Picture the scene: an artificial intelligence system analyzes the medical record of a patient with cancer and suggests a treatment protocol. The recommendation seems reliable — after all, the promise of the technology is precisely to help doctors make faster, more accurate decisions.
But during internal testing of IBM’s Watson for Oncology, the tool produced suggestions considered inappropriate and potentially dangerous had they been applied to a real patient, including recommendations inconsistent with good medical practice.
The episode raised a question that is simple to ask but complex to answer: if an AI tool suggests something wrong during a medical encounter, and that harms a patient, who will be held liable for the error?
In February of this year, Brazil’s Federal Council of Medicine (CFM) established new rules to tackle this challenge. CFM Resolution No. 2,454/2026 regulates the use of AI in medical practice and makes clear, right from the start, that the tool supports clinical decision-making but does not replace it. In other words, the physician remains ultimately responsible.
In practice, the resolution also requires that the use of AI systems as decision support be recorded in the medical record, and it guarantees patients the right to information and the right to refuse. However, turning this principle into reality involves challenges that go far beyond the rule itself.
To understand what this regulation actually resolves — and what remains open — Prime Health Report spoke with the person who drafted the resolution and with someone who studies, from a legal-practice perspective, what happens when it is put to the test.
What does the law say about liability when an AI gets it wrong?
Attorney Rafaella Nogaroli — a legal opinion writer in medical and health law and author of the book Responsabilidade Civil Médica e Inteligência Artificial (Medical Civil Liability and Artificial Intelligence) — sums up the spirit of the resolution directly: the physician remains fully responsible, even when AI is involved.
But that does not automatically mean being liable for any technological error.
“The resolution itself protects professionals against undue liability when the failure is attributable exclusively to the system and they acted with diligence, critical judgment and sound technical reasoning,” explains Nogaroli, who holds a master’s degree in law from the Universidade Federal do Paraná (UFPR).
In practice, the resolution’s guidelines are not confined to the medical sphere. They also come to serve as a reference in the courts, helping define what is — or is not — diligent conduct in the use of AI.
Because determining medical error depends on expert examination, decisions by the Councils of Medicine frequently enter lawsuits as a benchmark, even though they are not binding on the judge. “It should be no different in future cases involving artificial intelligence,” the attorney says.
This alignment follows a global trend. According to Nogaroli, international bodies such as the World Health Organization and France’s High Authority for Health argue that AI should expand the physician’s capabilities, not replace their judgment.
The effect is almost counterintuitive — instead of easing the burden, the technology reinforces long-standing duties. Vigilance, keeping up to date, documentation. And “keeping up to date” now also includes knowing the capabilities, limitations and biases of the tools used day to day.
Is there a precedent from a real case that has already tested this liability in court?
In Brazil, Nogaroli says, there are not yet any court decisions directly addressing medical liability in cases involving AI. But with the growing use of the technology and the well-known “Brazilian litigiousness,” she believes that should change soon.
In the US, the case Sampson v. HeartWise Health Systems (2023) became emblematic. At age 29, Joshua Sampson underwent preventive testing after his father died of a hereditary heart disease. The screening software classified the results as “normal,” and the physician signed off on the report without considering his family history. A few weeks later, the young man died suddenly of hypertrophic cardiomyopathy.
The case never reached a final ruling: it ended in a confidential settlement before a judgment on the merits. Even so, for Nogaroli, the episode serves as a clear warning — the risk lies not only in the AI’s error but in turning an algorithmic recommendation into an automatic clinical conclusion.
While the Brazilian judiciary has yet to test this kind of case, a change in attitude is already beginning to show up in clinical routine. Jeancarlo Cavalcante, a federal councilor of the CFM and rapporteur of the resolution on AI, says the new rule had an immediate effect: greater caution in the use of these tools.
Day to day, this translates into small gestures. Faced with an AI-generated report, the physician goes back to the scan, reviews it point by point, cross-checks information —
as if slowing the process down to make sure nothing was missed. According to Cavalcante, this care has been especially visible in fields such as diagnostic imaging. “Human oversight has always been necessary in these cases,” the specialist tells PHR.
Do hospitals and technology companies share this responsibility?
For Nogaroli, liability does not rest solely with the physician — it tracks the degree of control each party has over the risk. The technology company is responsible for what falls within its purview: the system’s development, data quality, testing and clarity about its limitations.
On the side of health care institutions, the focus shifts: hospitals and clinics choose the tool carefully, ensure it makes sense for the population they serve, train their teams and monitor its performance over time. It is no coincidence that the resolution itself reinforces this by requiring risk assessment, governance and auditing — and even suggesting the creation of an AI and Telemedicine Committee at institutions with their own systems.
The physician, in turn, comes in at another point in the chain: clinical oversight is theirs. That means understanding the tool well enough to question its recommendations, check them against the specific case and, above all, document how they arrived at the final decision.
When something goes wrong, there is rarely a single cause. If the problem originates in a flawed algorithm, passes through weak governance and ends with uncritical use at the point of care, liability tends to be shared. “What is not acceptable,” Nogaroli sums up, is passing the buck — “the company to the hospital, the hospital to the physician and the physician to the machine.”
Cavalcante brings this issue of transparency down to the clinic floor, where the conversation really happens. Asked how he would explain to a patient the extent to which AI was involved in their care, he prefers to be direct: he says he would use a tool to make the process faster, but makes a point of stressing that everything goes through medical review before any decision is made.
In the end, the message is simple — “I would make it very clear that the tool served to speed up the process, not to replace it,” he concludes.
Does the CFM resolution settle this question, or does it merely formalize what was already expected?
For Cavalcante, the resolution does not invent a new responsibility — it simply takes what was implicit and puts it on paper. Something that already existed in practice now has clearer contours. “It served as a regulatory milestone and, consequently, as a differentiator in the way we use artificial intelligence in medicine,” he emphasizes.
Nogaroli agrees but offers an important refinement: the rule’s clarity does not simplify the problem — it only shifts where it lies. “Following or ignoring the AI’s suggestion, on its own, does not determine liability,” she says. In both cases, the central element will be the degree of care: questioning the result, checking it against the patient’s history, understanding the tool’s limitations.
This is where a point that is likely to carry ever more weight comes in: “the CFM resolution expressly requires physicians to record in the medical record the use of AI as decision support.” That record has to tell the whole story — which system was used, what it suggested, and why the physician accepted or rejected that recommendation.
Because, at the end of the day, the debate is no longer “who was right, the doctor or the machine?” but something else, far more decisive: “was the physician diligent in interacting with the artificial intelligence?” concludes the medical and health law opinion writer.