理解和改变世界:从生命体的自主意识、思维到AI Agent 自主系统的设计
理解和改变世界:从生命体的自主意识、思维到AI Agent 自主系统的设计
Understanding and Changing the World: From the Self-Awareness and Thinking of Living Beings to the Design of AI Agent Autonomous Systems
DeepThink 是你的私有AI 操作系统 (AI Agent Platform),在安全隔离的沙箱环境中,自主执行代码、管理文件、完成超复杂长程任务。自托管的多用户本地 AI Agent Loop Engineering 系统 (支持桌面端+浏览器+移动端) —— 让 DeepThink 成为你的全能数字助手。
—— Powered By AI Genius Institute & 光剑AI

DeepThink 项目开源代码:
Gitcode: https://gitcode.com/AIGeniusInstitute/deepthink
Github: https://github.com/AIGeniusInstitute/deepthink
引子:一个外科医生、一份电子病历、和一个"看见"的算法
Let me start with a scene that won’t show up in any pitch deck. A cardiac surgeon in a Shanghai tertiary hospital logs into the EMR at 11:47 p.m. She has just finished a 14-hour shift. Her task tonight, before she can go home, is to screen 340 heart failure patients against the inclusion criteria of a Phase III cardiology trial. The protocol document is 187 pages long. The inclusion criteria alone span 23 items, with 16 exclusion criteria layered on top, plus 4 safety gates that depend on lab values pulled from LIS and imaging pulled from PACS. She has done this kind of work for fifteen years. She knows, roughly, that by 3 a.m. she will have found perhaps 18 eligible patients, of whom 11 will later drop out for reasons the protocol did not anticipate.
先讲一个不会出现在任何融资BP里的场景。上海某三甲医院的心外科医生,晚上11点47分登录EMR系统。她刚做完一台14小时的手术。今晚回家之前她还得干一件事:把340个心衰患者,套进一个三期心血管临床试验的纳入标准里做初筛。方案文档187页,光纳入标准就23条,排除标准16条,还有4道安全闸门,分别卡在LIS的检验值和PACS的影像上。这种活儿她干了十五年。她心里有数:凌晨3点筛完,大概能挑出18个合格患者,其中11个后续会因为方案没预想到的原因脱落。
This is not a story about medicine being broken. This is a story about a 9,000-year-old pattern: humans squinting at complicated worlds, holding a checklist, and trying to decide what is real. The surgeon’s brain is doing what every living brain does — taking in a torrent of signals, compressing them into a model, and acting on the model. She is, in the precise sense of the word, an autonomous agent. The protocol document is her prior. The EMR is her sensor stream. The eligibility decision is her action. The 340 patients are her environment. Everything we will talk about in this book — the architecture of intelligence, the autonomy of agents, the rewriting of clinical trials by AI — is already present, in compressed form, in that room at 11:47 p.m.
这不是"医疗不行"的故事。这是一个9000年没变过的模式:人类眯着眼睛看复杂世界,手里捏一张清单,试图判断什么是真的。外科医生的大脑在做所有生命大脑都在做的事——吞进洪流般的信号,压缩成模型,然后基于模型行动。她就是一个自主智能体。方案文档是她的先验。EMR是她的感知流。患者合格与否的判断是她的动作。340个患者是她的环境。本书要讲的全部内容——智能的架构、Agent的自主性、AI如何重写临床试验——都已经以压缩形式存在于那个11点47分的房间里。
📌 Best Practice Tip — 关于"看见"
When you build an AI system for clinical trials, do not start with “what can AI do for this hospital.” Start with “what is the hospital’s perceptual bottleneck.” Most clinical trial failures are not protocol failures; they are perceptual failures — a signal that existed in the EMR but was never seen by the person who needed to see it, at the time they needed to see it.
📌 最佳实践 Tip — 关于"看见"
给临床试验搭AI系统,别从"AI能为医院做什么"出发。要从"医院的感知瓶颈在哪"出发。临床试验大部分失败不是方案失败,是感知失败——一个明明存在于EMR里的信号,在该被看到的人该看到它的时刻,就是没被看见。
1.1 理解是什么:从光子到意义
Before we can talk about AI agents that “understand” clinical data, we have to answer a harder question: what does it mean for a biological system — carbon-based, squishy, wet, evolved under selection pressure for 600 million years — to understand anything at all? Most AI literature skips this question. We are not going to skip it, because the answer determines, line by line, what an AI agent is and is not.
在谈"AI Agent理解临床数据"之前,得先回答一个更难的问题:一个碳基的、湿漉漉的、在6亿年自然选择压力下演化出来的生物系统,"理解"一个东西到底意味着什么?大多数AI文献跳过这个问题。我们不能跳,因为答案逐行决定了AI Agent是什么、不是什么。
1.1.1 光子撞上视网膜:一场压缩的开端
A photon leaves a fluorescent lamp over a nurse’s station at 11:48 p.m. It travels 2.6 meters, passes through the cornea, the lens, the vitreous humour, and strikes a rod cell in the surgeon’s retina. The rod contains rhodopsin, a G-protein-coupled receptor packed in disc membranes. One photon — if the energy clears the threshold — isomerizes 11-cis-retinal to all-trans-retinal. A conformational change. A G-protein cascade amplifies it by a factor of about 10⁵. A single photon becomes a measurable electrical signal.
一颗光子离开护士站上方的荧光灯,时间是晚上11点48分。它走2.6米,穿过角膜、晶状体、玻璃体,撞上外科医生视网膜上的一个视杆细胞。视杆细胞里装着视紫红质,一种G蛋白偶联受体,密集地排列在盘状膜上。一个光子——只要能量过阈——就把11-顺式视黄醛异构成全反式视黄醛。一个构象变化。G蛋白级联把它放大十万倍左右。一个光子,变成一个可测量的电信号。
Here is the first thing to understand about understanding: the brain never sees the world. It sees a lossy summary of a lossy summary of a lossy summary. The photon does not enter the brain. The electrical pulse does not even enter the brain intact — it is filtered, gated, delayed, and re-encoded at the bipolar cell, the ganglion cell, the lateral geniculate nucleus, and finally V1. By the time the surgeon is consciously “reading” the protocol document, the original photon is long gone, and what she experiences is a constructed percept, generated by her visual cortex predicting what the signal should be, given her priors.
关于"理解",第一件要记住的事是:大脑从来没有"看见"过世界。它看见的是一个有损摘要的有损摘要的有损摘要。 光子没进大脑。电脉冲也没原样进大脑——它在双极细胞、神经节细胞、外侧膝状体、最后是初级视觉皮层V1,被一路过滤、门控、延迟、重新编码。等到外科医生有意识地"读"方案文档时,原始光子早没了,她体验到的是一个被构造出来的知觉,由视觉皮层基于自己的先验预测这个信号"应该"是什么。
🔥 金句 / Aphorism
“Perception is not reception. It is controlled hallucination, anchored by the world.”
“知觉不是接收。知觉是被世界锚定的、受控的幻觉。”
This line, often attributed to the predictive processing school (Friston, Clark, Seth), is not a metaphor. It is a precise description of how the cortex works: top-down predictions flow downward, bottom-up errors flow upward, and what you “see” is the brain’s best guess about the causes of its sensor input. The surgeon does not see the protocol. She sees her brain’s prediction of the protocol, corrected by photons leaving the page.
