific.

  • Causation: Proof may need to separate model output, interface, clinician response, institutional workflow, and underlying disease.

Evolving Legal Standards and Case Law

Why So Few Cases?

Published medical-AI precedent remains limited and difficult to characterize through a universal negative. Reasons that reported cases may lag deployment include:

  1. Cases Settle: Most malpractice claims settle confidentially, preventing precedent development
  2. Causation Challenges: Plaintiffs must prove AI (not physician error) caused harm, which is difficult to establish for probabilistic systems
  3. AI is Recent: Many AI deployments are too new for adverse outcomes to reach the litigation stage (cases take years from injury to verdict)
  4. Liability Diffusion: Uncertainty about whom to sue (physician, hospital, vendor) may deter plaintiffs’ attorneys

The broader litigation over AI-generated legal filings is a separate domain. It illustrates that courts can sanction professionals who submit unverified false material, but it does not establish medical malpractice standards. A privately maintained database or law-firm review should not be treated as an official count of precedent or transferred directly to medicine.

Beyond physician-centered malpractice hypotheticals, Mansi and Riedl analyze 31 US legal cases and reported harms involving AI in care delivery and argue that patients often face tools deployed by insurers, facilities, and other stakeholders, not only bedside clinicians (Mansi and Riedl, 2026). Their patient-centred frame pushes liability design and AI tooling that help advocates reconstruct what happened across that web. Case-tracker analysis of reported litigation and harms, not a new binding liability rule.

Analogous Precedents Courts May Apply

Computer-Aided Detection (CAD) Cases:

Older computer-aided detection provides technical and clinical analogies, but the cited Brenner paper is a medical review, not a judicial holding (Brenner et al., 2006). It cannot prove that courts adopted a rule of full radiologist responsibility or predict how a court will treat a modern product with a different intended use and workflow.

Medical Device Product Liability:

Medical-device cases offer doctrines that counsel may examine, but their elements, defenses, and application vary:

  • Strict liability: Some jurisdictions recognize strict product-liability claims for qualifying products and defects. Whether software qualifies and what defenses apply are jurisdiction-specific.
  • Design Defect: Product unreasonably dangerous as designed (risk-utility balancing test)
  • Learned intermediary doctrine: In some settings, adequate warnings may run through a clinician. The doctrine does not automatically eliminate vendor duties.

Application to AI: - A regulated device software function may face product, warning, warranty, contract, or other claims, subject to applicable law - Design defect claims for biased training data, inadequate validation - A learned-intermediary argument may be raised, but product labeling, user role, warnings, direct-to-patient communication, and jurisdiction matter (Char et al., 2018)

The “Black Box” Problem and Explainability

A recurring AI legal challenge is that some models do not provide a human-understandable account of how each input contributed to an individual output. Opacity is not binary: documentation, uncertainty, intended use, feature information, counterfactual testing, model cards, user-interface design, and empirical validation can provide different forms of transparency.

Legal Questions: - Can physicians reasonably rely on unexplainable AI? - Does lack of explainability constitute a design defect or failure to warn? - Can informed consent be meaningful if mechanism is unknown?

Evidence and legal boundary: FDA requirements depend on the product and submission, not a universal performance-only rule. Rudin argues that high-stakes decisions should prefer interpretable models where possible, but the paper does not predict judicial acceptance (Rudin, 2019). GDPR includes safeguards and information rights for certain solely automated decisions, but the phrase “right to explanation” is contested and should not be stated as a simple universal entitlement. The EU AI Act adds transparency, documentation, risk-management, and human-oversight obligations within defined scopes.

International Liability Frameworks

The U.S. liability framework described above differs from emerging international approaches. The WHO 2025 guidance on large multi-modal models proposes liability frameworks that may influence future U.S. legislation and provide reference points for institutions operating globally (WHO, 2025).

Presumption of Causality

The WHO guidance discusses a proposed EU AI Liability Directive that would have permitted a rebuttable presumption under specified conditions. The European Commission withdrew that proposal on October 6, 2025 (EUR-Lex procedure 2022/0303/COD). No general presumption now shifts causation to a hospital or physician merely because AI was used.

