Informed Consent in the Age of Clinical AI

Beyond the One-Time Authorization Model

Author

Marina Hovhannisyan, and J. Wesley Boyd, MD, PhD

Publish date

Informed Consent in the Age of Clinical AI: Beyond the One-Time Authorization Model
Topic(s): Artificial Intelligence Clinical Ethics Editorial-AJOB Ethics

This editorial appears in the September Issue of the American Journal of Bioethics

Artificial intelligence (AI) is increasingly embedded in all aspects of clinical care, shaping how clinical information is gathered, notes are produced, and judgments are formed—often invisibly, and rarely disclosed to patients. Where disclosure does occur, it is typically procedural—a checkbox or boilerplate acknowledgment—rather than a substantive communication that informs deliberation and supports autonomous choice.

Informed consent is the legal and ethical architecture undergirding the doctor-patient relationship and is the mechanism through which autonomy is recognized and protected. The foundational assumptions of the informed consent doctrine are historically built around interventions that are bounded and stable at the moment of authorization, with a relatively fixed risk-benefit profile and a temporally discrete authorization at a specific point of care. Standard informed consent doctrine also presupposes that a clinician can describe a proposed intervention with sufficient clarity so that patients can understand it well enough to choose freely and deliberately. With the introduction of AI into the doctor-patient encounter, that presupposition is now imperiled.

We believe that genuine informed consent in AI-mediated clinical care is highly difficult for two reasons. The first is invisibility: AI is often embedded in the ambient clinical infrastructure in ways that are largely unavoidable and unseen by patients. The second is dynamism. Clinical AI systems are subject to model updates, recalibration, and expanded deployment, such that the AI employed at an initial medical encounter might bear little or no meaningful relationship to the AI a patient is subsequently exposed to. In response, herein we argue that in the era of clinical AI, the one-time authorization model for informed consent is no longer ethically defensible and that going forward health systems should instead implement a redesigned continuous, two-pronged consent architecture built around two coordinating principles: visibility and temporality.

INVISIBILITY: AI AS AMBIENT CLINICAL INFRASTRUCTURE

The invisibility problem arises when AI shifts from an optional decision-support to infrastructure embedded at the institutional level. Such embedding spans scheduling, triage, risk scoring, documentation, and language translation. This transforms the moral stakes: patient exposure to AI is no longer a discrete, traceable event but something ambient, passive, and often unavoidable.

Ambient AI scribing systems exemplify this form of infrastructural invisibility, given that they often operate in the background of clinical encounters and capture conversations, perhaps unbeknownst to patients. Even when disclosure is provided, clinicians might be ill-equipped to inform patients about all of the potential negative ramifications of having AI serving as a scribe to their encounter. Moreover, if clinicians are able to inform patients, patients typically are unable to opt out of AI in their clinical encounters without risking disruption to their own care. Furthermore, ambient scribes are frequently retrained on accumulating clinical data and updated post-deployment, such that their outputs increasingly shape clinical documentation, billing, and downstream medical decision-making over time.

When meaningful opt-out options are not available, patients may face soft coercion to accept the use of AI, driven by concern about losing access to care. One significant risk posed by this invisibility is the potential compromise of patient confidentiality. Sensitive health data may be exposed to systems whose cybersecurity protections are not equipped to keep pace with rapidly advancing computing power. This raises a fundamental concern: at what point does the pervasiveness of AI transform informed consent from a mechanism of genuine patient agency into a largely symbolic administrative hurdle?

DYNAMISM: LIFECYCLE AI AND THE TEMPORAL BREAKDOWN OF CONSENT

Clinical AI is defined by temporal instability: it is a dynamic, evolving sociotechnical system, subject to continuous change in ways that no single moment of consent can capture. Change over time is an intended feature of many AI deployments, allowing for fine-tuning and recalibration that alters performance characteristics, error distributions, and clinical behavior. These changes occur post-consent and almost always without patient awareness (see Figure 1).

Figure 1. Medical AI system transformation.Show detailed figure description

Five stages of medical AI transformation, progressing from a simple, transparent interface to complex, opaque systems that leave patients without meaningful awareness of AI’s role in their care.Display full size

AI-mediated mental health tools that are currently employed provide a particularly clear example of this temporal instability. These systems adapt their response strategies and intervention styles through model updates and ongoing optimization. However, despite their ever-evolving nature, informed consent is still generally offered at the point of initial use, with no mechanism to alter or update consent over time.

