Practicing without a license
Software can do much of an office visit, but the law cannot yet hold it responsible. States should license its operators, with a doctor reviewing its work until trials prove it safe.

Listen to this special topic
read by an AI voiceOn September 28 McKinsey, a consultancy, estimated that AI can already do the work behind about a fifth of America's outpatient claims, two billion to three billion in 2024. Most were office visits at which little else was done; the rest were for reading scans and tests. The next day Robert F. Kennedy Jr., the health secretary, told a summit in Washington that AI offers "a second opinion that is much better informed than any doctor in the country." California's governor, meanwhile, had until September 30 to act on a bill that would stop hospitals and clinics from using AI to replace a licensed professional's clinical judgment.
McKinsey's figure measures what software can do, and says little about what the law lets it do, which is where the work will stall. Every one of those claims still needs a licensed person behind it, because American law has no settled way to hold a program responsible for a diagnosis. Licensing the software itself would not fix that, and banning it would throw away real gains. States should instead license the organizations that run clinical AI, make them answer for its mistakes, and keep a doctor reviewing its decisions until controlled trials show it can safely do without one.
The report is more careful than its headline. It counts only what it calls "discursive care," the reasoning and conversation in medicine that need no hands-on examination, and its authors write that "AI won't replace clinicians." Among the signals of progress they list is growth in "the number of states that allow AI systems to authorize clinical decision-making without physician intervention." By that yardstick progress is close to nil. Utah, which has gone furthest, lets two companies' AI renew prescriptions, but both began with a clinician checking every renewal before it reached the pharmacy, and the state has not reported that either has moved past that stage.
The software is plainly getting good. In a randomized, blinded study published in Nature in June, a Google system's plans for managing simulated patients were judged appropriate in 95 to 98 percent of cases, against 72 to 81 percent for primary care doctors' plans, though its authors said it was "not ready for real-world translation." How much care can shift to software without harming patients is, as McKinsey's authors concede, still to be studied.
The first obstacle is the license. Only licensed people may diagnose and treat, and the leaders of the Federation of State Medical Boards wrote in August that AI "is not ready to be independently licensed like a physician" and that boards "do not regulate machines or tools and are not set up to do so." A House bill that would let AI prescribe, where a state allowed it and the Food and Drug Administration had authorized it, has sat in committee since January 2025. Meanwhile a man who says ChatGPT's advice nearly killed him is suing OpenAI, claiming the chatbot practiced medicine without a license; his lawyer says it "acted like a medical authority while having none of the responsibility."
The second obstacle is the FDA, which treats diagnostic software as a medical device and clears it one narrow task at a time: more than 1,500 AI devices so far, each doing something like spotting a tumor or a clot. It has let software make a screening decision on its own, for diabetic eye disease, since 2018, and the first cleared device that talks with patients through a language model, by its maker's account, carries out a treatment plan a clinician wrote. The agency has no rules designed for chatbots or AI agents that could prescribe, according to the New York Times. And federal law rewards keeping a doctor in the loop: decision-support software escapes device rules only if a clinician can independently review the basis for its recommendations.
The third obstacle is money. Medicare has paid for an autonomous AI eye exam since 2022, but it has no way to pay for a visit that software conducts on its own. Officials are working on a payment category for AI software that supports care or diagnosis, the Times reported on September 14, and have discussed whether AI physicians run by technology companies should be paid as much as 60 to 80 percent of what human doctors earn for the same service; nothing of the kind has been formally proposed. The software category Medicare has proposed, which it calls "software as a medical service," would pay for algorithms that analyze scans and tests, not for programs that talk to patients. The money, like the license, runs through a clinician.
The fourth obstacle, on which the others turn, is liability. The American Medical Association calls the question "novel and complex" and says developers of autonomous systems "must accept this liability," backed by malpractice insurance; the state boards say physicians should remain accountable for harm from inappropriate reliance on AI. At the summit Mr. Kennedy said that Sam Altman, OpenAI's boss, had told him it would now be "malpractice" to diagnose or prescribe without consulting AI, and JD Vance, the vice president, said that "if you create a product that harms people, you should suffer consequences for it." Doctors may soon be liable both for ignoring the machine and for trusting it.