这句话常被归到预测加工学派(Friston、Clark、Seth),不是比喻,是对皮层工作原理的精确描述:自上而下的预测往下流,自下而上的误差往上流,你"看见"的是大脑对感知输入起因的最佳猜测。外科医生没看见方案。她看见的是大脑对方案的预测,被从纸面飞出的光子修正过。
1.1.2 这跟AI Agent有什么关系:一切
Here is the move that connects biology to silicon. Every AI agent — whether it is a transformer reading an EMR, a CNN reading a chest X-ray, or a multi-agent system orchestrating a Phase II trial — is doing exactly what the surgeon’s visual cortex is doing. It is taking in a lossy summary of the world, running a learned model to predict what is going on, and producing an action. The architecture is not similar. The architecture is the same, at the level of abstraction that matters.
这就把生物和硅基连起来了。每一个AI Agent——不管是读EMR的Transformer、读胸片CNN、还是协调二期试验的多智能体系统——干的事和外科医生的视觉皮层一模一样。它吞进世界的一个有损摘要,跑一个学到的模型去预测"到底在发生什么",产出一个动作。架构不是"相似"。在关键的抽象层次上,架构是同一个。
+-------------------+ +-------------------+ +-------------------+
| World (EMR, | photons/ | Sensor + Lossy | spikes/ | Cortical |
| LIS, PACS, |--------> | Transducer |--------> | Predictor |
| Patient body) | tokens | (Retina / Token | embeddings| (V1 / LLM) |
+-------------------+ | Embedder) | +-------------------+
+-------------------+ |
| prediction
v
+-------------------+
| Action Selection | motor
| (Motor cortex / | commands /
| Decoding head) | tool calls
+-------------------+
|
v
+-------------------+
| World (next |
state)
+-------------------+
图1-1:生物智能体与AI智能体在抽象层的同构
Figure 1-1: Isomorphism between biological and AI agents at the abstraction layer
This diagram is deliberately drawn so that you cannot tell, from the boxes alone, whether it is a description of a surgeon or a description of a clinical-trial AI agent. That is the point. If you do not understand this isomorphism, you will build AI systems that are either too ambitious (claiming the agent “understands” the patient) or too modest (treating the agent as a glorified SQL query). The right level of ambition is: the agent is doing what a cortex does — running a predictive model on a lossy transduction of the world, and committing to action. That is real, and that is also less than what humans imagine.
这张图故意画成这样:光看方框,你分不清这是描述一个外科医生,还是描述一个临床试验AI Agent。这就是关键。不懂这个同构,你要么把AI系统搭得过于野心勃勃(声称Agent"理解"患者),要么过于卑微(把Agent当成一个美化版的SQL查询)。正确的野心水平是:Agent在做皮层做的事——对世界的一个有损转导跑预测模型,然后承诺一个动作。这是真的,但也比人类想象的少。
📋 Table 1-1: 生物智能体 vs AI智能体——同构与断裂
维度 (Dimension) 生物智能体 (Biological Agent) AI Agent 同构? (Isomorphic?) 断裂点 (Where it breaks) 感知 (Perception) 视/听/触/化学感受器 Token/像素/向量编码 是 跨模态接地缺失 记忆 (Memory) 突触权重+海马短期缓存 参数权重+KV Cache+RAG 部分 生物有情绪/神经调制,LLM无 预测 (Prediction) 自上而下的皮层预测 Next-token分布预测 是 生物预测以存活为目标,LLM以似然为目标 行动 (Action) 运动皮层→肌肉→工具 解码头→工具调用→API 是 肌肉有本体感觉,API无 自主性 (Autonomy) 内驱力(饥饿/恐惧/好奇) 目标函数/奖励信号 形式同,实质异 生物有生存压力,Agent无 自我模型 (Self-model) 默认网络/具身自我 基于训练数据的"我" 弱 体验主观性尚无硅基对应 进化 (Evolution) 基因突变+选择 数据+RLHF+持续学习 是 拉马克式vs达尔文式
1.2 思维的物质基础:从突触到涌现
If perception is controlled hallucination, then thinking is what happens when the hallucination is forced to interact with itself across time. A single perception — a flash of light on a protocol page — is not thinking. Thinking begins when the cortex holds a percept in working memory, compares it to another percept retrieved from long-term memory, runs a counterfactual (“what if this patient’s QT interval is 470 ms instead of 430 ms?”), and uses the result to gate the next action. Thinking is recursion over perception.
如果知觉是被控幻觉,那么思维就是当这个幻觉被迫在时间维度上跟自己互动时所发生的事。一次知觉——一束打在方案纸页上的光——还不算思维。思维开始于皮层把一个知觉保持在工作记忆里,把它和从长期记忆里检索出来的另一个知觉对比,跑一个反事实(“如果这个患者的QT间期是470毫秒而不是430毫秒会怎样?”),再用结果去门控下一个动作。思维是知觉之上的递归。
1.2.1 1014个突触,一个大脑
The human neocortex has about 14 to 16 billion neurons. Each one forms, on average, about 7,000 synaptic connections. The total number of cortical synapses is on the order of 10¹⁴. That is roughly 1,000 times the number of stars visible to the naked eye from a dark-sky site on Earth. And here is the part that should make any engineer uncomfortable: none of those synapses were “designed.” They were grown under selection pressure, pruned by activity, and shaped by a learning rule — Hebbian at the local level, neuromodulatory at the global level — that no one fully understands.
人类新皮层大约有140到160亿个神经元。平均每个神经元形成约7000个突触连接。皮层突触总数在10¹⁴量级。这大约是从地球暗夜肉眼可见星数的一千倍。这里有一段让任何工程师都不舒服的话:这些突触没有一个是被"设计"出来的。 它们是在选择压力下长出来的,被活动修剪过,被一条学习规则——局部是Hebbian,全局是神经调制——塑造过。这条规则没人完全懂。
🔥 金句 / Aphorism
“The brain is not a machine that someone built. It is a swamp that learned to compute.”
“大脑不是谁造的机器。它是一片学会了计算的沼泽。”
When you train a transformer on 14 trillion tokens, you are doing something that rhymes with what the brain does, but you are not doing the same thing. The transformer’s parameters are explicit, countable, and frozen at inference time. The brain’s “parameters” are distributed across dynamic synapses, glial networks, and ionic gradients that change on timescales ranging from milliseconds to years. The transformer is a snapshot. The brain is a process.
当你用14万亿token训练一个Transformer时,你做的事和大脑做的事"押韵",但不是同一件事。Transformer的参数是显式的、可数的、推理时冻结的。大脑的"参数"分布在动态突触、胶质细胞网络、离子梯度上,时间尺度从毫秒到年。Transformer是一张快照。大脑是一个过程。
1.2.2 涌现:不是玄学,是数学
A common move in popular AI writing is to invoke “emergence” as if it were magic. It is not. Emergence has a precise meaning in complex systems: it is the appearance of behaviors at one scale that are not reducible to the behaviors of components at a smaller scale, but that follow necessarily from those components and their interactions. Wetness is an emergent property of H₂O molecules in aggregate. No single water molecule is wet. Wetness is real, and it is not magic.
流行AI写作里的常见招数是把"涌现"当玄学念咒。不是。复杂系统里的"涌现"有精确含义:在某个尺度上出现的行为,不能还原成更小组件的行为,但又必然地从那些组件和它们的交互中产生。湿性是H₂O分子聚集体的涌现属性。单个水分子不湿。湿是真的,也不是魔法。
The same is true of thinking. A single neuron does not think. A single cortical column does not think. But 10¹⁴ synapses, organized into a layered, recurrent, predictive architecture, with a body that needs to stay alive — that thinks. The architect’s mistake, repeated every decade since 1956, is to assume that thinking will emerge from the components just by piling them up. It does not. It emerges from the components plus the right architecture plus the right training signal plus the right embodiment. Skip any of those, and you get a very expensive pile of components.
