TL;DR: AI malpractice claims rose 14% from 2022 to 2024. Liability is distributed across AI developers (product defect), hospitals (negligent implementation), and physicians (over-reliance). California AB 2013 creates new training-data disclosure obligations effective January 2026. Following an AI recommendation is not a defense to malpractice.
When a diagnostic AI gets it wrong and a patient is harmed, the question of who pays is genuinely complicated. The answer depends on where the failure occurred: in the AI's training or design, in the hospital's implementation and oversight, or in the physician's failure to apply independent clinical judgment. In practice, all three may be defendants in the same case.
Malpractice claims involving AI tools rose 14% between 2022 and 2024, with the majority concentrated in radiology, cardiology, and oncology, the specialties where AI diagnostic tools have the highest penetration. The law has not caught up with the technology, but cases are accumulating and patterns are emerging.
The three liability zones
Zone 1: AI developer liability (product liability)
When the AI itself is defective, when it was designed or trained in a way that makes it unreasonably dangerous for its intended use, the AI developer faces product liability claims. Product liability in medical AI can arise from:
Defective design. A radiology AI trained primarily on imaging data from one demographic group that performs systematically worse on other groups may have a defective design if the disparity was foreseeable and the developer did not address it. California AB 2013, which took effect January 1, 2026, requires disclosure of training data composition, creating a documentary basis for plaintiffs to identify training data gaps.
Manufacturing defect. In software, manufacturing defects are rare in the traditional sense, but a model that was correctly specified but corrupted in deployment, through a failed update, data poisoning, or configuration error, could be analogized to a manufacturing defect.
Failure to warn. Even a well-designed AI has known limitations. A developer that markets an AI for a use case where known performance limitations apply, without disclosing those limitations in labeling and documentation, may face failure-to-warn claims. FDA's GMLP standards and PCCP requirements create an expectation that limitations be documented and communicated; failure to meet those standards strengthens failure-to-warn claims.
Inadequate instructions for use. Developers must provide clear guidance on the AI's intended use, contraindications, and the clinical context in which its performance was validated. An AI cleared for use in academic medical centers with fellowship-trained radiologists, deployed by a developer's own sales team in rural emergency departments without caveats, creates a use-outside-indication gap that generates both regulatory and product liability risk.
Zone 2: Hospital and health system liability (negligent deployment)
Hospitals and health systems are not passive conduits for AI tools, they select, configure, integrate, and monitor these tools in their clinical environments. Organizational liability for AI-related patient harm can arise from:
Negligent selection. Selecting an AI tool that was not validated for the patient population or clinical setting where it will be used. An AI radiology tool validated on adult imaging deployed without modification in a pediatric hospital may perform differently than the cleared indication warrants.
Negligent implementation. Deploying AI in a workflow that makes meaningful physician review impractical, for example, integrating an AI recommendation into a high-volume, time-pressured workflow where reviewers routinely do not have time to question the AI's output.
Inadequate training. Failing to train clinical staff on how to use AI outputs appropriately, what the AI's known limitations are, and under what circumstances they should override or question AI recommendations.
Failure to monitor. Not tracking AI performance in the clinical environment after deployment and not responding to signals that the AI is underperforming in the specific patient population. FDA's post-market surveillance requirements create an expectation that AI device performance is monitored, hospitals that contract with vendors should be receiving performance reports.
Failure to respond to known problems. If a hospital receives reports from clinical staff that an AI tool is generating incorrect recommendations, and fails to investigate and remediate, liability for subsequent harms will be harder to defend.
Zone 3: Physician liability (failure to exercise independent judgment)
Physician liability in AI-assisted care turns on the standard of care, what a reasonable physician in the same specialty and circumstances would have done.
The foundational principle: "the AI said so" is not a standard of care defense. Physicians are expected to apply clinical judgment to AI recommendations, not defer to them. A physician who accepts an AI diagnostic recommendation without considering whether it is consistent with the patient's clinical presentation, history, and other findings may be liable for over-reliance if that recommendation was clinically questionable.
Courts are beginning to grapple with what independent clinical judgment means in an AI-assisted context. Some emerging principles:
Volume and tempo matter. A physician reviewing 200 AI-flagged chest X-rays in a shift has less time per case than one reviewing 50. If workflow design means that AI-assisted review has become rubber-stamp review, both the physician and the institution may face liability when errors occur.
Transparency of reasoning affects the duty. If the AI provides transparent reasoning, showing which image features drove the recommendation, a physician reviewing that reasoning has more basis to validate or question it. If the AI is a black box, the physician's ability to exercise independent judgment is limited, and that limitation does not transfer the full burden back to the physician. It may instead shift it toward the developer and deploying institution.
