AI in Health Research Is Moving Fast. Can Research Ethics Keep Up?
By Jon Scaccia
20 views

AI in Health Research Is Moving Fast. Can Research Ethics Keep Up?

The same artificial intelligence tools that could accelerate health research are also creating ethical problems that traditional research oversight was never designed to handle. A new World Health Organization report argues that the solution is not simply more IRB review: it is a fundamentally broader system of responsibility.

Artificial intelligence is rapidly becoming part of the machinery of health research.

Researchers can use AI to analyze enormous datasets, identify patterns in medical images, generate synthetic data, recruit or monitor participants, develop hypotheses, analyze qualitative information, and even help write scientific outputs. AI itself is also increasingly the object of health research, as investigators evaluate algorithms designed to diagnose disease, predict risk, influence behavior, or support clinical decisions.

The promise is obvious. Research that once required months of human analysis may sometimes happen dramatically faster.

But that speed creates a problem.

The ethical oversight system governing human-subjects research was largely built for a world in which researchers developed a protocol, recruited identifiable human participants, collected data, and submitted the project to a research ethics committee before beginning.

AI can scramble nearly every part of that model.

In its 2026 report, Artificial intelligence-related health research: ethics review and oversight, the World Health Organization (WHO) argues that existing research ethics systems may not adequately account for the distinctive risks created by AI. Some national guidelines have been updated, but others have not, while institutions may apply inconsistent standards and ethics committees may lack the expertise or capacity to evaluate increasingly complex AI research.

The central question is no longer simply “Did this research receive ethics approval?”

Increasingly, it may be: Who is responsible for protecting people when AI-enabled research falls outside the boundaries of traditional ethics review?

What Counts as AI-Related Health Research?

WHO’s definition is intentionally broad. The report divides AI-related health research into three major categories: health research using data and AI, research conducted with AI tools and technologies, and health research on AI tools and technologies.

Consider a research team training an algorithm on thousands of previously collected mammograms. Researchers might compare the algorithm’s ability to recognize signs of breast cancer with physicians’ performance.

No new patient necessarily needs to walk into a laboratory. Researchers might never interact with the people whose images are being analyzed.

Yet ethical questions remain: Was the original consent appropriate for this new use? Could people be reidentified? Is the dataset representative? Who labeled the data? How accurately does the model perform across different populations? And who could eventually be harmed if a biased or inaccurate model reaches clinical practice?

WHO argues that AI-related data science can generate important public-health and medical benefits, but the absence of direct interaction with participants does not eliminate ethical concerns.

That is one of the fundamental tensions running through the report.

The Research Ethics System Was Built for a Different Kind of Research

Traditional research ethics revolves heavily around identifiable human participants.

That makes sense. Institutional review boards—called research ethics committees, or RECs, in the WHO report—were developed to protect the rights, dignity, safety, and welfare of people participating in research.

But AI changes what “participation” can look like.

A researcher might analyze millions of publicly available social media posts. Another might use anonymized electronic health records. Another might generate synthetic patients from an existing dataset. Still another might adapt a commercially available large language model for a health application.

Some of those activities may fall outside conventional definitions of human-subjects research. That does not necessarily make them ethically uncomplicated.

WHO points to this as a potentially significant oversight gap: research using publicly available, anonymized, or otherwise exempt data can still generate risks involving bias, privacy, discrimination, scientific validity, or downstream use.

And the problem becomes more important because AI research can move extraordinarily quickly.

AI Can Turn Research Into Products Much Faster

One of the most consequential differences WHO identifies is the compressed research-to-product lifecycle.

Traditional pharmaceutical research can take many years before a discovery becomes a widely used intervention. AI technologies can move from research to commercial deployment far faster.

That means mistakes made during research can potentially propagate into real-world systems before the traditional scientific process has had much time to catch them.

Imagine that a model systematically performs worse for a particular population. Or that researchers unknowingly train a system on data that poorly represent the patients where the technology is eventually deployed.

