Analysis / 001

Agentic AI in Clinical Medicine Is a Control Problem, Not a Demo Problem

Agentic AI in medicine fails or succeeds at the handoff points, where plans become orders, and orders become patient care. The right question is not whether the agent sounds smart, but whether the hospital can constrain, audit, and reverse its actions.

Author

Dr. Sina Bari, MD

Physician-Technologist | Healthcare AI Executive | Stanford Medicine

Published

October 2, 2026

Reviewed

October 2, 2026

Last Tuesday, a nurse manager showed me a vendor demo that looked polished until the second step. The agent could summarize a chart in seconds, but when it was asked to route a follow-up task into the actual workflow, it stalled, guessed at the order of operations, and created three messages no one had authorized. I remember thinking that the room got quiet in a way that only happens when clinicians realize the software is more confident than it is competent.

Agentic AI in clinical medicine should be treated as a controlled workflow layer, not an autonomous clinician. The safest deployments are those that constrain tool use, require human approval at high-stakes steps, and preserve audit trails, because the clinical failure mode is usually not bad language, it is bad action.

I used to think the central question was whether agentic AI could think well enough to help doctors. Then I watched how easily a model could drift from summarizing to deciding, and how quickly a small permission mistake could become a clinical workflow problem. Now I think the real question is narrower and more practical: can we cage the agent, log every move, and still make it useful enough to matter?

What agentic AI changes inside a hospital

Agentic AI is different from a passive chatbot because it does more than answer a question. It can plan steps, call tools, query records, draft messages, trigger queue actions, and loop back when the first attempt fails. In a hospital, that means the unit of risk is no longer the sentence. It is the sequence of actions that follows the sentence.

That matters because hospitals are already full of fragile handoffs. A model that writes a brilliant discharge summary but cannot distinguish between a draft and a signed instruction is a liability, not an assistant. In my experience, the most dangerous demos are the ones that look least dangerous, because they hide their error until the workflow catches fire two steps later.

The current literature points in the same direction. The paper Caging the Agents: A Zero Trust Security Architecture for Autonomous AI in Healthcare argues for zero-trust controls around autonomous systems, which is exactly the posture I want when a model can touch clinical tools. The companion idea in Model Medicine: A Clinical Framework for Understanding, Diagnosing, and Treating AI Models is also useful, because it treats model failures like clinical problems, with symptoms, differential diagnosis, and treatment rather than vibes.

That framing fits how I brief a hospital board. I do not ask whether the model is impressive. I ask what it can access, what it can change, who reviews it, and how we know when it has gone off-script. If the answer to any of those questions is vague, the deployment is premature.

Where I draw the line

What I would not do is let an autonomous agent place an order, message a patient, or alter a chart without a clinician in the loop. I would not accept “the model recommended it” as a control. I would not allow tool access to outrun policy. In a clinical environment, convenience is not a safety plan.

The best evidence for that caution comes from studies that show benefit depends on governance, not just model output. In the NEJM 2023 in-hospital deterioration work, when AI alerts were paired with a clinical response, 30-day mortality after the alert threshold fell by 3.8 percentage points, with an adjusted relative risk of 0.84 and about 3.0 deaths avoided per 1,000 eligible patients. The takeaway is blunt: the alert helped because people acted on it. The model alone did nothing useful.

The same logic appears in the WHO European Region survey on AI for health, which covered 53 Member States and received 50 responses, a 94% response rate. It found that only 25 of 50 countries, or 50%, had a health data governance framework in place. That is the bottleneck I worry about most. Not model ambition. Governance maturity.

For hospitals, the relevant regulatory map still runs through familiar pathways. FDA oversight for AI-enabled software is still anchored in the device world, including 510(k), De Novo, and PMA routes when submission is required. NIST’s AI Risk Management Framework gives a practical structure, especially its Govern, Map, Measure, and Manage functions. Those are the words I want on the wall before anyone says “pilot.”

What actually makes an agent clinically trustworthy

The strongest 2026 papers are converging on the same answer: trustworthy clinical agents need constraints, not just capability. The survey Towards trustworthy agentic AI: a comprehensive survey of safety, robustness, privacy, and system security treats trustworthiness as an engineering discipline. The point is obvious once you have seen one bad workflow integration. Security, privacy, and robustness are not separate add-ons. They are the product.

I also pay attention to the human-cognition side. Grounding Clinical AI Competency in Human Cognition Through the Clinical World Model and Skill-Mix Framework matters because clinicians do not work as isolated prompt responders. We use context, pattern recognition, interruption management, and a sense of what should never happen. An agent that cannot model that skill mix will miss the kind of error that a tired resident catches in one glance.

A concrete failure mode I have seen is mundane and ugly. The model drafts a follow-up plan that looks clinically correct, but it sends the wrong task to the wrong inbox because the routing logic treats a chart label as a destination. Nobody notices until the patient calls two days later. These are not dramatic sci-fi failures. They are clerical errors with clinical consequences.

