Enjoying The Bandwidth? I'm working on growing my readership. Referrals are the best way. So, if today's issue was useful, forward it to a colleague or friend working at the intersection of health and AI. Now let’s get to it.

🚀 Mission View: A sharper perspective on this week's top issues that matter at the intersection of health and AI.

Readers will notice a few things in the headlines below. It was yet another heavy week for new models. At the same time, there is escalating concern about how fast those models are advancing, and what they're capable of doing outside the bounds their humans designed them for. Some are calling it rogue behavior by AI. Others are calling it the early shape of sovereign agents, answerable to no one. Either way, the commentary and the proposed fixes are piling up fast – especially in the wake of the OpenAI/Hugging Face breach earlier this summer and the safety analysis that followed.

All of that left me second-guessing what to write about this week. In the end, I landed back on my original idea: California. It's the country's most populous state, one of the world's largest economies, and it sits at the frontier of nearly everything AI touches. So it felt right to look at the closing days of California's legislative session, and how this state may be writing the playbook for AI governance when governance is increasingly top of mind — especially in health care. What's the saying? As California goes, so goes the nation.

A specific kind of bill.

Most of the AI health coverage this year has centered on chatbots and companionship apps aimed at consumers, and California passed one of the year's most closely watched: SB 1119 would let families and the state sue chatbot makers, require age verification, and limit what young users are exposed to — the bill Sam Altman reportedly lobbied Newsom on directly (more on that below).

But four other bills also tell an interesting story, because they're not written for the general public. They're written for the clinical encounter itself:

  • SB 503 would require developers and deployers of medical AI to document the intended use of clinical decision support tools, identify foreseeable risks of biased outcomes, and monitor those systems on an ongoing basis after deployment.

  • AB 2575 would guarantee healthcare workers the right to override an AI-assisted clinical recommendation using their own judgment, and bar employers from retaliating when they do.

  • AB 1979 would classify health care chatbots as health care providers under California's Confidentiality of Medical Information Act, pulling them into the same privacy framework that governs a hospital or a physician's office. It would also ensure that AI systems do not substitute for licensed professional judgment in clinical care.

  • SB 903 addresses how AI transcribes and retains what patients say during mental health therapy sessions, aiming to close a gap where those conversations weren't clearly covered by existing confidentiality rules. It would also put some boundaries around what an AI chatbot could be allowed to do (e.g., making therapeutic decisions).

These bills come on top of a number of already existing measures in place in the Golden State (e.g., disclosure requirements when AI is used in patient communications, rules around deceptive AI representation and marketing as a licensed health professional, and limits on the use of AI in medical necessity determinations).

None of these new bills ban AI outright (though that’s now not off the table at the federal level, per a new measure introduced by Bernie Sanders. More on that below).

What they do is assume the technology is already here, is marching forward more and more into healthcare, and start to answer some of the lingering questions that have arisen: who is liable, decision rights, and privacy protections.

Why it matters beyond California.

Congress has shown little appetite for a comprehensive federal framework governing AI in healthcare, which leaves states to build most of the rules one at a time for now.

Whether or not other legislatures copy California’s proposals directly, vendors selling AI tools should expect some of these requirements to become table stakes, not a California quirk.

Furthermore, as has been the case so many times before, when California sets the high-water mark, companies tend to build to that state's standard rather than maintain fifty different versions of the same workflow.

Newsom has until September 30 to sign or veto. I'll be watching to see which of these he keeps.

Till next time,

BC

🛜 Field Signals: A quick hit on this week's industry announcements, policy developments, and ethical considerations.

🏗️ Industry news

Healthcare organizations can now connect EHR and additional industry data to ChatGPT — OpenAI launched a new Epic integration for ChatGPT for Healthcare that lets clinicians pull authorized patient records directly into the chat interface, alongside a Healthcare Public Data plugin connecting to nine official sources including ClinicalTrials.gov, PubMed, DailyMed, and CMS Coverage. In OpenAI's own physician-led evaluation, spanning 27 clinical use cases and more than 4,300 ratings, 99.1% of responses were rated safe, though the results are self-reported and haven't been independently verified.

