<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.0 20120330//EN" "http://jats.nlm.nih.gov/publishing/1.0/JATS-journalpublishing1.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="1.0" article-type="other">
  <front>
    <journal-meta>
      <journal-id journal-id-type="nlm-ta">Art Int Surg.</journal-id>
      <journal-id journal-id-type="publisher-id">ais</journal-id>
      <journal-title-group>
        <journal-title>Artificial Intelligence Surgery</journal-title>
      </journal-title-group>
      <issn pub-type="epub">2771-0408</issn>
      <publisher>
        <publisher-name>OAE Publishing Inc.</publisher-name>
      </publisher>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">10.20517/ais.2026.49</article-id>
      <article-id pub-id-type="publisher-id">AIS-2026-49</article-id>
      <article-categories>
        <subj-group>
          <subject>Perspective</subject>
        </subj-group>
      </article-categories>
      <title-group>
        <article-title>Auditable medical AI in surgery: an architectural response to the ethics imperative</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author" corresp="yes">
		<contrib-id contrib-id-type="orcid">https://orcid.org/0009-0003-7653-1561</contrib-id>
          <name>
            <surname>Mastari</surname>
            <given-names>Fatima Azzahra</given-names>
          </name>
          <xref ref-type="corresp" rid="cor1">*</xref>
        </contrib>
      </contrib-group>
      <aff id="I1000">CLINETHIX LLC, Sheridan, WY 82801, USA.</aff>
      <author-notes>
        <corresp id="cor1">Correspondence to: Dr. Fatima Azzahra Mastari, CLINETHIX LLC, Sheridan, WY 82801, USA. E-mail: <email>contact@clinethix.com</email></corresp>
        <fn fn-type="other">
          <p><bold>Received:</bold> 2 Jun 2026 | <bold>First Decision:</bold> 12 Aug 2026 | <bold>Revised:</bold> 19 Aug 2026 | <bold>Accepted:</bold> 26 Aug 2026 | <bold>Published:</bold> 3 Sep 2026</p>
        </fn>
        <fn fn-type="other">
          <p><bold>Academic Editor:</bold> Andrew Gumbs | <bold>Copy Editor:</bold> Tong Wang | <bold>Production Editor:</bold> Tong Wang</p>
        </fn>
      </author-notes>
      <pub-date pub-type="ppub">
        <year>2026</year>
      </pub-date>
      <pub-date pub-type="epub">
        <day>3</day>
        <month>9</month>
        <year>2026</year>
      </pub-date>
      <volume>6</volume>
      <issue>3</issue>
      <fpage>433</fpage>
	  <lpage>40</lpage>
      <permissions>
        <copyright-statement>© The Author(s) 2026.</copyright-statement>
        <license xlink:href="https://creativecommons.org/licenses/by/4.0/">
          <license-p>© The Author(s) 2026.<bold>Open Access</bold>This article is licensed under a Creative Commons Attribution 4.0 International License (<uri xlink:href="https://creativecommons.org/licenses/by/4.0/">https://creativecommons.org/licenses/by/4.0/</uri>), which permits unrestricted use, sharing, adaptation, distribution and reproduction in any medium or format, for any purpose, even commercially, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons license, and indicate if changes were made.</license-p>
        </license>
      </permissions>
    </article-meta>
  </front>
  <body>
    <sec id="sec1">
      <title>INTRODUCTION: A FORENSIC QUESTION, ASKED FROM A CLINICAL CHAIR</title>
      <p>In <italic>Mata v. Avianca</italic> (S.D.N.Y., 2023), counsel was sanctioned for filing generative-model citations that could not be verified when challenged<sup>[<xref ref-type="bibr" rid="B1">1</xref>]</sup>. The same forensic question - on what basis did the system say this, from which source, and when - will arise when a surgical artificial intelligence (AI) output is reviewed after an adverse event. The system either produces a reconstructible evidentiary artefact or it does not.</p>
      <p>The journal’s founding editorial placed surgeons at the centre of defining Artificial Intelligence Surgery<sup>[<xref ref-type="bibr" rid="B2">2</xref>]</sup>. Capelli <italic>et al.</italic> articulated trustworthy surgical AI as explainable, fair, accountable, robust, and safe<sup>[<xref ref-type="bibr" rid="B3">3</xref>]</sup>; World Health Organization (WHO) framed comparable commitments for health AI<sup>[<xref ref-type="bibr" rid="B4">4</xref>]</sup>; the surgical-training consensus extended them to pedagogy<sup>[<xref ref-type="bibr" rid="B5">5</xref>]</sup>; and the Artificial Intelligence Organization for the Next Generation of Surgeons (AIONS) supplied working definitions for AI Surgery, surgomics, and robotics<sup>[<xref ref-type="bibr" rid="B6">6</xref>]</sup>.</p>
      <p>These documents articulate what trustworthy systems should be; they do not specify the architectural artefacts by which those claims can be externally verified. This Perspective addresses that implementation gap.</p>
      <p>The proposition is that high-trust surgical AI requires an assurance architecture spanning pre-operative support, training, and intra- and post-operative ambient assist, built around four externally inspectable properties. These are proposed as engineering determinants of defensibility, not regulatory mandates.</p>
    </sec>
    <sec id="sec2">
      <title>WHERE THE ETHICS FRAMEWORK REACHES ITS OPERATIONAL LIMIT</title>
      <p>Ethical principles remain necessary but do not by themselves make system behaviour reconstructible. Transparency, for example, cannot be established from fluent outputs alone; it depends on what the system is structurally required to retrieve, refuse, and record. Architecture therefore supplies artefacts against which ethical claims can be tested.</p>
      <p>Evidence and adjacent professional failures illustrate the problem: a widely implemented sepsis model performed substantially worse on external validation than originally reported<sup>[<xref ref-type="bibr" rid="B7">7</xref>]</sup>; generative systems can fabricate citations<sup>[<xref ref-type="bibr" rid="B1">1</xref>]</sup>; and clinical language-model outputs may require verification against the health record<sup>[<xref ref-type="bibr" rid="B8">8</xref>]</sup>. Aggregate performance or fluent output alone therefore cannot establish defensibility at the point of use.</p>
      <p>The task is to identify architectural properties that make ethical claims auditable rather than merely asserted. The four properties below are candidate choices for high-trust clinical AI environments and are treated as load-bearing commitments rather than features.</p>
    </sec>
    <sec id="sec3">
