AI & Computingpreprint2026-08-29

Bounding Inaction in Clinical AI Safety Arguments from Fail-Safe to Fail-Operational

Open access0 citations

Abstract

Safety arguments for clinical artificial intelligence are stated in one direction: the system must not do what it should not do. Other fields have recognised the complement - automotive functional safety requires fail-operational rather than merely fail-safe behaviour, and the safety-of-the-intended-functionality standard addresses hazards arising from specification insufficiency with no component failure - but clinical AI safety work has not adopted it. In clinical medicine a treatment withheld is a harm, so an argument bounding only commission describes half the problem. We enumerate the reachable state space of a verified clinical kernel exhaustively. Of 384 states, 80 admit no intervention at any admissible dose; 24 of 32 distinct contexts remain so in every treatment phase; and all 80 arise from two individually correct rules whose interaction the specification never anticipated. Sampling 1,350 synthetic rule sets shows that redundancy suppresses this region without removing it, and that the protection it affords is nowhere declared and nowhere checked. We propose four symmetric invariants that bound how far a system's caution may contract what it will consider.

// Source

View paper (DOI)Open access versionOpenAlexZenodo (CERN European Organization for Nuclear Research)Published 2026-08-29

Authors: Lu-An Chiu

Institutions: Tainan University of Technology