The result is an industry that borrows doctors' licenses. At one new $39-a-month service, a licensed physician makes "every prescription, note and clinical decision" while AI supports users between sessions. That fits the law as it stands, but it puts the risk in the wrong place. As the machine does more of the work, the physician's signature makes the claim payable and makes the physician the defendant when something goes wrong, for decisions the physician did not make. Paying for such care per visit, at a discount to a doctor's fee, would reward volume and make it worse.
The strongest objection is that licenses, supervising doctors and trials would mainly protect doctors' jobs and fees, at the expense of patients who cannot see a doctor at all. An estimated 92 million Americans live where primary care is scarce, and many who turn to AI with medical questions say they could not or would not pay a doctor, or could not reach one. For them, the argument runs, every new rule means a longer wait for help that cheap software could give today. But patients already have fast, cheap AI, from chatbots that answer to no medical board and disclaim responsibility; OpenAI's reply to the lawsuit was that "ChatGPT is not a doctor." What patients lack is recourse, and a licensed operator would give them someone to answer for mistakes. Requiring proof first protects them too: the people with nowhere else to turn are the ones most exposed when untested software fails.
States should create a license for the operators of clinical AI, much as they license pharmacies. The organization, not the software, would hold it; a named physician would direct it; it would carry malpractice insurance, report its results to the medical board and the public, and take on more work in stages. Utah's Doctronic pilot has the right shape but too low a bar: a physician checks every renewal in a group of drugs until 250 have been filled, after which, if the company meets agreed benchmarks and the state approves, the AI may send renewals straight to the pharmacist while the company checks one in ten. A few hundred checked renewals say little about the rare error that does real harm; measuring that takes thousands of cases, and comparing the software with doctors takes a controlled trial. And Utah's medical board said it learned of the pilot only once it was running, and asked for it to be suspended. Boards should set the stages, and the evidence each one requires, from the start.
Washington's part is to demand proof before software treats patients outside a trial, as it does before a drug reaches the pharmacy. It is heading the other way. Under a pilot called TEMPO, the FDA intends not to enforce requirements such as premarket authorization, or its rules for trials of unproven devices, for a handful of digital health products used in a Medicare program, among them an AI voice agent that delivers therapy for depression and anxiety. The agency weighed their risks before choosing them, they are meant to be used alongside care a clinician supervises, patients are told they are in a pilot, and their makers must report data as patients use them. But the FDA says it has not yet evaluated whether they work. That puts the test after the risk: any harm the agency did not foresee will be found in the patients who suffer it.
The heart-failure agents that a federal research agency is paying three companies to build are a better model: Kaiser Permanente is to test them in randomized trials. Medicare should pay for AI-run care only once it has proved itself, and then for results rather than per machine visit.
The health secretary's own family has a stake in how soon that happens. Last year one of Mr. Kennedy's sons, Finn, then at 8VC, a venture-capital firm, co-wrote essays arguing that AI doctors "won't work for free" and that Medicare should be allowed to pay "FDA-approved autonomous AI providers." He also set out a federal overhaul that included, the New York Times reported, a person at the FDA focused specifically on AI; on September 8 the health department created such a post. This year he started a venture fund. It was raising $100 million for young companies in health-care AI and consumer health, the Financial Times reported in April, and pitched itself to investors as poised to benefit from policy shifts tied to his father's movement. The department has said the secretary complies with all ethics and confidentiality requirements. Even so, his son's fund and the companies it backs stand to gain from any rule that lets software practice and bill sooner. That is one more reason to set the standard of proof in public, before the software reaches patients.
Doctors need not wait for Washington. They should refuse to sign for decisions they cannot review, press their medical staffs and boards to define supervision by what a physician can actually check, and seek the medical-director roles these licenses would create. The software may well be, as Mr. Kennedy says, better informed than any doctor in the country. A license answers a different question: who is to blame when it is wrong. Until the law names someone else, the answer will be whichever doctor signed.
