Summary

A BMJ editorial argues that major risks are often worsened when organisations fail to act on warning signs. It connects concerns about AI, vaccine safety surveillance and NHS management to weaknesses in risk escalation and accountability.

A BMJ editorial published on 18 September 2026 argues that institutions often have access to warning signs but fail to convert them into action. Kamran Abbasi, editor in chief of The BMJ, links concerns about artificial intelligence, vaccine-safety surveillance and failures in England’s NHS to a common problem: weak risk management and unclear responsibility.

The article is an editorial synthesis rather than a new empirical study. Its central argument is that serious harm can grow when warnings are dismissed, safety systems are overwhelmed or leaders are not prepared to hold responsibility for risk.

Three examples of warnings that were not acted on

The editorial begins with current concerns about AI. It refers to warnings that AI could pose an extreme threat to humanity, an AI researcher’s public departure from Anthropic over safety concerns and Anthropic’s warning that people were attempting to use its Claude system in biological-weapons research. The editorial also points to a BMJ analysis describing how surveillance for biological threats might be designed.

These examples are presented as reasons to treat AI safety warnings as a governance issue rather than as speculative distractions. The editorial acknowledges that some critics believe AI safety concerns are exaggerated to protect the influence of leading companies and shape regulation. Its position is that uncertainty about the scale of the risk is not a sufficient reason to set the warnings aside when control over AI systems is not absolute.

The second example concerns the United States’ Vaccine Adverse Event Reporting System, or VAERS. The editorial summarises a BMJ investigation which found that the system was flooded with adverse-event reports after COVID-19 vaccines were introduced, making it harder for the system’s algorithm to detect safety signals. It also says that the US Food and Drug Administration knew about this monitoring problem but did not act on it.

The editorial makes an important distinction: a failure of the surveillance system did not necessarily demonstrate that COVID-19 vaccines were unsafe. The concern was that a postmarketing safety system, which is intended to identify possible problems after a product reaches wider use, was not functioning effectively under the volume of reports it received.

The third example comes from England’s NHS and the Thirlwall inquiry into infant deaths at the Countess of Chester Hospital. According to the editorial, the inquiry criticised senior management for failing to implement safety measures identified in earlier reports. It also concluded that one death should have triggered an investigation, but senior management appeared not to know about the relevant guidance.

The editorial describes the resulting failure as involving several groups: managers did not act, doctors may not have escalated concerns far enough, nurses defended their own area and teams became dysfunctional. It uses the case to illustrate how professional boundaries and confused accountability can prevent warnings from reaching a decisive response.

Risk responsibility is a management problem

The editorial also draws on a BMJ lecture by Chris Whitty, England’s chief medical officer, about “risk holding” in the NHS. Risk holding refers to the responsibility for recognising, evaluating and acting on threats to patients and services.

Whitty’s analysis, as summarised by The BMJ, says that risk holding in the NHS is concentrated too heavily at the top and is not delegated sufficiently to early- and mid-career doctors. Senior members of clinical teams should retain the main responsibility, but training and preparation for that role are poor. Responsibility also increases abruptly when clinicians move into senior leadership positions.

That pattern matters beyond hospitals. A warning system is useful only when people know who must interpret the signal, who has authority to act and how concerns can be escalated when an initial response fails. In AI governance, the same principle applies to warnings about misuse and loss of control. In public health, it applies to surveillance systems that must identify possible safety problems while evidence is still developing.

The editorial’s conclusion is that the recurring danger is not simply a lack of reports or technical information. It is the failure to manage risk collectively and to act when evidence indicates that a system may be failing. Its cases therefore point towards stronger accountability, clearer escalation pathways and better preparation for people who carry formal responsibility for safety.

Sources