Rationale: Patients cannot access proprietary algorithms, training data, or model weights. They lack the technical expertise to prove AI causation. Shifting the burden to parties with access to this information is more equitable.

Current status: The WHO document remains policy guidance for large multimodal models, not enacted global law. The withdrawn EU proposal should be discussed historically, not as a current directive. The EU AI Act is principally a regulatory framework and should not be conflated with the withdrawn civil-liability proposal.

Strict Liability for AI

WHO states that governments may wish to consider strict liability for large multimodal models used in health care. That is a policy option, not a rule that currently makes all developers and deployers liable regardless of fault (WHO, 2025).

Standard Requirements Application to AI
Negligence Plaintiff generally proves the applicable elements under jurisdictional law Conduct, standard, causation, defenses, and damages remain fact-specific
Strict-liability policy option Fault may not be required for a qualifying product or activity Scope, parties, defect or harm requirements, and defenses would depend on enacted law

Arguments for strict liability:

  • AI systems are too complex for patients to prove negligence
  • Incentivizes developers to maximize safety rather than shift risk to users
  • Ensures compensation for injured patients

Arguments against:

  • May discourage beneficial AI adoption
  • Unfair to physicians who reasonably relied on FDA-cleared systems
  • Could increase defensive medicine

No-Fault Compensation Funds

Modeled conceptually on no-fault compensation programs, WHO discusses compensation mechanisms that would not require proving negligence. This is a policy proposal for consideration, not an existing medical-AI program.

Potential structure:

  • Funded by fees on AI device manufacturers
  • Administered by designated agency
  • Claimants demonstrate injury and AI use, not negligence
  • Faster resolution than traditional litigation

Current status: The chapter does not identify an enacted medical-AI compensation fund. Before making a universal claim about every jurisdiction, a current legal survey would be required.

EU AI Act: Regulatory Requirements for Medical AI

The EU Artificial Intelligence Act (Regulation 2024/1689) entered into force in August 2024 and applies in stages. Medical-device AI may also fall under the Medical Device Regulation or In Vitro Diagnostic Medical Devices Regulation.

High-Risk Classification for Medical Devices

Medical device AI qualifies as “high-risk” under the AI Act when: - The AI is a safety component of a device or a medical device itself, AND - The AI requires third-party conformity assessment by a Notified Body

The two conditions are cumulative. The relevant question is whether the AI is a safety component of, or itself constitutes, a product covered by Annex I legislation and whether that product requires third-party conformity assessment. Medical or health-related purpose alone does not make every AI system high risk under this route.

Requirements for High-Risk AI Systems

Requirement Description
Risk management Systematic identification and mitigation of AI-specific risks
Data governance Training data quality, representativeness, bias assessment
Transparency Clear disclosure of AI use to patients and clinicians
Human oversight Mechanisms enabling human review and override
Technical documentation Comprehensive documentation of design, validation, performance
Accuracy and robustness Demonstrated reliability under expected conditions
Conformity assessment Third-party evaluation by Notified Body

Current implementation timeline

  • Prohibitions, definitions, and AI-literacy provisions have applied since February 2025.
  • Governance and general-purpose AI obligations began applying in August 2025.
  • Article 50 transparency requirements apply from August 2, 2026.
  • The European Commission’s current implementation materials state that high-risk Annex III rules apply from December 2, 2027, and rules for AI embedded in regulated products such as medical devices apply from August 2, 2028 (European Commission AI Act FAQ).

The medical-device deadline is August 2, 2028 under the current Commission implementation materials, not August 2026 or August 2027. MDCG 2025-6 addresses the interaction among the AI Act, MDR, and IVDR.

Practical Implications for U.S. Physicians

  1. Global device selection: Verify the exact CE-marking, intended purpose, class, conformity assessment, and AI Act status rather than assuming that every European product meets the same obligations.
  2. Vendor due diligence: Ask for current documentation, responsible parties, implementation timeline, and evidence of compliance.
  3. Institutional procurement: International controls can inform due diligence, but they do not prove U.S. clinical utility or legal compliance.
  4. Change management: Recheck obligations after material product, workflow, or legislative changes.