      <title>THE FIRST ARCHITECTURAL COMMITMENT: SOURCE-GROUNDED RETRIEVAL</title>
      <p>A clinical AI system that generates medical content from model parameters without runtime retrieval against a curated, version-controlled source corpus is structurally weaker under audit: it cannot reconstruct the source pathway supporting a contested answer.</p>
      <p>Source-grounded retrieval is not a novel form of retrieval-augmented generation (RAG). Conventional RAG combines parametric generation with retrieved non-parametric memory<sup>[<xref ref-type="bibr" rid="B9">9</xref>]</sup>, and recent conceptual clinical work has proposed curated medical knowledge bases, provenance-aware RAG, and tamper-evident logging<sup>[<xref ref-type="bibr" rid="B10">10</xref>]</sup>. The contribution advanced here is their coupling to permission and authorisation gates: for evidence-dependent assertions, retrieved material must support the claim within identifiable provenance, version, and authorised scope; otherwise, the system enters a typed defer/refusal state and records it.</p>
      <p>Support is assessed at claim level, not by exact-text matching. Multiple sources may be synthesised if each material claim remains traceable and disagreement is preserved. When no guideline directly addresses atypical anatomy or a rare intra-operative presentation, the system may provide a bounded synthesis of relevant primary literature, state the evidence gap, request context, or defer a prescriptive recommendation. Refusal applies to the unsupported or unauthorised claim, not to all potentially useful evidence.</p>
      <p>Independent clinical work supports separating information supply from claim authorisation. In a controlled breast-cancer decision-snapshot evaluation, RAG without an authorisation gate did not reduce unjustified inference relative to an unconstrained large language model (LLM), whereas an evidence-graded authorisation framework reduced unsupported claims and increased appropriate refusal<sup>[<xref ref-type="bibr" rid="B11">11</xref>]</sup>. This preprint does not establish a standard, but supports the distinction: retrieval supplies evidence; governance determines what may be asserted.</p>
      <p>The audit objective is reconstructibility: which source passage, corpus version, authorisation rule, and system state supported or prevented an assertion. Benchmarks such as MedHELM remain useful for task-level performance<sup>[<xref ref-type="bibr" rid="B12">12</xref>]</sup>, but do not replace output-level provenance.</p>
      <p>In surgery, the pre-operative guideline query is one text-based example, not the architecture’s modality limit. Before laparoscopic cholecystectomy or liver resection, a query about updated society guidance should return an answer bound to an identifiable document section and date, or an evidence-insufficiency/defer state rather than an unsupported assertion. Intra-operative observations may instead originate from video or sensors; their governance is addressed below.</p>
    </sec>
    <sec id="sec4">
      <title>THE SECOND ARCHITECTURAL COMMITMENT: PERMISSION-FIRST GOVERNANCE</title>
      <p>Medical AI often operates at the boundary between patient care and governed clinical content, including society guidelines, copyrighted literature, and institutional protocols. A permission-first architecture inverts ingestion: content is ingested, indexed, retrieved for synthesis, or used to generate an output only when an explicit upstream permission or licence covers that use. Content scopes are defined before deployment and enforced at retrieval time rather than moderated after the fact.</p>
      <p>Machine-readable frameworks establish precedents for <italic>ex ante</italic> control. The World Wide Web Consortium (W3C) Open Digital Rights Language (ODRL) represents permissions, prohibitions, duties, and constraints over digital assets<sup>[<xref ref-type="bibr" rid="B13">13</xref>]</sup>, while the Global Alliance for Genomics and Health (GA4GH) Data Use Ontology (DUO) encodes allowable uses of biomedical datasets to support authorisation decisions<sup>[<xref ref-type="bibr" rid="B14">14</xref>]</sup>. They govern different objects but show that permitted uses can be represented with content and evaluated computationally.</p>
      <p>For guideline authorities, retrospective takedown cannot fully preserve source authority once content has been ingested and paraphrased. Under this proposal, issuing bodies define permitted uses ex ante and those constraints are enforced during retrieval and synthesis, preserving source authority, version, scope, and jurisdiction.</p>
      <p>For surgical societies and guideline authorities, permission-first governance therefore offers a mechanism for AI-mediated distribution while preserving enforceable control over content, version, scope, and jurisdiction<sup>[<xref ref-type="bibr" rid="B13">13</xref>,<xref ref-type="bibr" rid="B14">14</xref>]</sup>. <xref ref-type="fig" rid="fig1">Figure 1</xref> illustrates the evidence-governance path when an evidence-dependent question lacks an eligible, current source in the authorised corpus.</p>
      <fig id="fig1" position="float">
        <label>Figure 1</label>
        <caption>
          <p>Permission-first evidence governance: supported output, defer state, human fallback, and auditable record. A clinician’s evidence-dependent question is evaluated only against an authorised evidence corpus. When an eligible and current source is available within the permitted corpus, the system may produce a supported output linked to the retrieved source, its version, scope, and permission status. When no eligible source is available, the system enters an evidence-insufficiency/defer state and does not generate an evidence-dependent clinical assertion from material that has not been retrieved or is not authorised for synthesis. Official publisher links may optionally be presented outside the synthesis boundary for direct consultation, but are not retrieved, ingested, indexed, or synthesised. The clinician retains the standard clinical pathway. The request identifier, timestamp, corpus version, permission policy, retrieval event, output state, and hash-chain reference are retained in a tamper-evident audit record. The “less than five years” condition shown in the figure reflects the corpus-currency policy applied to guideline sources in the illustrated architecture; it is not proposed as a universal criterion for clinical validity. This figure is conceptual and does not constitute clinical validation.</p>
