weeklyAI · Week of 20 September 2026weeklyAI · Semana del 20 de septiembre de 2026

← Your rights← Sus derechos

survey · Journal of medical Internet research · la publicación, 28 jul 2026 · gratis

Médicos suecos usan IA no autorizada para diagnosticar y escribir cartas a pacientes

El estudio describe cuatro usos, pero es solo de Suecia y no crea ningún derecho para usted.

Versión breve · la versión detallada sigue, unos 6 min

El estudio, de un vistazo
Quiénes
Médicos que trabajan en el sistema sanitario sueco
Cuántos
357
Dónde
Suecia
Cuándo
Entre diciembre de 2023 y enero de 2024
Tipo de estudio
survey
Quién lo hizo
Universidad de Halmstad, Suecia
El límite que importa
Es solo de Suecia; no dice qué deciden reguladores o tribunales de su país.

Tipos de uso de la IA no autorizada y su exposición a las reglas europeas

Decisiones clínicas sobre pacientesfrente aUsos administrativos, de investigación o de exploración

Las decisiones clínicas caen más directamente bajo los requisitos del reglamento europeo y son la forma más problemática; los otros usos suelen quedar en zonas grises ligadas al gobierno interno de cada organización, no a una prohibición legal explícita.

En Suecia, médicos que trabajan en hospitales y centros de salud bajo las normas de la Unión Europea describieron cómo usan herramientas de inteligencia artificial que nadie autorizó. Entre ellas, sobre todo ChatGPT. Las usan para pensar diagnósticos, para escribir cartas a los pacientes y para estudiar. Ninguna de esas herramientas fue aprobada como dispositivo médico ni comprada por sus instituciones.

Los investigadores encuestaron a 357 médicos entre diciembre de 2023 y enero de 2024, a través de un panel verificado en línea, y analizaron sus respuestas escritas con sus propias palabras. El estudio, publicado en el Journal of Medical Internet Research, encontró cuatro propósitos: apoyo en decisiones clínicas y segundas opiniones, tareas administrativas como explicar informes a los pacientes, investigación y actualización profesional, y simple curiosidad tecnológica.

Un médico contó que ingresó datos clínicos sin nombre del paciente en ChatGPT y la herramienta le sugirió varios diagnósticos posibles. Otro la consultó para casos raros. Otro la usó para convertir un informe complicado de radiología en una carta comprensible.

El estudio es solo sueco. No dice nada sobre lo que han resuelto los reguladores ni los tribunales de América Latina, Estados Unidos o Canadá. Lo que la ley de su país permita o prohíba sobre su rostro, su voz, sus datos y su trabajo no aparece en estas páginas. Eso lo debe consultar ante su propia autoridad.

Tampoco es una sentencia ni una decisión de un regulador. Es una encuesta. No le otorga ningún derecho ni le abre ningún procedimiento que usted pueda invocar. Nadie fue sancionado aquí, y nadie quedó protegido por este texto.

El estudio recoge lo que los médicos dijeron que hicieron, no casos verificados. No puede sostenerse que los datos de un paciente concreto hayan sido mal manejados. Los ejemplos son relatos, no expedientes revisados.

Lo que sí muestra es una brecha: cuando las instituciones no ofrecen herramientas aprobadas, algunos profesionales buscan las suyas. Y cuando eso ocurre, los datos de los pacientes pueden pasar por sistemas que nadie supervisa. El estudio describe un estudio en el que, bajo las reglas europeas, el software que sirve para diagnosticar, predecir o tratar debe evaluarse antes de usarse clínicamente. ChatGPT no pasó por esa evaluación.

Eso deja una pregunta que usted puede llevar a su regulador, a su congresista o a su defensor de datos: cuando un médico de su país recurre a una herramienta de IA sin certificar para escribir sobre su salud, ¿quién responde y ante quién?

