No. 317 / 339

Who's accountable when a semi-autonomous surgical robot, guided by AI, is involved in a bad outcome?

The shift

Discrete operative sub-tasks — suturing, tissue-plane dissection, camera control, retraction — move from surgeon-executed to system-executed, and AI shapes intra-op decisions (where to cut, when to stop, which plane to follow) in real time. So control over the physical act becomes shared and partially delegated, while the accountability model it enters still assumes one licensed surgeon held the instrument and made every call from incision to close.

The axioms

  • The operating surgeon owns the outcome and is the answerable party. Rests on the scarcity of the operative act: one person performed the physical work, so one person answers for it.
  • Accountability attaches to the licensed hand — whoever performed the manipulation is responsible for it. Rests on manipulation being non-transferable and tied to a license.
  • The standard of care is what a reasonable surgeon would have done — measured against peer practice. Rests on a stable, slow-moving consensus of what "reasonable" technique is.
  • A device maker is liable for the tool's defects, not for the surgeon's use of it. Rests on a clean line between a product's design and a professional's judgment in operating it.
  • The harmed patient has a defined, solvent party to sue and recover from. Rests on there being an identifiable, accountable defendant.
  • The physical act of surgery is irreducibly human-owned — a machine assists, a surgeon operates. Rests on dexterity and operative judgment being scarce and human.
  • The surgeon controls the operative field continuously and can intervene at any moment. Rests on the surgeon being the one making each motion, so takeover is instant and costless.

Invalid axioms

  1. The physical act of surgery is irreducibly human-owned — a machine assists, a surgeon operates. When the system executes a suture line or follows a dissection plane on its own, part of the act is performed by the robot under AI guidance, not by the surgeon's hand. The manipulation is no longer scarce or singular. The habit-trap: consent forms, credentialing, and liability all still name "the surgeon who performed the procedure" as if every motion were theirs, so they attribute an act that was partly delegated to a single human author.

Unchanged axioms

  1. A licensed human must own the outcome and be answerable for it. This is a legal and regulatory fact, not a capability gap: robotic platforms are cleared as surgeon-controlled instruments, licensure sits with people and institutions, and a robot can't hold privileges, carry malpractice insurance, or be sanctioned. More autonomy doesn't move this — it loads more weight onto the "surgeon-in-control" premise that locates accountability, even as that premise gets thinner in fact.
  2. The standard of care still governs. The content is moving hard (see NEW), but the mechanism survives: there is still a benchmark of reasonable practice, and deviation from it is still what liability turns on. Autonomy changes what "reasonable" requires; it doesn't remove the question.
  3. The patient still needs a defined, solvent party to recover from. Recourse is the point of the system. Spreading control across surgeon, hospital, and robot-vendor doesn't shrink the patient's claim to being made whole — it only makes the defendant harder to name. The need is untouched; satisfying it got harder.
  4. Judgment about when to trust or override the system stays with the accountable human. The scarce act isn't performing the sub-task — it's deciding, on this anatomy with these stakes, whether the system's execution is safe to allow and when to take over. That call sits with the person who answers for the outcome.

New axioms

  1. The liability chain across surgeon, hospital, and robot-vendor is unsettled, and each party is incentivized to point at the others. The vendor disclaims via "surgeon-controlled" labeling and use-of-device terms; the hospital points to the surgeon's independent judgment and credentialing; the surgeon points to a platform they were trained and often pressured to adopt. Absent a rule that allocates the loss, the patient's recourse degrades into a multi-party fight — and the deepest-pocketed, most-disclaimed party (the vendor) is often the best-insulated. This hinges on fast-moving law: product-liability doctrine, FDA's evolving framing of autonomous surgical functions, and the first appellate rulings on autonomy-involved harm are actively forming as of mid-2026, and a few decisions or a statute could reset the whole allocation.
  2. The standard of care is shifting toward "should have used the robot" and "should have overridden it" — in both directions at once. As autonomous sub-tasks demonstrably reduce certain errors, declining to use the platform can become the deviation; but deferring to it when a reasonable surgeon would have caught its error is also a deviation. The surgeon is exposed on both sides of a line peer practice hasn't drawn yet. This is the fastest-moving call here: the standard follows adoption, and autonomous-function adoption is climbing.
  3. The surgeon is held accountable for autonomy they didn't fully control. During an autonomously executed sub-task, the surgeon's role shifts from operator to supervisor — but the accountability stays operator-grade. "You performed the procedure" assumes continuous control the surgeon didn't have while the system was executing. Nothing yet defines what responsible supervision of a semi-autonomous instrument requires, or how much of the outcome a supervising surgeon should own for motions they monitored but didn't make.
  4. Automation bias and the takeover problem make mid-procedure intervention slow and unreliable — a new failure mode. A surgeon watching the system perform is more likely to miss an error than one performing it, and regaining manual control mid-task carries its own latency and risk (the handoff itself can be where harm happens). The old premise that intervention is instant and costless breaks: the safest moment to take over may pass before the supervisor recognizes it's needed. This tracks fast-moving human-factors evidence on how autonomy degrades operator vigilance.
  5. Vendors are disclaiming liability faster than the law is assigning it. "Surgeon-controlled instrument" labeling and contractual liability caps let vendors capture the influence of increasingly autonomous functions while offloading the downside onto the licensed human. Whether product-liability and defective-design doctrine can reach probabilistic autonomous behavior — an action that isn't a classic defect but isn't purely the surgeon's either — is unresolved. Until it is, the party shaping the physical act is the party least likely to pay for it.

Where it breaks

"The surgeon owns the physical act" (invalid) collides with "the surgeon is accountable for autonomy they didn't fully control" plus the takeover problem (new): the system reconstructs one operator who performed the procedure, but it now faults that operator for supervising a machine mid-task — sole authorship for the blame, supervisory control for the act, and a takeover window that may have closed before intervention was even possible. The surgeon is treated as the hand on every motion while being, in fact, a monitor who couldn't always intervene in time.

A second collision: "the patient needs a solvent, identifiable defendant" (still holds) meets "vendors are disclaiming faster than the law assigns" (new). The party with the deepest influence over the autonomous act and the deepest pockets is contractually the hardest to reach, so recourse routes by default to the individual surgeon — the least-resourced link, and increasingly the one with the least direct control over what the instrument actually did. Nobody has decided whether that's acceptable; it's just where the disclaimers currently push the loss.

Related axioms

Other axioms