        </caption>
        <graphic xlink:href="ais6049.fig.1.jpg"/>
      </fig>
    </sec>
    <sec id="sec5">
      <title>THE THIRD ARCHITECTURAL COMMITMENT: REFUSAL AS A FIRST-CLASS BEHAVIOUR</title>
      <p>Abstention is established in selective prediction and learning-to-defer, where models withhold or defer predictions when uncertainty or expected error is unacceptable<sup>[<xref ref-type="bibr" rid="B15">15</xref>,<xref ref-type="bibr" rid="B16">16</xref>]</sup>; medical-LLM work also shows failures to abstain appropriately under clinical uncertainty<sup>[<xref ref-type="bibr" rid="B17">17</xref>]</sup>. Here, refusal is extended beyond statistical uncertainty as a typed governance event. The working taxonomy separates capability states (out-of-scope, insufficient retrieval evidence, internal source conflict) from authorisation states (out-of-licence, out-of-mandate)<sup>[<xref ref-type="bibr" rid="B18">18</xref>]</sup>. Each event is recorded with its trigger in the audit trail.</p>
      <p>Refusal is an AI output state, not an instruction to halt care. Intra-operatively, the system withholds an unsupported or unauthorised assertion while the surgeon retains control and the standard clinical pathway. Fallbacks may request missing context - an interactive strategy evaluated in MediQ<sup>[<xref ref-type="bibr" rid="B19">19</xref>]</sup> - provide a traceable bounded synthesis, expose unresolved conflicts, defer to the clinician, or withhold the unsupported recommendation. Selective-prediction studies frame abstention against the costs of error and non-assistance<sup>[<xref ref-type="bibr" rid="B20">20</xref>]</sup>, while ClinDet-Bench shows that incomplete information can produce both premature conclusions and excessive abstention<sup>[<xref ref-type="bibr" rid="B21">21</xref>]</sup>. Refusal frequency should therefore depend on task, case mix, evidentiary availability, and institutional mandate; the auditable requirement is the recorded trigger, resulting state, and human override.</p>
    </sec>
    <sec id="sec6">
      <title>THE FOURTH ARCHITECTURAL COMMITMENT: A CRYPTOGRAPHICALLY CHAINED AUDIT TRAIL</title>
      <p>The three commitments converge on a fourth: retrievals, generations, refusals, and overrides are recorded in an integrity-protected audit trail. Secure logging mechanisms are well established: Schneier and Kelsey described constructions designed to make earlier entries resistant to undetectable modification or destruction after compromise<sup>[<xref ref-type="bibr" rid="B22">22</xref>]</sup>. In the proposed architecture, records are hash-linked so each payload binds to the digest of the preceding record. Independent recomputation additionally requires deterministic serialisation or canonicalisation and an initial trust anchor; these are implementation specifications of this proposal, not requirements established by reference<sup>[<xref ref-type="bibr" rid="B22">22</xref>]</sup>.</p>
      <p>National Institute of Standards and Technology (NIST) Special Publication (SP) 800-92 addresses operational log management<sup>[<xref ref-type="bibr" rid="B23">23</xref>]</sup>; International Organization for Standardization (ISO) 27789:2021 defines electronic health record (EHR) audit trigger events and audit data<sup>[<xref ref-type="bibr" rid="B24">24</xref>]</sup>; and healthcare implementations have demonstrated immutable access logs on permissioned distributed ledgers<sup>[<xref ref-type="bibr" rid="B25">25</xref>]</sup>. These precedents ground durable, reviewable, tamper-evident records without prescribing this architecture.</p>
      <p>The audit trail is the artefact available to regulators, review boards, or expert witnesses. Without it, <italic>post-hoc</italic> reconstruction of how unsupported content was generated or surfaced becomes substantially more difficult.</p>
      <p>Three properties are central: integrity protection and tamper-evidence, content selectivity, and retention. Integrity protection makes unauthorised modification detectable; selectivity enables reconstruction of retrieved sources, refusal class, model and corpus versions, and applied thresholds without exposing clear-text patient data; retention keeps the artefact available on a medically meaningful time horizon.</p>
      <p>Stronger implementations may add external timestamping, independent verification, or distributed-ledger anchoring; these are implementation options rather than requirements of the proposed architecture<sup>[<xref ref-type="bibr" rid="B22">22</xref>-<xref ref-type="bibr" rid="B25">25</xref>]</sup>.</p>
    </sec>
    <sec id="sec7">
      <title>THE SURGICAL TRIAD IS ALREADY THERE: PREPARATION, TRAINING, DAILY COMPANION</title>
      <p>Surgical practice already spans three operational phases: preparation, training, and daily clinical work. Source checking, institutional protocols, curricula, case records, and handoffs already embody expectations of justification and traceability; AI should preserve rather than erode them.</p>
      <p>The question is therefore whether AI preserves the auditability expected of these established practices, not how the four commitments map onto a product line.</p>
      <p>In preparation, a source-grounded retrieval system with a tamper-evident audit trail instruments the surgeon’s existing source-checking reflex<sup>[<xref ref-type="bibr" rid="B9">9</xref>,<xref ref-type="bibr" rid="B10">10</xref>,<xref ref-type="bibr" rid="B23">23</xref>,<xref ref-type="bibr" rid="B24">24</xref>]</sup>. Assertions should remain traceable to retrieved passages, refusals classified, and interactions recorded for later reconstruction.</p>
      <p>In training, the 2025 consensus supports simulation, AI-enabled objective feedback, automated skill assessment, error identification, and validation before widespread adoption<sup>[<xref ref-type="bibr" rid="B5">5</xref>]</sup>. The proposed architecture adds inspectability of evidentiary basis, system version, trainee interaction, and feedback, allowing training or accreditation bodies to review an auditable artefact.</p>