UK MHRA AI Framework

The UK Medicines and Healthcare products Regulatory Agency maintains official guidance for software and AI as a medical device, including qualification, classification, postmarket vigilance, and the ongoing change programme. UK requirements should be evaluated separately from EU MDR and AI Act obligations.

UK National Commission recommendations (September 2026)

On 10 September 2026, the MHRA-hosted National Commission into the Regulation of AI in Healthcare published recommendations for a future UK regulatory framework (GOV.UK recommendations; GOV.UK news). The Commission reports engagement with more than 12,000 patients, carers, clinicians, and technologists. Secondary summaries describe 44 recommendations; cite the GOV.UK primary text for wording.

The clinician-facing keep is lifecycle regulation: staged authorisation for new AI models under tight guardrails (described in government communications as similar to learner-driver “L-plates”), continuous real-world monitoring after deployment, stronger traceability and version control, proportionate transparency when AI is used in care, public access to safety information, and enhanced MHRA enforcement tools. Recommendations also address dependencies on general-purpose AI models (including proposed master-file style transparency mechanisms).

These are independent advisory recommendations. A formal government and MHRA response was stated as forthcoming at publication; they are not automatically UK law and do not determine U.S. clinician liability. Keep the older MHRA Software and AI as a Medical Device Change Programme material for historical pathway context, and add this 2026 Commission layer beside it. Public Health readers: deeper system-assurance treatment can live on the Public Health AI Handbook policy chapter with a pointer back here for clinician liability framing.

Implications for U.S. Physicians

While these frameworks remain theoretical in the U.S., physicians practicing internationally or at institutions deploying global AI systems should:

  1. Monitor regulatory developments: Verify effective dates and enacted text rather than relying on an earlier implementation calendar.
  2. Document proportionately: International frameworks do not create one universal charting rule, and documentation does not guarantee legal protection.
  3. Verify vendor agreements: Understand indemnification provisions and how liability is allocated across jurisdictions
  4. Participate in governance: Institutional AI committees should consider international standards when developing policies
  5. Evaluate international claims: Request evidence for any vendor claim of EU, UK, U.S., or other compliance.

Practical Documentation Strategies

Documentation should be clinically relevant, accurate, and proportionate to the system’s role. It should improve continuity, accountability, and traceability rather than become a universal requirement to paste every output or write a defensive essay in every note. Whether patient-level AI documentation is needed depends on the workflow, materiality, law, policy, professional standards, and records-management requirements.

Boilerplate that obscures the actual reasoning can increase rather than reduce risk. System identity, version, intended use, labeling, validation, and change history may be better maintained in an institutional inventory than repeated in every patient note.

Illustrative Template: AI-Assisted Diagnosis Documentation

This template is a discussion aid, not a universal legal requirement. It should be adapted with clinical documentation, privacy, health-information-management, compliance, and legal review. The example facts, probabilities, and management plan are hypothetical.

Chief Complaint: [Standard documentation]

History of Present Illness: [Standard documentation]

Physical Examination: [Standard documentation]

Diagnostic Studies:
- [Imaging/labs ordered]

AI-Assisted Interpretation:
- System Used: [Name, version, FDA clearance status]
- AI Finding: [Summary of AI output, e.g., "AI flagged 2.3 cm nodule
  in RLL with malignancy probability 78%"]
- Independent Assessment: [Your own interpretation: "Reviewed images
  independently. Concur with AI identification of nodule. Morphology
  concerning for malignancy given irregular margins and spiculation."]
- Synthesis: [How you integrated AI into clinical reasoning: "Given
  patient's smoking history, nodule characteristics per AI analysis,
  and my independent assessment, high suspicion for lung malignancy.
  Discussed findings with patient and recommended PET-CT and
  pulmonology referral for biopsy."]

Assessment and Plan: [Standard documentation incorporating above]

Illustrative Template: Documentation When Disagreeing with AI

This hypothetical example shows how a record could distinguish the AI output from the clinician’s assessment. It does not imply that every alert override requires a separate narrative or that these facts justify withholding sepsis treatment in a real patient.

