A new research gateway lets AI agents read live hospital device data without ever letting them touch a control.
The system, described in a newly published paper, sits between AI agents and the IEEE 11073 Service-Oriented Device Connectivity (SDC) standard used in many hospitals to network medical devices. It translates device metrics, alarms, and semantic metadata into read-only resources that agents can query through the Model Context Protocol (MCP), the emerging standard for connecting language models to external tools. Any device action an agent proposes is treated as a policy-validated dry run rather than a real command - the researchers call this a safety-bounded design, meaning no agent request can actually trigger an SDC device operation. The team built a Python prototype and tested it against simulated faults and device lifecycle events, backed by independent Java and Python implementations of the protocol path.
MCP has become the default way to wire AI agents into external systems, and most safety debate around it focuses on prompts and permissions that a model can, in theory, be talked around. This paper instead makes the no-execution guarantee structural - the gateway itself has no path to issue a real device command, not just a rule telling the agent not to. That distinction matters more in a hospital than almost anywhere else.
The more revealing result may be a side finding: agents that produce confident, readable answers about alarm states still frequently fail to return that same information in the structured, machine-readable format a real system would need - a gap between sounding right and being usable that any team building clinical AI tools will need to close.