Five Categories of AI Risk

Pharmacy Buyer AI Guardrails, a RealActivity educational resource
Back to the resource hub

One shared language for classifying any proposed AI use in pharmacy. Score every request against all five categories at the approval gate; most real uses touch more than one.

1. Clinical and patient safety

Dosing, interactions, substitutions, and any output that can reach a patient.

Control question: Who verifies the output before it touches a patient, and what happens when they disagree with it?

2. Data and privacy

PHI exposure, training-data leakage, and access control.

Control question: Where does our data live, who can see it, and what may the vendor learn from it?

3. Model and accuracy

Hallucination, drift, and bias.

Control question: How is accuracy measured, against what baseline, and how often is it rechecked after go-live?

4. Operational and workflow

Automation errors and over-reliance.

Control question: What happens when staff stop checking, and how would we notice?

5. Compliance and regulatory

CMS, HIPAA, state board of pharmacy, and continuing-education integrity.

Control question: Which rules does this use touch, and who in our organization owns each one?

How to use this page: classify one proposed AI use right now. Write its name at the top, mark every category it touches, and answer the control question for each. An unanswerable control question goes to the vendor as an evidence request.
Educational tool. Not legal, regulatory, clinical, or contracting advice. No vendor is endorsed or criticized.