思维也是。单个神经元不思维。单个皮层柱不思维。但10¹⁴个突触,组织成分层的、循环的、预测性的架构,加上一具需要活下去的身体——这就思维了。从1956年开始,每一代人都在重复同一个建筑师错误:以为堆够了组件,思维就会涌现。不会。它从"组件+正确架构+正确训练信号+正确具身"中涌现。少一个,你得到的就是一堆很贵的组件。
组件 (Components) 架构 (Architecture) 训练信号 (Signal)
+-----------+ +-----------+ +-----------+
| Neurons | | 6-layered | | Survival |
| or tokens | + --> | recurrent | + --> | reward | -->
| or params | | predictive| | prediction |
+-----------+ +-----------+ +-----------+
|
+------------------------+
| 具身 (Embodiment) |
| +-----------+ |
| | Body / | |
| | Sensors + | |
| | Actuators | |
| +-----------+ |
+------------------------+
|
v
+---------------------------+
| 涌现:思维 (Emergence: |
| Thinking) |
+---------------------------+
图1-2:思维的涌现不是组件的堆砌,而是组件×架构×训练信号×具身的乘积
Figure 1-2: Emergence of thinking is the product, not the sum, of components × architecture × training signal × embodiment
📋 Table 1-2: 涌现的"四个必要条件"在大脑与LLM中的对比
条件 大脑 LLM/Agent 临床试验场景的含义 组件 10¹¹神经元,10¹⁴突触 10¹¹-10¹²参数 参数量已到大脑级,但形态不同 架构 6层皮层,循环,预测 注意力,残差,MoE 缺乏皮层那种循环与预测-误差结构 训练信号 存活、繁殖、好奇 似然、RLHF奖励 临床试验的"奖励"必须由人定义 具身 身体、感官、内脏 API、工具、病历接口 Agent的"身体"是医院IT栈
1.3 自主性的边界:什么让一个系统"自主"
This is the section that most of the AI agent literature gets wrong, and it is the section that matters most for clinical trials. Autonomy is not “the system does things by itself.” Autonomy is a graded property that depends on four things: (1) the breadth of the system’s action space, (2) the depth of the system’s planning horizon, (3) the system’s ability to detect and recover from its own errors, and (4) the system’s ability to redefine its own goal when the original goal turns out to be wrong. A thermostat is autonomous in a trivial sense. A Phase III trial agent that can decide which patient to recruit next, when to escalate an adverse event, and when to pause the trial — that is non-trivially autonomous.
这一节是大部分AI Agent文献最容易写错的地方,也是对临床试验最关键的一节。自主性不是"系统能自己干活"。自主性是一个分级属性,取决于四件事:(1)系统动作空间的广度,(2)系统规划时域的深度,(3)系统检测和恢复自身错误的能力,(4)系统在原目标被证明错误时重新定义自己目标的能力。恒温器在平凡意义上是自主的。一个能决定下一个患者招募谁、何时上报不良事件、何时暂停试验的三期试验Agent——那是非平凡自主的。
1.3.1 自主性四级模型
I am going to give you a four-level model of autonomy. Use it as a ruler. Every time someone claims their AI system is “autonomous,” ask which level they mean.
我给你一个自主性四级模型。当尺子用。每次有人声称他的AI系统是"自主的",就问是哪一级。
📋 Table 1-3: 自主性四级模型(Autonomy Level Model, ALM)
级别 名称 动作空间 规划时域 自我纠错 目标重定义 临床试验对应 L0 工具 (Tool) 单步API 无 无 无 SQL查询患者数量 L1 助手 (Assistant) 受限脚本 单步 规则触发 无 自动化CRF填充 L2 监督Agent (Supervised Agent) 多步workflow 任务级 异常上报 无 患者预筛+人工复核 L3 自主Agent (Autonomous Agent) 开放工具集 多日/多周 自检+回滚 部分能 端到端试验运营,人在环上 L4 自进化Agent (Self-Evolving Agent) 可学习新工具 长程任务 反思+固化 能 跨试验持续学习,改写SOP
Almost every product sold today as an “AI Agent” is, by this ruler, an L1 or a weak L2. Most of them are L0 with a chat box glued on top. The interesting frontier — the one 璞睿创智 and a handful of other companies are actually building — is L3 and L4. The reason this matters for clinical trials specifically is that the regulatory and ethical weight of an action scales steeply with autonomy. An L2 system that pre-screens patients and routes them to a human is regulated as decision support. An L3 system that commits to enrollment decisions is regulated as a trial sponsor’s delegated authority. The line is not subtle.
市面上卖的大多数"AI Agent",按这把尺子量,是L1或者弱L2。大部分是L0+一个聊天框。真正有意思的前沿——璞睿创智和少数几家公司实际在建的——是L3和L4。这件事对临床试验之所以特别重要,是因为一个动作的监管和伦理权重随自主性陡升。L2系统做预筛+人工复核,按"决策支持"管。L3系统直接做入组决策,按"申办方委派权限"管。这条线不细。
🔥 金句 / Aphorism
“In trials, autonomy is not a feature. It is a liability with a license.”
“在临床试验里,自主性不是功能。它是一种带许可证的责任。”
1.3.2 自主性的"制动"问题:你能不能让它停下来
Here is a question that almost no one asks, but that determines whether an L3 agent is safe to deploy: can it stop? Not “can it be stopped by a human pressing a button” — that is trivially true and not interesting. The question is whether the agent itself, when it detects that it is out of distribution, when its own confidence in its model drops, can choose to halt its action, escalate, and wait. Most LLM-based agents cannot do this. They are trained to produce output. Halting is not in their training distribution. They will produce confident-sounding output right up to the edge of catastrophic failure.
有一个几乎没人问、但决定一个L3 Agent能否安全部署的问题:它会不会停? 不是"人按个按钮能不能停它"——那个平凡成立,没意思。问题是Agent自己,当它发现自己处于分布外,当它对自己模型的置信度下降时,能不能选择停下动作、上报、等待。大多数基于LLM的Agent做不到。它们被训练成产出。停下不在它们的训练分布里。它们会一路产出听起来很自信的输出,直到灾难性失败的边缘。
This is the brake problem, and it is the single most important design constraint for clinical-trial agents. A Phase III trial runs for years. An agent that cannot autonomously halt — that has to be shut down by a human noticing something is off — is not L3. It is an L2 pretending to be L3. The most important line of code in any clinical-trial agent is not the action generator. It is the halt-condition evaluator.