      <p>In the daily companion layer, Article 14 of the EU AI Act makes human oversight salient for high-risk AI, while medical-device AI remains subject to the Medical Devices Regulation (MDR) and In Vitro Diagnostic Medical Devices Regulation (IVDR) and their interplay with the AI Act<sup>[<xref ref-type="bibr" rid="B26">26</xref>,<xref ref-type="bibr" rid="B27">27</xref>]</sup>. Mascagni <italic>et al.</italic> demonstrated a deep-learning computer-vision system that segments hepatocystic anatomy and assesses critical-view-of-safety criteria from laparoscopic images<sup>[<xref ref-type="bibr" rid="B28">28</xref>]</sup>. That perception layer is distinct from the proposed governance layer: provenance can identify video or frame context, model and version, and observation; permission and mandate constrain use; abstention or refusal governs outputs outside validated or authorised conditions; and audit records the resulting events. Source-grounded retrieval becomes relevant when an observation is converted into an evidence-dependent assertion or recommendation. The same governance pattern can surround future multimodal or vision-language components without requiring them.</p>
      <p>Latency controls need not share one path. Pre- or post-operative consultation can perform retrieval, authorisation checks, and durable logging synchronously. In high-frequency intra-operative perception, the validated perception model remains on the real-time path while audit records are committed at event level asynchronously or in short batches; retrieval is invoked when an observation becomes an evidence-dependent assertion rather than on every frame. Event granularity, batching, and acceptable latency must be validated for intended use and risk; no universal latency budget is proposed. Auditable clinical RAG architectures likewise identify latency and usability as feasibility constraints<sup>[<xref ref-type="bibr" rid="B10">10</xref>]</sup>.</p>
      <p>Thus, the four commitments provide a coherent governance and assurance posture across phases, with implementation adapted to modality and workflow.</p>
    </sec>
    <sec id="sec8">
      <title>REGULATORY CONVERGENCE: OVERLAPPING OBLIGATIONS AND ARCHITECTURAL IMPLICATIONS</title>
      <p>The EU AI Act, MDR/IVDR, and General Data Protection Regulation (GDPR) impose overlapping obligations rather than a single system architecture. The AI Act classifies systems as high risk in specified circumstances and Articles 9-15 address risk management, data governance, technical documentation, record-keeping, transparency, human oversight, accuracy, robustness, and cybersecurity<sup>[<xref ref-type="bibr" rid="B26">26</xref>]</sup>. Where personal data are processed, GDPR adds accountability, data protection by design and default, records of processing where applicable, and security<sup>[<xref ref-type="bibr" rid="B29">29</xref>]</sup>. Medical Device Coordination Group (MDCG) 2025-6 addresses the interplay between MDR/IVDR and the AI Act for medical-device AI<sup>[<xref ref-type="bibr" rid="B27">27</xref>]</sup>.</p>
      <p>These regimes do not mandate source-grounded retrieval, typed refusal, or cryptographic chaining<sup>[<xref ref-type="bibr" rid="B26">26</xref>,<xref ref-type="bibr" rid="B27">27</xref>,<xref ref-type="bibr" rid="B29">29</xref>]</sup>. The four commitments are candidate engineering patterns that may help operationalise and evidence requirements for documentation, record-keeping, transparency, oversight, governance, accountability, and security. Their records can contribute to broader conformity and accountability artefacts but do not establish regulatory compliance by themselves.</p>
    </sec>
    <sec id="sec9">
      <title>EXTENDING THE SAME COMMITMENTS TO ADJACENT LAYERS</title>
      <p>The same governance principles extend beyond the immediate clinical decision to institutional governance and scholarly knowledge, with implementation adapted to modality, content type, and workflow.</p>
      <p>At the institutional layer, hospitals, academic centres, and guideline authorities define which AI behaviour is permitted, against which protocols, and under which oversight. Applying the same provenance, authorisation, refusal, and audit principles can connect a clinical event to the rule governing it.</p>
      <p>At the scholarly knowledge layer, the relevant objects are the corpus, its version discipline, and its relationship to source authorities. Permission-first, machine-readable policies can support AI-mediated distribution while preserving explicit control over scope, version, and jurisdiction<sup>[<xref ref-type="bibr" rid="B13">13</xref>,<xref ref-type="bibr" rid="B14">14</xref>]</sup>.</p>
      <p>These extensions locate the argument at the structural layer where clinical assertions, institutional rules, and published guidance must remain reconstructible and attributable.</p>
    </sec>
    <sec id="sec10">
      <title>CONCLUSION: THE NEXT COLLECTIVE TASK</title>
      <p>Surgery has advanced by embedding ethical duties into practices that alter the conditions under which harm occurs. Auditable medical AI requires the same move from principle to inspectable architecture.</p>
      <p>Source-grounding, permission-first governance, typed refusal, and cryptographically chained audit trails are proposed as architectural conditions supporting defensibility in surgical AI.</p>
      <p>The author-developed Refusal Stack specification underlying the taxonomy is publicly deposited<sup>[<xref ref-type="bibr" rid="B18">18</xref>]</sup> as a citable starting point, not a final standard. The surgical community should now subject the architectural layer to the same collective scrutiny applied to definitions, training standards, and clinical practice.</p>
    </sec>
  </body>
  <back>
    <sec>
      <title>DECLARATIONS</title>
      <sec>
        <title>Authors’ contributions</title>
        <p>The author contributed solely to the article.</p>
      </sec>
      <sec>
        <title>Availability of data and materials</title>
        <p>No datasets were generated or analysed. The author-developed technical specifications informing this Perspective are publicly deposited on Zenodo: Sovereignty by Design - Why Guideline Authorities and Regulators Need Their Own Distribution Rail for Clinical AI, DOI:<uri xlink:href="https://www.linkedin.com/pulse/sovereignty-design-dr-fatima-azzahra-mastari-o1a4f">10.5281/zenodo.20258141</uri>; and The Refusal Stack - Engineering Medical AI for Adversarial Audit, DOI:<uri xlink:href="https://www.linkedin.com/pulse/refusal-stack-dr-fatima-azzahra-mastari-kjage">10.5281/zenodo.20257894</uri>.</p>
      </sec>
      <sec>
        <title>AI and AI-assisted tools statement</title>
        <p>During the preparation of this manuscript, the AI tool ChatGPT (version GPT-5.6 Sol, released 2026-07-09) was used solely for language editing. The tool did not influence the study design, data collection, analysis, interpretation, or the scientific content of the work. The author takes full responsibility for the accuracy, integrity, and final content of the manuscript.</p>