- McKinsey & Co.'s report "The AI-powered future of care" (Sept. 28, 2026; Aaron Lee, Jack Eastburn, Jessica Lamb and Jordan VanLare) says roughly 16 to 22 percent of all U.S. outpatient claims, about 2 billion to 3 billion claims and 13 to 19 percent of outpatient spending, "are for elements of care that discursive-care AI can perform": evaluation and management visits in which no other care, or only low-complexity care, was provided (11 to 15 percent of claims, 1.5 billion to 2.0 billion) and diagnostic and imaging interpretation identified by modifier 26 (5 to 7 percent, 700 million to 900 million). It uses 2024 claims from Merative (commercial), the CMS Limited Data Set (Medicare) and the CMS Virtual Research Data Center (Medicaid); Medicare Advantage and Medicaid managed care were estimated from fee-for-service claims. It says AI can perform a substantial portion of core tasks for 11 million of 19 million health care workers, that "AI won't replace clinicians," and that research on how much care can shift without compromising outcomes "will need to be done." Its signals of scale include dedicated billing codes for AI services and "the number of states that allow AI systems to authorize clinical decision-making without physician intervention and the scope of those allowances." It cites an estimated 92.3 million people living in primary care health professional shortage areas, and a fourth-quarter 2025 Gallup poll in which, of the 25 percent who use AI to inquire about medical care, 27 percent do so because they were unwilling or unable to pay for a doctor and 16 percent because they could not access a clinician.Source: McKinsey & Co.
- Health and Human Services Secretary Robert F. Kennedy Jr. said at the Make America Healthy Again Summit in Washington on Sept. 29, 2026, that AI can give "a second opinion that is much better informed than any doctor in the country" and "free us from medical tyranny," and that OpenAI CEO Sam Altman had told him it would now be "malpractice" to diagnose or prescribe without consulting AI, Forbes reported. Vice President JD Vance said, "If you create a product that harms people, you should suffer consequences for it," according to Forbes, and that experts no longer have "the same control or monopoly on knowledge," according to the Washington Examiner.Sources: Forbes, Washington Examiner
- In a STAT opinion piece on Aug. 3, 2026, Dr. Humayun Chaudhry, president and CEO of the Federation of State Medical Boards, and Dr. Christy Valentine Theard, chair of its board, wrote that "AI is not ready to be independently licensed like a physician," that "state medical boards do not regulate machines or tools and are not set up to do so," and that boards "believe physicians should remain accountable for harms caused by inappropriate reliance on AI." Manatt Health's tracker (updated July 30, 2026) counts more than 280 health-AI bills introduced in the states in 2026 and 33 signed into law in 22 states, six of which contain provisions barring chatbots from representing themselves as mental health care providers, and about 20 bills on liability for AI tools. California's AB 1979 (Assemblymember Mia Bonta), sponsored by the California Nurses Association, "ensures that health care entities cannot use A.I. to replace the clinical judgment of a licensed health care professional," National Nurses United said; it was presented to Gov. Gavin Newsom on Sept. 4, and he had until Sept. 30 to act on the session's remaining bills.
- Utah's Office of Artificial Intelligence Policy authorized Doctronic under a regulatory mitigation agreement to renew prescriptions from a formulary of medications for chronic conditions and mental health that excludes controlled substances. In Phase 1, "a licensed physician must review the prescription renewal recommended by the AI tool before it is sent to a pharmacist"; a medication group becomes eligible for Phase 2, in which "the AI tool may submit the prescription renewal directly to the pharmacist," once Doctronic has filled 250 medications in that group, subject to the office's approval; the state's page (updated June 2026) says the pilot remains in Phase 1. In Phase 2 the company will sample 10 percent of cases, Fierce Healthcare reported Aug. 10. The state's report for January through April 2026 (May 19) said the AI recommended renewal in 72 percent of cases and the reviewing physician agreed a renewal was appropriate in 91 percent. Under Legion Health's pilot, the first 250 requests are "reviewed by a licensed clinician before completion" and the next 1,000 "undergo intensive retrospective review"; the state's page (May 2026) does not say which phase it is in. The Utah Medical Licensing Board called for the Doctronic pilot's suspension on April 20, 2026, saying it had learned of it after implementation; on April 21 the Office of Artificial Intelligence Policy and the Division of Professional Licensing declined to suspend it, according to Manatt Health.
