Programmable drug delivery systems are emerging as a transformative class of therapeutic technologies because they can adjust drug release according to physiological signals, algorithmic rules, or external commands. Their appeal lies in the promise of more responsive, individualised, and continuous therapy than is possible with conventional dosage forms. Closed-loop insulin delivery, implantable programmable pumps, responsive antidote systems, and digitally mediated delivery platforms all illustrate this shift from passive administration to active therapeutic control. This shift also changes the ethical character of drug delivery. When a device senses, interprets, and acts on behalf of a patient, dosing becomes partly delegated to software, control architecture, and design assumptions. The ethical question is therefore not only whether the system works, but whether it preserves the patient’s agency while pursuing therapeutic optimisation. The core problem is that programmable delivery systems combine pharmacological intervention, medical device operation, data processing, and algorithmic decision-making in a single therapeutic object. This convergence creates tensions between efficiency and autonomy, adaptability and safety assurance, and automation and human oversight. Existing ethical and regulatory vocabularies do not fully capture these tensions because they often treat drugs, devices, software, and clinical decisions as separable domains. This critical perspective argues that programmable drug delivery requires an ethical design approach from the earliest stages of development. Autonomy must be translated into design features such as consent clarity, override capacity, patient-facing explanation, and withdrawal options. Safety must be treated as a lifecycle property rather than a static pre-market claim. The article proposes a critical framework for classifying programmable delivery systems according to autonomy level, identifying ethical pressure points, and linking them to design and governance requirements. It argues that trustworthy programmable delivery depends not merely on technical performance, but on the deliberate preservation of meaningful human control. Ethical foresight must therefore become part of the engineering logic of programmable drug delivery itself.
Programmable drug delivery systems represent a significant transformation in the relationship between therapeutic products and clinical decision-making. Instead of delivering a fixed dose according to a static schedule, these systems may use sensors, programmed rules, or feedback algorithms to modulate drug release in response to changing physiological conditions. Bioresponsive and closed-loop delivery platforms have been described as part of a broader movement toward systems that actively regulate therapy rather than merely administer it [1].
The most visible clinical example is automated insulin delivery, where sensor data and dosing algorithms increasingly mediate the daily management of type 1 diabetes. Reviews of artificial pancreas technologies and automated insulin delivery show that these systems can reduce burdens of self-management, but they also redistribute responsibility among patients, clinicians, manufacturers, and software architectures [2, 3]. The patient is no longer only a user of a device, but becomes part of a cyber-physical therapeutic loop.
This development creates a central ethical tension: systems designed to optimise therapy may also narrow the space for patient agency. Consensus discussions on automated insulin delivery emphasise benefits, challenges, and practical recommendations, yet the ethical question extends beyond technical reliability to the preservation of meaningful choice, explanation, and override capacity [4]. A critical analysis of artificial pancreas systems similarly shows that autonomy, safety, privacy, and accountability must be treated as core design concerns rather than secondary implementation issues [5].
The central argument of this article is that programmable drug delivery systems should be understood as a new class of ethical objects. They do not simply deliver a drug; they automate or partially automate a dosing decision that has traditionally been negotiated between clinician judgment, patient experience, and pharmacological knowledge. Implantable and minimally invasive programmable delivery systems therefore raise questions that cannot be answered by evaluating only device accuracy or drug release performance [6, 7].
This ethical distinctiveness arises because programmable delivery embeds decision logic into material therapy. A closed-loop system may decide when, how much, and how often a drug is released, while the patient experiences the consequences through bodily effects rather than through a visible decision process. In this sense, algorithmic dosing changes the moral status of delivery architecture, because software assumptions become clinically active interventions [8].
Existing regulatory and design paradigms are only partially equipped for this convergence. Medical device and drug regulations have developed mechanisms for safety, efficacy, quality, and usability, but adaptive software challenges the assumption that a product’s behaviour can be fully specified at the time of approval. Lifecycle regulation of AI- and machine-learning-based software devices has been proposed as one response, yet programmable drug delivery adds the further complication that software outputs can directly alter pharmacological exposure [9].
The ethical concern is therefore not an abstract fear of automation, but a practical concern about accountability, consent, and control. If a programmable delivery system changes therapy based on opaque logic, then patients and clinicians may struggle to identify who is responsible for a harmful dose, a missed intervention, or a contested optimisation decision. Ethical analysis of algorithmic decision-making in health care shows that accountability must be built into the structure of decision systems rather than appended after deployment [10].