      </sec>
      <sec>
        <title>Financial support and sponsorship</title>
        <p>None.</p>
      </sec>
      <sec>
        <title>Conflicts of interest</title>
        <p>Mastari FA is founder and CEO of CLINETHIX LLC, which developed the author-deposited technical specifications described above. The Perspective reports no original clinical data, author-generated benchmark results, patient-specific recommendations, or commercial offer. The specifications are disclosed as citable technical materials and are not used as independent evidence where established external literature is available. No commercial promotion of CLINETHIX systems is intended.</p>
      </sec>
      <sec>
        <title>Ethical approval and consent to participate</title>
        <p>Not applicable.</p>
      </sec>
      <sec>
        <title>Consent for publication</title>
        <p>Not applicable.</p>
      </sec>
      <sec>
        <title>Copyright</title>
        <p>© The Author(s) 2026.</p>
      </sec>
    </sec>
    <ref-list>
      <ref id="B1">
        <label>1</label>
        <element-citation publication-type="web">
          <comment>Mata v. Avianca, Inc., 678 F. Supp. 3d 443 (S.D.N.Y. 2023). Available from: <uri xlink:href="https://law.justia.com/cases/federal/district-courts/new-york/nysdce/1%3A2022cv01461/575368/54/">https://law.justia.com/cases/federal/district-courts/new-york/nysdce/1%3A2022cv01461/575368/54/</uri>. [Last accessed on 2 September 2026]</comment>
        </element-citation>
      </ref>
      <ref id="B2">
        <label>2</label>
        <element-citation publication-type="journal">
          <person-group person-group-type="author">
            <name>
              <surname>Gumbs</surname>
              <given-names>AA</given-names>
            </name>
            <name>
              <surname>Perretta</surname>
              <given-names>S</given-names>
            </name>
            <name>
              <surname>d’Allemagne</surname>
              <given-names>B</given-names>
            </name>
            <name>
              <surname>Chouillard</surname>
              <given-names>E</given-names>
            </name>
          </person-group>
          <article-title>What is Artificial Intelligence Surgery?</article-title>
          <source>Art Int Surg.</source>
          <year>2021</year>
          <volume>1</volume>
          <fpage>1</fpage>
          <lpage>10</lpage>
          <pub-id pub-id-type="doi">10.20517/ais.2021.01</pub-id>
        </element-citation>
      </ref>
      <ref id="B3">
        <label>3</label>
        <element-citation publication-type="journal">
          <person-group person-group-type="author">
            <name>
              <surname>Capelli</surname>
              <given-names>G</given-names>
            </name>
            <name>
              <surname>Verdi</surname>
              <given-names>D</given-names>
            </name>
            <name>
              <surname>Frigerio</surname>
              <given-names>I</given-names>
            </name>
            <etal/>
          </person-group>
          <article-title>; Artificial Intelligence Surgery Editorial Board Study Group on Ethics. White paper: ethics and trustworthiness of artificial intelligence in clinical surgery</article-title>
          <source>Art Int Surg.</source>
          <year>2023</year>
          <volume>3</volume>
          <fpage>111</fpage>
          <lpage>22</lpage>
          <pub-id pub-id-type="doi">10.20517/ais.2023.04</pub-id>
        </element-citation>
      </ref>
      <ref id="B4">
        <label>4</label>
        <element-citation publication-type="web">
          <comment>World Health Organization. Ethics and governance of artificial intelligence for health. Available from: <uri xlink:href="https://www.who.int/publications/i/item/9789240029200">https://www.who.int/publications/i/item/9789240029200</uri>. [Last accessed on 2 September 2026]</comment>
        </element-citation>
      </ref>
      <ref id="B5">
        <label>5</label>
        <element-citation publication-type="journal">
          <person-group person-group-type="author">
            <name>
              <surname>Grasso</surname>
              <given-names>SV</given-names>
            </name>
            <name>
              <surname>Spolverato</surname>
              <given-names>G</given-names>
            </name>
            <name>
              <surname>Capelli</surname>
              <given-names>G</given-names>
            </name>
            <etal/>
          </person-group>
          <article-title>The role of advanced technologies and artificial intelligence (AI) in surgical training: a consensus report</article-title>
          <source>Cureus.</source>
          <year>2025</year>
          <volume>17</volume>
          <fpage>e98371</fpage>
          <pub-id pub-id-type="doi">10.7759/cureus.98371</pub-id>
          <pub-id pub-id-type="pmid">41487718</pub-id>
          <pub-id pub-id-type="pmcid">PMC12758081</pub-id>
        </element-citation>
      </ref>
      <ref id="B6">
        <label>6</label>
        <element-citation publication-type="journal">
          <person-group person-group-type="author">
            <name>
              <surname>Gumbs</surname>
              <given-names>A</given-names>
            </name>
            <name>
              <surname>Diana</surname>
              <given-names>M</given-names>
            </name>
            <name>
              <surname>Rawicz-Prusyński</surname>
              <given-names>K</given-names>
            </name>
            <etal/>
          </person-group>
          <article-title>AIONS consensus conference on definitions of artificial intelligence surgery, surgomics and robotics</article-title>
          <source>Art Int Surg.</source>
          <year>2026</year>
          <volume>6</volume>
          <fpage>98</fpage>
          <lpage>113</lpage>
          <pub-id pub-id-type="doi">10.20517/ais.2025.113</pub-id>
        </element-citation>
      </ref>
      <ref id="B7">
        <label>7</label>
        <element-citation publication-type="journal">
          <person-group person-group-type="author">
            <name>
              <surname>Wong</surname>
              <given-names>A</given-names>
            </name>
            <name>
              <surname>Otles</surname>
              <given-names>E</given-names>
            </name>