AI-Assisted Analysis:
- System Used: [Name, version]
- AI Recommendation: [What AI suggested, e.g., "AI sepsis alert triggered;
  recommended blood cultures and broad-spectrum antibiotics"]
- Clinical Judgment: [Your assessment: "Reviewed AI inputs. Patient's
  vital sign changes explained by pain and anxiety related to fracture.
  No signs of infection on examination. Lactate normal. WBC normal."]
- Decision: [What you did: "Did not initiate sepsis protocol. Continued
  fracture care. Will monitor for signs of infection. Discussed rationale
  with nursing staff to avoid alert fatigue on future similar cases."]

What Clinically Useful Documentation Can Show: - which information materially influenced the decision - what independent assessment occurred - why discordant evidence was resolved in a particular way - what escalation or monitoring followed

Reddy and colleagues discuss governance and accountability considerations; the article does not establish that a particular template creates a legal defense (Reddy et al., 2020).

Illustrative Discussion Aid: Significant AI Use

No universal rule requires this exact consent for every clinical AI use. Separate disclosure, consent, notice, research, state-law, product-labeling, or institutional requirements may apply. Accuracy should not be reduced to one percentage when the endpoint, population, threshold, uncertainty, and failure modes differ.

Informed Consent Discussion: AI-Assisted Treatment Planning

Discussed with patient:
1. Treatment planning will utilize [AI system name], FDA-cleared software
   that analyzes [patient data type] to recommend [treatment options]

2. AI accuracy: System has been shown to be accurate in approximately [X]%
   of cases based on clinical studies. However, it is not perfect and can
   make errors, particularly in [known limitations].

3. Physician role: I will review the AI recommendations and use my medical
   judgment and expertise to develop a personalized treatment plan. The AI
   assists me but does not make the final decisions.

4. Patient data use: Your medical information will be analyzed by the AI
   system. Data is [de-identified/kept confidential] and [does/does not]
   leave our institution.

5. Alternatives: We can develop a treatment plan without using AI, relying
   on standard clinical guidelines and my expertise.

6. Patient questions: [Document any questions and your answers]

7. Patient decision: Patient [consents/declines] AI-assisted treatment
   planning.

Signature: ___________________ Date: ___________

Red Flag Documentation: What NOT to Do

Avoid:

  • “Followed AI recommendation” (implies no independent thought)
  • “AI cleared the patient” (AI does not have authority)
  • No mention of AI when it materially influenced decision (lack of transparency)
  • Generic documentation that does not specify which AI system or its output

Better:

  • “Integrated AI analysis into clinical decision-making as follows…”
  • “After reviewing AI output and independently assessing patient, my clinical judgment is…”
  • “AI system provided supplemental data that, combined with [other clinical information], informed my decision to…” Price et al., 2019

Professional Liability Insurance Considerations

Understanding Your Coverage

Professional-liability policies may be occurrence-based or claims-made and can differ in covered professional services, defense, exclusions, conditions, retentions, limits, reporting, and endorsements. No universal statement can establish that a policy covers AI because AI is a “tool” or that only FDA-authorized AI is covered.

AI-Specific Questions:

1. Does the policy cover the exact AI-assisted activity and professional role? - Absence of an AI-specific exclusion does not by itself establish coverage. - Action: Request written confirmation tied to the exact use, jurisdiction, policy, endorsement, and role.

2. Are there conditions on AI use for coverage to apply? - Some insurers require FDA-cleared AI only - Some require institutional approval/governance - Some require specific training or credentialing - Action: Review policy carefully; comply with any stated conditions

3. What notice requirements apply to an AI-related incident? - Review the policy’s definitions of claim, circumstance, incident, regulatory inquiry, and notice deadline. - Action: Clarify who must notify which insurer or broker and follow counsel’s advice for the actual event.

