Agent-Based AI in Medicine: Potential, Practice, and Guidelines

Although already in use in research, agent-based AI still lacks clear rules in practice. A policy brief from the Leopoldina examines the opportunities and legal hurdles. An overview.

Photo: Generated by Gemini
Hanna Sachse
July 23, 2026
Leopoldina Focus | Leopoldina National Academy of Sciences; FirstWord Pharma; BMG; EMA

First, an overview

  • Proactive Scope of Action: Unlike standard, reactive AI, agent-based AI acts proactively based on large language models and foundation models (LLMs/Foundation Models) and can independently coordinate complex clinical processes, from diagnosis through follow-up care. (Source: Policy Brief from the German National Academy of Sciences Leopoldina.)‍
  • Practical Applications in Research: In the pharmaceutical and biotech industries, agent-based and data-driven systems are already being used in specific applications such as molecular drug discovery, protein analysis, and reducing the number of failed clinical trials. (Sources: Practical applications from Bayer & Iambic Therapeutics, Chan Zuckerberg Biohub, Verge Labs, Anthropic, Bristol Myers Squibb & NVIDIA, and OpenAI.)‍
  • Security Risks and Regulation: Risks such as the re-identification of patient data, a lack of traceability (“black box”), and cyber threats require a clear legal framework. (Sources: Study by the Technical University of Munich, Imperial College London, and the HPI (Nature); University of Marburg (FlowXAI); Leopoldina; draft legislation (GeDIG); and statements from the EMA (Emer Cooke) and the EU AI Act.)

How It Works: The Difference Between Conventional and Agent-Based AI

The digitization of the healthcare system continues to face structural challenges: a shortage of skilled workers, high administrative burdens, and insufficient integration of clinical data are straining healthcare delivery. Against this backdrop, the German National Academy of Sciences Leopoldina is investigating the use of agent-based artificial intelligence.

Compared to AI applications used to date, agent-based AI differs primarily in its scope of action:

  • Conventional AI systems operate reactively. They perform specific, predefined tasks—such as identifying structures in medical images or conducting statistical analyses of datasets—and provide recommendations to staff.
  • Agent-based AI systems operate proactively. They are typically based on large language models (LLMs) combined with domain-specific foundation models. These systems can automate processes based on medical guidelines, standard operating procedures (SOPs), or medication rules.

In clinical practice, this means that in the event of an acute heart attack, agent-based AI would no longer simply make the diagnosis. It would immediately alert the treatment team, propose a guideline-based therapy, monitor vital signs in real time, and independently coordinate follow-up appointments and rehabilitation during the post-treatment period. In oncology as well, AI could in the future create personalized treatment plans based on molecular genetic tumor analyses and manage preliminary examinations.

(Glossary | Graphic: Gemini Generated)

Current Applications in Pharmaceutical and Clinical Practice

In medical and pharmaceutical research, data-driven and agent-based systems are already being used for specific subtasks:

  • ‍Molecular drug discovery: Bayer is using the AI platform developed by Iambic Therapeutics to identify small molecules that specifically target hard-to-reach protein structures using structure prediction models. The Chan Zuckerberg Biohub released ESMC and ESMFold2, AI models for calculating and predicting protein interactions.‍
  • Reducing Clinical Trial Dropouts: The startup Verge Labs uses the vBx-1.0 model to simulate molecular activity in the brain based on blood samples. The goal is to determine in advance, for neurological diseases such as Parkinson’s, which patients will respond to specific drugs, in order to reduce high dropout rates in clinical trials.‍
  • Research Platforms: With Claude Science, Anthropic provides a software environment that links data from genomics, proteomics, and cheminformatics with scientific literature to enable centralized analysis of research workflows. Bristol Myers Squibb uses NVIDIA’s supercomputing infrastructure to run data-intensive analytical models in oncology and immunology.‍
  • Safety Assessments for Language Models: OpenAI had the GPT-5.5 Instant model evaluated by doctors using standardized criteria (HealthBench). The goal is to ensure that the model provides more accurate answers to users’ medical questions and identifies emergencies more reliably.

‍

Security Risks: Data Protection, Traceability, and Cybersecurity

The use of autonomous systems in the medical field entails specific risks, as highlighted by both the research community and the Leopoldina:

1. Re-identification Due to Data Protection Gaps‍

A study by the Technical University of Munich (TUM), Imperial College London, and the Hasso Plattner Institute, published in the journal *Nature*, shows that medical AI models are vulnerable to so-called membership inference attacks (MIAs). Using this method, attackers can determine whether a specific person’s data was used to train the model. This risk particularly affects rare medical conditions or underrepresented patient groups, which can be identified with near certainty. If third parties can draw conclusions about diagnoses, those affected may face disadvantages, such as when taking out insurance policies. The researchers are calling for the use of protective measures such as differential privacy, in which noise is incorporated into the training data.‍

2. Traceability (“Black Box Problem”)

To ensure that decisions remain understandable to medical staff, AI models must operate transparently. One example of this approach is the FlowXAI system developed by the University of Marburg for diagnosing B-cell lymphomas. The system not only displays the diagnostic result but also reveals which cell characteristics were decisive and rates its own reliability in categories such as “certain,” “probable,” or “difficult.”

3. Systemic and Organizational Risks

The Leopoldina also points to the risk of “deskilling,” in which medical staff lose practical skills due to excessive automation. Furthermore, AI agents’ autonomous access to clinical databases increases the attack surface for cyberattacks. There is also a structural conflict of objectives: To avoid biases in the algorithms, large amounts of data are required, which in turn places high demands on data protection.

‍

Regulatory Framework and Legislation

To reduce dependence on non-European providers, the Leopoldina recommends making domain-specific AI models for medicine a priority in the German federal government’s high-tech agenda. In addition, regional centers of excellence should be established, and collaboration between university hospitals and industry should be facilitated.