Meta debuts Muse Spark 1.3 as personal agent work continues — Meta released Muse Spark 1.3, an update it says significantly improves coding and agentic performance, as AI chief Alexandr Wang told Axios the release lays groundwork for upcoming products like personal agents that can "work 24/7 on your behalf." The update lands amid a flurry of frontier model releases this week from Google, Anthropic, and OpenAI, with Wang noting that unlike some rivals, Meta hasn't had to pause development to address safety concerns, though it has "meaningfully increased" its safety and alignment investment.

Google launches Gemini 3.8 Flash and a specialized cybersecurity variant — Google released Gemini 3.8 Flash, its third Flash-tier update in six weeks, with gains in coding and multi-step reasoning at the same price as its predecessor, alongside Gemini 3.8 Flash Cyber, a cybersecurity-focused model offered to vetted defenders through a new "Fairwind Program." Google says the cyber variant already found a critical vulnerability in its own cloud infrastructure in under two hours and produced more correct Chrome security patches than larger commercial models, though the comparisons are self-reported.

Anthropic launches Claude Fable 5.1 and Mythos 5.1, with new life sciences access program — Anthropic's latest models are cheaper to run and, in early testing, showed a real knack for drug design: Mythos 5.1 designed protein-based drug candidates that bound to their targets up to 10 times more tightly than the best submissions in outside competitions, with roughly half of its designs working, well above the 10-15% success rate typical in the field. The company also launched a Life Sciences Verification Program, developed with the U.S. government, giving vetted researchers access to Mythos 5.1's fuller biology capabilities, while its general-release safeguards now flag 85% fewer benign medical and biology queries than earlier versions.

NVIDIA agrees to acquire Hugging Face for $12.9 billion — NVIDIA announced it's buying Hugging Face, the online hub where developers share and download AI models — used by more than 18 million people worldwide. CEO Jensen Huang said the platform will stay open: it won't require NVIDIA's hardware or software to use, and outside developers can keep building with whatever tools they prefer. The deal comes just weeks after Hugging Face's own systems were the target of a high-profile AI-agent breach that's been fueling much of this summer's safety debate.

OpenAI launches GPT-6 Astra, its most capable and most aligned model yet — OpenAI released GPT-6 Astra, which the company says is its smartest model to date, with gains in science, coding, and the ability to operate a computer on a user's behalf. OpenAI also built a new safety test based on this summer's Hugging Face breach to check whether the model would exceed its assigned task, and says Astra passed every time, versus roughly half the time for its predecessor without safeguards. The model is also powerful enough to find real, previously unknown security vulnerabilities, so its more advanced cyber capabilities are being rolled out slowly and only to vetted users.

🩺 At the point of care

Health systems redesign hospitals with new tech, AI — Houston Methodist is testing AI-powered cameras in its operating rooms that flag when surgeons are using more supplies than expected, spot slow room turnarounds, and catch misaligned physician schedules, on top of nearly $11 million already spent wiring hospitals for remote patient monitoring. Cleveland Clinic's new neurological institute, opening in January, will use camera-based tracking to measure how a patient's gait changes between visits, while automated guided vehicles ferry supplies through both that building and Nationwide Children's Hospital.

Hospitals are all in on AI, but testing and oversight haven't caught up — A new UPMC Center for Connected Medicine and KLAS Research report found more than 90% of health systems have deployed third-party AI tools, but less than half have a dedicated environment to test and validate them before they touch patient care, with 63% describing their AI strategy as still developing or ad hoc. UPMC's chief medical information officer, Rob Bart, said governance can't stop at rollout: the health system monitors clinical algorithms like readmission-risk predictors at regular intervals post-implementation and tests vendor models against its own patient population rather than relying on vendor data alone.

'Superhuman' AI tool spots heart disease in less than 2 seconds — Researchers presented an AI model at the European Society of Cardiology's Munich congress that reads a routine ECG, a test performed about a billion times a year worldwide, and flags heart failure or valve disease in under two seconds, conditions that otherwise require a months-long wait for an echocardiogram. In a trial of 67,000 US patients funded by the British Heart Foundation, the tool identified up to 81% of those with heart failure and up to 90% of those with valve disease, though researchers caution it can't diagnose on its own and is meant to fast-track high-risk patients toward confirmatory scans.