4. Does coverage extend to AI implementation or governance roles? - Clinical informaticists selecting AI systems - Quality improvement work involving AI deployment - AI governance committee participation - Action: These may be administrative functions outside standard clinical coverage; verify coverage Char et al., 2018

Emerging Insurance Products

The insurance market includes professional, institutional, product, technology errors-and-omissions, and cyber products that may respond differently. Availability and terms must be verified rather than inferred from a category label:

Technology errors-and-omissions and product coverage: - May address developer or vendor errors, subject to actual terms and exclusions - Does not automatically extend to a clinical deployment partner - Vendor insurance certificates and contractual promises should be reviewed with the underlying limits, insured entities, and indemnity terms

Cyber coverage: - May address specified breaches, security incidents, business interruption, response costs, or regulatory matters - Does not necessarily cover diagnostic error, product defect, or every adversarial attack - AI systems can create security attack surfaces, but the cited research does not interpret insurance coverage (Finlayson et al., 2019)

Coordinated coverage and contracts: - Multiple policies may respond to one event, and priority or allocation can be disputed - Contracts can allocate defense, indemnity, notice, and insurance obligations, subject to enforceability and exclusions - The organization should identify gaps before deployment rather than assume that “shared coverage” exists

Insurance Carrier Risk Management Recommendations

An insurer or broker may provide risk-management guidance. If so, organizations should distinguish policy conditions from nonbinding recommendations and retain the current written source:

  • Training documentation: Keep records of AI training completion
  • Competency assessment: Demonstrate proficiency before independent AI use
  • Audit participation: Engage in institutional AI performance audits
  • Incident reporting: Report AI near-misses and adverse events
  • Documentation standards: Follow insurer-recommended documentation templates

Following a recommendation does not guarantee a premium reduction, an affirmative defense, or a finding of reasonable care. Kelly and colleagues discuss barriers to clinical impact, not insurance pricing or legal defenses (Kelly et al., 2019).

Conclusion and Recommendations

For Individual Physicians

1. Build Role-Appropriate Competence: - Understand the system’s intended use, validation, limitations, uncertainty, and failure modes - Stay current with specialty society guidelines on AI - Participate in AI training offered by your institution

2. Document Accurately and Proportionately: - Follow applicable clinical-record and institutional standards - Separate model output from the accountable assessment when material - Explain clinically material discordance without defensive boilerplate

3. Verify Insurance Coverage: - Obtain a written, use-specific coverage position - Understand notice requirements for AI incidents - Ask about emerging AI-specific riders or exclusions

4. Maintain Clinical and Downtime Capability: - Avoid dependency that exceeds the validated role of the system - Maintain an approved workflow for outages, degraded performance, and withdrawal

5. Communicate Under Applicable Requirements: - Inform patients when law, policy, professional standards, consent, or the clinical relationship requires it - Address patient concerns or preferences - Document informed consent when appropriate Topol, 2019

For Hospitals and Health Systems

1. Establish AI Governance: - Create multidisciplinary AI governance committee - Develop AI procurement and vetting standards - Implement post-deployment monitoring programs

2. Provide Training and Support: - Mandatory training before AI system access - Ongoing education on updates and new systems - Clinical decision support for understanding AI outputs

3. Develop Legal Infrastructure: - Review vendor contracts for liability provisions - Ensure professional liability insurance covers AI use - Create AI-specific policies and procedures - Establish adverse event reporting systems Reddy et al., 2020

4. Monitor and Audit: - Regular performance audits comparing real-world to validation results - Detect and respond to performance drift - Track subgroup performance to identify disparate impact Obermeyer et al., 2019

5. Foster Safety Culture: - Encourage reporting of AI errors and near-misses - Non-punitive learning environment - Systematic analysis of AI-related incidents - Continuous quality improvement

For AI Vendors

1. Transparency: - Provide clear validation data and performance metrics - Disclose training data characteristics and limitations - Communicate known failure modes and edge cases

2. Post-Market Surveillance: - Monitor real-world performance actively - Provide performance feedback to customers - Issue alerts if performance degradation detected

3. User Training: - Comprehensive training programs for clinical users - Competency assessment before independent use - Ongoing education on updates and new features

4. Contractual Clarity: - Clear liability allocation in service agreements - Consider offering indemnification or insurance coverage - Define respective responsibilities of vendor and provider Nagendran et al., 2020

5. Regulatory Compliance: - Pursue FDA clearance/approval when appropriate - Follow Good Machine Learning Practice principles - Engage proactively with regulators

The Path Forward

Medical liability law is struggling to keep pace with AI innovation. Current frameworks evolved for human decision-making and physical devices; AI challenges these models. The pace of change is accelerating:

