The things I won't automate for a client
I’m a pharmacist by registration and an AI builder by trade, and those two things pull against each other more often than you’d think. This post is my actual boundary list — the things I refuse to automate for a client, why each one is a hard no rather than a “depends,” and what it costs to hold the line. If you’re deciding what to hand to AI and what to keep human, this is meant to be a usable answer, not a hedge.
What shouldn’t you automate?
Three categories, in order of how non-negotiable they are: anything that legally or clinically requires a human sign-off, anything that touches identifiable patient data, and anything where a wrong answer fails silently instead of loudly. The first two are bright lines. The third is a judgement call I make on every build, and I run the same checklist each time rather than trust my gut in the moment: what does a wrong output look like, would anyone notice before it did damage, and is there a human in the loop before it goes anywhere that matters.
Everything else — drafting, summarising, scheduling, first-pass data entry, the boring middle of a workflow — is fair game. The “don’t automate this” list is short on purpose. If it were long, I wouldn’t be an AI consultant, I’d just be a pharmacist with a blog.
Why doesn’t clinical sign-off move?
Because the license is mine, not the model’s. When I do Home Medicines Review work, the report that goes to a GP carries my name and my registration number. An AI system can draft a summary, flag a drug interaction I might have skimmed past, or restructure notes into something readable faster than I could type it. What it cannot do is be the reason a dose recommendation was correct. That accountability doesn’t transfer, and no amount of model capability changes who’s answerable when it’s wrong.
This isn’t caution for its own sake. It’s the actual legal and professional structure I operate under, and it would be true whether or not I thought AI was any good. The tool gets faster, the sign-off stays mine.
How is patient data handled?
It isn’t — not through general AI tools, not ever, not even the good ones. If something could identify a real person, it gets stripped before it goes near a model, full stop, even when that costs me time I’d rather not spend. I’ve written the full version of this rule, and what it actually costs in practice, separately: De-identify first.
What does a silent failure look like?
Loud failures are fine. If an automation breaks, throws an error, or produces obvious garbage, someone notices and stops before damage is done. What I won’t build is anything where a wrong output looks plausible enough to pass unchecked — a model that’s confidently, quietly wrong in a way that reads as correct to a tired human skimming it at the end of a shift.
That’s a judgement call because almost every AI output has some risk of this. What changes it from “fine to automate” to “not automating this” is the downstream check. If a human reviews the output before it does anything — sends, prescribes, bills, deletes — a plausible-sounding error gets caught. If the output goes straight through, I want a much higher bar before I’ll wire it up that way, and for anything clinical the bar is: it doesn’t go straight through, ever.
What does this actually cost you?
Slower delivery on the things I won’t fully automate, and sometimes a client wanting something I’ll say no to. The fastest version of a clinical workflow — skip de-identification, skip the human check, let the model’s output go straight through — is usually technically possible, and I won’t build that version, no exceptions. That’s a real cost: less impressive demo, more manual steps, a build that takes longer because a person still has to sit in the loop.
I think it’s the right trade, and not just because I’m a pharmacist first. An AI system that fails quietly in a business context costs money. One that fails quietly in a clinical one costs more than that, and it’s not the kind of mistake you get to learn from and iterate. The evidence-over-hype thing I keep coming back to on this site isn’t a slogan — it’s what happens when you’ve had a professional obligation to be right before you had an interest in AI being fast.
When I run an AI opportunity audit, this list is meant to be one of the deliverables — not a disclaimer at the end, but a named section: here’s what we’re not touching, and why.
Want a boundary list drawn up for your own business? That’s what the AI opportunity audit on /work actually delivers.
Get the next one in your inbox
One graded breakdown a week — health, AI, or building. Five minutes, sourced.