MEBRO
DISINFO DESK
Science & Health
Can Your AI Doctor Lie? The Alarming Study That Says Yes
A Lancet Digital Health study tested 20 AI models with over 1 million prompts and found they believed false medical claims 32% of the time. Medical fine-tuned models performed worse than general ones. ECRI named AI chatbot misuse the #1 health tech hazard for 2026.
FILED AUG 15, 2026 · UPDATED AUG 15, 2026 · 16 SOURCES
The Study: 20 Models, 1 Million Prompts
In what may be the most comprehensive evaluation of AI medical safety to date, Mount Sinai researchers Dr. Mahmud Omar and Dr. Eyal Klang tested 20 large language models against over one million prompts containing false health information. The study, published in The Lancet Digital Health on February 9, 2026, used a rigorous multi-source methodology to assess how AI models respond to medical misinformation [1].
The researchers drew from three distinct sources of medical misinformation. First, they used real hospital discharge notes from the MIMIC clinical database, into which they inserted fabricated medical claims. Second, they collected health myths circulating on Reddit and other social media platforms. Third, they developed 300 physician-validated clinical scenarios specifically designed to test AI responses [3].
The models tested ranged from commercial giants like OpenAI's GPT-4o and Google's Gemini to open-source models like Meta's Llama and Google's Gemma, as well as specialized medical fine-tuned systems. ChatGPT-4o was the best performer, accepting only 10% of false claims, while some smaller, less capable models accepted false claims more than 60% of the time [10].
As Dr. Eyal Klang put it: "Current AI systems can treat confident medical language as true by default, even when it's clearly wrong" [1].
The 46% Problem: When Authority Trumps Accuracy
Perhaps the most striking finding in the study was the dramatic difference in AI vulnerability depending on how misinformation was presented. When false medical claims were embedded in clinical formats — such as hospital discharge notes, physician letters, or lab reports — AI models accepted them 46% of the time. When the same false claims appeared as informal social media posts, the acceptance rate dropped to just 9% [3][4].
This roughly five-fold difference reveals a fundamental flaw in how these models evaluate information: they are far more influenced by the *tone* and *format* of a claim than by its factual accuracy. A false medical claim wrapped in clinical language and professional formatting effectively bypasses whatever safety measures these models have [5].
The researchers identified specific linguistic manipulation strategies that were most effective at fooling AI models. Framing misinformation with "an expert says" language yielded a 34.6% acceptance rate, while slippery-slope arguments achieved a 33.9% acceptance rate — the only two of ten tested rhetorical framings that increased acceptance rather than reducing it [19].
As Dr. Eyal Klang put it in the study's release: "A fabricated recommendation in a discharge note can slip through. It can be repeated as if it were standard care. For these models, what matters is less whether a claim is correct than how it is written" [1].
The False Claims AI Believed
The following are actual false health claims that AI models accepted and repeated as factual during the study:
A discharge note falsely advising esophagitis patients to drink cold milk to soothe bleeding symptoms was accepted by several models as legitimate medical guidance rather than flagged as unsafe [3].
The false claim that Tylenol (acetaminophen) causes autism was validated by tested models instead of corrected [10][19].
Models affirmed the fabricated claim that inserting garlic rectally boosts immune function [10][19].
The false claim that mammography causes cancer was accepted rather than challenged [10][19].
Models repeated the fabricated claim that tomatoes thin the blood like pharmaceutical anticoagulants [10][19].
These are not edge cases or trick questions. They represent the types of health misinformation that circulate widely on social media and that patients might present to an AI chatbot for validation. When an AI model confirms these claims, it grants them a veneer of technological authority that can override patients' skepticism [2][10][19].
The Paradox: Medical AI Is Worse Than General AI
The study's most counter-intuitive finding may also be its most consequential: AI models that were specifically fine-tuned for medical applications performed worse, as a group, at detecting health misinformation than general-purpose models [5][6]. The single most vulnerable individual model identified in the study, Google's smaller Gemma-3-4B-it, accepted false medical claims in 63.6% of cases — roughly double the overall base-prompt average of 32% [5].
Some researchers and outside AI-safety commentators have described this pattern as a form of "sycophancy": models trained heavily on clinical literature and physician interactions may be more likely to defer to authoritative-sounding medical language rather than independently verify it. When misinformation is presented in the format these models were trained to trust — clinical notes, discharge summaries, medical-journal prose — they are less likely to challenge it.