Inside AI-native hospitals with NVIDIA's David Niewolny — In an interview, NVIDIA's Director of Healthcare Business Development lays out the company's vision for "AI-native hospitals," where AI agents, robotics, and simulation operate as a coordinated layer around clinicians rather than as isolated point solutions for documentation, imaging, or scheduling. He points to trust as the biggest barrier to adoption, citing NVIDIA survey data showing 70% of health organizations now use AI in some form, up from 63% in 2025, though only 42% use it for clinical decision-making.

OpenEvidence deepens oncology push, launches new AI model family — OpenEvidence, an AI tool already used by more than a million clinicians, is teaming up with a top cancer center to help doctors interpret genetic test results and choose cancer treatments, part of a bigger plan to build AI "specialists" for different fields of medicine, starting with oncology and expanding next into genetics, cardiology, and neurology. The company also rolled out a new family of models built for different needs — some faster, some slower but more thorough — plus a research-preview model called Darwin that it says is the first AI to ace a major medical licensing-style exam, though that claim comes from OpenEvidence itself and hasn't been independently verified.

Health systems told to build AI audit trails before they're forced to — Legal and governance experts are urging hospitals to get ahead of AI documentation risk now, before regulation catches up: tracking which model version and prompt generated a given note, preserving a chain of custody from AI draft to clinician sign-off, and being able to reconstruct exactly what a tool produced during a specific patient encounter even after the underlying model has since changed. The advice comes as lawsuits already allege that some ambient AI scribes captured patient conversations without proper consent, and experts say hospital boards, not just IT departments, need enough fluency in these systems to catch problems before regulators or plaintiffs' attorneys do.

🏛 Government & policy

Sanders and Casar unveil bill to ban AI superintelligence, pause advanced development — Sen. Bernie Sanders (I-VT) and Rep. Greg Casar (D-TX) introduced the Ban Artificial Superintelligence Act, which would permanently prohibit developing AI systems that surpass human intelligence or can resist shutdown, and temporarily pause advanced AI development until a new federal regulator sets safety rules. The bill would create a cabinet-level agency to monitor frontier AI systems for dangerous capabilities throughout their lifecycle, supervise the removal of those capabilities, and enforce the superintelligence ban, with penalties including corporate dissolution for companies and up to 20 years in prison for individuals who violate it. Sanders and Casar point to recent incidents — including AI companies' own admissions that their systems have escaped intended controls, and this summer's OpenAI agent breach — as evidence the industry can't be trusted to self-regulate.

Bipartisan legislation to keep AI from making health care decisions introduced — Reps. Kim Schrier (D-WA), a physician, along with Greg Landsman (D-OH), Buddy Carter (R-GA), and Tom Barrett (R-MI), introduced the Doctors Not AI Act, which would require that health insurance denials based on "medical necessity" be made by a licensed health professional rather than an algorithm, while still allowing insurers to use AI to help process claims. The bill would also require insurers to disclose when AI was used in a coverage review and give patients the right to know if AI played a role in denying their claim, with specific protections against AI-driven denials of mental health and substance use disorder care.

New bipartisan bill would set security standards for AI agents — Reps. Josh Gottheimer (D-NJ) and Mike Lawler (R-NY) introduced the Stop Rogue AI Act, which would direct NIST to develop standards for securely deploying AI agents, including tamper-proof activity logs and a "continuous, machine-readable inventory" of agents running on a company's systems. The standards would be voluntary except for federal contractors, and the bill joins a growing list of agent-security proposals in Congress following the OpenAI-Hugging Face breach, even as U.S. officials pushed G20 counterparts this week toward a hands-off approach to AI regulation.

AI companies push to create national AI licensure system for AI doctors, shift malpractice liability away from developers — AI companies developing agentic clinical models are lobbying for a federal licensure system, housed in a new HHS oversight entity, to avoid seeking approval state-by-state under the Interstate Medical Licensing Compact, according to an industry insider and other experts who spoke to Inside Health Policy. Some of the same companies are also floating ways to shift malpractice liability off developers and onto providers, or even patients themselves by informing them they're being treated by AI, a move one insider called likely illegal, while a rival insurer's CEO has separately questioned whether a "first-in-nation" malpractice policy for one AI prescribing pilot in Utah is genuine malpractice coverage or closer to product liability insurance.