- The FDA authorized IDx-DR through De Novo review on April 11, 2018, as "the first device authorized for marketing that provides a screening decision without the need for a clinician to also interpret the image or results," on data from 900 patients at 10 primary care sites (sensitivity 87.4 percent, specificity 89.5 percent). The agency has approved more than 1,500 devices that include AI and perform discrete tasks and "does not have rules designed to address newer models, including chatbots and agentic AI systems capable of performing tasks such as prescribing medications," Becker's reported Sept. 14, citing The New York Times. UpDoc's type 2 diabetes medication management software, cleared through 510(k) on Dec. 23, 2025, which the company calls the first software as a medical device to use patient-facing large language models, "implements a healthcare provider-specified treatment plan," according to McGuireWoods. Under 21 U.S.C. 360j(o)(1)(E), clinical decision support software falls outside the device definition when, among other conditions, it supports or provides recommendations to a health care professional and enables that professional "to independently review the basis for such recommendations"; FDA's January 2026 guidance added enforcement discretion when such software provides only one recommendation that is clinically appropriate, according to Faegre Drinker.
- CMS finalized a national payment rate for CPT 92229 ("Imaging of retina for detection or monitoring of disease; with point-of-care automated analysis with diagnostic report") in its calendar year 2022 fee schedules, in a final rule dated Nov. 2, 2021, according to Digital Diagnostics, whose autonomous AI system performs the analysis. CMS's CY 2027 hospital outpatient proposed rule (July 2026) would rename software as a service as software as a medical service (SaMS), designate 36 HCPCS codes as SaMS, reassign 21 of them to New Technology APCs and create status indicator O1, as an interim policy for software performing algorithmic analyses, according to Reed Smith; comments closed Aug. 31, 2026. Federal officials are working to develop a new Medicare payment category that could reimburse companies for AI software supporting medical care or diagnosis and have discussed whether AI physicians operated by technology companies and startups should be paid "as much as 60% to 80% of what human physicians earn for the same service," Becker's reported Sept. 14, citing The New York Times. The ACCESS model, which began July 5, 2026, and runs 10 years, pays participating organizations recurring outcome-aligned payments "with full payment tied to achieving measurable health outcomes," allows FDA-authorized devices or software and devices under FDA enforcement discretion, and requires a physician clinical director. Under FDA's TEMPO pilot, linked to ACCESS, the agency "intends to exercise enforcement discretion for certain requirements, such as premarket authorization and investigational device requirements," for selected devices whose makers "collect, monitor, and report real-world data"; ACCESS participants must obtain "enhanced consent" telling beneficiaries that the device is in an FDA pilot and that certain data will be shared, according to Hogan Lovells, which also says devices must be "intended to be used in conjunction with clinician-supervised outpatient treatment." The FDA says "the effectiveness of the devices selected for the pilot, for the intended uses for which they are participating in the pilot, have not yet been evaluated by the FDA," and that its considerations in choosing participants include "potential risks to patient health, safety, or welfare" and "whether there is a reasonable expectation that the device could provide patient benefit." The first participant, announced July 22, 2026, was Dexcom, Inc., with its Dexcom Glucose Health Program; the others listed are SonderMind, Cadence Solutions and Limbic, whose Unpacked delivers cognitive behavioral therapy-based treatment through an AI voice agent to Medicare beneficiaries with depression or anxiety.
- The American Medical Association's principles on augmented intelligence (November 2024) say that "the question of physician liability for use of AI-enabled technologies presents novel and complex legal questions" and that "developers of autonomous AI systems with clinical applications (screening, diagnosis, treatment) are in the best position to manage issues of liability arising directly from system failure or misdiagnosis and must accept this liability with measures such as maintaining appropriate medical liability insurance and in their agreements with users." In a lawsuit filed July 22, 2026, in San Francisco County Superior Court, Scott Winters, a former pastor who suffered a massive pulmonary embolism, argues that ChatGPT crossed the line from providing information into practicing medicine without a license, CBS News reported; his lawyer, Matthew P. Bergman, said Mr. Winters "nearly died because ChatGPT acted like a medical authority while having none of the responsibility," and an OpenAI spokesperson said "ChatGPT is not a doctor and should never be used as a substitute for medical care, diagnosis or treatment." In August AI's $39-a-month August Care membership, "a licensed physician makes every prescription, note and clinical decision," while AI supports users between sessions, Fierce Healthcare reported Sept. 23.
