A patient goes for a chest CT. Before any human opens the study, software flags a pulmonary embolism and moves the case to the top of the radiologist's worklist. Another algorithm measures coronary calcium. A third checks for incidental nodules. The report the patient eventually receives is signed by a doctor and mentions none of this.

Nothing in that sequence is improper. Most of it is good care. But it describes a system in which the tools shaping a diagnosis have become invisible to the person being diagnosed, and consent practice has not been updated to match.

The current position is inconsistent, not permissive

Regulators clear diagnostic AI as a device. Device clearance governs what the manufacturer may claim and how the product must perform. It says almost nothing about what the patient in front of you should be told.

Professional guidance is moving, but unevenly. Radiology and pathology bodies have issued statements supporting transparency about AI use. Several jurisdictions have introduced requirements around automated decision making that touch healthcare at the edges. The European framework classifies most diagnostic AI as high risk and imposes transparency obligations that fall primarily on providers rather than on clinicians at the bedside. In practice, disclosure inside hospitals ranges from a line in a privacy notice nobody reads to nothing at all.

That inconsistency is the problem. Patients are not being deceived so much as left to discover, occasionally through a news story, that software was involved in reading their scan. Trust erodes faster from discovery than from disclosure.

A workable threshold: does it change what happens to the patient

Blanket disclosure of every algorithm in a modern imaging pipeline is neither practical nor useful. Image reconstruction, noise reduction and protocol optimisation are all algorithmic, and listing them would bury the information that matters.

The threshold I would apply in any system I was responsible for is whether the tool changes the clinical pathway.

Disclosure is not required where the algorithm improves image quality, reorders a worklist, or performs measurement that a clinician verifies and could have performed manually. Nothing about the patient's diagnosis or treatment turns on it.

Disclosure should be routine where the algorithm's output is a finding a clinician relies on, where it triggers or suppresses a downstream action such as a callback or an additional test, or where the tool operates autonomously without a clinician reviewing the underlying study. Autonomous diabetic retinopathy screening is the clearest example: the software issues the result, and the patient should know that.

Explicit consent belongs to research use, to any deployment where the tool is being evaluated rather than used as validated standard of care, and to secondary use of a patient's images for model development.

What a good disclosure actually says

Most disclosure attempts fail because they are written by legal teams to manage liability rather than by clinicians to inform a decision. A disclosure that works is four sentences and answers four questions.

What the software does, in one plain sentence. Whether a doctor reviews the result before it reaches the patient. What the tool is known to be weaker at, stated honestly, including the populations where performance data is thinner. And what the alternative is if the patient declines, which must be a real alternative rather than a delay designed to discourage the request.

The fourth point is where most operational plans collapse. A right to opt out is meaningless if the only fallback is a six week wait for a manual read. If a service cannot deliver the alternative, it should say so and treat the AI step as part of standard of care, disclosed but not optional. That is a defensible position. Offering a choice that does not exist is not.

Why this is a safety issue and not only an ethics issue

Two failure modes make consent practically important rather than philosophically interesting.

The first is automation bias. When a tool is accurate most of the time, human reviewers begin agreeing with it, including when it is wrong. A patient who knows AI was involved and reports a symptom that contradicts the report gives the clinician a reason to look again. Silence removes that check.

The second is performance drift across populations. Diagnostic models perform differently across skin tones, body habitus, scanner vendors and demographic groups that were thinly represented in training data. Patients who fall outside the well represented middle have the strongest interest in knowing an automated read was used, and the least likelihood of being told under current practice.

There is also a documentation argument that health systems will care about even if the ethics do not move them. When an AI assisted diagnosis is later questioned, the record showing what tool was used, what version, and whether the patient was informed is the difference between a defensible clinical decision and an unexplained one.

What health systems should build now

Three things, none of them expensive.

Maintain an internal register of every diagnostic AI tool in clinical use, with the version, the indication, the validation data and the disclosure category assigned to it. Most organisations cannot currently produce this list, which is itself a finding.

Record AI involvement in the report, not in a separate policy document. A single standard line naming the tool and its role makes the information portable, auditable and visible to the next clinician.

Train the people who take the questions. The patient will not ask the radiologist. They will ask the technologist, the receptionist or their family doctor, and those people need two or three accurate sentences rather than an apology for not knowing.

Key signals

The consent gap in diagnostic AI is closing whether health systems lead it or not, and the organisations that write their own disclosure standard now will not be retrofitting one under regulatory pressure later. The workable test is clinical consequence: disclose when the tool changes what happens to the patient, stay quiet about the plumbing, and require explicit consent for anything experimental or for secondary use of patient images. Never offer an opt out the service cannot actually honour, because a fictional alternative damages trust more than a candid statement that the automated step is standard of care. And treat the tool register and the report level notation as safety infrastructure, since both become the evidence base the first time an AI assisted diagnosis is challenged.