# “The professional decides” is a boundary and a design duty

25 August 2026 · Essay · 3 min read

By [Ahsan Fazal](https://axiomatic.digital/en/about#ahsan), Founder and CEO

Reading on human oversight of AI in health care ends in one conclusion I share: a signature proves presence, not supervision. “The professional decides” has to mean two things at once. A line Inora does not cross, and a design duty to put in front of the professional what she needs to decide without redoing the work.

On 4 August Henry Conter at Kesis & Sisters published [The Human in the Loop Is a Regulatory Fiction](https://kesis.ca/insights/the-human-in-the-loop-is-a-regulatory-fiction/). His example is an oncologist who signs off a recommendation that left out one fact, and could only have caught it by redoing the whole review. Her signature, he writes, proves that a doctor was present, not that the system was supervised. I keep using the phrase “the professional decides” when I write about Inora. This is the essay in which I ask what it is worth.

## The danger of the phrase

Used carelessly, “the professional decides” does the opposite of what it says. It becomes a way to move risk to the person at the end of the chain. Conter makes the case with errors of omission: a reviewer sees what the system showed and cannot see what it left out. If the phrase is only a label on a product, it is a shield for the maker.

So I give it two parts and hold myself to both.

**A boundary.** Inora gives no clinical judgement and does not diagnose. It supports a professional with her organisation’s knowledge. That is a statement about what the product is for, and the reason it falls outside the rules for medical devices. Tools that report on their own, which Hardian, a regulatory consultancy, describes in [Clinician in the AI loop](https://hardianhealth.com/insights/clinician-in-the-ai-loop), sit on the other side of that line. We are not building one.

**A design duty.** If the decision stays with her, the system owes her what she needs to take it: the criterion that applies, the source it comes from, and the gap where the sources are silent. Put these in front of her, and deciding no longer means doing the work again. That is the difference from Conter’s oncologist, and it is why I think his case does not carry over unchanged. His is a generated recommendation across seventy pages. A care worker asking what her organisation’s protocol says is asking for a bounded, checkable lookup, and I wrote about what that does to oversight in June, in [Oversight has to be designed](https://axiomatic.digital/en/updates/oversight-is-designed-not-staffed).

## Who answers for what

Traceability brings back an old rule: responsibility follows where the error came from. The content is the organisation’s protocol. Finding it and assembling the answer is the maker’s harness. The decision is the professional’s. Each stays with the party that controls it. I make no statement here about what liability Axiomatic accepts; that is a matter for contracts and for lawyers, not for an essay.

The record of what she was shown protects her. It belongs in the organisation’s compliance record, and it must never become a surveillance file on the care worker.

## Where I disagree

Conter writes that a clinician cannot see what an update changed. That holds for a hosted black box. It does not hold for a deployment that is pinned, on premises, and evaluated before a change, where the power to intervene sits with the organisation and whoever implements it. That is one more reason why whoever implements it cannot stand apart from the product.

Hardian’s three routes to a better loop do not exclude each other. Be a partner inside the shift. Let knowledge owners audit samples and gaps from beside the loop, so that the care worker does not review every answer. And be bolder only where the evidence supports it. For us that last one is limited to provenance and abstention: the sources are current and owned, and the system says when it does not know. Never a diagnosis.

Finally, moving all liability away from the professional would run against professional law, which leaves her duty of care in place. A shield made of a signature is wrong. A world in which she answers for nothing is wrong too.

## Do you work in care and use Inora?

Sign-in and help go through your own organisation: your team’s project lead and ambassadors can help you.

## Read on

- [A language model does not reason](https://axiomatic.digital/en/updates/a-language-model-does-not-reason.md): In 2025 I announced “reasoning” as a feature. The word was wrong. A language model picks the most likely next text, astonishingly well, and does not know what it does not know. So: the model writes, the sources decide what is true, code does what must be exact, the professional decides.
- [Oversight has to be designed](https://axiomatic.digital/en/updates/oversight-is-designed-not-staffed.md): Last month the BMJ called the clinician in the loop a liability sink. Being present is not the same as judging. The authors concede that oversight works on tasks that are bounded and checkable, so that is the design target: make the task checkable, put approvals where someone has time and authority, and test whether people still catch an error.
- [Read in parallel, decide in one place](https://axiomatic.digital/en/updates/read-in-parallel-decide-in-one-place.md): Do not build multi-agent systems, said one lab in 2025; multi-agent systems are working, said the same lab in 2026. Both are right once you separate reading from writing. In care the implicit decisions behind an answer are specific, and the line between reading and deciding has to be drawn in the harness, not left to the model.