Clinical AI systems change in at least four distinct ways: model dynamism, contextual dynamism, relational dynamism, and normative dynamism (see Figure 2). They are described as follows:

Figure 2. Four types of dynamism.Show detailed figure description

Diagram showing four dynamism types: Model, Contextual, Relational, and Normative, each with icons and labels.Display full size

Model dynamism refers to the continuous fine-tuning of clinical decision support tools, which can introduce new error modes, biases, or failure conditions over time. Because valid informed consent requires that a patient authorize a specific intervention with known characteristics, each substantive update to a deployed system effectively changes what was consented to, altering the system’s underlying reasoning, risk calibration, and failure profile.

Contextual dynamism refers to shifts in environmental and population-level deployment, where changes in patient demographics, disease prevalence, or clinical setting can alter model validity and safety. As such, consent given in one deployment context may not meaningfully extend to another.

Relational dynamism describes the change in the clinician-AI relationship over time, given that the clinician’s use of and trust in AI outputs can, and likely will, evolve over time.

Normative dynamism describes how institutional norms and professional guidelines about the use of AI in clinical encounters may change over time, likely increasingly incorporating AI outputs as default practice, pressuring patients and clinicians into AI-mediated care without explicit re-consent.

Each form of dynamism can reshape the meaning of initial consent, such that even when the original disclosure was thorough and procedurally sound, subsequent changes in AI systems may render that consent ethically inadequate. Taken together, these forms of dynamism mean that the consent obtained at one point in time often no longer accurately describes the intervention patients might receive later. If we ignore this reality, informed consent becomes little more than a legal fiction rather than a truly ethical practice.

LIMITS OF CURRENT RESPONSES

Although certain aspects of AI operate as a “black box,” merely disclosing this fact is insufficient to render patients truly informed. The broad consensus across the bioethics community is that explaining AI models does not reliably translate into patient comprehension of how AI meaningfully shapes their care. Consent-relevant understanding should focus on the role AI plays in decision-making, how its output is used by clinicians, what kinds of errors it is known to make, and what alternatives the patient has. Regarding dynamism, researchers routinely reference adaptive systems, model updates, continuous improvement pipelines, and empirical drift in real-world performance. However, the literature seldom specifies concrete thresholds for when technical change becomes ethically significant enough to require renewed disclosure.

Researchers have found that patients’ expectations of disclosure are not tied to a technical understanding of how AI works, but rather to disclosure of when AI meaningfully shapes diagnosis, prognosis, triage, or treatment recommendations. Patients also draw a distinction between notification and consent: being informed that AI is being used is not the same as being asked for permission to use it. For example, a patient may agree to AI being used to help schedule appointments but may wish to opt out when AI is being employed to render a cancer diagnosis—wanting notification in both settings, but formal consent only in the latter. Additionally, patients want to know who can view, store, analyze, sell, or repurpose their conversational and clinical data, centering their concerns on governance, power, and downstream use.

These concerns indicate that informed consent for AI must include disclosure about data flows, retention, access, and secondary uses. Patient values are oriented toward control, dignity, and informational autonomy rather than technical interpretability of the underlying model.

REGULATORY CONTEXT AND SHORTCOMINGS

Major regulatory bodies already impose meaningful transparency, safety, and governance requirements on clinical AI. These entities prioritize regulatory compliance over meaningful patient consent—a gap that is particularly pronounced in the context of dynamic AI systems.

AI transparency requirements are largely upstream and institutional rather than patient-facing, even though regulatory frameworks already conceptualize AI as dynamic and lifecycle based, requiring ongoing monitoring, post-market updates, and recalibration. But even with this recognition at the regulatory level, clinical consent is still treated as a one-time event at the point of initial deployment.

This produces a decoupling of institutional accountability: AI systems may be fully compliant with regulatory transparency requirements while patient-facing informed consent remains shallow, outdated, or absent. Moreover, even where procedural compliance is achieved in clinical settings, it does little to produce actual patient understanding, deliberation, or agency, rendering such compliance functionally meaningless in AI-mediated care.