Off-label use increases physician risk. Using an AI diagnostic tool outside its FDA-cleared indication, a common occurrence as clinicians find new applications, increases physician liability because the physician cannot point to a validated performance claim for the use in question.
California AB 2013 and the evidence trail
California Assembly Bill 2013, effective January 1, 2026, requires AI developers to publish documentation about their training data, including the types of data used to train the AI, the sources of the data, and the intended use cases. For healthcare AI, this creates a paper trail that plaintiffs can use in discovery.
In a malpractice case involving an AI diagnostic error, plaintiffs can now use AB 2013 disclosures to establish:
- Whether the AI was trained on data similar to the patient population where it was deployed
- Whether the intended use described by the developer matches the use in the clinical setting
- Whether the developer identified limitations relevant to the patient's demographics or condition
AB 2013 applies to AI systems used in consequential decisions in California. Legal analysts expect similar legislation in other states, and in some cases in federal sector-specific guidance. The disclosure infrastructure created by state law is likely to become standard in AI developer practice regardless of where a case is brought.
What governance reduces liability exposure
Healthcare organizations cannot eliminate AI liability risk, but they can make defensible decisions that reduce exposure and demonstrate appropriate care.
Document the selection process. Record why an AI tool was selected, what alternatives were considered, and what performance validation data the organization reviewed before deployment. A documented, rational selection process is significantly easier to defend than an unrecorded decision.
Train and document. Provide clinical staff with training on the specific AI tool: its intended use, its known limitations, the population on which it was validated, and what circumstances should trigger skepticism. Document who received training and when. Update training when vendors release information about performance issues.
Define the human review requirement. Your AI governance policy should specify what a physician is expected to do when reviewing an AI recommendation, not just that review is required, but what information the reviewer should consider. See clinical AI decision support governance requirements for FDA's framework on substantive vs. procedural review.
Track override rates and adverse events. If AI recommendations are never overridden, that is not necessarily good news, it may indicate rubber-stamp review. Track override rates by physician, by AI tool, and by clinical context. Establish a process for clinical staff to report cases where AI performance was questionable.
Require vendors to provide post-market performance data. Your AI vendor due diligence process should include a requirement that vendors provide ongoing performance data for your patient population. An AI tool performing at its cleared benchmarks in an academic center may perform differently in your specific setting.
Review BAAs and vendor indemnification. Your contracts with AI diagnostic tool vendors should address indemnification for claims arising from product defects. If the vendor's BAA or service agreement excludes indemnification for clinical performance claims, that exclusion should be negotiated or your risk management team should account for it in coverage decisions.
For the broader framework on AI liability in multi-party AI systems, agentic AI liability covers how courts are approaching liability when multiple AI systems contribute to an outcome.
The informed consent dimension
One area where AI malpractice law is still unsettled is informed consent. Standard medical informed consent requires physicians to disclose material risks of a recommended procedure or treatment and alternatives. When AI is used to diagnose or recommend treatment, a separate question arises: does the patient have a right to know that AI was involved in the clinical decision, and does a failure to disclose constitute a breach of the informed consent duty?
No court has yet held that AI use in clinical decision-making creates a standalone informed consent obligation, but the legal analysis points in that direction for at least two reasons. First, patients who knew AI was involved might reasonably ask different questions, seek second opinions, or decline certain recommendations, meaning the information is arguably "material" under the objective patient standard. Second, several state legislatures are actively considering AI transparency laws for medical contexts that would codify disclosure requirements for clinical AI.
Healthcare organizations operating in jurisdictions considering clinical AI transparency legislation should track those bills and assess their consent documentation practices now. Adding a general disclosure that AI tools may be used in clinical workflows to standard consent forms, and documenting the specific AI systems used for each patient encounter in the chart, creates a defensible baseline regardless of how the law develops. The cost of adding that documentation is low; the benefit in managing liability exposure if disclosure becomes legally required is significant. A single sentence in the standard consent form, reviewed by legal counsel, is the minimum viable approach for organizations not yet ready for a full clinical AI disclosure policy.
Related Reading
- Midjourney's scanner: what FDA SaMD clearance actually requires
- HIPAA and AI vendor BAA requirements 2026
- FDA AI medical device SaMD compliance guide 2026
- Clinical AI decision support: FDA January 2026 guidance explained
- AI governance for healthcare startups: HIPAA, FDA, and vendor risk
- Agentic AI liability: who is responsible when autonomous AI causes harm