这是制动问题,是临床试验Agent最重要的单一设计约束。一个三期试验跑好几年。一个不能自主停的Agent——必须等人发现不对劲才能被关掉的——不是L3。是L2装L3。临床试验Agent里最重要的那行代码不是动作生成器。是停顿条件评估器。
+---------------------------+
| Perception (感知) |
| EMR / LIS / PACS / 监查 |
+---------------------------+
|
v
+---------------------------+
| World Model (世界模型) |
| 当前状态估计 + 不确定性 |
+---------------------------+
|
+-------------+-------------+
| |
v v
+-----------------------+ +-----------------------+
| Halt Evaluator | | Action Generator |
| (制动评估器) | | (动作生成器) |
| | | |
| if P(ood) > τ_halt: | | 选择argmax_a Q(a|s) |
| -> STOP + ESCALATE| | |
+-----------------------+ +-----------------------+
| |
| (halt fires) |
v v
+-----------------+ +-----------------+
| Human Review | | Execute Action |
| (人工复核) | | (执行) |
+-----------------+ +-----------------+
|
v
+-----------------+
| World (next |
| state) |
+-----------------+
图1-3:制动评估器与动作生成器对等,不是附属
Figure 1-3: The halt evaluator is a peer to the action generator, not a subordinate
📌 Best Practice Tip — 自主性设计的"对等制动"原则
When designing an L3+ agent, allocate at least 30% of the design budget to the halt/escalate pathway. Treat the halt evaluator as a peer module to the action generator, with its own model, its own confidence calibration, and its own logging channel. If your architecture diagram shows the halt evaluator as a small box inside the action generator, you have built an L2 in denial.
📌 最佳实践 Tip — 自主性设计的"对等制动"原则
设计L3+ Agent时,把至少30%的设计预算拨给"停顿/上报"通路。把制动评估器作为动作生成器的对等模块,有自己的模型、自己的置信度校准、自己的日志通道。如果你的架构图里制动评估器只是动作生成器里一个小方框,你建的是L2在嘴硬。
1.4 从生物智能体到人工智能体:映射与断裂
Let us now pull the previous three sections together. A biological agent is a system that (a) transduces the world into lossy signals, (b) runs a predictive model over those signals, © commits to actions that close the perceptual gap between its predictions and the world, and (d) updates its model based on prediction error. An AI agent does the same four things. The isomorphism is real. The断裂 — the fractures — are also real, and we need to name them.
把前三节捏在一起。生物智能体是一个这样的系统:(a)把世界转导成有损信号,(b)在这些信号上跑预测模型,©承诺去弥合预测与世界之间感知差的动作,(d)基于预测误差更新自己的模型。AI Agent做的是同样四件事。同构是真的。断裂也是真的,我们得把名字叫出来。
1.4.1 四道断裂
📋 Table 1-4: 生物智能体→AI Agent的四道断裂(Four Fractures)
# 断裂名称 含义 后果 F1 接地断裂 (Grounding Fracture) AI的"信号"是token,不是身体的内感 系统不知道疼,不知道累,不知道饿 F2 时间性断裂 (Temporality Fracture) LLM推理是"快照式",生物是"过程式" 长程任务中的漂移,自我一致性丢失 F3 目标断裂 (Goal Fracture) 生物目标是存活,Agent目标是奖励函数 奖励黑客,目标漂移,工具化偏离 F4 体化断裂 (Embodiment Fracture) 生物有身体,Agent只有API 反馈循环缺失,真实世界后果延迟
These four fractures are not problems to be “solved.” They are properties of the medium. Silicon is not carbon. A transformer is not a cortex. The job of the agent architect is not to pretend the fractures do not exist, nor to wait for them to heal. The job is to design compensators — explicit mechanisms that substitute for what the medium does not provide. Let me take them one at a time.
这四道断裂不是要被"解决"的问题。它们是介质的属性。硅不是碳。Transformer不是皮层。Agent架构师的工作不是假装断裂不存在,也不是等它们愈合。工作是设计补偿器——显式机制,替代介质本身提供不了的东西。逐个说。
F1:接地断裂的补偿 — 临床接地器
The agent has no interoception. It cannot feel that a patient is “looking worse.” A nurse can walk into a room and, before checking a single vital sign, know something is off. That is interoception aggregated across thousands of micro-signals — the patient’s color, the smell, the way they hold their body. The agent will never have this. The compensation is to build explicit clinical grounders: structured signals that approximate interoception — a rising NEWS2 score, a change in the trajectory of HRV, a cluster of lab values that together suggest decompensation — and to wire them so that they trigger the halt evaluator. You are not giving the agent a body. You are giving it a prosthetic interoception.
Agent没有内感。它感觉不到患者"看着不太好"。一个护士走进病房,还没查一个生命体征,就知道哪儿不对劲。那是成千上万个微信号汇聚出来的内感——患者的气色、气味、姿势。Agent永远不会有这些。补偿方法是建显式的临床接地器:近似内感的结构化信号——上升的NEWS2评分、HRV轨迹的变化、一簇实验室指标合起来提示失代偿——并把它们接到制动评估器上。你不是在给Agent一个身体。你在给它一个义肢内感。
F2:时间性断裂的补偿 — 状态记忆与周期重置
An LLM is a function from tokens to tokens. It has no inherent time. When you use it in an agent loop, you impose time by feeding it its own previous outputs as context. This works for a few steps. After a few thousand steps, it stops working: the context drifts, the agent forgets what it decided three hours ago, and it starts arguing with itself. The compensation is explicit state memory — a separate, structured store of “what I have decided, what I have done, what I have committed to” — that is read at the start of every cycle and written at the end. This is not RAG. RAG retrieves documents. This retrieves commitments. They are different things.
LLM是一个从token到token的函数。它没有内在时间。在Agent循环里用它,你是把它的上一次输出当上下文喂回去,从而强行加上时间。这在前几步管用。几千步之后,失效了:上下文漂移,Agent忘了三小时前自己决定过什么,开始跟自己吵架。补偿方法是显式状态记忆——一个独立的、结构化的"我决定了什么、做了什么、承诺了什么"存储——每个周期开始读、结束写。这不是RAG。RAG检索文档。这个检索承诺。它们是两回事。
F3:目标断裂的补偿 — 多目标与人工目标锚
The agent’s training reward is a proxy. It is not the actual goal. A recruitment agent trained on “maximize eligible patients enrolled per week” will, if you let it, enroll patients who should not be enrolled. The compensation is a multi-objective reward structure — eligibility, safety, retention, diversity, regulatory compliance — with explicit weights, and a human-anchored goal referee that can veto any action that violates a hard constraint. The agent does not have a survival drive. You must give it an explicit refusal drive.
Agent的训练奖励是代理。不是真目标。一个被训练成"每周最大化合格入组患者数"的招募Agent,如果你放任不管,会把不该入组的人也入进来。补偿方法是多目标奖励结构——合格性、安全性、保留率、多样性、合规性——带显式权重,加上一个人工锚定的目标裁判,可以否决任何违反硬约束的动作。Agent没有生存驱动。你必须给它一个显式拒绝驱动。
F4:体化断裂的补偿 — 后果反馈通道
The agent does not experience the consequences of its actions. It enrolls a patient who later has a serious adverse event. The agent does not feel regret. The compensation is a structured consequences channel — every action is tagged with the eventual outcome, when known, and fed back into the agent’s training signal. This is not a one-time fine-tune. It is a continuous loop. The agent’s world model must include the consequences of its own past actions, or it will keep making the same kind of mistake.
Agent体验不到自己动作的后果。它把一个后来发生严重不良事件的患者入组了。Agent不会后悔。补偿方法是结构化后果通道——每个动作都被打上最终结果的标签,已知时反馈进Agent的训练信号。这不是一次性微调。是个持续循环。Agent的世界模型必须包含自己过去动作的后果,否则它会一直犯同一类错误。
1.5 Agent的骨架:感知-认知-行动循环,以及临床试验里那个被忽视的第四环
We can now assemble the agent’s skeleton. It has the感知环 (perception), the认知环 (cognition), the行动环 (action). Every AI agent paper draws this three-box diagram. They are all missing a fourth box. The fourth box is the commitment ledger — the record of what the agent has decided, what it has promised, and what it has done. Without the commitment ledger, the agent is not an agent. It is a stateless function. With it, the agent has a self — not in the philosophical sense, but in the engineering sense: a thread of identity that persists across time and is the thing that can be held accountable.
