The Omission Problem Is a Balance Sheet Problem
A physician receives a clinical AI response. It looks complete. It reads authoritatively. It skips a drug interaction that matters. No error flag fires. No confidence score drops. The output just - doesn't say the thing.
That is the failure mode a new benchmark study surfaced this week, testing clinical AI tools from OpenEvidence, OpenAI, Anthropic, and Doximity. The finding, reported by Fortune on July 29, is that the dominant safety failure across these platforms isn't hallucination - models generating false information - but omission: models generating plausible, incomplete information that clinicians act on as though it were whole.
For healthcare CFOs, the instinct will be to forward this to the CMO. That instinct is expensive.
What Your Vendor Contract Actually Says
Omission failures don't generate audit trails. There is no logged event, no flagged output, no artifact that says "the model skipped this step." When harm results from what the AI didn't say, the liability chain runs through your vendor agreement - specifically through whatever indemnification language your legal team negotiated, almost certainly before omission risk had been benchmarked at scale.
The standard carve-out in clinical AI procurement agreements transfers liability at the moment of clinical use. Language referencing "clinical judgment," "physician discretion," or "final determination" is doing one job: moving the exposure from the vendor's balance sheet to yours. Vendors are also inserting output-related exclusions that disclaim responsibility for outputs generated in response to user prompts - particularly where the health system has customized or fine-tuned the model. Most of these agreements were signed when hallucination was the primary concern. Omission is a structurally different risk, and it is largely unaddressed in the contracts currently sitting in your legal files.
This is not a clinical governance problem that happens to have financial consequences. It is a procurement problem with a clinical origin.
Where the Insurance Gap Lives
The coverage question is more unsettled than most CFOs realize. ISO's generative AI exclusion endorsements - released in early 2026 - give commercial general liability carriers the option to exclude bodily injury and property damage arising from AI use. W.R. Berkley introduced what it describes as an absolute AI exclusion across D&O, E&O, and fiduciary liability products. The exclusion language is broad: "any actual or alleged use, deployment, or development of Artificial Intelligence." That definition doesn't require AI to be the sole cause of harm.
The practical consequence: a CFO who approved clinical AI deployment without notifying carriers may face a coverage dispute on material non-disclosure grounds at the next renewal. That is not a clinical problem. That is a balance sheet problem, and it is one the NOHARM benchmark - by quantifying how often complete-looking outputs are actually incomplete - makes newly legible to underwriters.
Ask your malpractice and D&O carriers one question before renewal: does current coverage explicitly address AI omission events, cases where harm resulted from information the AI failed to surface rather than information it stated incorrectly? If the answer requires a pause, you have a gap that predates this week's study and will outlast it.
The jurisdictional picture adds a layer that a U.S.-centric read tends to flatten. Illinois signed the Artificial Intelligence Safety Measures Act this month, mandating annual independent third-party audits for large AI developers beginning in 2028. Illinois is now the third state - after California and New York - to impose transparency and safety obligations on frontier AI vendors. Because these models don't stop at state lines, the audit disclosures those laws require will have national effects. Health systems operating across multiple states should expect that omission-rate data, once surfaced through mandated audits, will become discoverable in litigation regardless of where the incident occurred. The compliance clock is not uniform, but the liability exposure is.
The Three Moves That Matter Now
This is a tighten-controls-now, renegotiate-on-renewal situation. Clinical AI is embedded deeply enough in large health systems that wholesale removal creates its own operational risk. The immediate decisions are narrower and more tractable.
Pull every active clinical AI vendor agreement and flag indemnification clauses containing "clinical judgment," "physician discretion," or "final determination." Those are your liability transfer points. Then ask vendors for omission-rate data - not accuracy metrics, omission metrics. These are not the same number, and a vendor who responds with only an accuracy scorecard is answering a different question.
Brief your malpractice and D&O carriers before your next renewal on the benchmark findings. Voluntary disclosure is cheaper than a coverage dispute after an incident. Document in writing that governance controls for clinical AI omission risk have been reviewed - not because documentation solves the problem, but because undocumented awareness is the worst of all positions when litigation arrives 18 months from now.
Seventy-five percent of U.S. health systems have deployed at least one AI solution. Eighteen percent have mature governance frameworks. The distance between those two numbers is where this week's study lands.
Source: Fortune, July 29, 2026. Authority: secondary/trade. Claims from supplemental research context are directional and not independently verified.

Responses
(0)Responses0