Once incorporated into clinical workflows, those shortcomings could influence screening, diagnosis, treatment, resource allocation, or other decisions at scale.

The speed that makes AI attractive therefore becomes part of its ethical risk.

“Anonymized Data” Doesn’t Automatically Mean “No Ethical Problem”

There is another assumption WHO challenges: that removing someone’s name from a dataset largely resolves the ethical problem.

AI makes that increasingly difficult. Modern data analysis can combine seemingly innocuous pieces of information to infer sensitive characteristics. The distinction between “health data” and ordinary “personal data” can therefore become surprisingly fluid.

A person’s location history, purchasing patterns, internet activity, social media posts, or wearable-device data may not initially look like medical information. But algorithms may be able to use those data to infer something about health.

AI consequently expands not only what researchers can learn from data but potentially what counts as health data in the first place.

That creates difficult questions around consent, privacy, ownership, and reuse.

Synthetic Data Doesn’t Make Those Questions Disappear

One proposed solution is synthetic data: artificially generated datasets designed to reproduce important statistical characteristics of real populations without directly exposing individual records.

The approach could offer important privacy advantages. But WHO cautions against treating synthetic data as an ethical escape hatch.

Synthetic datasets face a fundamental tradeoff. If they reproduce the underlying dataset extremely closely, privacy risks can increase. If they diverge too much from reality, their scientific validity can deteriorate. Synthetic datasets can also reproduce or amplify biases present in the original data.

Creating synthetic representations of underrepresented populations is not necessarily equivalent to actually engaging those populations. WHO argues that researchers may sometimes need greater engagement with communities and better real-world data rather than simply generating artificial substitutes for missing populations.

In other words, technological sophistication does not eliminate the need for human relationships.

AI Research Can Fail in Populations It Was Never Designed to Serve

This becomes especially important when researchers move an AI system from one population to another.

An algorithm developed using data from one hospital, country, racial or ethnic group, or health system may not behave the same way elsewhere (and note, public health has wrestled with external validity for decades.).

AI can amplify the problem because models may encode enormously complex relationships that are difficult for researchers—or users—to see.

A model can therefore appear highly accurate overall while performing substantially worse for particular groups.

WHO argues that researchers need to test AI systems under real-world conditions, disclose their limitations, and provide enough information for ethics committees and other oversight bodies to evaluate whether a tool is appropriate for its intended use.

This changes the ethical question from “Does the algorithm work?” to “For whom does it work, under what conditions, and what happens when it doesn’t?”

The Global Equity Problem Is Even Bigger

Some of the report’s strongest warnings concern AI research in low- and middle-income countries.

Much of the world’s AI research capacity, infrastructure, funding, and technical expertise is concentrated in North America, Europe, and East Asia. Technologies developed in those environments may eventually be tested or deployed elsewhere despite limited involvement from researchers or communities in the places where they will actually be used.

WHO identifies several interconnected dangers: lack of inclusion, inequitable access to benefits, power imbalances between institutions, “ethics dumping,” and health data colonialism.

Health data colonialism describes situations in which researchers acquire data from lower-income settings to advance academic or commercial goals without adequate respect for consent, privacy, autonomy, or community interests.

More diverse data could make AI systems more representative. But collecting data from populations simply to improve algorithms developed and commercialized elsewhere is not necessarily equity. A dataset can be diverse while the underlying system remains profoundly unequal.

WHO therefore emphasizes genuine partnership: researchers in low- and middle-income countries should participate in conceptualizing, designing, and deploying research and share fairly in credit and other benefits.

So Should IRBs Review Everything Involving AI?

Probably not. And this is one of the more nuanced parts of the WHO report.

It would be easy to respond to these risks by dramatically expanding the jurisdiction of research ethics committees. But AI research is being conducted at such scale and speed that making RECs responsible for everything could overwhelm an already constrained system.

WHO explicitly cautions against treating ethics committees as a catch-all solution. Instead, it envisions something closer to a distributed ethics infrastructure.