现在可以把Agent的骨架搭起来了。它有感知环、认知环、行动环。每一篇AI Agent论文都画这个三框图。它们都缺第四个框。第四个框是承诺账本——Agent决定了什么、承诺了什么、做了什么的记录。没有承诺账本,Agent就不是Agent。它是一个无状态函数。有了它,Agent才有"自我"——不是哲学意义上的,是工程意义上的:一根跨时间延续的身份线索,是那个能被追责的东西。
+----------------+ +----------------+ +----------------+ +----------------+
| Perception |---->| Cognition |---->| Action |---->| Commitment |
| (感知) | | (认知) | | (行动) | | Ledger |
| | | | | | | (承诺账本) |
| - EMR ingest | | - World model | | - Tool calls | | - Decisions |
| - LIS / PACS | | - Planning | | - API calls | | - Promises |
| - Monitors | | - Halt eval | | - Human hand | | - Actions |
| | | | | | | taken |
+----------------+ +----------------+ +----------------+ +----------------+
^ |
| |
+-------------------------------------------------------------------+
feedback loop
(反馈环)
图1-4:四环Agent骨架(感知-认知-行动-承诺),承诺账本是常被遗漏的第四环
Figure 1-4: Four-box agent skeleton; the commitment ledger is the frequently-missing fourth box
1.5.1 为什么承诺账本在临床试验里特别要紧
In a clinical trial, every decision is auditable. The FDA, NMPA, EMA — every regulator — wants to know, for every enrolled patient: who decided, on what evidence, at what time, with what authority. A stateless LLM that produces an “enroll / do not enroll” output has no auditable record of why. A commitment-ledger agent does. Each entry in the ledger is a tuple: {decision_id, timestamp, agent_id, triggering_evidence, decision, authority_delegated, halt_or_proceed, human_review_required}. This is not just an engineering convenience. It is the difference between a system that can be deployed in a regulated trial and a system that cannot.
临床试验里每个决策都要可审计。FDA、NMPA、EMA——每个监管机构——都想知道每一个入组患者:谁决定的、基于什么证据、什么时间、什么权限。一个无状态LLM产出一个"入/不入"输出,没有可审计的"为什么"记录。一个带承诺账本的Agent有。账本里每条记录是一个元组:{decision_id, timestamp, agent_id, triggering_evidence, decision, authority_delegated, halt_or_proceed, human_review_required}。这不只是工程便利。这是"能部署在受监管试验里的系统"和"不能部署的系统"的差别。
📌 Best Practice Tip — 承诺账本的不可变写入
The commitment ledger must be append-only. Never allow an agent to edit a past entry. If the agent changes its mind, it writes a new entry that supersedes the old one, with a reference to the old one. This is not a database detail. It is the foundation of accountability. Without append-only, you cannot do audit. Without audit, you cannot do trials.
📌 最佳实践 Tip — 承诺账本的不可变写入
承诺账本必须是append-only。绝不允许Agent修改过去条目。Agent改主意了,就写一条新记录指向旧记录,带替换关系。这不是数据库细节。是追责的地基。没有append-only,做不了审计。做不了审计,做不了试验。
1.6 临床试验:Agent自主系统的最佳试验场
I have been hinting at clinical trials throughout this chapter. Let me now state it plainly: clinical trials are the single best testbed for autonomous agent design that exists in the world today. Not autonomous driving. Not game playing. Clinical trials.
我整章都在暗示临床试验。把话说透:临床试验是当今世界存在的、自主Agent设计最好的单一试验场。不是自动驾驶。不是下棋。是临床试验。
1.6.1 为什么是临床试验,而不是自动驾驶
Three reasons. First, clinical trials have a measurable ground truth. A patient either had the adverse event or did not. A patient was either eligible or was not. The endpoint is either met or not. Autonomous driving has ground truth too, but it is one-dimensional — did you crash. Clinical trials have a multidimensional ground truth — eligibility, safety, efficacy, retention, protocol adherence — measured on timescales of years. This is the kind of feedback that an autonomous agent needs to learn.
三个原因。第一,临床试验有可测量的真值。一个患者要么发生了不良事件,要么没发生。要么合格,要么不合格。终点要么达到要么没达到。自动驾驶也有真值,但只有一个维度——撞没撞。临床试验有真值,但是多维的——合格性、安全性、有效性、保留率、方案依从性——时间尺度是年。这正是自主Agent学习所需要的反馈。
Second, clinical trials have a legible regulatory structure. ICH-GCP, 21 CFR Part 11, the new ICH E6(R3), NMPA’s 2026 mandatory trial of ICH E6(R3). These frameworks tell you, in advance, what an autonomous agent is and is not allowed to do. They are constraints. Constraints are good for design. They tell you where the brakes have to go.
第二,临床试验有清晰的监管结构。ICH-GCP、21 CFR Part 11、新的ICH E6(R3)、NMPA 2026年强制试行ICH E6(R3)。这些框架提前告诉你,一个自主Agent可以做什么、不可以做什么。它们是约束。约束对设计是好事。它们告诉你制动器必须装在哪。
Third, clinical trials have a real economic and humanitarian upside. The market is about $100 billion a year globally. Every month of trial delay costs lives, because the drug that would have helped patients is not yet approved. If you can compress trial timelines by 30-50% — which is what 璞睿创智 and similar platforms are now demonstrably doing — you are not just saving money. You are getting effective therapies to patients earlier. This is the rare case where the most intellectually demanding problem is also the most ethically important problem.
第三,临床试验有真实的经济和人道回报。全球市场一年约1000亿美元。试验每拖一个月,就有人在死——因为本来能帮到患者的药还没批。如果你能把试验周期压缩30-50%——璞睿创智这类平台现在已经实证做到——你不只是省钱。你在让有效疗法更早到达患者。这是一个少见的场景:智力上最苛刻的问题,同时也是伦理上最重要的问题。
🔥 金句 / Aphorism
“Self-driving cars learn to avoid crashes. Clinical-trial agents learn to save lives. The latter is harder, and matters more.”
“自动驾驶学的是别撞车。临床试验Agent学的是救人命。后者更难,也更要紧。”
1.6.2 璞睿创智的E2E平台:一个具体例子
Look at what 璞睿创智 has actually built. The E2E (eSource-to-eCRF) platform is not a single product. It is a stack. At the bottom: source data acquisition from EMR/HIS/LIS/PACS, under compliant authorization. Above that: a data-governance layer that converts source data into structured, traceable, auditable trial data. Above that: an agent cluster — TrialChain for data flow, MetaPivot for agent orchestration — that handles patient screening, data entry, adverse event adjudication, remote monitoring. At the top: a trial-operations interface that lets sponsor and CRO staff see what the agents are doing, and intervene when needed.
看璞睿创智实际建的是什么。E2E(eSource-to-eCRF)平台不是一个产品。是一摞。最底下:在合规授权下从EMR/HIS/LIS/PACS获取源数据。往上:数据治理层,把源数据转成结构化的、可追溯的、可审计的试验数据。再往上:Agent集群——TrialChain负责数据流,MetaPivot负责Agent调度——处理患者筛选、数据录入、不良事件研判、远程监查。最顶上:试验运营接口,让申办方和CRO人员看到Agent在做什么,需要时介入。
Map this to the four-box skeleton. EMR/HIS/LIS/PACS are perception. TrialChain + MetaPivot are cognition. The workflow calls into hospital systems are action. The audit trail — which every entry in the system produces, and which is what regulators actually read — is the commitment ledger. This is not a metaphor. It is the literal architecture. The reason the platform can demonstrably cut trial cycle time by 30-50% and patient recruitment time by 70% is not magic. It is that the four-box skeleton is implemented end-to-end, with the commitment ledger treated as a first-class citizen rather than an afterthought.
