Artificial intelligence in medicine: where it helps and who decides
Artificial intelligence in healthcare already takes part of the work around the appointment off the doctor: answering messages, booking times, transcribing a conversation. The limit is just as clear: for the CFM, the Brazilian medical council, the decision is always the one of the doctor. This guide shows both sides, with the rules in hand.
What artificial intelligence already does in a practice today
Artificial intelligence in a medical practice shows up first in the work around the appointment. At 9 pm on a Sunday, a patient sends an audio asking whether there is a time on Thursday. The artificial intelligence transcribes it, looks at the calendar and offers the free times. On Thursday, the doctor records the appointment and comes out with a draft note to check.
There is also clinical use, such as reading images, risk alerts during a hospital stay and support for diagnosis, triage and treatment suggestions. That side follows another ruler, with other requirements, and the next sections show where it begins.
Front desk: answering questions about address, preparation and times on WhatsApp
Calendar: checking free times and booking the appointment
Transcription: turning the audio of the appointment into text
Summary: condensing the history of the patient for the doctor to read before seeing him
02
Artificial intelligence in clinics: before, during and after the appointment
Before the appointment, artificial intelligence answers whoever asks about the address, the preparation or the next free time. The CFM cites scheduling and a chatbot with general information, without personalized clinical advice, as examples of low risk.
During the appointment, the transcription takes the doctor away from the keyboard. Afterwards, artificial intelligence helps to organize the text into history and note. What it writes is a draft, and the doctor checks it before it counts.
Neither the CFM nor Anvisa explicitly classify the transcription of an appointment. CFM Resolution 2.454/2026 cites help in drafting clinical documents as a use of a language model, without giving it a risk level.
03
Artificial intelligence in medicine under CFM Resolution 2.454/2026
The CFM published Resolution 2.454 in the Official Gazette on 27 February 2026. It came into force 180 days after publication (art. 23). By the usual count, that means 26 August 2026. The summary is direct: it sets the rules for the use of artificial intelligence in medicine.
The central rule: artificial intelligence is exclusively a support tool. The doctor is the one finally responsible for clinical, diagnostic, therapeutic and prognostic decisions (art. 4, I), and answers in full for the acts he performs with artificial intelligence (art. 7). The resolution also protects him from answering for a failure attributable only to the system, when he shows diligent and critical use (art. 3, V).
The text carries a tension. Art. 5 speaks of informing the patient when artificial intelligence is a relevant support; art. 11 says that any use has to be communicated and explained. Telling the patient satisfies both.
Record in the health record the use of artificial intelligence as support for the medical decision (art. 4, V)
Inform the patient and respect an informed refusal of the use of artificial intelligence (art. 5)
Do not let artificial intelligence communicate a diagnosis, a prognosis or a treatment decision without human mediation (art. 5, paragraph 2)
Use artificial intelligence only with information security suited to sensitive data (art. 6, paragraph 3)
Keep human supervision: artificial intelligence systems are not sovereign (art. 15, sole paragraph)
04
Risk levels and what changes for the clinic
The resolution asks for a preliminary assessment of the degree of risk: low, medium, high or unacceptable (arts. 12 and 13). Annex II defines the first three. The unacceptable level was left without a definition in the text.
Even at low risk, the system has to be monitored and reviewed periodically. Whoever develops or hires artificial intelligence, an institution or a doctor, needs internal governance processes (art. 14). The technical director answers for the internal oversight, and the external one belongs to the CRM, the regional medical council (art. 15 and Annex III).
A doctor who does not follow the artificial intelligence, acting within technical and ethical precepts, cannot be penalized for it. And the institution cannot impose targets that put medical conduct below them (art. 19).
Low: appointment scheduling, a chatbot with general health information without personalized clinical advice, translation of health records, a summary of literature for internal use
Medium: systems that support clinical decisions without carrying out the decision on their own
High: systems that directly influence critical decisions or carry out automated actions with a clinical consequence
05
When software becomes a medical device at Anvisa
Anvisa, the Brazilian health surveillance agency, regulates software as a medical device through RDC 657/2022. Software used exclusively for administrative and financial management in a health service stays outside it (art. 1, paragraph 2, III).
In a questions and answers document, Anvisa says that a system for calendar, booking, health record and communication is not a device subject to registration, even with a chatbot, WhatsApp and voice recognition. The document is from 2022 and still cites RDC 185/2001, later replaced by RDC 751/2022.
By the same document, a system that includes automatic functions of diagnosis, triage or treatment suggestion becomes a medical device. The class follows RDC 751/2022 and depends on the use: software that informs a diagnosis or treatment decision falls, as a rule, between classes II and IV (Rule 11). Classes I and II ask for a notification; III and IV, for a registration.
The review of RDC 657 is in the Regulatory Agenda 2026/2027 of Anvisa, with the inclusion of artificial intelligence items among the goals. In the research for this guide, in September 2026, no new rule had been published.
06
LGPD: health data is sensitive data
For the LGPD, the Brazilian data protection law, data about health is sensitive personal data (art. 5, II). It may be processed without consent for the protection of health, exclusively in a procedure carried out by health professionals, health services or a health authority (art. 11, II, f).