From a legal perspective, the Academy calls for a pragmatic application of the General Data Protection Regulation (GDPR). Data protection should not be interpreted one-sidedly as a right to prevent action if doing so would undermine the goal of ensuring a high level of health protection. Legal requirements must be designed in such a way that processes run efficiently, while the final decision and responsibility remain demonstrably with healthcare professionals (Legal Design Thinking).

At the same time, the legal framework is changing:

  • National: The Federal Cabinet has approved the draft of the Act on Data and Digital Innovation in Healthcare (GeDIG). It provides for the expansion of the electronic patient record (ePA), the introduction of digital referrals, and the simplified use of health data for care and research purposes.
  • European: The European Medicines Agency (EMA) uses AI applications to support its evaluations and highlights the importance of regulated data spaces such as DARWIN EU and the European Health Data Space (EHDS). Together with the EU AI Act, the goal is to ensure that AI-driven developments meet quality and safety standards.
The cover of *Leopoldina Fokus* on the topic: Agent-Based AI in the Healthcare System. (Photo: Cover screenshot)
The conclusion in “Leopoldina Fokus” is:

“The integration of agent-based AI into the healthcare system is not a distant future scenario, but is already taking shape. Agent-based AI has the potential to improve the quality of care while simultaneously reducing the workload on medical and administrative staff. Therefore, the conditions for its responsible use should be established now. This requires effective funding strategies, a clearly defined legal and ethical framework, and a well-developed, interoperable, and resilient digital infrastructure. Agent-based AI systems offer concrete approaches for structuring processes in medical research and healthcare organizations and relieving specialized staff of administrative tasks.”

“Artificial intelligence is rapidly changing the way drugs are developed and regulated. As a regulatory agency, it is our responsibility to be both pioneers and gatekeepers...”
Emer Cooke, Executive Director of the European Medicines Agency (EMA) (Source: Euractiv Health Policy Conference and AIMed2026)
If you'd like to know more

The Policy Brief

The policy brief “Agent-Based AI in the Healthcare System: Opportunities and Challenges” is available at: www.leopoldina.org/agentische-ki

According to Leopoldina, the decision-making process of agent-based AI is divided into four phases:

  1. Target Acquisition: The system receives a higher-level directive.
  2. Planning: The task is broken down autonomously into logical substeps.
  3. Implementation: The agent uses application programming interfaces (APIs) to interact with external programs or databases.
  4. Feedback loop: In the event of deviations, the system either corrects the process automatically or transfers the task to qualified personnel.

Field Update: OpenAI Launches "ChatGPT Health" in the U.S. (July 23, 2026)

OpenAI has announced the launch of “ChatGPT Health” in the U.S. Health data, including entries from Apple Health and electronic health records from U.S. hospital systems, can be linked directly to the platform. The reason for this feature: According to OpenAI, over 300 million people already use the platform weekly for health-related matters, such as understanding lab results or preparing for doctor’s appointments.

As one user describes, the benefit is this: “…it helped me feel less lost when it came to my own medical history. Instead of just seeing a jumble of diagnoses, test results, and surgery reports, I was able to understand the big picture.”

Some other aspects include:

  • Organizing Data: Diagnoses, surgical reports, and lab results can be compiled into a chronological overview.
  • Preparing for doctor's appointments: Medical terms are translated into everyday language. Several testers reported that this helped them ask more specific questions during conversations with doctors or therapists.
  • No substitute for qualified staff: One participating caregiver emphasized that the main benefit does not lie in replacing medical staff, but rather in gaining a better understanding of one’s own data—for example, to specifically address unexpected entries in the medical record during the next doctor’s visit.
  • Privacy Policy: According to OpenAI, synchronized health data and the chats based on it are not used for training the base models or for advertising.
  • Model Architecture: The model variants used for evaluation are GPT-5.5 Instant (free to use) and GPT-5.6 Sol (paid subscriptions).

Impact on Healthcare and the Pharmaceutical Industry: When patients use AI to process medication plans, drug interactions, or package inserts, it changes their understanding of their own treatment and the accuracy with which they take their medication—or their adherence to treatment in general. Pharmaceutical companies must therefore present medical information in the future in a way that allows AI systems to interpret it accurately. Furthermore, manufacturer-specific apps will become less important if patients prefer to collect their health data on a single, centralized AI platform rather than across many different applications.

Background: The rollout is taking place amid legal disputes in the U.S. At least two lawsuits are currently pending against OpenAI, accusing the company of providing incorrect medical advice that led to serious health complications. OpenAI notes that the system is capable of making errors and is not a substitute for professional medical advice.

Cabinet Passes Law on Data and Digital Innovation in Healthcare

On July 15, 2026, the Federal Cabinet approved the draft of the Act on Data and Digital Innovation in Healthcare (GeDIG). The aim of the Act is to integrate the benefits of digitalization more fully into healthcare for insured individuals and healthcare providers, and to further improve opportunities for using health data for research, innovation, and healthcare.

More Articles
Deepfake Medical Professionals: “You want real truth in advertising”
July 30, 2026
Agent-Based AI in Medicine: Potential, Practice, and Guidelines
July 23, 2026
Pharmaceutical Communication: The Celebrity Factor vs. Patient Trust
July 9, 2026

Kicking Off the Industry Dialogue: The New Forward Pharma Podcast

Kicking Off the Industry Dialogue: The New Forward Pharma Podcast
August 10, 2026
Listen now
Listen to the podcast
"FORWARD PHARMA"
analyzes the key trends in the healthcare and pharmaceutical industries. We provide context for current topics and speak with experts.
Click here for the
FORWARD PHARMA
Podcast