Research ethics committees remain essential, particularly when research involves human participants or meaningful risks. But responsibility may also need to extend to funders, data access committees, health data hubs, scientific journals, medical societies, regulators, governments, and other institutions.

AI ethics cannot be a single checkpoint. It has to become part of the entire research system.

Ethics by Design Instead of Ethics by Approval

For researchers, WHO’s recommendations point toward what could be described as a lifecycle approach to research ethics.

Ethics should begin while research is being designed, not when an application arrives at an ethics committee.

Researchers should receive AI-specific ethics training, involve relevant health expertise early, identify potential bias and privacy problems during development, test systems for errors, consider broader social and environmental effects, disclose AI use, report negative or inconclusive evaluations, and make potential conflicts of interest visible.

WHO explicitly describes one component of this approach as “ethics by design.” The report recommends that researchers disclose which AI tools they used, their performance, and how they were applied—including, where relevant, prompts used with generative AI systems. It also calls for transparency around internal testing, including negative or inconclusive findings.

Using AI becomes part of the methodology—not merely a productivity tool operating invisibly behind the research.

Could AI Help Review the Ethics of AI?

There is one particularly recursive possibility. Research ethics committees themselves could use AI.

WHO discusses the potential for large language models and automated text-analysis systems to screen protocols, identify possible ethical issues, locate relevant precedents, or perform an initial review before human deliberation.

Potential benefits include faster reviews, greater consistency, and reduced administrative burden. WHO nevertheless frames these systems as potential adjuncts or “first-pass” tools, rather than replacements for human ethical judgment.

Ethics is not merely pattern recognition. Questions about acceptable risk, fairness, autonomy, community values, benefit sharing, or competing rights ultimately involve normative judgments. An algorithm may help humans identify the issues, but determining what society ought to do remains a human responsibility.

What This Means for Public Health

The WHO report is ostensibly about research ethics, but its implications extend well beyond research institutions.

Public health is becoming increasingly data-intensive. Agencies and researchers now have access to machine learning, generative AI, enormous administrative datasets, mobility data, electronic health records, social media data, and other information sources that would have been unimaginable to previous generations of epidemiologists.

The temptation will be to equate technical possibility with scientific legitimacy. But the ability to analyze data does not automatically confer the right to use it. The ability to build an algorithm does not mean that algorithm should be deployed. And statistically impressive performance does not guarantee equitable public-health impact.

AI also weakens some of the institutional boundaries that previously helped determine responsibility.

Who is accountable when a university researcher uses a commercial AI model trained on undisclosed data? What happens when a technology company conducts something that looks like health research but does not consider itself a research institution? Who monitors an algorithm after the original study ends? And who represents communities whose data helped build the technology but who may never benefit from it?

Those are governance questions as much as technical ones.

The Bigger Lesson: AI Is Turning Research Ethics Into a System-Level Responsibility

The WHO report does not argue that AI is incompatible with ethical health research. AI could generate important scientific insights and improve health. But realizing those benefits requires an oversight model capable of operating at the same speed and scale as the technology.

That probably cannot be accomplished through a single institutional review board meeting before a study begins.

Researchers need to anticipate risks. Ethics committees need greater AI expertise and more diverse representation. Funders can make ethical practices conditions of funding. Journals can demand transparency. Data governance bodies can scrutinize access and reuse. Regulators can examine downstream applications. Communities can have meaningful input into technologies affecting them.

And those responsibilities may continue long after a research protocol receives its initial approval.

WHO itself emphasizes that its recommendations are a starting point because AI technologies, uses, benefits, and risks are changing rapidly.

That may ultimately be the defining ethical challenge of AI in public health.

Our institutions were designed to review research before it happened. AI may require us to govern research while it is happening—and continue paying attention to what happens afterward.

Discussion

No comments yet

Share your thoughts and engage with the community

No comments yet

Be the first to share your thoughts!

Join the conversation

Sign in to share your thoughts and engage with the community.

New here? Create an account to get started