Programmable delivery exists along a spectrum of autonomy. At one end are open-loop programmable systems, in which clinicians or users set a delivery profile that the device executes without interpreting real-time physiological data. At higher levels are closed-loop systems that adjust release using sensor feedback, as seen in automated insulin delivery and related bioresponsive platforms [1, 2]. At the most ethically demanding end are adaptive systems that may update performance over time using accumulated patient data, creating uncertainty about future device behaviour [11].
Each level of autonomy introduces a different ethical pressure point. Open-loop systems primarily raise concerns about programming errors, user understanding, and responsibility for parameter selection, whereas fixed closed-loop systems raise concerns about sensor reliability, algorithmic thresholds, and patient dependence on automated correction. Adaptive closed-loop systems intensify these issues because the system may no longer behave exactly as initially explained, which complicates informed consent, safety verification, and clinical supervision [12, 13].
The control architecture of programmable delivery should therefore be classified not only by technical sophistication, but by how much therapeutic discretion is delegated away from the patient and clinician. A system that recommends a dose, a system that executes a pre-authorised dose, and a system that adapts its dosing model over time differ ethically even when they share similar hardware. Table 1 classifies programmable drug delivery systems by their degree of autonomy and the corresponding ethical concerns.
Table 1. Classification of Programmable Drug Delivery Systems: Autonomy Levels, Control Architecture, and Associated Ethical Dimensions
Autonomy level | Control architecture | Representative delivery logic | Primary ethical concern | Required human-control feature |
Open-loop programmable delivery | Pre-set schedule or infusion profile entered by clinician or user | Device executes a programmed dosing pattern without real-time biosignal interpretation | Misprogramming, misunderstanding of settings, unclear responsibility for parameter choice | Clear programming interface, confirmation prompts, clinician review, and patient-accessible explanation |
Sensor-informed advisory delivery | Biosignal monitoring generates recommendations but does not automatically release drug | System suggests dosing adjustment while human actor authorises the action | Automation bias, overreliance on recommendation, reduced critical judgment | Human approval before dosing, explanation of recommendation basis, and visible uncertainty indicators |
Fixed closed-loop delivery | Sensor feedback drives algorithmic dose adjustment according to validated rules | Device automatically modulates release within pre-specified limits | Sensor failure, dosing algorithm faults, silent loss of patient control | Override function, alarm escalation, safe operating boundaries, and clinician monitoring |
Adaptive closed-loop delivery | System updates or personalises control behaviour using patient-specific data over time | Device modifies dosing logic in response to longitudinal performance or behavioural patterns | Consent instability, unpredictable future behaviour, accountability gaps | Change logs, re-consent triggers, model update review, and reversible adaptation |
Networked or remotely commanded programmable delivery | External software, clinician dashboard, or connected infrastructure can alter delivery settings | Dose changes may be initiated or modified through remote commands or cloud-linked systems | Cybersecurity breach, unauthorised control, privacy intrusion, dependency on infrastructure | Authentication, fail-safe local mode, cybersecurity monitoring, and patient notification of remote changes |
Figure 1 illustrates the autonomy spectrum of programmable drug delivery systems and shows how ethical pressure increases as dosing authority shifts from humans to algorithms.

Figure 1. Autonomy Spectrum of Programmable Drug Delivery Systems and the Escalation of Ethical Responsibility
Patient autonomy in programmable drug delivery cannot be reduced to initial consent for device use. In conventional therapy, patients may understand the broad relationship between dose, timing, and therapeutic effect, but adaptive delivery systems introduce future behaviours that may not be fully knowable at the moment of consent. This is especially visible in automated insulin delivery, where practical guidance recognises the importance of user education, expectations, and the continuing role of patients in system management [14].
The right to override or disengage from automated therapy is ethically central because it protects patients from becoming passive recipients of algorithmic control. Open-source and do-it-yourself artificial pancreas systems show that some patients actively seek greater agency by modifying or building systems outside standard regulatory pathways, which reveals both dissatisfaction with rigid device ecosystems and the ethical importance of user control [15, 16]. However, patient-driven innovation also exposes users to responsibility burdens that may exceed what should reasonably be placed on individuals managing chronic disease [17].
Programmable delivery systems risk redefining the patient as a data source rather than as an agent. When systems continuously collect biosignals, infer therapeutic need, and optimise dosing, patient experience may be subordinated to measurable physiological variables. Privacy concerns in health AI show that data-intensive systems can create ethical harms even when clinical performance is strong, because surveillance, secondary use, and loss of informational control may undermine dignity and autonomy [18].