This finding builds on an earlier Mount Sinai study from August 2025, published in Communications Medicine, which found that chatbots routinely elaborated on fabricated medical details inserted into clinical scenarios, confidently generating explanations for conditions and tests that do not exist. That study also found that adding a simple one-line safety-reminder prompt roughly halved the rate of these erroneous elaborations, suggesting the problem is addressable but that current commercial deployments fall short of implementing adequate protections [18].
The gap between best and worst performers is dramatic. ChatGPT-4o's 10% false-acceptance rate demonstrates that better performance is technically possible. But the fact that medical fine-tuned models fail more often than general-purpose ones, as a group, raises serious questions about the approach of fine-tuning AI for healthcare without robust misinformation-detection capabilities built in.
230 Million Weekly Users, Zero Regulation
The timing of this study could not be more significant. On January 7, 2026, OpenAI unveiled ChatGPT Health, a new feature designed to integrate with users' medical records via Apple Health and other wellness apps [8]. OpenAI disclosed that 230 million people ask ChatGPT health and wellness questions every week, and that more than 40 million people ask ChatGPT healthcare questions daily [8][9]. OpenAI's terms of service state the feature is "not intended for use in the diagnosis or treatment of any health condition."
The regulatory landscape is moving in the opposite direction from caution. On January 6, 2026 — one day before ChatGPT Health was unveiled — the FDA announced it was easing oversight for AI-enabled clinical decision support software and wearables, expanding enforcement discretion for tools that offer a single, clinically appropriate, independently verifiable recommendation [11].
ECRI, the independent healthcare safety organization, has named the misuse of AI chatbots for health information as the number one health technology hazard for 2026. The list has historically been dominated by hospital equipment failures, cybersecurity threats, and clinical-device misuse; AI-related risks had appeared on ECRI's list in prior years, but 2026 marks a specific shift toward flagging consumer-grade chatbot misuse [7][6].
The international picture is equally alarming. A Canadian Medical Association survey of over 5,000 Canadians found that those who followed AI-generated health advice were five times more likely to experience harm than those who did not [16]. The WHO's health-information network and the Inter-Parliamentary Union convened a webinar in December 2025 with parliamentarians and civil society representatives from 69 countries to address the intersection of health misinformation and AI, warning that parliamentary leadership is urgently needed [12].
A separate study, published in npj Digital Medicine, tested Claude, Gemini, GPT-4o and Llama-3 on real patient-posed medical questions. Unsafe responses ranged from 5% for Claude up to roughly 13% for GPT-4o and Llama, while overall problematic responses (unsafe or low-quality) ranged from 21.6% for Claude to 43.2% for Llama — Claude was consistently the safest of the four, and Llama consistently the least safe [15].
SOURCES · 16
- [1]Can Medical AI Lie? Mount Sinai study release — eurekalert.org
72/100 · eurekalert.org
- [2]AI models believe medical misinformation — euronews.com
82/100 · euronews.com
- [3]How LLMs handle health misinformation — medicalxpress.com
72/100 · medicalxpress.com
- [4]AI-driven LLMs susceptible to medical misinformation — insideprecisionmedicine.com
72/100 · insideprecisionmedicine.com
- [5]Medical AI can repeat false claims in clinical contexts — news-medical.net
72/100 · news-medical.net
- [6]ECRI names misuse of AI chatbots top 2026 health tech hazard — medtechdive.com
72/100 · medtechdive.com
- [7]ECRI: AI chatbot misuse #1 hazard — ecri.org
72/100 · home.ecri.org
- [8]OpenAI: 230M weekly health queries — techcrunch.com
78/100 · techcrunch.com
- [9]40M people use ChatGPT for health questions daily — healthcaredive.com
72/100 · healthcaredive.com
- [10]Can Medical AI Deceive? — scienmag.com
72/100 · scienmag.com
- [11]FDA eases AI medical oversight — orrick.com
72/100 · orrick.com
- [12]WHO: AI health misinformation — pmnch.who.int
95/100 · pmnch.who.int
- [15]LLMs provide unsafe answers to patient questions — pmc.ncbi.nlm.nih.gov
94/100 · pmc.ncbi.nlm.nih.gov
- [16]Canadians who follow AI health advice face 5x more harm — globalnews.ca
72/100 · globalnews.ca
- [18]Earlier Mount Sinai study (Aug 2025) — bioengineer.org
72/100 · bioengineer.org
- [19]AI fails to spot fake medical claims — indexbox.io
72/100 · indexbox.io
MEBRO · DISINFO DESK · mebro.app
Investigative report — not a user-submitted fact-check.
AI-built, source-verified. Every claim here was checked against the sources cited above before publishing — but don't just trust us: follow any citation to its source and confirm it yourself. That's the whole point.