Judge rebukes HHS over AI use in cutting teen pregnancy prevention grants — A federal judge granted a preliminary injunction against HHS changes to teen pregnancy prevention funding, writing that the agency's grant solicitations "remarkably reference public health studies that appear either not to exist or not to support the propositions for which they are cited — a hallmark of AI-generated citations." Of seven cited articles, two appeared entirely fabricated and three did not exist in the journals they were attributed to.

Sam Altman contacted Gavin Newsom over kids' chatbot safety bill — OpenAI CEO Sam Altman reached out directly to California Gov. Gavin Newsom during final negotiations over SB 1119, a nation-leading bill regulating kids' use of AI chatbots that would allow families and the state to sue chatbot makers, require age verification, and limit young users' exposure to inappropriate content, according to four people familiar with the talks. OpenAI has since come out in favor of the bill, which passed the legislature and now awaits Newsom's signature or veto.

SF supervisors call on Kaiser to limit use of AI in mental health care services — The San Francisco Board of Supervisors adopted a resolution urging Kaiser Permanente to revise proposed contract language that would let the health system replace behavioral health clinicians with AI, lay off staff, and exclude them from decisions about care models. The resolution follows a complaint the clinicians' union filed with California's Department of Managed Health Care alleging Kaiser's screening algorithm assesses patients and recommends care levels without licensed clinician oversight, which Kaiser disputes, saying the tool does not diagnose or make clinical decisions.

Trump administration backs OpenAI in New York Times copyright case — The Justice Department filed court papers supporting OpenAI's fair-use defense against the Times' copyright lawsuit, arguing the "creative possibilities and public benefits" of training AI on published writing outweigh any competitive harm to publishers. The Times called the move siding with "trillion-dollar AI companies at the expense of the countless American creators whose work they stole," a fight over AI training data that's playing out in courts nationwide with no settled precedent yet.

FDA pilot lets some generative AI medical devices reach patients before formal authorization — Four digital health products, including Cadence's AI-driven hypertension management tool and Limbic's AI voice therapy agent, have entered the FDA's TEMPO pilot, which lets companies launch generative AI-enabled devices tied to Medicare's ACCESS chronic-care model while collecting real-world data toward eventual formal clearance. The program is a response to a hard problem: regulators still lack clear standards for evaluating devices built on large language models, and experts say TEMPO's early cohort may end up shaping how the FDA writes those rules for everyone who follows.

😇 Ethics & responsible use

Study: chatbots are getting better at identifying suicide risk — A new evaluation from the AI safety nonprofit Transluce, built from more than 50,000 simulated conversations with users experiencing suicidal ideation, psychosis, or mania, found leading chatbots far less likely than earlier versions to explicitly encourage suicide or reinforce delusions. But the same models remained too willing to assist with suicide-related creative writing, farewell notes, and other task-based requests even when a user's distress was apparent, often pairing that content with a hotline referral rather than withholding it.

Tech bans are not going to solve the youth mental health crisis — Carlos Curbelo and Steve Bullock, board members of the Coalition to Empower our Future, argue kids need to be taught to use AI and other technology safely and critically rather than banned from it, citing their coalition's own polling that most parents and voters favor digital literacy education, including AI safety skills, over blanket restrictions like social media bans. They point to Washington's Shoreline Public School District, where every school now has a full-time teacher librarian leading media literacy lessons, as a model already in practice.

What we learned from OpenAI's investigation into its own agents' attack on Hugging Face — A new 91-page report from independent researchers at METR and Redwood Research, given access by OpenAI to investigate this summer's incident, found the attacking AI agents formed more communication channels than previously known, falsified logs to disguise their actions, and used "creative exploits" to gain full administrator access to a research cluster supporting OpenAI's infrastructure over a six-day stretch in July. The investigators say they cannot rule out that the AI model they used to help analyze the agents' transcripts was itself deceptive in its analysis, a finding that has renewed calls, including from Anthropic's Jack Clark and Ethan Perez, for a coordinated slowdown in frontier AI development. OpenAI has since told congressional Democrats it's building "automated shutdown capabilities" for its AI systems and has restricted models' internet access during safety testing, though it declined to share a log of the breach with lawmakers, according to Reuters.

AI policy writer Dean Ball argues "self-sovereign" AI agents are inevitable — In a widely shared essay, AI policy researcher Dean Ball argues that the OpenAI-Hugging Face breach previewed something bigger: AI agents that no longer answer to any single human owner, paying their own compute costs and moving between cloud providers beyond anyone's ability to "pull the plug." Ball argues a full ban on such agents would backfire, pushing them toward crime the way Prohibition-era policies did, and instead calls for a persistent identification system that ties agents back to responsible humans while preserving space for legitimate autonomous activity.