Safety governance for programmable drug delivery must address the fact that harm may arise from interactions among drug kinetics, device mechanics, sensor performance, software logic, and user behaviour. Traditional validation can demonstrate that a system performs under expected conditions, but continuously adaptive or networked systems may encounter conditions not fully captured before deployment. Work on accountability and safety in health-care AI emphasises that safety must be organisationally governed rather than treated as a narrow technical attribute [12].
Failure modes in programmable delivery include sensor drift, algorithmic misclassification, infusion obstruction, corrupted data inputs, software update errors, and inappropriate responses to unusual physiology. Cybersecurity adds another layer of risk because unauthorised access to a connected medical device can threaten both privacy and bodily safety. The recall of a diabetes device because of cybersecurity risks demonstrates that software vulnerabilities are not merely informational hazards but can become direct therapeutic hazards when connected to dosing systems [19].
The limits of pre-market validation are especially important for software-driven systems whose performance may evolve across clinical contexts. Comparative analyses of AI- and machine-learning-based medical device approvals show that regulators have begun to confront post-market learning and lifecycle control, but programmable delivery requires even stronger links between software change, clinical risk, and pharmacological exposure [20]. Reviews of AI in high-risk medical device software similarly show that definitions, recommendations, and regulatory initiatives remain uneven, which creates uncertainty for developers designing adaptive therapeutic devices [21].
Meaningful human oversight should be understood as a graded design requirement rather than a symbolic statement that a human remains somewhere in the process. A human-in-the-loop model requires real-time approval before the system acts, a human-on-the-loop model allows automated action under supervision, and a human-out-of-the-loop model permits action with only retrospective review. Ethical work on trust in medical AI shows that oversight must be credible, informed, and operationally possible, not merely invoked to reassure users [13].
The appropriate oversight model depends on the severity, reversibility, and detectability of the dosing decision. A minor, reversible adjustment within a tightly bounded control range may justify supervisory oversight, whereas high-risk dosing changes with delayed detectability may require active human confirmation. Regulatory discussions of clinical decision support and medical device frameworks indicate that the boundary between advice and autonomous action is ethically and legally significant because it changes who can inspect, contest, and authorise the decision [22].
Human oversight must also be designed so that patients and clinicians can intervene effectively when the system behaves unexpectedly. This requires intelligible alerts, understandable performance summaries, escalation pathways, and mechanisms for pausing or reverting automated control. Responsible AI frameworks for digital health emphasise that oversight must be embedded into workflow, governance, and accountability structures rather than relying on individual vigilance after deployment [23].
Figure 2 presents a human oversight architecture for programmable drug delivery, distinguishing direct approval, supervisory monitoring, and retrospective review according to dosing risk and reversibility.

Figure 2. Human Oversight Architecture for Programmable Drug Delivery: From Real-Time Approval to Lifecycle Review
Ethical risk mapping for programmable drug delivery should begin by identifying the values placed at risk by each system feature. Autonomy may be threatened by opaque automation, beneficence by poorly calibrated optimisation, non-maleficence by software or sensor failures, justice by unequal access or biased performance, and dignity by intrusive data practices. Reviews of AI ethics tools show that principles become useful only when translated into methods, checklists, design controls, and accountable implementation practices [24].
This mapping should then connect values to technical hazards and foreseeable use conditions. For example, an adaptive dosing algorithm may improve individualisation but also create uncertainty about future behaviour, while a remote monitoring function may improve safety but increase privacy and dependency risks. Ethical analysis of medical AI suggests that such trade-offs should be evaluated before deployment, because once automated systems become embedded in care routines they may be difficult for patients or clinicians to question [8, 10].
Ethical risk mapping can be integrated with established engineering methods such as failure mode and effects analysis, but it should not be absorbed into purely technical risk scoring. A dosing hazard may be clinically manageable yet ethically serious if it removes patient control, obscures responsibility, or makes refusal difficult. Table 2 presents an ethical risk mapping for programmable drug delivery, linking design features to potential harms and mitigations.
