Artificial intelligence is already part of contemporary medical practice, whether as visible support in tests and alerts or as silent infrastructure that organizes queues, summarizes information and automates routines. In this scenario, the question is no longer “whether” AI will be used, but how to incorporate it with clinical judgment, preserving patient safety, confidentiality and professional autonomy.
Resolution No. 2.454/2026 of the CFM (Brazil's Federal Council of Medicine) comes to give shape to this use. It neither promotes technological infatuation nor prohibits innovation. It establishes a principle that, for medicine, is non-negotiable: AI is a support tool; the decision and the responsibility remain with the physician.
Below is what changes in practice and how to apply this understanding in the doctor's office, in emergency care and in the management of the service.
1) What this Resolution is (and what it is not)
What it is
The Resolution works as an ethical and professional framework to guide the use of artificial intelligence in medicine, covering everything from research and development to governance, auditing, monitoring, training and the responsible use of models, systems and applications in the healthcare context.
It also plays an essential role in “naming things”: it presents a set of structuring definitions that help reduce ambiguity in practice and in management. These include concepts such as AI model, AI system, AI application in medicine, lifecycle, generative AI, LLM, auditability, explainability, contestability, privacy by design and privacy by default.
What it is not
At the same time, it is important to understand what the Resolution does not intend to do:
- It does not authorize replacing clinical judgment with automation.
- It does not turn the output of a system into a “mandatory course of action”.
- It does not exempt compliance with the Code of Medical Ethics or other CFM rules.
2) The central idea: AI supports, but does not decide
The Resolution authorizes the use of artificial intelligence as a tool to support medical practice, but is careful to delimit, unambiguously, where the role of technology ends and where the non-transferable core of the profession begins.
In practice, this means that AI can contribute suggestions, alerts and analyses, but the physician must use it exclusively as a support tool, remaining ultimately responsible for clinical, diagnostic, therapeutic and prognostic decisions. Likewise, models, systems and applications cannot restrict or replace professional authority: the decision on diagnosis, prognosis, prescription or any medical act always remains subject to human judgment, and the physician may accept or reject the system's recommendation according to their clinical judgment.
“AI informs; the physician decides.”
3) The physician's checklist: what changes in clinical practice
The Resolution sets out explicit duties, and several of them directly affect day-to-day practice.
3.1 Human oversight and critical judgment (non-negotiable)
Physicians must exercise critical judgment over the information and recommendations provided by AI and keep up to date on the capabilities, limitations, risks and known biases of the systems they use. The rule reinforces that solutions are not sovereign and that human oversight is mandatory.
- Being wary of overly confident answers in complex cases.
- Validating against history, physical examination, tests and epidemiology.
- Treating AI as support, not as an arbiter.
3.2 Recording in the medical record when AI is used as support
The Resolution is explicit: there is a duty to record in the medical record the use of AI systems as support for medical decisions. A sufficient record should contain:
- Tool or system (name and version, if available)
- Purpose (support for a hypothesis, triage, summarization, drafting, etc.)
- Relevant result (in clinical terms)
- Medical validation (what was confirmed or ruled out and why)
- Final course of action
3.3 Informing the patient when the use of AI is relevant
Patients have the right to be informed, clearly and accessibly, when AI models, systems or applications are used as relevant support in their care, diagnosis or treatment.
Suggested approach: “In addition to my assessment, we use a computational support tool that suggests hypotheses and alerts. I have checked its consistency with your condition, and the final decision is a medical one.”
3.4 Health data: confidentiality and security
The Resolution requires safeguarding the confidentiality, integrity and security of health data used by AI (under the LGPD, the Brazilian General Data Protection Law), limits sharing to the stated purpose and prohibits solutions that do not guarantee minimum security standards.
3.5 Failures and incidents: the duty to report
The physician remains fully responsible for medical acts performed with the use of AI and must report relevant failures or risks to the competent bodies.
4) The physician's rights: autonomy, information and refusal
- The right to clear information on operation, purpose and scientific evidence.
- The right to refuse systems without the relevant regulatory validation or certification.
- The right not to be obliged to follow AI recommendations automatically and uncritically.
- Protection against undue liability for failures attributable exclusively to AI (diligent use).
There is also a relevant organizational point: institutions and health plan operators must not impose targets or policies that subordinate physicians' conduct to automated results.
5) Risk classification: when AI becomes a governance matter
The Resolution requires a preliminary assessment to define the level of risk (high, medium, low or unacceptable), taking into account impact, criticality, model autonomy and data sensitivity.
- Low risk: minimal or no potential for negative consequences.
- Medium risk: potential adverse impact, which can be mitigated with active human oversight.
- High risk: high potential for harm; requires rigorous validation, audits and monitoring.
6) What changes for hospitals, clinics and health plan operators: real governance
The Resolution requires specialized audit mechanisms and continuous monitoring. Institutions that adopt their own systems must create an AI and Telemedicine Committee under medical coordination.
The EU AI Act (Regulation (EU) 2024/1689) is useful as a map of regulatory maturity, with risk-based governance, documentation and post-market monitoring. It focuses on transparency, accuracy, robustness and cybersecurity.
The Bill points to trends such as effective human oversight, explainability and auditability throughout the lifecycle. It reinforces the path towards more traceability and governance in healthcare.
FAQ: questions physicians actually ask
Yes, as support, with critical review. Clinical judgment and recording in the medical record are required.
Yes, when AI is used as relevant support in care or diagnosis.
No, not without human mediation. There is an express prohibition.
Yes. The duty is explicit.
The physician. The final decision is always human.
Yes. The rule protects autonomy and prohibits policies that subordinate medical conduct to automated results.
How to bring AI use into compliance: 10 steps to get started
For the Physician
- Define the clinical purpose and avoid use outside that context.
- Maintain human oversight and validate recommendations.
- Inform the patient clearly.
- Record the tool, purpose and validation in the medical record.
- Report failures and risks to the competent bodies.
For Management
- Carry out a documented preliminary risk assessment.
- Classify the system and communicate its limits to users.
- Implement governance proportionate to the risk.
- Ensure compliance with the LGPD and health data security.
- Protect medical autonomy and avoid automated pressure.