REDESIGNING CONSENT: A TWO-PRONGED ARCHITECTURE FOR CLINICAL AI

To bring informed consent into the AI era, we argue that a new model is necessary, one that includes continuous, iterative consent, treating it as an ongoing relationship between patient and institution, evolving in response to meaningful changes in the system in use. Importantly, implementing this new model of consent cannot be left to individual clinicians; instead, hospital systems and health care organizations should be responsible for designing, implementing, and maintaining consent practices that embody these two prongs.

This reframing entails three concrete normative commitments. First, substantive model updates—those that materially alter risk distribution, error profiles, or decisional authority—should trigger a new consent process, on par with a new clinical intervention. Second, consent should focus on the AI’s role in clinical decision-making—how it shapes care—while model iteration remains a secondary, auditable factor. And third, when new risks or biases are identified in a deployed system, institutions bear an affirmative obligation to notify affected patients and offer them a meaningful opportunity to revisit their consent.

To carry this out, we propose a two-pronged framework to address both invisibility and dynamism:

Prong 1: Decision Architecture Visibility targets the moment of care and requires that patients be informed (1) that an AI system is involved in clinical decision-making; (2) what functional role it plays; and (3) whether the AI output is subject to clinician review or operates with effective autonomy in the workflow.

Prong 2: Post-Encounter Data Governance operates downstream, given that consent ought to be treated as a continuous obligation over time. It requires separate, explicit disclosure covering (1) whether patient data will be retained beyond the encounter; (2) whether it may be used for model training or secondary analysis; and (3) which third-party vendors, if any, have access to the data, no matter whether those data are de-identified or not.

The importance of maintaining the separation between these two prongs is nicely illustrated in the case of ambient clinical scribing. For example, a patient may reasonably accept AI-assisted documentation during a visit while objecting to indefinite storage of that conversational data, its use in future training sets, or its transmission to an external vendor. Collapsing these two prongs into a single consent moment does not do justice to choices that patients should be entitled to make independently. In addition, we believe that re-disclosure ought to be required if and when any of the following occur (see Figure 3

):

Figure 3. Triggers for updated consent.Show detailed figure description

Circular flowchart showing "Patient," "Healthcare System," "Patient Alert," and "AI Model Update," connected by arrows.Display full size

Material changes in model performance: a significant shift in sensitivity, specificity, or calibration in a clinically relevant subgroup – for example, a diagnostic algorithm whose false-negative rate increases substantially in an older patient cohort after retraining.

Expanded scope of deployment: use of a model beyond the population or clinical context for which it was validated – for example, applying an imaging model validated on adult patients to pediatric populations.

Shifts in decisional authority: a change in AI functional role in the care workflow – for example, a transition from a model requiring active clinician override to one in which AI output is accepted by default unless a clinician intervenes.

These triggers are necessary in order to prevent the silent erosion of consent as systems evolve beyond what patients originally authorized. Patients should have the right to decline AI-mediated care where clinically feasible, without penalty in terms of access to care or quality of care. If opting out leads to longer wait times, reduced access, or lower diagnostic support, the choice is not truly voluntary.

CONCLUSION

In conclusion, informed consent for clinical AI will fail unless it is designed to make AI both visible and responsive to changes over time. When AI is embedded in clinical infrastructure without disclosure, patients cannot form meaningful awareness of how AI might be influencing their care. At the same time, because AI systems continue to evolve after initial disclosure, patients are inevitably exposed to a different intervention than the one to which they originally agreed. The two-tier consent architecture we propose—built around tiered patient rights and temporal triggers—recasts informed consent as an implementable design obligation for medical institutions, regulators, and health systems. The responsibility to implement these consent systems should rest primarily with those institutions and regulators, not with individual clinicians who generally lack control over AI deployment and infrastructure. Such a redesign would allow institutions to respect patient autonomy while enabling patients to benefit from clinical AI in ways that they have genuinely authorized.

Given that AI-mediated care is here to stay, the changes we are advocating for are not optional; instead, they are essential if patients are to be truly informed about their medical care going forward.

Marina Hovhannisyan, and J. Wesley Boyd, MD, PhD

We use cookies to improve your website experience. To learn about our use of cookies and how you can manage your cookie settings, please see our Privacy Policy. By closing this message, you are consenting to our use of cookies.