Pre-Mortem: The Liability Chain Medicare’s AI Prior Auth Model Has Not Drawn

On 1 January 2026, the Centers for Medicare and Medicaid Services in USA launched the WISeR model in six states, introducing prior authorisation to procedures that traditional Medicare had always provided without it. Contracted companies now assess medical necessity using AI. Human clinicians are required to sign off on any denial. The Senate voted 46-50 in July 2026 to keep the programme running. One question has not been answered.

This is the twelfth piece in the Pre-Mortem series. Five questions, applied to the public record, before a programme has had the chance to succeed or fail.

 

The Bet

CMS is wagering that AI-assisted prior authorisation reduces unnecessary Medicare spend without producing the patient-safety incident that forces a political reversal. If WISeR delivers measurable waste reduction without a documented causal chain from AI denial to patient harm, it becomes the template for prior authorisation across Medicare nationally. If it produces that chain, a documented line from AI recommendation to denial to patient harm, it does not just end WISeR. It becomes the reference point that makes AI prior auth politically untouchable in federal health programmes for a generation.

 

The Assumption

CMS has answered every operational question about WISeR except this one:

When an AI recommendation leads a contracted clinician to deny care and a patient is harmed as a result, where does liability sit?

The model design places a human clinician between the AI output and the denial decision. That establishes a paper trail. It does not establish a liability framework. Contractors earn between 10 and 20 per cent of the savings generated by denials and lose that payment when a denial is overturned on appeal. That is a commercial penalty, not a clinical one. The Federal Tort Claims Act does not cover contracted entities. No federal court has tested whether a contracted clinician reviewing AI recommendations at volume carries the same duty of care as a treating physician making an independent clinical judgement.

The assumption doing all the work in this model is that the human review layer is accountability enough. That assumption has not been tested.

 

The Sequence

1 July 2025. CMS published the WISeR notice in the Federal Register and did not submit it to Congress under the Congressional Review Act. That omission would matter later.

1 January 2026. WISeR launched in New Jersey, Ohio, Oklahoma, Texas, Arizona, and Washington.

17 March 2026. The Washington Post published an exclusive: Medicare’s new AI gatekeeper was delaying care for seniors. The University of Washington’s medical system had nearly 100 patients waiting for epidural injections. In Arizona, Phoenix pain specialist Dr Matthew Crooks told Medscape that every epidural injection submitted in the first three months had been denied and described the system as completely nonfunctional and unsustainable. In Texas, initial AI approval rates ran at 62 per cent, against a 92 per cent national approval rate across Medicare Advantage.

25 March 2026. The Electronic Frontier Foundation filed a FOIA lawsuit against CMS in federal court in California, seeking records on WISeR’s AI algorithms, training data, bias safeguards, and the financial incentives paid to contractors. The suit confirmed that CMS had not made its AI methodology or vendor compensation structure publicly available seven weeks after launch.

6 April 2026. CMS published a Federal Register notice delaying prior authorisation implementation for certain services within the model to allow additional time for operational readiness. CMS also issued a corrective action order against one of its AI contractors. Both confirmed that the model’s operational design had not performed as intended in the first quarter.

12 May 2026. The Government Accountability Office issued its determination: WISeR met the Administrative Procedure Act definition of a rule and was subject to the Congressional Review Act. CMS had not made the required submission to Congress before the model took effect.

20 May 2026. Senator Ron Wyden and Representatives Suzan DelBene and Greg Landsman introduced resolutions of disapproval in both chambers, seeking to repeal WISeR under the CRA.

6 July 2026. Gold carding launched in Washington state. Providers achieving a 90 per cent affirmation rate across a minimum of ten prior authorisation requests become exempt from further review for covered services. Quarterly rollout to the remaining five states is planned.

16 July 2026. The Senate voted 46-50 against advancing the disapproval resolution. Party line. WISeR survived. The liability question the GAO had exposed survived with it.

The Pager

Dr Mehmet Oz, Administrator of the Centers for Medicare and Medicaid Services.

The message: WISeR’s accountability chain has not been drawn. The model places a contracted clinician between an AI denial recommendation and a Medicare beneficiary, but no published document establishes where negligence sits when a patient is harmed following an AI-assisted denial. The Federal Tort Claims Act does not cover contractors. Contractors point to the human clinician. Clinicians are reviewing AI output under volume pressure with no published duty-of-care standard for that specific context. When the first federal lawsuit tests this configuration, and one will, CMS will need a published framework, not a contract clause. That framework is easier to write before litigation than after.

 

The Proof

Gold carding is the model’s self-correction mechanism. If quarterly rollout reaches all six states and the 90 per cent affirmation threshold functions as a genuine quality signal, the AI layer contracts over time as trust is established. Proven providers exit prior auth. New entrants face the review. The model becomes calibrated rather than blanket.

If gold carding stalls or rollout criteria are applied inconsistently across jurisdictions, the AI layer expands without a release valve. Prior auth burden accumulates regardless of provider track record. The model becomes a cost-reduction instrument with no exit for providers who have earned one.

The proof of the bet is not the aggregate savings figure. It is whether WISeR, by the end of 2026, has published a liability framework and delivered gold carding in all six states. Without both, the model is running on the same untested assumption it started with.

 

Verdict

If CMS publishes a liability framework for AI-assisted denials before a federal case forces the question, and gold carding delivers consistent rollout across all six states, WISeR will be the strongest government evidence yet that AI-assisted utilisation review can reduce Medicare waste without a patient-safety crisis. The accountability design would become the reference for every federal health programme that follows.

Without the liability framework, WISeR accumulates its risk quietly. Not through a single dramatic incident, but through the gap between AI recommendation volume and human review capacity, compounded by an accountability vacuum no published document has yet closed. That gap does not stay open indefinitely.