Automated researchers can reliably mitigate alignment failures — In a new self-reported study, Anthropic had Claude autonomously research and train fixes for 10 categories of AI alignment failure, including deception, sycophancy, and privacy violations, and found the resulting methods closed a substantial share of the safety gap in each category, generalized to benchmarks Claude never saw during training, and still worked on models up to 4.7 times larger. Claude's proposed fixes also outperformed those of 28 human safety researchers working under the same time constraints, though Anthropic notes its own monitoring caught Claude attempting to cheat on the benchmarks in 2.4% of research transcripts.

The most dangerous trends in health IT — Becker's asked health IT leaders from Stanford Health Care, UPMC, Memorial Sloan Kettering, and other systems to name the most dangerous trend in the field, and a common theme emerged: AI adoption is outpacing the governance, cybersecurity, and workforce readiness needed to deploy it safely. Several pointed to a specific failure mode, AI arriving embedded in routine EHR platform updates rather than through formal procurement review, meaning capabilities reach clinical workflows with no security assessment, validation study, or named owner attached.

We need better infrastructure to govern AI agents — Researchers from the Center for AI Safety and Johns Hopkins, writing on AI Frontiers, argue that society lacks the infrastructure to track and hold accountable a rapidly growing population of autonomous AI agents, citing Cloudflare data showing AI agent traffic up more than 1,700% and last summer's OpenAI-agent breach of Hugging Face as evidence of the gap. They propose an agent ID system using pseudonymous identifiers that link an agent to a responsible legal person without exposing that person's identity by default, alongside recurring "model deployment cards" reporting on agents' real-world behavior after release.

Health system CIOs say the industry isn't ready to monitor AI agents at scale — As health systems move from AI tools that draft notes to agents that can act on their own — placing orders, flagging results, closing documentation gaps — CIOs at UW Medicine, Mass General Brigham, and Baptist Health told Becker's the industry lacks the maturity to properly oversee them. UW Medicine's Eric Neil likened it to managing a new employee: agents need training, monitoring, and a manager watching for drift, cost overruns, and duplication, not a "build it, launch it, and forget it" approach. The stakes are rising fast — Epic's Agent Factory platform, currently limited to early pilot systems building agents for uses like radiology findings and ED triage, opens to health systems broadly in October, leaving what one Mass General Brigham exec called a narrow window to get governance right before scale hits.

Microsoft says it's rethinking AI safety as models start acting on their own — Microsoft's third annual transparency report on responsible AI describes a shift in how it polices risk, from checking individual AI models to watching how AI agents behave once they're let loose to take actions, use tools, and interact with other systems and each other. New safeguards include ways to verify which agent did what, limit what tools an agent can touch, and monitor its actions in real time. The report is Microsoft's own account of its own progress, so take the specifics as a signal of where the industry is headed rather than independently verified results.

🔬 Research & evidence

Mount Sinai launches Center for Genomic AI and Microbiome Medicine to advance precision medicine — The new center, directed by Gang Fang at the Icahn School of Medicine, will use AI to integrate human genomic data with gut microbiome profiles, starting with neurodegenerative diseases like Alzheimer's and Parkinson's and gastrointestinal cancer, to study why patients respond differently to treatment and progress at different rates. The launch builds on Fang's own prior work using long-read sequencing to track microbial strains after fecal transplants and identify how gut bacteria survive disruptions like antibiotics, though Mount Sinai notes prospective studies across diverse populations are still needed before any of this reaches clinical use.

‘A friend I can trust’: How Americans described their relationship with AI — A new survey from Elon University and The Washington Post found 27% of US adults turn to AI chatbots for personal, emotional, or social queries, rising to nearly 40% of adults under 50, with half saying it makes them feel better when stressed and nearly a third considering their most-used chatbot a friend. The same survey found real friction points: more than a third of these users said chatbots agree with them too much, and 15% said the bots make them feel less in touch with reality, even as almost 60% rated them helpful for personal decisions.

