The burden of lung cancer is immense. With 2.48 million new cases and 1.8 million deaths recorded in GLOBOCAN 2022, lung cancer remains the leading cause of cancer-related mortality worldwide. More than half of patients are diagnosed at late stages when curative treatment is no longer possible, and the 5-year survival rate sits between 10 and 20% in most regions.
Artificial intelligence is transforming lung cancer care. AI and machine learning tools now assist in interpreting CT scans, predicting patient outcomes, staging disease, guiding surgical decisions, and personalizing treatment plans. Deep learning models applied to CT imaging can match human experts in sensitivity while surpassing them in specificity, and next-generation ensemble models have achieved sensitivity and specificity above 98%.
Yet AI's rise brings serious concerns. From the earliest expert systems like MYCIN in the 1970s through today's autonomous deep learning tools, questions about patient privacy, algorithmic bias, accountability for errors, and the interpretability of opaque "black box" systems have shadowed AI's clinical promise. As AI becomes more powerful, the need for clear ethical and legal frameworks grows more urgent.
The economic stakes are staggering. Lung cancer is projected to impose the largest global economic burden of all cancers, with costs estimated to reach $3.9 trillion by 2050. Technologies that enable earlier detection and better treatment could substantially reduce this burden - but only if deployed responsibly and equitably.
The researchers chose a scoping review design because the literature on AI ethics and law in lung cancer is both novel and heterogeneous - spanning technical, medical, and legal publications. This approach is suited to mapping the breadth of a field rather than synthesizing effect sizes, and was conducted following the established Arksey and O'Malley framework alongside Joanna Briggs Institute guidelines.
The search covered seven major databases including PubMed, Scopus, Web of Science, Cochrane Library, PROSPERO, OAIster, and CABI. No restrictions were placed on language or publication date. The search combined terms for lung cancer, AI technologies, and ethical or legal concepts, and results were supplemented through snowball searching of reference lists.
Eligibility was defined using the PEO framework - Population (lung cancer patients at any stage), Exposure (AI technologies including imaging analysis, predictive modeling, and decision-support), and Outcome (ethical and legal issues plus proposed solutions). All publication types were included except study protocols, and articles had to address AI in lung cancer with at least some ethical or legal discussion.
From 581 retrieved records, 20 met the eligibility criteria. Two independent reviewers screened titles, abstracts, and full texts, with discrepancies resolved through consensus meetings and third-party adjudication. Ethical concerns were categorized across five domains (informed consent, safety and transparency, algorithmic bias, data privacy, and others), and legal concerns across five parallel domains.
The 20 included studies covered AI across the full lung cancer care pathway. Applications were grouped into four categories: screening (detecting pulmonary nodules on chest radiographs and CT using computer-aided detection systems), diagnosis (classifying nodules as benign or malignant and differentiating cancer subtypes), treatment (surgical planning, robotic-assisted surgery, radiation therapy optimization, and drug selection), and prognosis (predicting survival, complications, and recurrence).
Diagnosis was by far the most common application area. The majority of reviewed publications reported AI algorithms classifying pulmonary nodules on imaging or distinguishing lung cancer subtypes using histological and cytological data. Deep learning - particularly convolutional neural networks - was the dominant technology across studies.
Treatment applications showcased AI's expanding surgical role. Studies reported AI assisting in robotic-assisted thoracic surgery to enhance precision and reduce invasiveness, personalizing radiation therapy by regulating dose rates and beam angles, and integrating radiomics with liquid biopsy data to guide targeted therapy selection.
Prognostic AI tools addressed outcomes from surgery and radiotherapy. Models were used to predict postoperative complications, mortality risk, treatment failure, lung adenocarcinoma recurrence, and cardiorespiratory morbidity, with some studies also predicting genetic mutations relevant to prognosis and drug choice.
Data privacy was the dominant ethical concern by a wide margin, cited in 13 of 20 included publications. This concern arises especially in studies using sensitive imaging or genomic data to train AI models, where the scale of data required makes meaningful individual privacy protection both technically challenging and legally complex.
Patient harm and informed consent were the next most prominent issues. Four studies each raised non-maleficence concerns - specifically the risk of patient harm if AI fails to distinguish true from false-positive lung lesions, or provides inaccurate diagnoses and treatment recommendations. Four other studies identified informed consent as essential to preserving patient autonomy in AI-assisted diagnostic and surgical decision-making.
Transparency and algorithmic bias received meaningful but less frequent attention. Three studies flagged the "black box" nature of deep learning models as a critical transparency deficit that undermines clinician trust and model reliability. Two studies addressed algorithmic bias, noting that training data unrepresentative of diverse populations can produce unfair diagnostic outcomes across racial and income groups.
Equity, trust, and liability were the least-discussed ethical concerns. Only single publications addressed equity in AI access, trust in opaque AI systems, and the ethical dimensions of liability - suggesting that while researchers are aware of these issues, the literature has not yet engaged with them in depth.