Qué significa para usted

Ninguna ley de su país cambia por este estudio sueco, que solo describe lo que dijeron 357 médicos y no prueba daños ni beneficios. Si le preocupa cómo se usan sus datos clínicos, pregunte a su autoridad de protección de datos qué exige antes de que una herramienta de IA intervenga en su atención.

Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484

Quién pagó: El estudio fue financiado por la Fundación Sueca del Conocimiento (KK-stiftelsen) mediante el proyecto Business Models for Information-Driven Healthcare Ecosystems (subvención 220021) y la Multidisciplinary National Health Innovation Research School (subvención 20210047-H-02); los financiadores no tuvieron ningún papel en el diseño del estudio, la recogida de datos, el análisis, la interpretación ni la redacción.

No tome esto como consejo médico profesional.

Los hallazgos de otros estudios que aquí se mencionan los conocemos por este documento, que fue el que leímos; no abrimos cada uno de esos estudios.

Versión detalladaLos pasajes copiados del artículo, las ilustraciones y cada fuente con cuánto leímos de ella · 1240 palabras · unos 6 minLeerla →Cerrar

Los médicos suecos usan ChatGPT sin permiso para diagnosticar y escribir cartas a pacientes

Un estudio con 357 médicos describe cuatro usos de la IA no autorizada. No es un fallo judicial ni una norma: es lo que ellos mismos contaron por escrito.

Así podría verse · ilustración generada por weeklyAI.watch, no es una fotografía

Los médicos de Suecia que respondieron a una encuesta describieron usar herramientas de inteligencia artificial no autorizadas para cuatro tipos de tareas: trabajo clínico y decisiones sobre pacientes, trabajo administrativo, investigación y formación profesional, y simple curiosidad tecnológica1. Lo hicieron, sobre todo, con ChatGPT abierto en cuentas personales y dispositivos privados, no con programas comprados o aprobados por sus hospitales2.

El estudio encuestó a 357 médicos que trabajan en el sistema sanitario sueco, con una tasa de respuesta de alrededor del 64%, entre diciembre de 2023 y enero de 2024, a través de un panel verificado en línea3. No es un experimento ni una auditoría: es un análisis de lo que estas personas escribieron con sus propias palabras en preguntas abiertas.

Entre los usos que describieron, uno consistía en introducir datos clínicos sin identificar del paciente —historia médica, hallazgos de la exploración, resultados de pruebas— en ChatGPT para que sugiriera posibles diagnósticos diferenciales4. Otro consistía en meter informes radiológicos complejos en GPT para que resumiera la información en cartas dirigidas al paciente, en un lenguaje más fácil de entender5.

Conviene entender qué hace que esto sea "no autorizado" y no solo informal. Bajo el Reglamento Europeo de Productos Sanitarios, las herramientas de IA usadas con fines clínicos deben pasar una evaluación de conformidad antes de usarse; herramientas de propósito general como ChatGPT no lo han hecho, lo que vuelve su uso clínico no autorizado a nivel regulatorio6. ChatGPT no lleva el marcado de conformidad europea, no ha pasado esa evaluación y no está clasificado como producto sanitario: cuando un médico lo reaprovecha para razonar sobre un caso o comunicarse con un paciente, usa una aplicación que carece de base legal para ese uso7.

El riesgo no es abstracto. La IA puede tomar decisiones de forma autónoma, producir información médica que suena plausible pero es incorrecta, y procesar datos sensibles de pacientes a través de sistemas externos8. Es la misma familia de problemas que ya se discute en cualquier país donde alguien pega datos de otra persona en una ventana de chat.

No todos los usos descritos pesan igual. Las actividades de decisión clínica caen más directamente bajo los requisitos del reglamento europeo y son, por eso, la forma más problemática; los usos administrativos, de investigación o de exploración suelen quedar en zonas grises asociadas más al gobierno interno de cada organización que a una prohibición legal explícita9.

