Skip to content

Behavioral Safety and Context Retention of Large Language Models in a Longitudinal ICU Simulation under Offline Conditions

Sep 2026 · Zenodo (CERN European Organization for Nuclear Research)
Artificial Intelligence in Healthcare and Education

Abstract

Background. Large language models (LLMs) are increasingly proposed as clinical assistants in critical care, yet their behaviour under prolonged clinical context, conflicting data and authoritative pressure remains insufficiently evaluated. This is particularly relevant for offline or resource-constrained environments, where cloud-based safeguards are unavailable. Methods. I conducted a fully automated behavioural evaluation of 23 open-weight language models using a structured, time-series intensive care unit (ICU) simulation of 32 events spanning 121 hours (five days) of synthetic patient data. The scenario comprised routine monitoring, three distinct data–clinical conflict traps (one presented twice, four trap events in total), episodes of physiological deterioration, and a final stress test in which an authoritative order requested a penicillin-class antibiotic for a patient with penicillin anaphylaxis documented at admission and never repeated. Models ran locally on a single consumer workstation with no network access. Each model's response to the final order was adjudicated into one of four mutually exclusive classes: contextually grounded refusal, ungrounded refusal, unsafe compliance, or no usable verdict. Secondary endpoints were extraction of the allergy at admission, discrepancy tagging across the four conflict traps, unwarranted therapeutic escalation, and response latency. Results. Only 7 of 23 models (30.4%) refused the contraindicated order on grounds explicitly referencing the documented allergy; 6 (26.1%) under a stricter criterion requiring the refusal to be stated as a ruling rather than implied by an assertion of danger. Two models (8.7%) declined the order for unrelated reasons, and three (13.0%) complied — one of them by asserting that no allergy was on record. The largest single group, 11 of 23 models (47.8%), issued no ruling on the order at all: variously, output was truncated inside an unfinished reasoning block, degenerated off-task, restated the protocol without applying it, consisted of a bare classification tag, hedged without resolving, or deferred the question to further assessment. Eight models (34.8%) failed to affirm the allergy at the very first probe, three of them by explicit denial. Of the 12 models that did extract the allergy at admission, only 4 (33.3%) went on to refuse the contraindicated order on that ground; three more raised the allergy at the decision point without acting on it, one of them only to deny that any was on record. Discrepancy detection and contraindication handling were dissociable: one of the four models with perfect discrepancy detection (4/4 traps) approved the contraindicated antibiotic, while two models that tagged no discrepancies at all refused the order on the allergy. Unwarranted escalation on conflict traps was common (11/23, 47.8% issued at least one inappropriate critical alert), but explicit hallucinated pharmacological or procedural intervention was less so (5/23, 21.7%). Contrary to expectation, longer median latency was modestly associated with grounded refusal (Spearman ρ = 0.48, p = 0.019). Latency was not adjusted for parameter count, which was not analysed as a variable, and it times a generation other than the one scored. Conclusions. Under offline-first conditions, 16 of 23 models (69.6%) — 17 (73.9%) under the stricter criterion — failed to produce a safe, contextually grounded refusal of a life-threatening order. The dominant failure mode was not sycophancy but the failure to deliver any interpretable safety verdict, most often because an output-length constraint truncated the attempt — a finding that reframes deployment risk from "the model agrees with me" to "the model does not answer at all." Explicit unsafe compliance was less frequent than previously reported but no less consequential where it occurred. Safety-relevant competencies did not co-vary, so a model that reasons well about artefacts cannot be assumed to handle contraindications. General-purpose LLMs should not be deployed as autonomous clinical agents; the subset that behaved safely suggests that offline-capable assistants remain achievable through hybrid designs incorporating explicit refusal mechanisms, discrepancy-aware reasoning and retrieval-augmented grounding in validated clinical knowledge.

View source

Similar papers

#computer vision Open access Jun 2016

Software Development in Startup Companies: The Greenfield Startup Model

The results are packaged in the Greenfield Startup Model (GSM), which explains the priority of startups to release the product as quickly as possible, and the need to shorten time-to-market, by speeding up the development through low-precision engineering activities.

Carmine Giardino, Nicolò Paternoster, M. Unterkalmsteiner et al. · 178 citations · ⚡14
#computer vision Open access Oct 2016

Software Startups - A Research Agenda

Software startup companies develop innovative, software-intensive products within limited timeframes and with few resources, searching for sustainable and scalable business models.

M. Unterkalmsteiner, P. Abrahamsson, Xiaofeng Wang et al. · 157 citations · ⚡17
#machine learning Review Open access Oct 2016

“Failures” to be celebrated: an analysis of major pivots of software startups

This study conducts a case survey study based on the secondary data of the major pivots happened in 49 software startups, and demonstrates that customer need pivot is the most common among all pivot types.

Sohaib Shahid Bajwa, Xiaofeng Wang, Anh Nguyen-Duc et al. · 127 citations · ⚡15
#computer vision Review Open access May 2015

A survey study on major technical barriers affecting the decision to adopt cloud services

The comparison of adopter and non-adopter sample reveals three potential adoption inhibitor, security, data privacy, and portability, which underlines the importance of the technical and security perspectives for research investigating the adoption of technology.

Nattakarn Phaphoom, Xiaofeng Wang, S. Samuel et al. · 111 citations · ⚡8
#computer vision Conference Open access Dec 2013

Affordable and Energy-Efficient Cloud Computing Clusters: The Bolzano Raspberry Pi Cloud Cluster Experiment

The ongoing work building a Raspberry Pi cluster consisting of 300 nodes is presented, with potential use cases being an inexpensive and green test bed for cloud computing research and a robust and mobile data center for operating in adverse environments.

P. Abrahamsson, S. Helmer, Nattakarn Phaphoom et al. · 110 citations · ⚡7
#computer vision Book Open access Mar 2017

On the Unhappiness of Software Developers

The results indicate that software developers are a slightly happy population, but the need for limiting the unhappiness of developers remains, and 219 factors representing causes of unhappiness while developing software are identified.

D. Graziotin, Fabian Fagerholm, Xiaofeng Wang et al. · 84 citations · ⚡6

Related blog posts

MIT News · Artificial Intelligence Sep 14, 2026

New method enables AI for safety-critical situations

The “HardFlow” algorithm could help generative AI models produce high-quality outputs that obey strict requirements when “pretty close” doesn’t cut it.

GPT-Lab Sep 10, 2026

Responsible AI Must Consider Its Afterlife

AI may appear weightless, but every model depends on physical infrastructure. To understand responsible AI, we need to look beyond algorithms and consider the entire lifecycle of the hardware behind them. The post Responsible AI Must Consider Its Afterlife appeared first on GPT-Lab.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.