Legal concerns mirrored ethical ones but were less thoroughly analyzed. Data protection and privacy led all legal categories, cited in nine studies, with researchers pointing to compliance challenges under GDPR in Europe and HIPAA in the United States. Liability ambiguities appeared in three studies, particularly around who bears responsibility when AI tools generate diagnostic or treatment errors.
Cybersecurity and regulatory gaps were also identified. Two studies raised concerns about hacking threats to AI training datasets - a vulnerability that could corrupt algorithms or expose sensitive patient data. Notably, only two studies comprehensively addressed the broader lack of regulation governing AI integration in lung cancer care, and only one each discussed safety and effectiveness standards and intellectual property law around AI algorithm ownership.
Technical solutions proposed spanned encryption, federated learning, and blockchain. Homomorphic encryption was proposed to allow computations on encrypted CT images without exposing data. Federated learning - training shared models across institutions without transferring raw data - was recommended by multiple studies. Blockchain-based data sharing was suggested as another privacy-preserving approach. Explainability tools like class activation maps (CAM and Grad-CAM) were proposed to improve transparency in deep learning image classification.
Policy and legal solutions ranged from guidelines to liability frameworks. Several studies called for specific guidelines governing AI development and deployment in healthcare, and for legal frameworks addressing data ownership and liability. One study controversially proposed granting robots a legal status as "electronic persons" responsible for damages they cause - a proposal widely considered legally ambiguous under current jurisprudence.
The solutions landscape is fragmented and largely unvalidated. Most proposed technical safeguards were demonstrated in experimental or small-scale contexts, and their scalability to real clinical environments was rarely assessed. Trade-offs such as reduced model performance from bias mitigation or higher computational demands from federated learning were seldom acknowledged.
The type of AI system used shapes the ethical and legal risks it generates. Diagnostic deep learning applications - particularly those interpreting CT and chest X-ray images - are most strongly associated with data privacy risks, a lack of transparency, and algorithmic bias. These concerns stem directly from the "black box" nature of deep neural networks and their dependence on large, potentially unrepresentative datasets.
Hybrid and multimodal AI systems generate compounded concerns. Systems that integrate clinical records, genomic data, and imaging raise simultaneously issues of data privacy (from multiple sensitive data streams), informed consent (for use of each data type), and regulatory gaps (because no existing framework comprehensively governs such integrated tools). Yet most studies addressed these concerns in general terms without explicitly linking them to specific AI architectures.
A strong geographic bias limits the review's generalizability. The vast majority of included studies originated from high-income countries - China, Italy, France, Australia, and the United States. This means the review captures almost nothing about how AI ethics and legal frameworks apply in low- and middle-income countries where healthcare infrastructures, regulatory environments, and cultural perspectives on ethics may differ fundamentally.
Ethical concerns were explored more thoroughly than legal ones across the literature. Eight studies recognized ethical issues like data privacy and informed consent but gave no consideration to corresponding legal frameworks. This asymmetry reflects a broader pattern in healthcare AI research where technical and ethical discussions dominate while legal analysis remains shallow or absent.
The gap between proposed solutions and validated practice is substantial. Promising technical approaches like federated learning, homomorphic encryption, and explainability tools have been described primarily in experimental settings. Their deployment at clinical scale - across diverse hospital systems, regulatory environments, and patient populations - has rarely been tested, and the trade-offs between privacy enhancement and model performance are rarely quantified.
Legal analysis throughout the literature lacks depth and jurisdiction-specific detail. Recommendations for data ownership laws and liability frameworks are often aspirational, without accounting for the very different legal landscapes of different countries or the interoperability challenges between frameworks like GDPR and HIPAA. The concept of "electronic personhood" for AI robots, while creative, is inconsistent with current international jurisprudence.
Global equity demands urgent attention. The near-complete absence of studies from low- and lower-middle-income countries means the field lacks understanding of how to implement AI responsibly in contexts with limited healthcare infrastructure, weaker data protection laws, and different cultural frameworks for medical ethics. Future research must actively include these perspectives.
Context-aware, AI-type-specific governance frameworks are the critical next step. Rather than generic ethical guidelines, what is needed are governance frameworks tailored to specific AI technologies (such as diagnostic deep learning vs. multimodal prognostic systems), grounded in realistic clinical environments, legally binding across jurisdictions, and designed with global equity as a core principle.
Data privacy and protection emerged as the most prominent concern in both ethical and legal domains - a finding consistent with broader reviews of AI in healthcare decision-support. The scale of data required to train effective AI models fundamentally conflicts with individual privacy expectations, making technical and regulatory solutions to this tension a central challenge for the field.
The ethical-legal divide is a significant weakness in current research. Ethical concerns are more frequently raised and more thoroughly analyzed than their legal counterparts, leaving a gap in understanding how existing law applies to AI-driven lung cancer care and what new law is needed. Many studies recognized risks but stopped short of proposing legally actionable remedies.
The review calls for governance that is technically feasible, legally binding, and globally inclusive. A meaningful step forward would be the development of AI-type-specific governance frameworks that link specific technologies to specific risks, propose solutions validated in clinical environments, and address the needs of healthcare systems across all income levels - a need not currently met by the existing literature.