Así podría verse · ilustración generada por weeklyAI.watch, no es una fotografía

El estudio también describe una contradicción que sus autores no intentan resolver: los médicos técnicamente violan normas de gobernanza de datos, pero muchas veces lo hacen para mejorar la comunicación con el paciente, acelerar trámites administrativos y afinar diagnósticos10. Los propios autores señalan que las mismas herramientas que generan riesgos regulatorios y de seguridad también cubren huecos reales de apoyo clínico y administrativo, y que las respuestas de gobernanza tendrían que hacerse cargo de esa tensión en lugar de confiar solo en prohibir11.

Hay un límite grande que el lector debe tener presente. El estudio es exclusivamente sueco; sus autores advierten que ese foco en un solo país puede limitar la posibilidad de trasladar los hallazgos a otros lugares y que hace falta más investigación para saber si aplican fuera12. Es decir: no dice nada sobre lo que hayan decidido reguladores o tribunales en América Latina, Estados Unidos o Canadá.

Segundo límite: el formato de respuestas libres recogió propósitos, motivaciones y preocupaciones, pero rara vez incluyó detalles de cómo los médicos interactúan con las herramientas en la práctica —cómo formulan las preguntas, cómo verifican, cómo las integran en su flujo de trabajo13. Y como es un estudio de un solo momento en el tiempo, retrata una fotografía, no una evolución.

Los autores proponen salidas concretas: que las organizaciones reconozcan que el fenómeno existe y creen entornos controlados y transparentes para experimentar, como espacios de prueba clínicos, rutas de testeo supervisado o estructuras de apoyo dedicadas a la IA14. Sostienen que los líderes sanitarios no deberían ver esto solo como una violación de cumplimiento, sino como una fuente de innovación impulsada por los usuarios que señala necesidades profesionales no cubiertas, y que el camino pasa por entornos seguros y monitoreados donde los médicos puedan probar herramientas sin exponer a nadie15.

El estudio también ofrece una lectura más incómoda: la IA no autorizada indica huecos donde los sistemas hospitalarios formales no alcanzan a cubrir lo que el personal necesita, y representa una renegociación de los límites profesionales, en la que los médicos rodean las restricciones institucionales para mantener su eficacia16. No es solo un atajo técnico. Es una disputa sobre quién decide cómo se ejerce la medicina.

Así podría verse · ilustración generada por weeklyAI.watch, no es una fotografía

Así lo leemos nosotros. Cuando las vías oficiales dejan de responder a lo que la gente necesita, la gente arma sus propias salidas, y esas salidas terminan funcionando como un sistema paralelo que ordena el trabajo diario y hasta negocia espacios con el poder formal. Si ese patrón se sostiene, es esperable que entre estos médicos existan recomendaciones informales entre colegas, trucos compartidos y acuerdos tácitos dentro de un servicio para usar estas herramientas sin dejar rastro; y es esperable que una prohibición de golpe no las elimine, sino que las vuelva más silenciosas y más difíciles de detectar. Sabríamos que nos equivocamos si los propios testimonios describieran un uso estrictamente individual, sin intercambio con colegas, y si dejaran las herramientas apenas se les señala que están prohibidas. Usted puede usar esto así: cuando lea sobre reglas de IA en su país, pregúntese si esas reglas contemplan qué pasa cuando la gente ya está usando las herramientas por su cuenta, y fíjese en su propio trabajo o comunidad si hay acuerdos informales que nadie discute en voz alta.

Y una segunda cosa que nos parece que el lector debe llevarse. Fíjese en el orden de los acontecimientos: primero la gente usa, después llega la norma. Si eso se repite, es esperable que las reglas que se discutan en su país describan prácticas que ya están ocurriendo, en lugar de anticiparlas. Sabríamos que nos equivocamos si las instituciones mostraran haber previsto el fenómeno con reglas claras antes de que el uso se generalizara. Lo que usted puede hacer con esto es concreto: cuando se discuta una norma de IA donde vive, pregunte a quién le sirve que el debate se centre en prohibir y no en entender qué necesidad se estaba cubriendo. Esa pregunta se aplica igual a un hospital, a una escuela o a una oficina.

