skip to main content
iatroX JournalClinical insight

One Wrong Assumption, Five Automated Actions: The Safety Challenge of End-to-End AI Care

Featured image for One Wrong Assumption, Five Automated Actions: The Safety Challenge of End-to-End AI Care

An end-to-end AI care system can produce several internally consistent outputs that all depend on the same wrong assumption. The danger is not limited to an inaccurate sentence. It includes what happens when that sentence becomes a treatment proposal, a patient message or a fact that another professional later relies on.

The scenario in this article is entirely fictional. It is not a reported incident involving Nolla Health, nor an allegation that its software handles information in the way described. It is a proposed test case for any service that coordinates several stages of care.

The central question is where uncertainty is preserved, where it becomes an instruction and whether new information can stop actions that are already pending.

The unanswered question that becomes a negative finding

A fictional patient completes a remote assessment. One question about relevant previous treatment is unanswered. The absence is not caused by deception; the patient simply overlooks it.

When the system prepares its summary, the empty field becomes no relevant previous treatment. A subsequent component treats that statement as established context. Nothing in the remaining workflow looks obviously incoherent because every later step is consistent with the same incorrect premise.

This is an information-state error. Unknown and negative are different states, even when an interface might prefer a simple yes-or-no value. The problem would exist whether the initial transformation came from an AI model, a badly designed form or a human copying information.

The significance of automation is that the premise can be reused quickly across several actions. Faster execution makes it more important to identify the point at which an unverified interpretation becomes consequential.

Trace the assumption through five actions

The following table describes a constructed failure chain and proposed safeguards. It is not a measured product test.

Downstream actionHow the unsupported assumption could matterProposed point of intervention
Clinical summaryAn unanswered item is recorded as an established negative.Preserve the missing status and show the originating field.
Treatment proposalA plan is selected without recognising that relevant history is incomplete.Require clarification of consequential unknowns before the decision proceeds.
Patient messageThe patient is told the plan accounts for their history when that has not been established.Check that the explanation distinguishes known information from assumptions.
Follow-up scheduleMonitoring is based on the initial interpretation without considering unresolved context.Tie the schedule to a reviewed plan and flag changes that require reconsideration.
Shared recordAnother service receives the inferred negative as an established fact.Carry source, date and uncertainty into the transfer.

The problem is not solved by making the later documents more fluent. A polished explanation can actually make the shared premise harder to notice when the original unanswered question is no longer visible.

The useful review target is therefore the relationship between the conclusion and its source, not only the style or plausibility of the conclusion itself.

Several checks may still depend on the same evidence

Suppose one AI component produces the summary and another checks the treatment proposal. If the second receives only the summary, it cannot establish whether the missing history was originally collected. It may confirm consistency without independently checking the premise.

A third component might find a reference supporting the proposed treatment in a suitably selected patient. That does not establish that this patient meets the selection conditions. The source can be genuine while the recommendation remains insufficiently grounded in the encounter.

These are logical limitations of the proposed workflow, not claims about the relative accuracy of particular models. Adding another reviewer can be valuable, but the service should specify what new evidence or different failure detection that reviewer contributes.

A useful challenge question is: could every component agree while the original assumption remains wrong? Where the answer is yes, agreement should not be presented as independent confirmation.

Preserve different kinds of information

A proposed record design should distinguish patient-reported information, verified records, professional findings and software inferences. It should also retain when each item was obtained and whether it has been superseded.

For example, the patient saying that they have not previously used a treatment is different from a medication record showing no prescription, and both differ from a blank form field. Depending on the clinical question, each might be useful, but their limitations are not identical.

The GMC guidance on deciding whether it is safe to prescribe, checked on 5 October 2026, emphasises sufficient, reliable information. It provides a UK professional reason to examine these distinctions rather than treating a completed digital form as adequate context by itself.

The proposed safeguard is not to demand exhaustive verification of every detail in every encounter. It is to identify which uncertainties could change the decision and make sure those uncertainties cannot disappear merely because the workflow prefers a completed field.

Check transitions before consequential action

A service could separate preparation from commitment. It might draft a plan while information is incomplete, but prevent an irreversible or consequential action until the relevant condition is resolved.

The approval view should then show what is being authorised, which assumptions support it and what remains unknown. An approval button without that context tests whether someone clicked, not whether they could meaningfully assess the plan.

Changed information should trigger reconsideration of dependent actions. If a patient corrects their history after a message is prepared but before it is sent, the service should not continue simply because an earlier version was approved.

These are proposed design controls. Their effectiveness would need to be tested with interrupted workflows, contradictory updates and delayed messages. A diagram showing an approval step is not evidence that the step detects the relevant error in practice.

Recovery must reach beyond the original note

When an unsupported assumption is discovered, correcting the source entry is only the beginning. The service needs to identify which outputs and actions relied on it.

A correction may need to reach the patient, a dispensing provider or another clinical team. Pending actions may need to stop, and completed actions may require an appropriate clinical response. Editing a record cannot reverse treatment that has already been supplied or used.

The GMC's Good medical practice guidance on records and continuity, checked on 5 October 2026, supports accurate records and sharing relevant information for continuing care. The operational design question is how the service ensures a correction reaches the people who need it.

A proposed recovery test should therefore measure more than time to edit the original text. It should establish whether dependent actions were identified, whether the patient received understandable advice and whether the responsible professional could reconstruct what happened.

Practise finding the premise before reviewing the plan

A useful learning exercise gives the clinician a convincing plan and asks them to identify the assumptions that would have to be true for it to be appropriate. The source material is then revealed, including one consequential gap.

The learner should explain which part of the plan remains reasonable, which part cannot yet be justified and what information would resolve the uncertainty. The task is not to reject the whole plan because AI helped prepare it.

As described on 5 October 2026, iatroX's published methodology discusses source grounding and uncertainty handling in clinical reference. Those are relevant concepts for this exercise, not evidence that iatroX acts as a validated audit system for Nolla or any other provider.

The broader lesson applies to people and software alike: a coherent sequence is only as defensible as the information and assumptions on which it rests.

iatroX's companion article on AI memory and continuity explores how an unsupported assumption can persist over time, while the whole-pathway evaluation article examines how to test these failures before making broader service claims.

Frequently asked questions

Can several AI checks all miss the same problem?

Yes, particularly when they rely on the same incomplete information. Agreement alone does not demonstrate that the original premise was independently verified.

Is an unanswered clinical question equivalent to a negative answer?

No. Missing information should remain distinguishable from a finding that was assessed and absent.

Does correcting the original record reverse the consequences of an error?

No. The service must also consider dependent actions, communications and any treatment already supplied or used.

Practise identifying assumptions in clinical reasoning →

More from the Journal