  • Regulatory milestones: FDA finalized PCCP guidance in August 2025, revised its final CDS guidance in January 2026, and still labels the January 2025 AI-device lifecycle document as draft guidance. An August 2026 discussion paper on generative-AI-enabled devices is a request for feedback, not guidance. Current European Commission materials place the high-risk medical-device deadline on August 2, 2028.
  • State legislation: Texas, Illinois, Arizona, and Colorado illustrate different scopes, actors, duties, enforcement, and effective dates. They should not be collapsed into a national rule.
  • Empirical legal-perception research: Mock-juror studies quantify responses to scripted facts. They do not provide physicians with a proven defense or determine real-world liability.
  • Insurance and contracts: Coverage, indemnity, control, and notice depend on the actual text and parties.
  • Professional guidance: Society documents can inform governance and expert analysis while expressly disclaiming creation of a legal standard.

In this uncertain legal environment, the principles of good medicine remain constant:

  • Patient safety first: Use AI to improve care, not replace judgment
  • Transparency: With patients, colleagues, and regulators
  • Continuous learning: About AI capabilities, limitations, and evolving standards
  • Humility: Recognize AI is a tool that augments, not supplants, clinical expertise
  • Documentation: Create clear records of AI-assisted decision-making Char et al., 2018

These principles can improve clinical governance, but no checklist guarantees reduced liability. The defensible position begins with precision: exact product, version, intended use, jurisdiction, evidence, workflow, contract, and applicable law.

Questions About Clinical AI Liability

Who is liable when AI recommendations cause patient harm?

Liability is fact- and jurisdiction-specific. Potential duties may attach to clinicians, institutions, developers, manufacturers, and other actors depending on intended use, control, warnings, workflow, standard of care, causation, contract, and applicable law. No universal rule makes the physician, hospital, or vendor always primary.

Does FDA clearance protect physicians from malpractice liability?

No. FDA authorization concerns marketing of a device for an intended use. A 510(k) clearance is based on substantial equivalence; De Novo and PMA use different pathways. Authorization does not decide negligence, causation, civil liability, local transportability, or clinical benefit.

What documentation is required when using AI in clinical practice?

No universal AI-specific charting rule applies to every use. The record should accurately document clinically material information, decisions, verification, and reasoning under applicable law, institutional policy, professional standards, and the workflow. Logging should also respect privacy, security, and retention requirements.

Can physicians be liable for not using AI when it becomes standard of care?

A failure-to-use theory is possible as evidence and practice evolve, but no AI tool becomes legally required merely because it is available, FDA-authorized, reimbursed, or widely marketed. The applicable standard of care depends on the jurisdiction, clinical context, evidence, professional guidance, availability, and expert testimony.

Clinical Bottom Line

Key Takeaways

Liability Reality: 1. There is no universal primary-liability hierarchy. Clinician, institution, vendor, product, integration, contract, and jurisdiction must be analyzed separately. 2. FDA authorization is not a malpractice safe harbor. It establishes a specific marketing decision and labeling, not local utility or civil liability. 3. Failure-to-use is a possible theory, not a settled mandate. Availability, adoption, reimbursement, or authorization alone does not create a duty. 4. Documentation should be clinically useful and proportionate. Traceability matters, but indiscriminate output retention and defensive boilerplate create their own risks.

Risk Mitigation Priorities: 1. Know the exact system: version, intended use, labeling, evidence, limitations, and change pathway. 2. Map control and responsibility: clinician, institution, vendor, data, interface, monitoring, and incident response. 3. Maintain clinical and downtime capability: avoid dependency beyond the validated role. 4. Verify insurance and contracts: obtain written, use-specific answers on coverage, notice, indemnity, and limits. 5. Follow applicable law and governance: do not generalize one state, specialty, product, or policy to every use.

Legal Landscape: - Few cases have reached courts; law is evolving - Litigation and regulatory interpretation will continue to evolve - Professional guidance may inform analysis without deciding the legal standard - Insurance and product terms require current, primary-document review

The Non-Negotiable Rule: Do not replace a jurisdiction-specific legal analysis with a slogan about physicians, hospitals, or vendors always bearing responsibility. Use AI within a defined role, maintain accountable human and institutional controls, and preserve the evidence needed to reconstruct what occurred.

Continue Reading