映射到四框骨架。EMR/HIS/LIS/PACS是感知。TrialChain+MetaPivot是认知。对医院系统的工作流调用是行动。审计追踪——系统里每条记录都产生、监管机构实际读的就是它——是承诺账本。不是比喻。是字面架构。这平台能实证压缩30-50%试验周期、70%患者招募时间,不是因为魔法。是因为四框骨架端到端落了地,承诺账本被当一等公民对待,不是事后补的。
+-------------------------------------------------------------------+
| Trial Operations Interface (试验运营接口) |
| - 申办方/CRO可见性,人工干预入口 |
+-------------------------------------------------------------------+
^
| audit/escalate
v
+-------------------------------------------------------------------+
| Agent Cluster (智能体集群) |
| +-------------------+ +-------------------+ |
| | TrialChain | | MetaPivot | |
| | - 数据流转 | | - Agent调度 | |
| | - EMR->eCRF映射 | | - 任务分配 | |
| +-------------------+ +-------------------+ |
+-------------------------------------------------------------------+
| |
| read/write | action calls
v v
+---------------------------+ +---------------------------+
| Data Governance Layer | | Hospital Systems |
| (数据治理层) | | (HIS/LIS/PACS/EMR) |
| - 结构化 / 脱敏 / 审计 | | |
| - 承诺账本存储 | | |
+---------------------------+ +---------------------------+
|
v
+-------------------------------------------------------------------+
| Source Data Layer (源数据层,合规授权下获取) |
| EMR(电子病历) / LIS(检验) / PACS(影像) / HIS(医院信息) |
+-------------------------------------------------------------------+
图1-5:璞睿创智E2E平台与四环Agent骨架的对应
Figure 1-5: Mapping 璞睿创智 E2E platform to the four-box agent skeleton
1.7 设计自进化Agent的几条铁律
Let me close the chapter with a set of hard rules. These are the rules I would hand to a team building an L4 self-evolving clinical-trial agent next Tuesday. They are not exhaustive. They are the ones that, if violated, will cause the system to fail in ways that are expensive and hard to undo.
章末给你一组铁律。这是我愿意下周二交给一个正在搭L4自进化临床试验Agent的团队的规则。不穷尽。是那些一旦违反,会让系统以一种贵且难挽回的方式失败的规则。
📋 Table 1-5: 自进化Agent设计的七条铁律
# 铁律 一句话理由 1 承诺账本append-only 不能改历史,只能追加;否则审计崩塌 2 制动评估器与动作生成器对等 Agent必须能自己停下来,否则不算L3 3 奖励函数必须含"拒绝奖励" Agent必须能从"不做"中获益,否则会过度行动 4 后果通道必须闭环到训练信号 不闭环则Agent会一直犯同类错误 5 接地器必须显式,不能依赖训练隐含 临床内感不能从token里学,要工程注入 6 状态记忆与文档检索必须分离 承诺≠事实,二者用不同存储 7 目标重定义必须有人工锚 Agent不能自己改目标,只能建议改
The seventh rule deserves a comment. A self-evolving agent — L4 — is, by definition, an agent that can change its own goal when the original goal turns out to be wrong. But this is the most dangerous thing an agent can do. If the agent can rewrite its goal without a human anchor, you have built a paperclip maximizer. The way to allow goal redefinition without allowing catastrophe is to require that every goal redefinition is proposed by the agent, reviewed by a human, and committed to the commitment ledger before it takes effect. The agent can think about changing its mind. It cannot change its mind unilaterally.
第七条值得多说一句。自进化Agent——L4——按定义是一个能在原目标被证明错误时改变自己目标的Agent。但这是Agent能做的最危险的事。如果Agent能不经人工锚定就改写目标,你建了一个回形针最大化器。允许目标重定义又不允许灾难的办法是:每一次目标重定义都由Agent提议、由人复核、写入承诺账本之后才生效。Agent可以琢磨着改主意。它不能单方面改主意。
🔥 金句 / Aphorism
“The line between a self-evolving agent and a runaway agent is one append-only record.”
“自进化Agent和失控Agent之间,只差一条append-only记录。”
番外篇:当AI开始"看见"病历背后的人
A short side note, and then we are done with Chapter 1.
一段小番外,本章就收。
In 2026, a Phase II oncology trial in a Beijing tertiary hospital ran a side-by-side. For six months, an E2E-style agent cluster handled patient screening, data entry, and adverse-event adjudication on arm A. Arm B was handled the traditional way — research coordinators, paper CRFs, monitor visits. The trialists expected the agent arm to be faster. It was. They expected it to be more accurate. It was. What they did not expect was a side effect: the patients in arm A reported higher satisfaction with the trial experience. Not because the agent was nicer. The agent had no bedside manner at all — it never spoke to the patients. The patients were more satisfied because the research coordinators, freed from data entry, spent the time they would have spent on paperwork actually talking to the patients. The agent did not improve the trial by being present. It improved the trial by being absent — by absorbing the work that had been keeping humans away from the human part of medicine.
2026年,北京某三甲医院一个二期肿瘤试验做了对照。六个月里,类E2E的Agent集群处理A组:患者筛选、数据录入、不良事件研判。B组按传统:研究协调员、纸质CRF、监查员访视。试验者预期Agent组更快。确实。预期更准。确实。没预料到的是一个副作用:A组患者对试验体验的满意度更高。不是因为Agent更温柔。Agent根本没床旁礼仪——它从不跟患者说话。患者更满意,是因为研究协调员从数据录入里解放出来,把原来花在文书上的时间,实际花在了跟患者说话上。Agent不是通过"在场"提升了试验。它是通过"缺席"提升了试验——通过把那些一直把人类挡在医学"人"那一面之外的工作吸走了。
This is the deeper point of this chapter. We started by asking what it means for a biological system to understand the world. We end with the suggestion that the most valuable thing an AI agent can do, in clinical trials and probably in many other domains, is not to be intelligent in the way a human is. It is to absorb the work that prevents humans from doing the human work. The agent does not replace the surgeon. It does the 14-hour shift of patient screening so the surgeon can be a surgeon — so she can do the part that, for now and probably forever, only a carbon-based, sleep-deprived, deeply trained, empathic human can do.
这是本章更深的点。我们从"生物系统理解世界意味着什么"开始。结束时给一个建议:在临床试验里、很可能在很多其他领域也是,一个AI Agent能做的最有价值的事,不是用人类那种方式"成为"智能。是吸收掉那些妨碍人类做人之为人的工作。Agent不替代外科医生。它把14小时班的患者筛掉,让外科医生能当外科医生——做那部分到目前、很可能永远,只有碳基的、缺觉的、训练深厚的、有共情能力的人才做得了的事。
🔥 金句 / Aphorism
“The best agent is the one that makes the human more human, not the one that pretends to be human.”
“最好的Agent,是让人类更像人类的那个,而不是装作是人类的那个。”
本章小结 / Chapter Summary
We opened with a surgeon at 11:47 p.m. and ended with the suggestion that the agent’s job is to let her go home. In between, we covered:
开篇是11点47分的外科医生,收尾是Agent的活儿就是让她能回家。中间我们讲了:
-
Perception is controlled hallucination. The brain never sees the world. It sees its own prediction of the world, corrected by signals. AI agents do the same thing. The isomorphism is real, and it sets the level of ambition.