            <name>
              <surname>Donnelly</surname>
              <given-names>JP</given-names>
            </name>
            <etal/>
          </person-group>
          <article-title>External validation of a widely implemented proprietary sepsis prediction model in hospitalized patients</article-title>
          <source>JAMA Intern Med.</source>
          <year>2021</year>
          <volume>181</volume>
          <fpage>1065</fpage>
          <lpage>70</lpage>
          <pub-id pub-id-type="doi">10.1001/jamainternmed.2021.2626</pub-id>
          <pub-id pub-id-type="pmid">34152373</pub-id>
          <pub-id pub-id-type="pmcid">PMC8218233</pub-id>
        </element-citation>
      </ref>
      <ref id="B8">
        <label>8</label>
        <element-citation publication-type="journal">
          <person-group person-group-type="author">
            <name>
              <surname>Chung</surname>
              <given-names>P</given-names>
            </name>
            <name>
              <surname>Swaminathan</surname>
              <given-names>A</given-names>
            </name>
            <name>
              <surname>Goodell</surname>
              <given-names>AJ</given-names>
            </name>
            <etal/>
          </person-group>
          <article-title>Verifying facts in patient care documents generated by large language models using electronic health records</article-title>
          <source>NEJM AI.</source>
          <year>2026</year>
          <volume>3</volume>
          <pub-id pub-id-type="doi">10.1056/AIdbp2500418</pub-id>
        </element-citation>
      </ref>
      <ref id="B9">
        <label>9</label>
        <element-citation publication-type="web">
          <person-group person-group-type="author">
            <name>
              <surname>Lewis</surname>
              <given-names>P</given-names>
            </name>
            <name>
              <surname>Perez</surname>
              <given-names>E</given-names>
            </name>
            <name>
              <surname>Piktus</surname>
              <given-names>A</given-names>
            </name>
            <etal/>
          </person-group>
          <comment>Retrieval-augmented generation for knowledge-intensive NLP tasks. <italic>Adv Neural Inf Process Syst.</italic> 2020;33:9459-74. Available from: <uri xlink:href="https://proceedings.neurips.cc/paper/2020/hash/6b493230-Abstract.html">https://proceedings.neurips.cc/paper/2020/hash/6b493230-Abstract.html</uri>  [Last accessed on 2 September 2026]</comment>
        </element-citation>
      </ref>
      <ref id="B10">
        <label>10</label>
        <element-citation publication-type="journal">
          <person-group person-group-type="author">
            <name>
              <surname>Alu</surname>
              <given-names>FF</given-names>
            </name>
            <name>
              <surname>Oluwadare</surname>
              <given-names>S</given-names>
            </name>
          </person-group>
          <article-title>An auditable and source-verified framework for clinical AI decision support: integrating retrieval-augmented generation with data provenance</article-title>
          <source>Front Artif Intell.</source>
          <year>2026</year>
          <volume>9</volume>
          <fpage>1737532</fpage>
          <pub-id pub-id-type="doi">10.3389/frai.2026.1737532</pub-id>
          <pub-id pub-id-type="pmid">41716615</pub-id>
          <pub-id pub-id-type="pmcid">PMC12913532</pub-id>
        </element-citation>
      </ref>
      <ref id="B11">
        <label>11</label>
        <element-citation publication-type="journal">
          <person-group person-group-type="author">
            <name>
              <surname>Lin</surname>
              <given-names>C</given-names>
            </name>
            <name>
              <surname>Lin</surname>
              <given-names>JY</given-names>
            </name>
            <name>
              <surname>Lin</surname>
              <given-names>YS</given-names>
            </name>
          </person-group>
          <article-title>Evidence-graded decision authorization for safe clinical AI: a constrained reasoning framework. <italic>medRxiv</italic> 2026; Epub ahead of print</article-title>
          <pub-id pub-id-type="doi">10.64898/2026.05.19.26353565</pub-id>
        </element-citation>
      </ref>
      <ref id="B12">
        <label>12</label>
        <element-citation publication-type="journal">
          <person-group person-group-type="author">
            <name>
              <surname>Bedi</surname>
              <given-names>S</given-names>
            </name>
            <name>
              <surname>Cui</surname>
              <given-names>H</given-names>
            </name>
            <name>
              <surname>Fuentes</surname>
              <given-names>M</given-names>
            </name>
            <etal/>
          </person-group>
          <article-title>Holistic evaluation of large language models for medical tasks with MedHELM</article-title>
          <source>Nat Med.</source>
          <year>2026</year>
          <volume>32</volume>
          <fpage>943</fpage>
          <lpage>51</lpage>
          <pub-id pub-id-type="doi">10.1038/s41591-025-04151-2</pub-id>
          <pub-id pub-id-type="pmid">41559415</pub-id>
          <pub-id pub-id-type="pmcid">PMC13267972</pub-id>
        </element-citation>
      </ref>
      <ref id="B13">
        <label>13</label>
        <element-citation publication-type="web">
          <comment>World Wide Web Consortium. ODRL Information Model 2.2. W3C Recommendation, 15 February 2018. Available from: <uri xlink:href="https://www.w3.org/TR/odrl-model/">https://www.w3.org/TR/odrl-model/</uri>. [Last accessed on 2 September 2026]</comment>
        </element-citation>
      </ref>
      <ref id="B14">
        <label>14</label>
        <element-citation publication-type="journal">
          <person-group person-group-type="author">
            <name>
              <surname>Lawson</surname>
              <given-names>J</given-names>
            </name>
            <name>
              <surname>Cabili</surname>
              <given-names>MN</given-names>
            </name>
            <name>
              <surname>Kerry</surname>
              <given-names>G</given-names>
            </name>
            <etal/>
          </person-group>
          <article-title>The Data Use Ontology to streamline responsible access to human biomedical datasets</article-title>
          <source>Cell Genom.</source>