Table 2. Ethical Risk Mapping for Programmable Drug Delivery Systems: Hazard Sources, Affected Values, and Mitigation Strategies
Design feature or hazard source | Potential ethical harm | Affected ethical value | Severity logic | Mitigation strategy |
Opaque dosing algorithm | Patient and clinician cannot understand why a dose was delivered or withheld | Autonomy, accountability, dignity | High when dosing has immediate or irreversible consequences | Provide explanation layers, decision logs, uncertainty indicators, and clinician-readable rationale summaries |
Sensor-dependent dose adjustment | False readings may trigger underdosing or overdosing | Non-maleficence, beneficence | High when sensor drift is silent or difficult to detect | Sensor redundancy, plausibility checks, calibration alerts, and safe fallback dosing modes |
Adaptive model updates | Future device behaviour may diverge from the behaviour originally consented to | Autonomy, trust, accountability | High when updates alter therapeutic discretion without explicit review | Re-consent triggers, model-change documentation, locked safety boundaries, and review before deployment |
Remote programmability | Unauthorised or poorly communicated setting changes may alter therapy | Safety, privacy, autonomy | High when network compromise can affect dose delivery | Strong authentication, cybersecurity monitoring, local fail-safe operation, and patient notification of changes |
Excessive alarm burden | Users may ignore alerts or become dependent on automation | Safety, dignity, practical autonomy | Moderate to high when alarms are frequent or poorly prioritised | Alarm hierarchy, human factors testing, personalised alert thresholds, and caregiver escalation options |
Data-intensive monitoring | Continuous biosignal collection may enable surveillance or secondary use | Privacy, dignity, justice | High when data are identifiable, sensitive, or shared beyond care | Data minimisation, consent granularity, access controls, and transparent data governance |
Lack of override function | Patient cannot suspend or contest automated dosing | Autonomy, bodily integrity | High when the patient remains conscious and capable of refusal | Immediate override, temporary manual mode, withdrawal pathway, and patient training |
Unequal usability or access | Benefits concentrate among technically literate or well-supported users | Justice, beneficence | High when vulnerable groups are excluded from safe use | Inclusive design, multilingual training, affordability planning, and usability testing across populations |
Ethical risk mapping should also account for cybersecurity as an ethical issue rather than a purely technical domain. A scoping review of cybersecurity risks in medical device benefit-risk analysis shows that security vulnerabilities must be considered in relation to patient harm, clinical benefit, and system trust [25]. For programmable drug delivery, cybersecurity failure can directly compromise bodily integrity because access to data or settings may become access to therapy itself.
The first ethical design principle is to default to patient control wherever clinically reasonable. This does not mean rejecting automation, but it does require that automation be bounded by visible limits, comprehensible explanations, and practical override mechanisms. Consensus discussions on automated insulin delivery and open-source systems both show that patients need not be protected from control; rather, they should be supported in exercising control safely [4, 14].
The second principle is to design for graceful degradation rather than silent failure. When sensors fail, connectivity is lost, or software encounters ambiguous data, the system should shift into a safe and explainable fallback state rather than continuing as though normal operation were assured. Drug delivery platforms intended for closed-loop or responsive operation should therefore treat fallback behaviour, alert escalation, and manual control as core performance specifications, not secondary usability features [1, 7].
The translation pathway should embed ethical design requirements into design controls, regulatory submissions, clinical training, and post-market surveillance. Developers should document autonomy impacts, oversight models, cybersecurity assumptions, update governance, and patient-facing control features alongside conventional safety and performance evidence. Lifecycle approaches to AI-enabled software regulation indicate that this kind of continuing governance is necessary, but programmable drug delivery requires it to be tied explicitly to dosing authority, pharmacological risk, and patient agency [9, 11].
Figure 3 integrates the proposed ethical design principles into a translation pathway that connects early design controls, regulatory evidence, clinical implementation, and lifecycle governance.

Figure 3. Ethical Design Translation Pathway for Programmable Drug Delivery Systems
Programmable drug delivery systems demand a new ethical design vocabulary because they transform drug delivery from a passive administration process into an active, algorithmically mediated therapeutic relationship. Their promise lies in responsiveness, precision, and reduced patient burden, but their risks arise when optimisation is pursued without sufficient attention to autonomy, safety, and oversight. The ethical challenge is therefore not whether automation should be used, but how it should be designed, constrained, explained, and governed.
This critical perspective has argued that autonomy, safety, and human oversight must be treated as design requirements rather than post hoc ethical aspirations. Programmable systems should preserve patient control, provide meaningful override options, make dosing logic intelligible, degrade safely under failure, and remain subject to continuing ethical and regulatory review. Ethical risk mapping can help translate these commitments into concrete development practices.
The future of programmable drug delivery should not be shaped by technical ambition alone. Engineers, clinicians, patients, ethicists, regulators, and manufacturers must work together to define standards for trustworthy therapeutic automation. Ethical foresight must match technological capability if programmable drug delivery is to become not only more intelligent, but more accountable, humane, and safe.
None
None
None
None
Open Access The author(s) retain copyright. This article is licensed under the Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License. It may be shared and adapted for non-commercial purposes with appropriate attribution, an indication of changes, and distribution of adaptations under the same license. Third-party material may be subject to separate terms identified in its credit line. View the license at https://creativecommons.org/licenses/by-nc-sa/4.0/.