The four-module series addresses clinical judgment, patient trust and AI oversight, but California practices must separately manage disclosure, recording consent, privacy and liability concerns.

The American Medical Association launched a continuing medical education series on Aug. 26 to help physicians evaluate and use artificial intelligence responsibly in clinical practice.

Developed with the Duke Institute for Health Innovation and Health AI Partnership, the Ethical AI Use in Medicine Series includes four case-based modules. The curriculum covers AI evaluation and monitoring, clinical decision-making, mortality-prediction tools, and ambient AI scribes. It emphasizes bias awareness, patient communication, physician verification, and appropriate reliance on AI-generated information.

The subjects are potentially relevant across specialties as physicians encounter AI-generated documentation, patient communications, and clinical recommendations. The AMA’s central message is that AI can augment care but should not replace physician judgment or ethical responsibility.

For California physicians, however, ethical guidance represents only part of the implementation challenge.

Since Jan. 1, 2025, California’s AB 3030 has required physician offices, group practices, clinics, and health facilities to notify patients when they use generative AI to create specified communications containing patient clinical information. The law excludes administrative communications involving matters such as scheduling and billing.

The notice requirement does not apply when a licensed or certified human healthcare provider reads and reviews the communication. Practices must therefore decide whether each covered communication will undergo qualified human review or include the required notice. Medical assistants do not qualify as healthcare providers for this exemption.

Ambient scribes raise separate consent questions. California Penal Code Section 632 generally prohibits intentionally recording a confidential communication without the consent of all parties. Practices using an ambient system that records clinical encounters should determine how they will obtain and document consent and what workflow they will follow when a patient declines. Whether the law applies to a particular product may depend on how the technology captures, processes, and retains audio. 

Practices must also determine whether an AI vendor creates, receives, maintains, or transmits protected health information on their behalf. When that relationship makes the vendor a HIPAA business associate, the practice generally needs an appropriate business-associate agreement. Contracts should address permitted data uses, security, subcontractors, retention, deletion, and incident reporting. 

A business-associate agreement does not resolve every privacy issue. California practices must also evaluate their obligations under the Confidentiality of Medical Information Act, including how vendors access, reuse, and disclose medical information.

Liability allocation remains less settled. The AMA’s guidance says physicians should critically evaluate AI output, apply patient-specific context, and override results that conflict with sound clinical judgment or patient goals. The CME series does not purport to create a legal safe harbor or determine how responsibility would be divided among physicians, healthcare organizations, and technology vendors after an AI-related error. 

The new series may help physicians ask better questions about clinical AI. It cannot replace practice-level governance, vendor review, legal analysis, or continued monitoring of AI performance. The AMA has not yet published enrollment, completion, physician-behavior, or patient-outcome data for the program.

Key takeaways for physicians

  • Review each AI application for disclosure, consent, and privacy implications.

  • Determine whether covered AI-generated clinical communications will receive qualified human review or carry the notice required by AB 3030.

  • Establish consent and alternative-workflow procedures for ambient recording.

  • Examine vendor contracts, data use, retention, security, and deletion practices.

  • Verify AI-generated documentation and clinical recommendations before relying on them.

  • Do not assume that completing CME establishes legal compliance or limits liability.