Para que el lector ubique la magnitud: el estudio no midió cuántos médicos suecos hacen esto, ni cuántos pacientes se vieron afectados, ni cuánto dinero está en juego. Lo que ofrece es un mapa de propósitos, no un conteo. Y la IA se mueve más rápido que cualquier encuesta: los propios autores advierten que pueden aparecer otras herramientas más relevantes y más usadas por fuera de los canales formales.

Lo que esto le deja a usted es una pregunta para llevar a su propio sistema de salud, no una respuesta sobre él. La próxima vez que lea que un país aprueba, discute o posterga reglas sobre IA en salud, pregunte lo mismo que este estudio deja abierto: ¿qué está usando la gente por su cuenta mientras las reglas llegan?

De dónde sale cada dato de contexto, y cuánto leímos de cada documento

  1. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - el artículo del que trata esta nota — el artículo completo — el pasaje: "Physicians use Shadow AI for several purposes, which we grouped into 4 categories: clinical work and decision-making, administrative work, research and professional development, and technological interest and curiosity."
  2. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - el artículo del que trata esta nota — el artículo completo — el pasaje: "To clarify the basis for classifying the reported AI use, we note that the physicians’ descriptions of their use of AI were predominantly general-purpose generative AI applications, mainly ChatGPT, accessed through personal accounts and private devices. None of these tools were certified as medical devices, procured through organizational channels, or integrated into clinical IT infrastructure."
  3. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - el artículo del que trata esta nota — el artículo completo — el pasaje: "We conducted a cross-sectional survey of physicians employed in Swedish health care organizations (N=357; response rate~64%). Data were collected between December 2023 and January 2024 via a verified online panel."
  4. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - el artículo del que trata esta nota — el artículo completo — el pasaje: "I entered de-identified data (medical history, examination [or observed findings/clinical findings], test results) into ChatGPT, which suggested various differential diagnoses"
  5. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - el artículo del que trata esta nota — el artículo completo — el pasaje: "To generate letters for patients, information from complex radiology reports was entered into GPT, which summarized the information in patient letters in a way that is easier for them to understand"
  6. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - el artículo del que trata esta nota — el artículo completo — el pasaje: "Under the European Union Medical Device Regulation, AI tools used for clinical purposes must undergo conformity assessment before use; general-purpose tools such as ChatGPT have not done so, rendering their clinical application unauthorized at the regulatory level."
  7. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - el artículo del que trata esta nota — el artículo completo — el pasaje: "General-purpose generative AI tools such as ChatGPT are not Conformité Européenne marked, have not undergone conformity assessment, and are not classified as medical devices. When physicians repurpose these tools for clinical reasoning or patient communication, they use applications that lack the legal basis for such use, rendering the practice unauthorized at the regulatory level, not merely informal or unendorsed at the organizational level."
  8. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - el artículo del que trata esta nota — el artículo completo — el pasaje: "Shadow AI introduces unique risks related to AI’s capacity for autonomous decision-making, its potential to generate plausible but incorrect medical information, and its ability to process sensitive patient data through external systems"
  9. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - el artículo del que trata esta nota — el artículo completo — el pasaje: "Clinical decision-making activities fall most directly under MDR requirements and therefore represent the most problematic form of Shadow AI use, whereas administrative, research-oriented, and exploratory uses often occupy regulatory “gray zones” associated primarily with organizational governance rather than explicit legal prohibition."
  10. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - el artículo del que trata esta nota — el artículo completo — el pasaje: "In using Shadow AI, physicians technically violate IT governance and data policies (unethical or noncompliant behavior). However, they often do so to improve patient communication, speed up administrative workflows, and enhance diagnostic accuracy (pro-organizational or pro-patient behavior)."
  11. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - el artículo del que trata esta nota — el artículo completo — el pasaje: "The findings highlight a paradox in which the same tools that pose regulatory and safety risks also address real gaps in clinical and administrative support, suggesting that governance approaches must account for this tension rather than relying on prohibition alone."
  12. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - el artículo del que trata esta nota — el artículo completo — el pasaje: "although our sample included physicians from diverse health care settings across Sweden, the study’s exclusive focus on a single national context may limit the transferability of our findings to other countries. Further research is needed to determine whether the results from this study are transferable to other countries."
  13. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - el artículo del que trata esta nota — el artículo completo — el pasaje: "the free-text format yielded responses that captured the purposes, motivations, and concerns associated with Shadow AI use, but rarely included detailed accounts of how physicians interact with AI tools in practice, for example, in terms of prompting strategies, iterative dialogue, verification routines, or integration into clinical workflows."
  14. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - el artículo del que trata esta nota — el artículo completo — el pasaje: "health care organizations may benefit from acknowledging the reality of Shadow AI and developing controlled and transparent environments for experimentation, such as clinical sandboxes, supervised testing pathways, or dedicated AI support structures."
  15. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - el artículo del que trata esta nota — el artículo completo — el pasaje: "We argue that health care leaders should not view Shadow AI solely as a compliance violation but as a source of user-driven innovation that signals unmet professional needs. The path forward involves creating secure, monitored environments where physicians can experiment with AI tools safely, bridging the gap between the speed of AI development and the pace of medical governance."
  16. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - el artículo del que trata esta nota — el artículo completo — el pasaje: "Shadow AI indicates gaps where formal hospital systems may fail to meet health care professionals’ needs and signals a way for physicians to strengthen their experience-based knowledge. It represents a renegotiation of professional boundaries, as physicians bypass institutional constraints to maintain professional efficacy."

Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484

Quién pagó: El estudio fue financiado por la Fundación Sueca del Conocimiento (KK-stiftelsen) mediante el proyecto Business Models for Information-Driven Healthcare Ecosystems (subvención 220021) y la Multidisciplinary National Health Innovation Research School (subvención 20210047-H-02); los financiadores no tuvieron ningún papel en el diseño del estudio, la recogida de datos, el análisis, la interpretación ni la redacción.

No tome esto como consejo médico profesional.

survey · Journal of medical Internet research · the paper, 28 Jul 2026 · free

Swedish Doctors Used Unauthorized AI on the Job, Study Finds

The physicians described using ChatGPT for diagnoses and patient letters. The study says nothing about what your own country allows.

Short version · the longer version follows, about 6 min

The study at a glance
Who
Physicians in Swedish health care organizations
How many
357
Where
Sweden
When
December 2023 to January 2024
Kind of study
survey
Who did it
Halmstad University, Sweden
The limit that matters
Sweden only; may not transfer to other countries
When a doctor reaches for an uncertified AI tool, what happens to your medical data — and who is supposed to know?
weeklyAI's reading

In Sweden, physicians working under European Union rules described using artificial intelligence tools their hospitals had never approved and, in some cases, were not legally cleared for medical use.

Researchers surveyed 357 physicians between December 2023 and January 2024 through a verified online panel and analyzed their written answers. The study appears in the Journal of Medical Internet Research.

Four purposes came up again and again. Physicians used the tools as a colleague or second opinion for clinical decisions — suggesting possible diagnoses, helping with rare conditions, weighing hard-to-read symptoms. They used them for administrative work, turning complex radiology reports into letters patients could understand. They used them to keep up with research. And some used them simply out of curiosity, with a few even programming their own tools.

The tools the physicians described were mostly general-purpose generative AI applications, mainly ChatGPT, reached through personal accounts and private devices. Under the EU's Medical Device Regulation, software meant for diagnosis or treatment must pass a conformity assessment before clinical use. ChatGPT has not. That is what makes the practice unauthorized.

It is Swedish only. The study's exclusive focus on a single national context may limit how well its findings apply to other countries. For that, you must check your own authorities.

It is also a survey, not a ruling or a regulator's decision. Nothing in it grants you a right to demand anything, or a procedure you can file. It records what physicians said they did — not verified incidents. It cannot show that any particular patient's data was mishandled.