Pasting the conversation of a patient into a generic artificial intelligence tool usually means sharing sensitive data with a third party. The CFM only allows that sharing when it is strictly necessary and rests on a sound legal basis (art. 6, paragraph 1).
Whoever processes data on behalf of the controller is the processor, and follows the instructions received (arts. 5 and 39). In the ANPD guide, the doctor who sees patients as an independent professional is the controller of the health records. In a system the clinic hires, the clinic or the doctor tends to be the controller, and the supplier the processor who follows those instructions.
07
How Clinivum uses artificial intelligence with the doctor in control
The artificial intelligence of Clinivum takes care of the administrative front desk and helps the doctor to record the appointment. On WhatsApp, the standard instruction is not to talk about diagnosis, exams or treatment, and to say that the doctor advises during the appointment. Inside the system, what it writes is text for the doctor to check. The one who decides is always the doctor.
No automatic message goes out to a number that is not on the allowed list of that WhatsApp connection. With the list empty, nothing goes out on its own. And the appointment can also be done without artificial intelligence, when the doctor or the patient prefers it.
The data of each clinic stays separate from the data of other clinics. The text sent to the artificial intelligence goes to a language model of another company, and the requests are set up to use only providers that declare they do not keep the data nor train models with it.
On WhatsApp, it answers questions and uses the real calendar: free times, booking and appointments already made
It understands a voice message: it transcribes the audio and answers
When someone on the team answers in the chat, the artificial intelligence pauses in that conversation. By default it comes back after 6 hours, and the clinic adjusts that interval
On WhatsApp with the patient, the artificial intelligence does not read a photo or a document it receives. In a conversation linked to a patient, the file becomes an attachment of the health record and raises a notice for the team to check
In an appointment with artificial intelligence, the recording becomes a transcription and a draft of history and note. The text is only saved to the health record when the doctor reviews and validates the appointment
The summary of the history helps the doctor to pick up the health record again before seeing the patient
Each appointment keeps whether artificial intelligence was used and which model, and the timeline of the patient marks the appointments done without it
08
A checklist for doctors before hiring artificial intelligence
Before turning on any tool, it is worth asking the supplier a few questions. They come straight from the rules cited in this guide.
A prudent start is with low risk use, such as scheduling and answers with general information, without personalized clinical advice. In Clinivum, the calendar and the WhatsApp front desk have pages of their own, in the features group in the footer.
Does the tool do only administrative work, or does it get into diagnosis, triage and treatment suggestions?
Which risk level does the supplier state, as CFM Resolution 2.454/2026 asks?
Where does the data of the patient go, and does the supplier use that data for other purposes?
Can you pause the artificial intelligence, take over the conversation and work without it when the patient refuses?
How does the use of artificial intelligence get recorded in the health record?
If it is a medical device, does it have a notification or a registration at Anvisa?
Questions
Frequently asked questions about artificial intelligence in medicine
Will artificial intelligence replace the doctor?
CFM Resolution 2.454/2026 does not allow artificial intelligence to restrict or replace the final authority of the doctor (art. 18, paragraph 1). Artificial intelligence is only a support tool, and the decision about diagnosis, prognosis and prescription always belongs to the doctor (arts. 4 and 18).
Is artificial intelligence in medicine regulated in Brazil?
For the CFM, yes: Resolution 2.454/2026 is already in force, because the period of 180 days after publication ended at the end of August 2026. Anvisa regulates the software that is a medical device through RDC 657/2022. The general artificial intelligence bill, PL 2338/2023, passed the Senate in December 2024 and, on 16 September 2026, was waiting for an opinion in the Chamber of Deputies. It is not law yet.
Is artificial intelligence in medicine safe?
It depends on the use and on the supervision. A language model can write, in a confident tone, something that is not in the data. That is why its text is a draft until the doctor checks it. The CFM requires human supervision and security suited to sensitive data, and asks that even low risk artificial intelligence be monitored.
Do I need to tell the patient that I use artificial intelligence?
Yes. The resolution of the CFM gives the patient the right to be informed, and art. 11 speaks of communicating and explaining any use. The patient may refuse, and the doctor has to respect that. Use as support for the decision also has to be recorded in the health record (art. 4, V).
Can I paste patient data into a generic artificial intelligence?
Health data is sensitive under the LGPD. The CFM only allows sharing data with artificial intelligence when it is strictly necessary, with a sound legal basis and with security suited to sensitive data. Before that, check where the data goes and what the supplier uses it for.
Can I use artificial intelligence to write a sick note, a report or a medical opinion?
As help with the drafting, you can. CFM Resolution 2.454/2026 cites help in drafting clinical documents as an example of the use of a language model. The doctor reviews it, signs it and answers in full for the document (art. 7).
Does the artificial intelligence of Clinivum decide anything for the doctor?
No. On WhatsApp, it takes care of administrative matters, checks the calendar and books a time, and the standard instruction is not to talk about diagnosis, exams or treatment with the patient. In an appointment with artificial intelligence, the text it writes is only saved to the health record when the doctor reviews and validates it. The clinical decision is always the one of the doctor.
Does artificial intelligence answer patients on its own on WhatsApp?
Only with artificial intelligence turned on in the front desk mode of that connection, and only for numbers on its allowed list. With the list empty, nothing goes out on its own. When someone on the team answers, the artificial intelligence pauses in that conversation.