Existing medical malpractice law technically covers AI-assisted care, but it was not built for it, and the 2026 legal literature is converging on the view that liability is currently allocated by accident, not by design. For anyone deploying clinical AI, that ambiguity is itself a risk to be managed, not a gap that resolves itself with time.
Does AI change the basic elements of malpractice law?
No, according to a detailed Law.com analysis by practicing malpractice attorneys: the fundamental elements of a malpractice claim, duty, breach, causation and damages, remain unchanged by the presence of AI in the care pathway. What changes, and changes significantly, is how difficult it is to establish breach and causation when a software system contributed to the clinical decision. Tracing exactly what the AI recommended, whether the clinician saw and relied on that recommendation, and whether a reasonable clinician would have overridden it, is a much harder factual inquiry than establishing what a human colleague did or did not do, because the AI's reasoning process is often not fully documented or even fully interpretable.
Two very different liability pathways, and the law treats them differently
An npj Digital Medicine analysis makes a distinction that clarifies the whole debate: AI chatbots increasingly provide prescribing-level advice through two structurally different pathways, and current law handles them very differently.
Pathway one: AI behind the clinician. The AI is a decision support tool used by a licensed provider who remains the treating clinician of record. Here, the learned intermediary doctrine, developed originally for drug manufacturer liability, applies with reasonable clarity: the manufacturer's duty is largely satisfied by adequately warning the clinician, and the clinician's independent judgment is the operative legal shield and the operative legal exposure. If a clinician accepts an AI recommendation without independent verification and it turns out wrong, existing malpractice standards generally still place primary liability on the clinician for failing to exercise independent judgment, not on the software vendor.
Pathway two: AI advising patients directly. No licensed intermediary sits between the AI's recommendation and the patient's decision. The learned intermediary doctrine does not cleanly apply because there is no intermediary. The paper argues this is the more urgent, less resolved liability gap: when a consumer-facing AI tool gives a patient prescribing-level or triage-level advice directly, it is unclear under current law whether standard product liability, a negligence theory, or some emerging AI-specific standard governs, and different jurisdictions are beginning to answer that question differently.
Where courts and legislators are actually drawing lines in 2026
- California's AB-2575, working through amendment in 2026, specifically addresses health care services and artificial intelligence, an early example of state-level legislative attempts to clarify obligations rather than waiting for case law to develop them organically, which typically takes years and many plaintiffs.
- Delegated clinical judgment scholarship, including an AI and Ethics analysis focused on oncology and pathology, argues that AI is increasingly being used in ways that functionally delegate clinical judgment rather than merely support it, particularly in molecular subtyping and prognosis, and that liability frameworks have not caught up to the reality that some AI tools are no longer decision support in the traditional sense, they are the decision, with a clinician's sign-off functioning more as ratification than as independent review.
- The EU's evolving framework, examined in a European Journal of Risk Regulation piece, finds that even the EU's dedicated AI Liability Directive leaves meaningful gaps specifically in healthcare, where causation is hardest to establish and where the risk categorization approach underlying EU AI regulation does not map cleanly onto the nuance of clinical decision-making.
What this means in practice, today, for three groups
For clinicians: documented independent clinical reasoning, not just an AI recommendation accepted or overridden, remains your strongest liability protection. If you cannot articulate why you agreed with an AI recommendation beyond "it said so," you have not exercised the independent judgment the law still expects of you.
For health systems: governance committees should explicitly classify each AI tool as either supporting or effectively delegating clinical judgment, using the oncology and pathology framework above as a model, and adjust supervision requirements accordingly. A tool functionally making the call needs more oversight structure than one genuinely just informing a human who retains real discretion.
For vendors: the "AI behind the clinician" pathway is legally safer for you and should be reflected honestly in your marketing and your intended use statement. Selling a product as decision support while designing its interface to encourage one-click acceptance without friction is building exactly the ambiguity the Law.com analysis warns will not favor vendors once litigated.
The takeaway
Liability law has not failed to address AI in medicine, it simply has not been asked to resolve the hard version of the question yet, because the case law is still thin. The organizations treating this ambiguity as a governance problem to manage now, with clear documentation and clear delegation classification, will be in a far stronger position than the ones waiting for a court to define the rules for them through the first major verdict.






