Accountability cannot end at launch
A medicine is not considered permanently safe just because it passed one trial. Side effects are tracked after approval; new evidence is reviewed; and action can be taken when harm emerges. AI needs the same culture of vigilance.
That is particularly important because an AI system can become less reliable even when the software appears unchanged. The population may shift, clinical practice may evolve, sensors may be updated or incoming data may no longer resemble the information used to train the model. This “drift” can gradually reduce performance and may affect some groups more severely than others.
This ongoing duty is known as lifecycle accountability. Once an AI system is in use, its recommendations, errors and adverse events should be recorded and audited. Serious failures should be investigated, with clear authority to modify, suspend or withdraw the system when necessary.
Regulators are beginning to adopt this lifecycle view. WHO’s regulatory considerations call for health AI to be well-documented, independently tested, and governed through shared responsibility across the healthcare system.
For healthcare organisations, buying an AI product should mark the start of governance, not its conclusion. Every deployment needs named owners, agreed monitoring measures, regular reviews, incident reporting, update procedures and a clear point at which use will be stopped.
Make responsibility impossible to dodge
When AI contributes to a harmful decision, responsibility can quickly become blurred. The developer points to the clinician, the clinician points to the software, and the health system points to regulatory approval. That circle of blame is not accountability.
Healthcare professionals using AI-supported recommendations must retain responsibility for clinical decisions, particularly while the limits of these systems remain poorly understood. But responsibility is also shared among developers, health services, regulators, policymakers and users. Shared responsibility must not become “nobody’s responsibility”.
The duties of each group need to be explicit. A clinician may answer for an individual care decision but cannot reasonably be expected to uncover a concealed flaw in training data or track model drift across an entire health service. Developers must demonstrate performance and disclose limitations. Health services must assess local suitability, train staff, and monitor use. Regulators must set enforceable rules. Policymakers must provide routes for redress and prevent commercial secrecy from obstructing safety scrutiny.
AI literacy is part of this bargain. Healthcare professionals do not need to become software engineers, but they do need to understand a system’s intended use, data limitations, common failure modes and uncertainty – and know when to reject or escalate an output. People living with diabetes deserve equally clear information about when AI is being used, what data it processes and how they can question a recommendation.