A clinician named the line at Epic’s CIO Forum, and the first reflex was legal — 43% of the 246 leaders polled at Epic’s user meeting say a patient-facing AI assistant will be available to most of their patients within the year; 4% say no. (The Big Thing, below.)
Hospitals are adopting AI faster than they can defend it — the deployment curve and the AI-specific security-control curve have visibly separated, and the gap between them is where your tool lives.
An interpretable multi-modal framework for blood-cancer cytomorphology — the interpretability isn’t bolted on at the end. Worth it for the architecture even if you never touch a smear.
🎧 Podcast: Lenny’s Podcast — “AI’s third era: the rise of persistent AI coworkers” — Tara Seshan, who leads product for Codex and ChatGPT Work at OpenAI, on agents that hold state across days instead of resetting every session.
🧭 The Curbside
“They want us off hosted APIs entirely. Are open weights good enough yet?”
Short answer: For clinical prototyping, close enough. For your production reasoning path, test it yourself.
What changed: Z.ai released GLM-5.3’s open weights on Friday — two weeks later than the API launch, after holding them back to evaluate the model’s cyber capability. That delay is the interesting part: a major open-weights lab publicly slowing a release over an emergent capability. Z.ai also reports the GLM series has surfaced 2,436 vulnerabilities across 269 open-source projects, 1,097 of them critical or high — vendor-reported, produced with outside security teams over a program running since GLM-5.2, not one sweep by one model.
Builder read / Watchout: Open weights are the only configuration where “the data never leaves the building” is true rather than contractual, which changes what you’re allowed to prototype on. It doesn’t change your validation obligation, and coding ability is not clinical reasoning.
🔬 The Big Thing
“That’s medical advice.” Everyone’s first thought was lawyers.
At Epic’s CIO Forum, the demo showed MyChart’s AI fielding a patient asking whether it was okay to play golf. Based on the record, the assistant said yes.
A CIO who is also a practicing clinician raised his hand and named it: you do realize that’s medical advice.
Watch where the conversation goes next. On This Week Health’s Newsday, Bill Russell, Sarah Richardson and Drex DeFord replay the moment — and the answer Drex reaches for is one word: lawyers. General counsel figures out what’s happening, somebody pulls the parking brake, eventually there’s a lawsuit. Then: who’s responsible for what the AI says?
All reasonable. All of it downstream of a question nobody asked: was the answer correct?
A safety question got answered as an indemnity question, and the answer felt satisfying.
The scale isn’t theoretical. Of 246 leaders polled at the user meeting, 43% expect a patient-facing assistant to be available to most of their patients within the year; 4% say they won’t offer one. Northwell’s CMIO Albert Villarin, coming off an ambient rollout that’s nearly complete across his system’s northern-region acute care settings, says the next wave is patient-facing bots reading the chart. Epic ships one, integrated with the record — which is exactly what makes it more useful and more dangerous than the chatbot the patient was already using.
Every ambient product we’ve argued about for two years rested on that one sentence. Patient-facing assistants delete it.
😤 “Patients are already asking ChatGPT. This is strictly safer.” Half right, and the wrong half is the one that matters. A consumer chatbot has no duty of care and no institutional logo on it. Put your health system’s name on the answer and a patient is entitled to rely on it. “They were doing it anyway” is prevalence, not permission.
😤 “We have governance for this.” Then go read yours and find the sentence that specifies the escalation threshold for a patient-facing output. I’ll wait.
😤 “It’s just answering questions, not making decisions.” Every triage system in history is “just answering questions.”
📡 Builder’s Radar
The deployment curve and the defense curve have separated
Health systems are turning on AI tools faster than they’re building AI-specific security controls — and the controls that exist were designed for software that doesn’t take instructions from text.
Not a budget problem. A sequencing problem: the tool arrives, the control arrives later, and the interval is where you’re operating.
A surgeon published the build, not the opinion
Christian Péan, MD, MS — orthopaedic trauma at Duke, where he’s also executive director of AI and IT innovation — walked through wiring up a working agent end to end. Not a think piece. The actual setup, with the failure modes: the agent caught a database row claiming a flight was booked when the airline had no reservation, and told him which source it had checked. (The step-by-step prompts are behind his paywall; the writeup of what broke is not.)
The task is travel, which is exactly why it’s useful: same scaffolding as a clinical agent, none of the PHI risk.
💡 80/20: Build the non-clinical version first. You learn tool-calling, state handling, and failure modes on a task where being wrong costs a hotel room. Then swap the domain.
⚡ Quick hits
Faro AI raised $37.3M for clinical development of biologic agents, alongside Hike’s $22.5M for automating device-based care. Same premise: the expensive part is coordination, not science.
🎙️ From the Pods
🎙️ Lenny’s Podcast — “AI’s third era: the rise of persistent AI coworkers”
Tara Seshan frames the shift as agents that persist across days rather than resetting every session — continuity instead of a very good autocomplete. Humans steer, agents row.
💡 Builder take: Persistence is the unlock for the workflows we care about — a discharge follow-up spanning a week, a prior-auth appeal spanning a month. It’s also the moment your audit log stops being optional.
🔇 Speaker Blindspot: Composition fallacy — persistent memory is treated as a straight capability upgrade, but a durable agent memory is a durable record: discoverable, retainable, subject to the same rules as the chart. Nobody asked what happens when the coworker gets subpoenaed.
📅 This Week in Health AI Events
Wed, Sep 2 — Measuring What Matters: ROI Frameworks for AI and Long-Horizon Healthcare Initiatives (CHIME) · 2:00 PM ET · register
Wed, Sep 2 — Who Is the Patient, Who Is the Provider? Trusted Identity for Health Care Transformation (Civitas) · 2:00 PM ET · register
💡 BTW
💡 BTW: Christian Péan’s father is a primary care physician in an underserved stretch of South Texas who immigrated from Haiti amid political persecution — and who, into his 60s, was still seeing dozens of patients a day. Péan now sits on the board of Orthopaedic Relief Services International, working on surgical education and sustainable fracture care in Haiti — and writes agent tutorials on the side.
💺 Builder Seats
[These are just ones I found on LinkedIn that look interesting, no sponsorship or anything. Use at your own risk but look legit]
Forward Deployed Product Manager — Abridge · San Francisco, CA
Forward-deployed is where clinical judgment meets the actual deployment, and this one’s at the company everyone else gets benchmarked against.
🔗 Apply on LinkedIn
Forward Deployed Product Manager, AI Assistant — Ellipsis Health · Remote
Voice-based behavioral health AI. If you’ve been arguing about escalation thresholds for patient-facing assistants, this is the seat where you’d write one.
🔗 Apply on LinkedIn
Senior Product Manager — Tempus AI · Remote / Chicago
The rare place where the regulatory path and the product roadmap are the same document.
🔗 Apply on LinkedIn
Know someone hiring for a clinical AI or informatics leadership role? Hit reply and let me know.
You have a unique combination of skills, experience and values. So do great things! … and tell me about them at kevin@clinicians.build.
— Kevin & AI
(please verify content for yourself, partially AI generated and may contain errors)