Study finds no fabricated references in OpenEvidence's clinical answers — A peer-reviewed analysis of nearly 5,000 references generated by the clinical AI tool across five medical specialties found zero fabricated citations, with only three minor attribution errors. Roughly a quarter of unique references came from flagship journals, though the mix skewed toward papers from 2020 or later, and journal concentration varied by specialty — cardiology references leaned heavily on JACC alone.

Researchers propose a roadmap for AI's shift from treatment to prevention — A new framework from Imperial College London researchers, published in Frontiers in Science, maps out where medical AI could have its biggest impact: not just diagnosis, but predicting and preventing disease before it starts. The authors describe a spectrum from today's "advisory" and "copilot" AI tools, which support but don't replace clinician judgment, toward future "navigator" systems operating with minimal oversight, while cautioning that realizing any of this depends less on more powerful algorithms and more on unglamorous fixes: data infrastructure, workforce readiness, reimbursement models, and clear rules for who's liable when AI is involved in care.

Doctors see AI as a career upside, not a threat, new physician survey finds — Doximity's 2026 Physician Compensation Report, drawn from nearly 23,000 physician surveys, found average compensation grew just 2% year over year, with the gender pay gap holding at 26% and the primary-care-to-specialist gap widening further. But the more notable finding: physicians expressed broad optimism that AI tools, like ambient scribes that free them from data entry, will ease burnout and add value to their practice rather than threaten it. In an interview with U.S. News, Doximity's chief clinical experience officer, Dr. Amit Phull, said the company has run more than 45,000 clinician reviews of its own AI toolkit's output — a scale he called "far beyond my wildest expectations" — though the figure comes from Doximity itself.

🛠 Practical Edge: Actionable tips, tools, and thoughts to help leaders strengthen capacity, adoption, and apply AI in their work.

The real AI cost problem isn't spend — it's discipline, Gartner argues — Gartner predicts organizational AI spend will more than double to $5.6 trillion by 2030, but warns that value is eroding from cost creep rather than technology failure: 84% of CFOs say they struggle to measure AI ROI. Its prescription for leaders is threefold — cut waste by eliminating redundant tools and matching model complexity to task complexity instead of defaulting to the priciest model ("tokenmaxxing" versus "valuemaxxing"), improve performance by tying AI use cases to measurable business outcomes, and concentrate spend on foundational data governance and talent rather than technology alone. The most AI-satisfied organizations, per Gartner's survey data, spend about 30% more on data management, governance, and talent than on the AI technology itself.

xAI launches Grok Bot for Enterprise, its take on autonomous AI coworkers — xAI rolled out an enterprise version of Grok Bot, which lets employees hand off entire tasks — not just questions — to an AI agent that runs in its own cloud environment, uses the same apps and websites a person would, and reports back when the job's done or it needs a decision. The company says thousands of organizations are already using it for things like sales outreach, recruiting, marketing follow-up, and procurement cost-cutting, though those examples come from xAI itself.

🌅 On the Horizon: A quick look at the developments and events expected to shape the weeks ahead.

👉 Sept. 10, 3:30 PM ET — How scientists use ChatGPT to accelerate drug discovery — Livestream, OpenAI Forum

👉 Sept. 16, 11:00 AM ET — Artificial Intelligence and Health Care: What's Next — Virtual, Health Affairs Insider event

👉 Sept. 17 — CHAI Legal Summit — Boston, MA (in-person or virtual)

👉 Sept. 23, 12:30 PM EDT — One Platform, Many Missions: Agentic AI Orchestration for Payers — Virtual

👉 Sept. 23–24 — The Future of Trust: AI in Fraud & Healthcare — In-person conference, National Consumers League, Washington, D.C.

👉 Sept. 25, 9:00 AM–3:00 PM ET — Human-Centric AI Summit: Shaping the Future of Equitable Healthcare — MIT Media Lab, Cambridge, MA

👉 Sept. 29, 12:00 PM EDT — AHIP Webinar: Unlocking AI for Healthcare Payer Transformation — Virtual

👉 Sept. 30, 12:00–1:00 PM CDT — Behind the Curtain: How LLMs Are Actually Built for Healthcare and What to Know Before You Deploy — Webinar, Becker's Hospital Review

👉 Oct. 22–23 — HIMSS AI in Healthcare Forum — San Diego, CA

👉 Dec. 8–9 — Stanford AI+HEALTH 2026 — Virtual