
AI in your medical practice: who's liable when something goes wrong?
Medical practices have adopted artificial intelligence quickly, particularly through the use of AI scribes. These tools promise to improve efficiency and reduce the time spent preparing clinical notes, helping both practitioners and practice teams.
However, rapid adoption has meant that laws and regulatory guidance have continued to evolve. One question comes up repeatedly: who is responsible when something goes wrong?
General legal considerations
When practitioners use an AI tool purely as a scribe, the position is relatively straightforward. They remain responsible for reviewing the output and ensuring the patient’s medical records are accurate and complete. Using an AI scribe does not transfer that professional responsibility to the technology provider.
This distinction matters because AI tools that are regulated as medical devices (i.e. Software as a Medical Device or SaMD) have safety requirements for obtaining approval to be supplied in Australia and registered on the Australian Register of Therapeutic Goods.
AI tools in general also have other safety obligations that apply under the general law for product liability, in addition to other statutory requirements under the Australian Consumer Law. Thus, the AI technology provider or manufacturer may be liable if the tool is defective, does not perform as promised or fails to meet its regulatory obligations.
However, the focus of this article is about a practitioner’s professional responsibility with respect to using AI tools for treatment purposes. The discussion below relates to AI used in clinical decision-making and treatment. Administrative AI tools, such as AI medical reception, raise different legal and operational considerations and are outside the scope of this article.
A practitioner's liability
The legal position for a practitioner's liability becomes more complicated when the AI tool moves beyond documenting the consultation and is used for treatment purposes, including diagnosis, prognosis and treatment options.
If a TGA-regulated AI tool contributes to patient harm, more than one party may be responsible. A practitioner may be liable if they rely on the tool without applying appropriate clinical judgement, fail to follow its instructions or use it outside its intended purpose.
A practice may also be liable. This may include vicarious liability for the actions of an employed practitioner, as well as liability arising from inadequate policies, training, supervision or systems for managing AI.
While the practitioner remains accountable for how they use AI in patient care, they may not be the only party who may be liable, depending on the circumstances.
Privacy adds another layer
Privacy and cybersecurity risks apply whenever AI is used, whether it’s an AI scribe or a tool that supports clinical decisions.
If patient information is exposed, misused or accessed without permission, responsibility will depend on what happened and who caused or contributed to the breach. This may include the practitioner, the practice, the AI supplier or a combination of them. Contractual arrangements with the AI supplier may also affect where responsibility and risk sit.
This is not always straightforward. Clinical liability and privacy are just two of the risks practices and practitioners need to consider when adopting AI.
What are the five key risks?
When introducing AI into a medical practice, it's important to consider more than whether the tool works as expected. You also need to understand the risks it may create for practitioners, the practice and the contractual arrangements that support its use.
The five key risk areas are:
- Professional misconduct: A practitioner may breach Ahpra's Code of Conduct if they rely on an AI output without applying appropriate clinical judgement. This remains the case even if the tool is included in the Australian Register of Therapeutic Goods.
- Professional negligence: A practitioner may face a negligence claim if their use of AI falls below the expected standard of care and causes patient harm. This could include relying too heavily on an incorrect output, failing to verify it or using the tool outside its intended purpose.
- Practice liability: A practice may also face liability for the way AI is used, particularly where practitioners are employees. The practice's policies, training, supervision and governance arrangements may all be relevant if something goes wrong.
- Privacy and cybersecurity breaches: Practices and practitioners must protect any personal information entered into or processed by an AI tool. If a breach occurs, responsibility may rest with the practice, the practitioner, the AI supplier or more than one party. From 10 December 2026, privacy policies must also explain when personal information is used in automated decision-making.
- Contracts and indemnity clauses: Contracts can shift significant risk. This includes agreements between practices and practitioners, as well as contracts with AI suppliers. Supplier agreements may contain broad indemnity clauses, liability limits or exclusions that seek to protect the supplier if something goes wrong.
How can Avant support your practice?
Navigating AI adoption doesn't need to be a solo effort. Avant can help you build the right foundations before AI becomes a liability issue:
- Practice Advisory can work with you to build internal governance around AI use, from clear policies on when and how AI tools are used, to processes for verifying outputs.
- Avant Law can review AI vendor contracts before you sign, checking indemnity clauses, liability caps and data-handling terms so you understand where risk sits if something goes wrong.
- HR Advisory can support the people side of AI adoption. This includes updating workplace policies and contracts to reflect AI use, and managing performance or misconduct issues connected to AI reliance.
- Risk Advisory Services can assess medico-legal risk, clarify obligations and support you to take proactive steps to strengthen systems and provide quality care.
AI in medical practices: key takeaways
AI can bring real efficiency gains to your medical practice, but it does not remove professional accountability.
The practitioner remains responsible for checking AI-generated information and making appropriate clinical decisions. The medical practice may also face liability because of its systems, governance, arrangements or responsibility for an employee’s conduct. A manufacturer or supplier may also be responsible if a regulated tool is defective, fails to perform as represented or does not meet its regulatory obligations.
Understand what AI tools do, check their regulatory status, ensure appropriate governance is in place, review relevant contractual arrangements, and use suppliers that can demonstrate appropriate security, governance and support.
To learn how Avant can support your practice, book a meeting with our team today.
The information in this article does not constitute legal, financial or other professional advice and should not be relied upon as such. It is intended only to provide a summary and general overview on matters of interest and it is not intended to be comprehensive. Persons implementing any recommendations contained in this article must exercise their own independent skill or judgment and seek appropriate professional advice relevant to their own particular circumstances. Compliance with any recommendations will not in any way guarantee discharge of the duty of care owed to patients and others coming into contact with the health professional or practice. Avant Practice Solutions and its related entities are not responsible to any person for any loss suffered in connection with the use of this information. Information is only current at the date initially published. © Avant Mutual Group Limited 2026.
Avant Law Pty Limited is an incorporated legal practice and not a partnership. Liability limited by a scheme approved under Professional Standards Legislation. Legal practitioners employed by Avant Law are members of the scheme.