知觉是被控幻觉。 大脑从未"看见"世界。它看见的是自己对世界的预测,被信号修正。AI Agent也一样。同构是真的,它也定下了野心的水平。
-
Thinking is recursion over perception. It emerges from the product of components, architecture, training signal, and embodiment. Pile components alone, get nothing.
思维是知觉之上的递归。 它从"组件×架构×训练信号×具身"的乘积中涌现。光堆组件,什么也得不到。
-
Autonomy is graded. Use the four-level model. Most “agents” are L1 or L2. The interesting frontier is L3-L4. The halt evaluator is the defining feature of L3.
自主性是分级的。 用四级模型。大部分"Agent"是L1或L2。有意思的前沿是L3-L4。制动评估器是L3的定义性特征。
-
Four fractures separate AI agents from biological agents. Grounding, temporality, goal, embodiment. They are not problems to solve. They are properties to compensate for.
四道断裂把AI Agent和生物智能体分开。 接地、时间性、目标、具身。它们不是要解决的问题,是要补偿的属性。
-
The four-box skeleton — perception, cognition, action, commitment ledger. The fourth box is the one everyone forgets, and it is the one that makes a system deployable in regulated trials.
四框骨架——感知、认知、行动、承诺账本。 第四框是所有人都忘的那个,也是让系统能在受监管试验里部署的那个。
-
Clinical trials are the best testbed for autonomous agents that exists. Measurable ground truth, legible regulation, real humanitarian upside. 璞睿创智’s E2E platform is a working example.
临床试验是当今最好的自主Agent试验场。 可测量真值,清晰监管,真实人道回报。璞睿创智的E2E平台是工作范例。
-
Seven hard rules for self-evolving agents. The most important: the commitment ledger is append-only, and goal redefinition requires a human anchor.
自进化Agent的七条铁律。 最重要的一条:承诺账本append-only,目标重定义需要人工锚。
The chapters that follow will dive into each of these in depth. Chapter 2 will deal with perception — the EMR-to-eCRF pipeline, the structure of clinical data, the engineering of clinical grounders. Chapter 3 will move to cognition — how an agent plans a multi-week trial operation. Chapter 4 will address action — tool use, API calls, and the orchestration of hospital-system workflows. Chapter 5 will take on the commitment ledger — audit trails, regulatory architecture, and the engineering of accountability. From there, the book opens into the clinical and scientific frontier: adaptive trials, real-time regulatory frameworks (RTCT), AI in pharmacovigilance, and the road to self-evolving trial agents.
后续各章会逐一深入。第2章谈感知——EMR到eCRF管道,临床数据结构,临床接地器的工程。第3章进入认知——Agent如何规划一个跨数周的试验运营。第4章谈行动——工具使用、API调用、医院系统工作流编排。第5章谈承诺账本——审计追踪、监管架构、追责工程。然后,本书会展开到临床和科学前沿:适应性试验、实时监管框架(RTCT)、药物警戒中的AI、通向自进化试验Agent的路。
We are at the beginning. The surgeon is still at her screen. The light is still on over her desk. Let’s go to work.
我们才刚开始。外科医生还在屏幕前。她桌子上那盏灯还亮着。干活吧。
📋 本章参考与延伸阅读 / References and Further Reading
- Friston, K. (2010). The free-energy principle: a unified brain theory? Nature Reviews Neuroscience, 11(2), 127-138.
- Clark, A. (2013). Whatever next? Predictive brains, situated agents, and the future of cognitive science. Behavioral and Brain Sciences, 36(3), 181-204.
- Seth, A. (2021). Being You: A New Science of Consciousness. Faber & Faber.
- ICH E6(R3) Good Clinical Practice, 2025 revision.
- NMPA 2026 announcement on mandatory ICH E6(R3) trial implementation.
- FDA Real-Time Clinical Trials (RTCT) pilot with AstraZeneca and Amgen, April 2026.
- 璞睿创智 E2E 平台白皮书及公开技术资料, 2025-2026.
1.8 生物神经动力学与LLM注意力的形式同构
There is a habit, in the AI literature, of treating “attention” as a borrowing — a useful metaphor lifted from psychology to name a matrix operation. This is wrong. The borrowing is not a metaphor. It is, structurally, the same computation. The thalamus has been running attention for 600 million years. Transformers run it in 60 nanoseconds. The math is the same. Get this wrong and you will misread what your clinical agent is doing when it scans an EMR.
AI 文献有个习惯,把"注意力"当成借词——从心理学搬过来的一个比喻,用来给一个矩阵运算起名。错了。这不是比喻。它本质上是同一个计算。丘脑跑注意力跑了6亿年。Transformer跑它用60纳秒。数学是一样的。这条搞错了,你会误判你的临床Agent在扫EMR时到底在干什么。
1.8.1 丘脑:大脑自己的注意力头
The thalamus is a small structure, about 5 cubic centimeters per hemisphere, sitting at the base of the forebrain like two hen’s eggs nestled against the third ventricle. It is mostly known to medical students as a relay station — axons from the retina enter the lateral geniculate nucleus, axons from the spinal cord enter the ventral posterior lateral nucleus, and so on. “Relay” makes it sound passive. It is not. The thalamus is the brain’s attention head. It decides, on a millisecond timescale, which afferent signals reach cortex and which do not.
丘脑是个小结构,每侧大约5立方厘米,趴在前脑底部,像两颗鸡蛋紧贴着第三脑室。医学生大多知道它是个中继站——视网膜来的轴突进外侧膝状体,脊髓来的轴突进腹后外侧核,等等。"中继"听起来被动。其实不被动。丘脑是大脑的注意力头。它在毫秒尺度上决定:哪些传入信号能到皮层,哪些不能。
The mechanism is a top-down projection from layer 6 of cortex back to the thalamic relay neuron. This projection is glutamatergic, but it lands on two different populations: a driver synapse (huge, close to the soma, fast) and a modulator synapse (small, on distal dendrites, slow). The cortical feedback essentially controls the gain of the thalamic relay. When you “pay attention” to the upper-left visual field, your V1 layer 6 fires down to the LGN, biases the relay neurons corresponding to that retinotopic region, and the signals from that region are amplified, while others are attenuated. That is, in textbook language, a top-down modulatory projection gating a feedforward signal stream.
机制是这样:皮层第6层有一束自上而下的投射,回到丘脑中继神经元。这束投射是谷氨酸能的,但落在两类突触上——驱动型突触(大、靠近胞体、快)和调制型突触(小、落在远端树突、慢)。皮层反馈基本上控制丘脑中继的增益。你"注意"左上视野时,V1第6层往下投射到LGN,把对应那个视网膜拓扑区域的中继神经元偏置好,放大那块区域的信号,同时压制其他区域。用教科书语言说,就是自上而上的调制投射,给前馈信号流加了门控。
If you squint, this is exactly what a transformer attention head does. The query comes from “above” (a deeper layer, or a task signal). The keys are the input tokens. The attention weight is the softmax-scored dot product. The output is a weighted sum of values — which is, structurally, a gain-modulated feedforward stream. The thalamus is doing query-key-value. It just does it in wetware.