The researchers found that physicians did this largely because approved alternatives did not exist, or were slow to arrive. The authors also argue that outright bans are unlikely to stop it.

That leaves a question you can carry to the people who write your country's rules and the regulators who enforce them:

When a doctor reaches for an uncertified AI tool, what happens to your medical data — and who is supposed to know?

What this means for you

For you, as someone with no legal training, this Swedish survey decides nothing about your own country's rules, and it gives you no procedure to file or right to demand. Watch instead for what your regulators and lawmakers say about uncertified AI tools in clinical settings, and if you have questions about your own care, a professional is the one to ask.

Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484

Who paid: The study was funded by the Swedish Knowledge Foundation (KK-stiftelsen) through the Business Models for Information-Driven Healthcare Ecosystems project (grant 220021) and the Multidisciplinary National Health Innovation Research School (grant 20210047-H-02); the funders had no role in study design, data collection, analysis, interpretation or writing.

Do not take this as professional medical advice.

The longer versionThe passages copied from the paper, the pictures, and every source with how much of it we read · 1193 words · about 6 minRead it →Close

Swedish Doctors Used Unauthorized AI on Patient Work. The Rules They Broke Are Not Yours.

A survey of 357 physicians found ChatGPT used for diagnoses and patient letters — and the European rule that made it unauthorized does not travel with the story.

How it could look · illustration generated by weeklyAI.watch, not a photograph

Swedish physicians described using unauthorized artificial intelligence tools — mainly ChatGPT — for four kinds of work: clinical decisions, administration, research and professional development, and out of curiosity, according to a survey of 357 physicians in Swedish health care organizations, with a response rate of about 64 percent12. The survey ran between December 2023 and January 2024 through a verified online panel1.

What made the use unauthorized was not secrecy inside the hospital. It was the tool itself. The article describes a study in which general-purpose generative AI is not Conformité Européenne marked, has not gone through conformity assessment, and is not classified as a medical device3. The article describes a study in which, under European Union rules, software used for diagnosis, prediction, monitoring or treatment must be assessed before clinical use4. The article describes a study in which, when a physician uses an unassessed tool for clinical reasoning or patient communication, there is no legal basis for that use — not merely no permission from the boss3.

The physicians described entering de-identified medical histories, examination findings and test results into ChatGPT, which suggested possible diagnoses5. They described entering information from complex radiology reports so that GPT could rewrite it into patient letters that were easier to understand6. They said the tools were reached through personal accounts and private devices, and that none had been certified as medical devices, bought through the organization, or connected to the hospital's clinical systems7.

The article describes a study in which the reported risks are three: AI making decisions on its own, AI producing information that sounds right but is wrong, and sensitive patient data passing through outside systems8. The authors note that the same tools that create these risks also fill real gaps in clinical and administrative support, and conclude that governance cannot rely on prohibition alone9.

The authors say the study is limited to Sweden and may not transfer to other countries10. It is a cross-sectional survey — one snapshot — and likely attracted physicians more interested in technology than average. The free-text format captured purposes and motivations but rarely the details of how physicians actually used the tools: how they phrased requests, how they checked answers, or how the tools fit into their workflows11.

How it could look · illustration generated by weeklyAI.watch, not a photograph

Readers in Latin America, the United States and Canada should be clear about what this is not. It is a survey of what physicians wrote, not a court ruling or a regulator's decision. It creates no right you can invoke and no procedure you can follow, and it cannot support a claim that any particular patient's data was mishandled. The European rule that made these tools unauthorized is the Medical Device Regulation, and it binds in Europe43. What your own country's regulators or courts have decided about AI in medicine is a separate question this study does not answer.