That is why the most credible health systems are moving toward human-guided agentic AI rather than free-running autonomy. The paper on Human-Guided Agentic AI for Multimodal Clinical Prediction: Lessons from the AgentDS Healthcare Benchmark supports that direction. In plain English, the better system is the one that knows when to ask for help.

My self-correction as a clinician-executive

I used to believe that if a model could outperform a junior clinician on a narrow task, the next step was to automate that task. Then I spent enough time around real workflows to see how often the task itself was the wrong atomic unit. Medicine is not a checklist business. It is a chain of judgment calls under uncertainty, and the chain breaks where context is stripped out.

That changed how I read the newer agentic systems. When I review a vendor proposal now, I ask a boring set of questions that save lives: Can the agent be sandboxed? Can every tool call be logged? Can permissions be scoped by role and encounter type? Can we reproduce the exact chain of actions after an adverse event? If the answer is no, the project is not ready for the hospital.

I have also become more skeptical of language that treats autonomy as a virtue in itself. Autonomy is only valuable when the system is accountable, reversible, and clinically bounded. Otherwise it is just a faster way to make a mistake.

What this means for regulation and governance

The regulatory conversation is catching up, but slowly. A useful reading of the FDA and NIST material is that clinical agentic AI should be governed as a dynamic risk system, not a static software package. For hospitals, that means pre-deployment review, ongoing monitoring, clear ownership, and a kill switch that actually works. It also means making the vendor prove what happens when the agent is confused, attacked, or denied access to a tool.

That is where zero trust becomes more than a cybersecurity slogan. In an autonomous clinical environment, every tool request deserves verification. Every privilege should be temporary. Every output should be attributable. The paper on vendor-neutral multitenant retrieval and tool use, Securing the Agent: Vendor-Neutral, Multitenant Enterprise Retrieval and Tool Use, is relevant because hospitals are not single-system toy environments. They are crowded, legacy, permissioned, and noisy.

From the physician-executive seat, I see the governance bar as very simple. If a tool touches care, it needs clinical ownership, security ownership, and operational ownership. If it cannot be monitored in real time, it does not belong in production. If it cannot be rolled back, it does not belong near patients.

How I think about the next year

I think the winners in clinical AI will not be the loudest systems. They will be the ones that earn the narrow right to act. That may sound modest, but it is how medicine has always scaled safely. We do not give every useful tool unlimited authority. We constrain it, observe it, and expand its role only after it proves it can be trusted.

That is also why I am more interested in agentic AI for operational medicine than for headline-grabbing clinical autonomy. A system that helps reconcile records, triage inboxes, draft prior-auth packets, or surface missing data can relieve real burden if it stays inside the rails. The same system becomes dangerous the moment it starts pretending it knows more than the clinician who owns the case.

So yes, I am optimistic. But my optimism has become conditional, procedural, and maybe a little boring. That is a good thing.

Back in the conference room

After the vendor demo, the nurse manager looked at me and said, “So what do we actually buy, if not the magic?” I told her the truth: we buy constrained usefulness. We buy a system that can help without improvising authority. We buy auditability, not theater.

That is where I have landed. Agentic AI in clinical medicine is not a race to maximum autonomy. It is a discipline of permission, provenance, and proof. Build that well, and the agent can help. Skip it, and the hospital is just hosting a very expensive error generator.

FAQ

What happens if a hospital deploys an AI agent without clinician oversight?

The most common failure is not a dramatic hallucination, it is an unreviewed action that lands in the wrong workflow. A model can draft, route, or trigger tasks faster than people can catch the mistake, which means the harm may show up as delays, duplicate work, or a missed follow-up. The safer standard is clinician approval for any step that changes care.

How does Dr. Sina Bari approach agentic AI in the hospital?

Dr. Sina Bari’s approach is to constrain the agent before expanding its scope. That means tight permissions, full logging, clear clinical ownership, and a hard stop if the system cannot explain its action chain. The goal is utility with accountability, not autonomy for its own sake.

What is the biggest governance mistake hospitals make with agentic AI?

They treat the model like a software demo instead of a clinical actor with permissions. If governance is added after deployment, the organization usually discovers the hard parts only after the first near miss. The better path is to define scope, review, audit, and rollback before go-live.

Why do zero-trust controls matter for clinical AI agents?

Because tool access is where agentic systems become real-world actors. Zero trust forces every request, permission, and data access to be verified instead of assumed, which reduces the chance that one bad prompt or one compromised session can affect patient care. In practice, that is how you keep a smart system from becoming an unsafe one.

Can agentic AI safely reduce clinician workload?

Yes, but only in bounded tasks with clear review points. The best targets are documentation support, inbox triage, data gathering, and administrative routing, where the agent can save time without making final clinical decisions. Once the system starts acting on treatment or communication without review, the risk rises fast.