          <year>2021</year>
          <volume>1</volume>
          <fpage>100028</fpage>
          <pub-id pub-id-type="doi">10.1016/j.xgen.2021.100028</pub-id>
          <pub-id pub-id-type="pmid">34820659</pub-id>
          <pub-id pub-id-type="pmcid">PMC8591903</pub-id>
        </element-citation>
      </ref>
      <ref id="B15">
        <label>15</label>
        <element-citation publication-type="web">
          <person-group person-group-type="author">
            <name>
              <surname>Mozannar</surname>
              <given-names>H</given-names>
            </name>
            <name>
              <surname>Sontag</surname>
              <given-names>D</given-names>
            </name>
          </person-group>
          <comment>Consistent estimators for learning to defer to an expert. <italic>Proc Mach Learn Res.</italic> 2020;119:7076-87. Available from: <uri xlink:href="https://proceedings.mlr.press/v119/mozannar20b.html">https://proceedings.mlr.press/v119/mozannar20b.html</uri> [Last accessed on 2 September 2026]</comment>
        </element-citation>
      </ref>
      <ref id="B16">
        <label>16</label>
        <element-citation publication-type="journal">
          <person-group person-group-type="author">
            <name>
              <surname>Kompa</surname>
              <given-names>B</given-names>
            </name>
            <name>
              <surname>Snoek</surname>
              <given-names>J</given-names>
            </name>
            <name>
              <surname>Beam</surname>
              <given-names>AL</given-names>
            </name>
          </person-group>
          <article-title>Second opinion needed: communicating uncertainty in medical machine learning</article-title>
          <source>NPJ Digit Med.</source>
          <year>2021</year>
          <volume>4</volume>
          <fpage>4</fpage>
          <pub-id pub-id-type="doi">10.1038/s41746-020-00367-3</pub-id>
          <pub-id pub-id-type="pmid">33402680</pub-id>
          <pub-id pub-id-type="pmcid">PMC7785732</pub-id>
        </element-citation>
      </ref>
      <ref id="B17">
        <label>17</label>
        <element-citation publication-type="conference">
          <person-group person-group-type="author">
            <name>
              <surname>Machcha</surname>
              <given-names>S</given-names>
            </name>
            <name>
              <surname>Yerra</surname>
              <given-names>S</given-names>
            </name>
            <name>
              <surname>Gupta</surname>
              <given-names>S</given-names>
            </name>
            <etal/>
          </person-group>
          <comment>Knowing when to abstain: medical LLMs under clinical uncertainty. Proceedings of the 19th Conference of the European Chapter of the Association for Computational Linguistics (Volume 1: Long Papers); 2026 Mar; Rabat, Morocco. Stroudsburg, PA, USA: Association for Computational Linguistics, 2026; pp. 6153-82</comment>
          <pub-id pub-id-type="doi">10.18653/v1/2026.eacl-long.291</pub-id>
        </element-citation>
      </ref>
      <ref id="B18">
        <label>18</label>
        <element-citation publication-type="web">
          <person-group person-group-type="author">
            <name>
              <surname>Mastari</surname>
              <given-names>FA</given-names>
            </name>
          </person-group>
          <comment>The refusal stack - engineering medical AI for adversarial audit. Zenodo, 17 May 2026. Available from: <uri xlink:href="https://zenodo.org/records/20257894">https://zenodo.org/records/20257894</uri> [Last accessed on 2 September 2026]</comment>
        </element-citation>
      </ref>
      <ref id="B19">
        <label>19</label>
        <element-citation publication-type="conference">
          <person-group person-group-type="author">
            <name>
              <surname>Li</surname>
              <given-names>S</given-names>
            </name>
            <name>
              <surname>Balachandran</surname>
              <given-names>V</given-names>
            </name>
            <name>
              <surname>Feng</surname>
              <given-names>S</given-names>
            </name>
            <etal/>
          </person-group>
          <comment>MediQ: question-asking LLMs and a benchmark for reliable interactive clinical reasoning. Advances in Neural Information Processing Systems 37; 2024 Dec 10-15; Vancouver, BC, Canada. San Diego, California, USA: Neural Information Processing Systems Foundation, Inc. (NeurIPS), 2024; pp. 28858-88</comment>
          <pub-id pub-id-type="doi">10.52202/079017-0908</pub-id>
        </element-citation>
      </ref>
      <ref id="B20">
        <label>20</label>
        <element-citation publication-type="journal">
          <person-group person-group-type="author">
            <name>
              <surname>Swaminathan</surname>
              <given-names>A</given-names>
            </name>
            <name>
              <surname>Lopez</surname>
              <given-names>I</given-names>
            </name>
            <name>
              <surname>Wang</surname>
              <given-names>W</given-names>
            </name>
            <etal/>
          </person-group>
          <article-title>Selective prediction for extracting unstructured clinical data</article-title>
          <source>J Am Med Inform Assoc.</source>
          <year>2024</year>
          <volume>31</volume>
          <fpage>188</fpage>
          <lpage>97</lpage>
          <pub-id pub-id-type="doi">10.1093/jamia/ocad182</pub-id>
          <pub-id pub-id-type="pmid">37769323</pub-id>
          <pub-id pub-id-type="pmcid">PMC10746316</pub-id>
        </element-citation>
      </ref>
      <ref id="B21">
        <label>21</label>
        <element-citation publication-type="conference">
          <person-group person-group-type="author">
            <name>
              <surname>Watanabe</surname>
              <given-names>Y</given-names>
            </name>
            <name>
              <surname>Kobashi</surname>
              <given-names>Y</given-names>
            </name>
            <name>
              <surname>Kojima</surname>
              <given-names>T</given-names>
            </name>
            <name>
              <surname>Iwasawa</surname>
              <given-names>Y</given-names>
            </name>
            <name>
              <surname>Okuno</surname>
              <given-names>Y</given-names>
            </name>