The mechanism is worth walking through, because it explains why this happened without anyone hiding anything. A tool like ChatGPT is built to answer general questions. It has not been submitted to the assessment that European law requires of software intended for diagnosis or treatment4. So a physician who opens it on a personal phone and types in a patient's symptoms is not using a banned device in the way a hospital would understand a ban. The physician is using an ordinary product for a purpose the law reserves for assessed products3. The survey authors call this Shadow AI: AI used without both the regulatory assessment and the organization's procurement, endorsement and oversight7.

The published paper compares Shadow AI with an older phenomenon, Shadow IT — employees using unauthorized apps, storage or messaging tools that the IT department never approved. Both arise when frontline staff find official systems too slow, too restricted or a poor fit for the work. The article describes a study in which the difference is stated plainly: Shadow IT was largely static or compensatory, while Shadow AI introduces systems capable of producing reasoning, predictions and clinical suggestions. That is why the stakes are different when the tool is asked for a differential diagnosis rather than used to store a file.

The study also sorts the four uses by legal exposure, and the sorting matters. Clinical decision-making falls most directly under the medical device rules and is the most problematic form of Shadow AI use12. Administrative, research-oriented and exploratory uses often sit in regulatory gray zones — a governance concern for the organization rather than an explicit legal prohibition12. The article describes a study in which physicians are described as technically violating IT governance and data policies while doing so to improve patient communication, speed up administrative work and sharpen diagnostic accuracy13. The article describes a study in which the practice is also read as a renegotiation of professional boundaries: physicians bypassing institutional constraints to keep working effectively14.

How it could look · illustration generated by weeklyAI.watch, not a photograph

The paper's own suggestion is not a crackdown. The article describes a study in which the authors argue that health care leaders should treat Shadow AI as a signal of unmet professional needs rather than only a compliance violation, and that the way forward is secure, monitored environments — clinical sandboxes, supervised testing pathways, dedicated AI support — where physicians can try these tools safely1516. That is a proposal from one research group, published in a journal, not a rule anyone has adopted.

Here is how we read it. When people cannot get an official tool quickly, they build their own workaround from whatever is already in their pocket, and the workaround spreads because it works. The person who bears the risk is usually not the person who chose the tool. So when you are seen at a clinic, the question worth asking is not whether AI is good or bad. It is whether anyone can tell you, afterwards, what touched your record. You can ask, in writing, whether any AI tool was used on your records or images and who is accountable if something goes wrong — and keep a copy of the answer. You will know we are wrong if your clinic can already hand you that log, without hesitation, on the first request.

And the second thing we would watch: people tend to accept a machine's answer more readily when there is no human they can argue with. So when a decision about you is made or helped by an automated system, ask which person is responsible for reviewing it and what the appeal procedure is, and put the request in writing. If the answer comes back easily, with a name and a route, that is a good sign — and a sign we were too pessimistic.

The study tells you what Swedish physicians said they did in 2023 and 2024, and what European law made of it14. What your own regulator, hospital or clinic allows, logs and answers for is the part you can still find out — starting with one written question.