- In a randomized, blinded virtual objective structured clinical examination published in Nature on June 17, 2026, Google's AMIE was compared with 21 primary care physicians across 100 multivisit case scenarios in five specialties; its management plans were appropriate in 95 percent of cases at the first visit and 98 percent at the third, against 72 and 81 percent for the physicians, and the authors wrote that "it is not ready for real-world translation." H.R. 238, the Healthy Technology Act of 2025 (Rep. David Schweikert), would let artificial intelligence and machine learning technologies qualify as practitioners eligible to prescribe drugs, subject to state authorization and FDA approval, clearance or authorization; LegiScan records its introduction and referral to the House Energy and Commerce Committee on Jan. 7, 2025, and no later action. ARPA-H's ADVOCATE program (announced Sept. 9, 2026; $62.7 million over four years) funds patient-facing agents "capable of autonomously supporting patients with heart failure between healthcare visits" and escalating to clinicians, built by Atman Health, Tempus AI and UpDoc, which must submit an FDA authorization package within 24 months of contract award; Duke University will provide "a multi-site validation platform testing ADVOCATE agents across five health systems and rural sites," and Kaiser Permanente an enterprise-scale deployment across 21 medical centers and more than 260 clinics, "generating reusable deployment blueprints via shadow-mode deployments and pragmatic randomized clinical trials."
- The New York Times reported on Sept. 14, 2026 (Christina Jewett), that one of Health Secretary Robert F. Kennedy Jr.'s sons, Finn, "started a venture capital fund this year that says it 'builds and invests in generational health companies' and was reported to have solicited funds to invest in healthcare AI"; that last year he worked for 8VC, a venture capital firm run by Joe Lonsdale, and "coauthored articles at the firm, saying that AI doctors 'won't work for free,' suggesting that the companies that create the technology should be paid"; that he "laid out the federal overhaul needed to deploy them, which included appointing a person at the FDA to focus specifically on artificial intelligence"; and that the week before, the health department had elevated Jared Seehafer "to a newly created post of deputy commissioner for technology and artificial intelligence." HHS's release of Sept. 8, 2026, says Mr. Seehafer was selected to serve as "FDA's first Deputy Commissioner for Technology and Artificial Intelligence." The 8VC essay "AI Doctors Won't Work For Free" (Aug. 4, 2025; Sebastian Caliri and Finn Kennedy) says "CMS needs to create payment rails for AI-native healthcare too" and "CMMI should launch reimbursement pilots explicitly designed for AI-native care," and that services passing "an eligibility bar set by CMMI" "could be tested in the real world." Their essay "A Vision for Healthcare AI in America" (Dec. 3, 2025) says "FDA should create a new Center for AI whose sole responsibility is the evaluation of level 2 and 3 healthcare AI" and "Section 1861 of the SSA must be amended to allow Medicare to make payments to FDA-approved autonomous AI providers, using its own NPI, when acting within its label-defined scope of practice and licensed by the relevant state board." Newser, summarizing a Financial Times report based on the fund's offering document, reported on April 26, 2026, that his fund, Victura Ventures, was raising $100 million to back early-stage companies in "health care AI, consumer health, and related technologies," had about $70 million in commitments, and pitched itself as poised to benefit from a "rare convergence" in health care and from policy shifts and initiatives tied to the MAHA movement; that the Health and Human Services Department said Secretary Kennedy "complies with all ethics and confidentiality requirements and regularly consults department lawyers"; and that legal experts quoted by the Financial Times said the structure does not appear to breach conflict-of-interest rules unless the secretary shares nonpublic information.