            <name>
              <surname>Matsuo</surname>
              <given-names>Y</given-names>
            </name>
          </person-group>
          <comment>ClinDet-Bench: beyond abstention, evaluating judgment determinability of LLMs in clinical decision-making. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 6: Industry Track); 2026 Jul; San Diego, California, USA. Stroudsburg, PA, USA: Association for Computational Linguistics, 2026; pp. 681-703</comment>
          <pub-id pub-id-type="doi">10.18653/v1/2026.acl-industry.47</pub-id>
        </element-citation>
      </ref>
      <ref id="B22">
        <label>22</label>
        <element-citation publication-type="conference">
          <person-group person-group-type="author">
            <name>
              <surname>Schneier</surname>
              <given-names>B</given-names>
            </name>
            <name>
              <surname>Kelsey</surname>
              <given-names>J</given-names>
            </name>
          </person-group>
          <comment>Cryptographic support for secure logs on untrusted machines. Proc 7th USENIX Security Symposium, San Antonio, TX, 26-29 January 1998; pp. 53-62. Available from: <uri xlink:href="https://www.usenix.org/conference/7th-usenix-security-symposium/cryptographic-support-secure-logs-untrusted-machines">https://www.usenix.org/conference/7th-usenix-security-symposium/cryptographic-support-secure-logs-untrusted-machines</uri>. [Last accessed on 2 September 2026]</comment>
        </element-citation>
      </ref>
      <ref id="B23">
        <label>23</label>
        <element-citation publication-type="web">
          <person-group person-group-type="author">
            <name>
              <surname>Kent</surname>
              <given-names>K</given-names>
            </name>
            <name>
              <surname>Souppaya</surname>
              <given-names>M</given-names>
            </name>
          </person-group>
          <comment>Guide to Computer Security Log Management. NIST Special Publication 800-92. Gaithersburg, MD: National Institute of Standards and Technology; 2006</comment>
          <pub-id pub-id-type="doi">10.6028/NIST.SP.800-92</pub-id>
        </element-citation>
      </ref>
      <ref id="B24">
        <label>24</label>
        <element-citation publication-type="web">
          <comment>International Organization for Standardization. ISO 27789:2021. Health informatics - Audit trails for electronic health records. ISO, 2021. Available from: <uri xlink:href="https://www.iso.org/standard/75313.html">https://www.iso.org/standard/75313.html</uri>. [Last accessed on 2 September 2026]</comment>
        </element-citation>
      </ref>
      <ref id="B25">
        <label>25</label>
        <element-citation publication-type="journal">
          <person-group person-group-type="author">
            <name>
              <surname>Tith</surname>
              <given-names>D</given-names>
            </name>
            <name>
              <surname>Lee</surname>
              <given-names>JS</given-names>
            </name>
            <name>
              <surname>Suzuki</surname>
              <given-names>H</given-names>
            </name>
            <etal/>
          </person-group>
          <article-title>Application of blockchain to maintaining patient records in electronic health record for enhanced privacy, scalability, and availability</article-title>
          <source>Healthc Inform Res.</source>
          <year>2020</year>
          <volume>26</volume>
          <fpage>3</fpage>
          <lpage>12</lpage>
          <pub-id pub-id-type="doi">10.4258/hir.2020.26.1.3</pub-id>
          <pub-id pub-id-type="pmid">32082695</pub-id>
          <pub-id pub-id-type="pmcid">PMC7010942</pub-id>
        </element-citation>
      </ref>
      <ref id="B26">
        <label>26</label>
        <element-citation publication-type="web">
          <comment>Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act). EUR-Lex, 2024. Available from: <uri xlink:href="https://eur-lex.europa.eu/eli/reg/2024/1689/oj">https://eur-lex.europa.eu/eli/reg/2024/1689/oj</uri>. [Last accessed on 2 September 2026]</comment>
        </element-citation>
      </ref>
	  <ref id="B27">
        <label>27</label>
        <element-citation publication-type="web">
          <comment>Medical Device Coordination Group. MDCG 2025-6: FAQ on Interplay between the Medical Devices Regulation (MDR) &amp; In Vitro Diagnostic Medical Devices Regulation (IVDR) and the Artificial Intelligence Act (AIA). European Commission, June 2025. Available from: <uri xlink:href="https://health.ec.europa.eu/latest-updates/mdcg-2025-6-faq-interplay-between-medical-devices-regulation-vitro-diagnostic-medical-devices-2025-06-19_en">https://health.ec.europa.eu/latest-updates/mdcg-2025-6-faq-interplay-between-medical-devices-regulation-vitro-diagnostic-medical-devices-2025-06-19_en</uri>. [Last accessed on 2 September 2026]</comment>
        </element-citation>
      </ref>
      <ref id="B28">
        <label>28</label>
        <element-citation publication-type="journal">
          <person-group person-group-type="author">
            <name>
              <surname>Mascagni</surname>
              <given-names>P</given-names>
            </name>
            <name>
              <surname>Vardazaryan</surname>
              <given-names>A</given-names>
            </name>
            <name>
              <surname>Alapatt</surname>
              <given-names>D</given-names>
            </name>
            <etal/>
          </person-group>
          <article-title>Artificial intelligence for surgical safety: automatic assessment of the critical view of safety in laparoscopic cholecystectomy using deep learning</article-title>
          <source>Ann Surg.</source>
          <year>2022</year>
          <volume>275</volume>
          <fpage>955</fpage>
          <lpage>61</lpage>
          <pub-id pub-id-type="doi">10.1097/SLA.0000000000004351</pub-id>
          <pub-id pub-id-type="pmid">33201104</pub-id>
        </element-citation>
      </ref>
      <ref id="B29">
        <label>29</label>
        <element-citation publication-type="web">
          <comment>Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation). OJ L 119, 4 May 2016; pp. 1-88. Available from: <uri xlink:href="https://eur-lex.europa.eu/eli/reg/2016/679/oj">https://eur-lex.europa.eu/eli/reg/2016/679/oj</uri>. [Last accessed on 2 September 2026]</comment>
        </element-citation>
      </ref>
    </ref-list>
  </back>
</article>