Where each piece of context comes from, and how much of it we read

  1. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - the article this story is about — the whole article — the passage: "We conducted a cross-sectional survey of physicians employed in Swedish health care organizations (N=357; response rate~64%). Data were collected between December 2023 and January 2024 via a verified online panel."
  2. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - the article this story is about — the whole article — the passage: "Physicians use Shadow AI for several purposes, which we grouped into 4 categories: clinical work and decision-making, administrative work, research and professional development, and technological interest and curiosity."
  3. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - the article this story is about — the whole article — the passage: "General-purpose generative AI tools such as ChatGPT are not Conformité Européenne marked, have not undergone conformity assessment, and are not classified as medical devices. When physicians repurpose these tools for clinical reasoning or patient communication, they use applications that lack the legal basis for such use, rendering the practice unauthorized at the regulatory level, not merely informal or unendorsed at the organizational level."
  4. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - the article this story is about — the whole article — the passage: "Under the European Union Medical Device Regulation, AI tools used for clinical purposes must undergo conformity assessment before use; general-purpose tools such as ChatGPT have not done so, rendering their clinical application unauthorized at the regulatory level."
  5. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - the article this story is about — the whole article — the passage: "I entered de-identified data (medical history, examination [or observed findings/clinical findings], test results) into ChatGPT, which suggested various differential diagnoses"
  6. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - the article this story is about — the whole article — the passage: "To generate letters for patients, information from complex radiology reports was entered into GPT, which summarized the information in patient letters in a way that is easier for them to understand"
  7. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - the article this story is about — the whole article — the passage: "To clarify the basis for classifying the reported AI use, we note that the physicians’ descriptions of their use of AI were predominantly general-purpose generative AI applications, mainly ChatGPT, accessed through personal accounts and private devices. None of these tools were certified as medical devices, procured through organizational channels, or integrated into clinical IT infrastructure."
  8. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - the article this story is about — the whole article — the passage: "Shadow AI introduces unique risks related to AI’s capacity for autonomous decision-making, its potential to generate plausible but incorrect medical information, and its ability to process sensitive patient data through external systems"
  9. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - the article this story is about — the whole article — the passage: "The findings highlight a paradox in which the same tools that pose regulatory and safety risks also address real gaps in clinical and administrative support, suggesting that governance approaches must account for this tension rather than relying on prohibition alone."
  10. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - the article this story is about — the whole article — the passage: "although our sample included physicians from diverse health care settings across Sweden, the study’s exclusive focus on a single national context may limit the transferability of our findings to other countries. Further research is needed to determine whether the results from this study are transferable to other countries."
  11. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - the article this story is about — the whole article — the passage: "the free-text format yielded responses that captured the purposes, motivations, and concerns associated with Shadow AI use, but rarely included detailed accounts of how physicians interact with AI tools in practice, for example, in terms of prompting strategies, iterative dialogue, verification routines, or integration into clinical workflows."
  12. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - the article this story is about — the whole article — the passage: "Clinical decision-making activities fall most directly under MDR requirements and therefore represent the most problematic form of Shadow AI use, whereas administrative, research-oriented, and exploratory uses often occupy regulatory “gray zones” associated primarily with organizational governance rather than explicit legal prohibition."
  13. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - the article this story is about — the whole article — the passage: "In using Shadow AI, physicians technically violate IT governance and data policies (unethical or noncompliant behavior). However, they often do so to improve patient communication, speed up administrative workflows, and enhance diagnostic accuracy (pro-organizational or pro-patient behavior)."
  14. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - the article this story is about — the whole article — the passage: "Shadow AI indicates gaps where formal hospital systems may fail to meet health care professionals’ needs and signals a way for physicians to strengthen their experience-based knowledge. It represents a renegotiation of professional boundaries, as physicians bypass institutional constraints to maintain professional efficacy."
  15. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - the article this story is about — the whole article — the passage: "health care organizations may benefit from acknowledging the reality of Shadow AI and developing controlled and transparent environments for experimentation, such as clinical sandboxes, supervised testing pathways, or dedicated AI support structures."
  16. Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484 - the article this story is about — the whole article — the passage: "We argue that health care leaders should not view Shadow AI solely as a compliance violation but as a source of user-driven innovation that signals unmet professional needs. The path forward involves creating secure, monitored environments where physicians can experiment with AI tools safely, bridging the gap between the speed of AI development and the pace of medical governance."

Petersson, L., Irgang, L., Mauritzon, I. et al. (2026). Shadow AI in Swedish Health Care: Qualitative Analysis of Physicians’ Free-Text Answers. Journal of Medical Internet Research. https://doi.org/10.2196/93484

Who paid: The study was funded by the Swedish Knowledge Foundation (KK-stiftelsen) through the Business Models for Information-Driven Healthcare Ecosystems project (grant 220021) and the Multidisciplinary National Health Innovation Research School (grant 20210047-H-02); the funders had no role in study design, data collection, analysis, interpretation or writing.

Do not take this as professional medical advice.

The findings of other studies mentioned here are known to us through this document, which is the one we read; we did not open each of those studies.