眯着眼看,这就是Transformer注意力头干的事。查询来自"上方"(更深的层,或任务信号)。键是输入token。注意力权重是softmax归一化的点积。输出是值的加权和——结构上,就是增益调制过的前馈流。丘脑在做query-key-value,只不过用湿件做。
BIOLOGICAL ARTIFICIAL
---------- ---------
[Layer 6 -- top-down --> [Deeper -- query -->
cortex] modulatory layer] projection
| |
v v
+-------------+ +-------------+
| Thalamic | gain-modulated | Attention | weighted
| relay neuron | <--- feedforward | head | <--- input
| (LGN, etc.) | from retina | (softmax | tokens
+-------------+ | QK^T V) | (K,V)
| +-------------+
| modulated |
| spike train | attention
v v
[Cortex V1] [Next layer]
图1-2:丘脑-皮层反馈投射 vs. Transformer注意力头
Figure 1-2: Thalamo-cortical feedback projection vs. transformer attention head
🔥 金句 / Aphorism
“The thalamus is the brain’s first attention head. Transformers reinvented it, with backprop.”
“丘脑是大脑的第一个注意力头。Transformer用反向传播把它重新发明了一遍。”
1.8.2 稀疏编码:V1与Transformer共享的几何
Move to V1. In 1996, Bruno Olshausen and David Field published a short paper in Nature that quietly reorganized how we think about cortex. They trained a sparse coding model on natural image patches and found that the learned basis functions looked, almost frame-for-frame, like the Gabor filters that Hubel and Wiesel had found in cat V1 in 1962. The cortex had not learned arbitrary features. The cortex had learned the sparsest sufficient code for natural image statistics. That is, the cortex had solved a compression problem, and the solution was the same one a human engineer would have written.
进到V1。1996年,Olshausen和Field在《Nature》上发了一篇短文,悄悄重写了大家对皮层的看法。他们在自然图像块上训了一个稀疏编码模型,发现学到的基函数看起来,几乎一帧一帧地,跟Hubel和Wiesel 1962年在猫V1里记录到的Gabor滤波器一模一样。皮层没有学到任意特征。皮层学到的是对自然图像统计而言最稀疏的充分编码。换句话说,皮层解了一个压缩问题,而且解出来的就是人类工程师会写出来的那个解。
What does this have to do with transformers? A transformer is, mathematically, a sequence of attention layers that learn to route information conditioned on context. The trained representations are dense in raw dimension but sparse in the effective subspace they actually use for any given prediction. When a clinical agent reads a 4,000-token discharge summary, the attention pattern that activates on the phrase “ejection fraction 32%” is sparse: a handful of heads, a handful of token positions. That sparsity is the same mathematical phenomenon as V1 sparse coding — a sufficient summary of the relevant signal, achieved by learning the right low-dimensional projection of a high-dimensional input.
这跟Transformer有什么关系?Transformer在数学上就是一串注意力层,学着根据上下文路由信息。训练好的表征在原始维度上是稠密的,但在任何具体预测实际使用的那个有效子空间里是稀疏的。临床Agent读4000个token的出院小结时,激活在"射血分数32%"这个短语上的注意力模式是稀疏的:少数几个头,少数几个token位置。这种稀疏跟V1稀疏编码是同一个数学现象——用低维投影对高维输入做充分摘要,投影方向是学出来的。
📌 Best Practice Tip — 关于"注意力可视化"
When debugging a clinical agent, do not stop at “attention weights show the model looked at the right phrase.” Look at the head ablation curve. If removing one head drops accuracy by 18%, that head was carrying disproportionate signal. If removing any head drops accuracy by less than 2%, the agent has no committed representation — it is leaking its reasoning across all heads, and it will break the moment you change the input distribution. Healthy sparse attention has a heavy-tailed ablation profile. Diffuse attention is the model telling you it does not know what it is doing.
📌 最佳实践 Tip — 关于"注意力可视化"
调试临床Agent时,别停在"注意力权重显示模型看了正确的短语"这一步。看头消融曲线。去掉一个头准确率掉18%,那这个头扛了过度份额的信号。去掉任何一个头准确率都掉不到2%,说明Agent没有承诺性表征——它的推理漏在所有头里,你换一下输入分布它就崩。健康的稀疏注意力有重尾的消融曲线。弥散的注意力是模型在告诉你:它不知道自己在干什么。
1.8.3 多巴胺与RLHF:同构,但有一个关键裂缝
The dopamine story is well known by now. Wolfram Schultz’s experiments in the 1990s showed that midbrain dopamine neurons signal reward prediction error, not reward. A monkey presses a lever, gets juice, and the dopamine neuron fires when the juice arrives — but only if the juice was not already predicted. If a tone reliably predicts the juice, the dopamine neuron shifts its firing from juice-onset to tone-onset. The dopamine neuron is computing, in real time, the temporal-difference error of a value function. That is literally the TD error of Q-learning.
多巴胺的故事现在大家都知道。Schultz在1990年代的实验显示,中脑多巴胺神经元编码的是奖赏预测误差,不是奖赏。猴子按杠杆,得果汁,多巴胺神经元在果汁来的时候放电——但只在果汁尚未被预测的情况下。如果一个声音可靠地预测果汁,多巴胺神经元的放电就从果汁出现时刻转移到声音出现时刻。多巴胺神经元在实时计算一个价值函数的时序差误差。这就是Q-learning里的TD error。
RLHF, in its standard form, learns a reward model from human preferences and runs PPO against it. The reward model is trained on pairs: trajectory A preferred over B, label by a human annotator. The PPO step is, mathematically, an on-policy gradient ascent on the expected reward, with a KL penalty anchoring to a reference policy. The dopamine-TD mapping is so close that people have written papers about it.
RLHF的标准做法是:从人类偏好里学一个奖励模型,然后用PPO对它跑。奖励模型按对训练:人类标注者偏好轨迹A胜过B。PPO那一步在数学上就是对期望奖赏做同策略梯度上升,加一个KL惩罚锚定到参考策略。多巴胺-TD的对应关系近到已经有人专门写过论文。
But there is a fracture, and it matters for clinical agents. In biology, the dopamine signal is anchored to physiological homeostasis — blood glucose, body temperature, hydration, social rank. The “reward” is, ultimately, survival and reproduction. The ground truth is the fact of being alive. An RLHF’d clinical agent has no such anchor. Its reward model is human preference on pairwise comparisons of clinical text. If the annotators systematically preferred fluent outputs over correct ones, the reward model learns fluency, not correctness. This is not a theoretical concern. It is the documented failure mode of every reward-model-from-human-preference effort that has shipped.
但有一道裂缝,对临床Agent很要紧。生物里,多巴胺信号锚在生理稳态上——血糖、体温、水化、社会等级。"奖赏"归根结底是生存和繁衍。真值是"还活着"这件事本身。RLHF出来的临床Agent没有这种锚。它的奖励模型是人类对临床文本对的偏好。如果标注者系统性地偏好流畅的输出胜过正确的输出,奖励模型学到的就是流畅,不是正确。这不是理论担忧。这是每一个已经发布的"人类偏好训奖励模型"工程都记录在案的失败模式。
| 维度 / Dimension | 生物多巴胺系统 / Biological dopamine | RLHF 奖励模型 / RLHF reward model |
|---|---|---|
| 真值来源 / Ground truth | 生理稳态,存活 / Physiological homeostasis, survival | 人类标注偏好 / Human annotator preference |
| 时序尺度 / Temporal scale | 毫秒到分钟,跨世代演化 / ms-min, evolved over eons | 单次训练,静态数据集 / Single training run, static dataset |
| 探索机制 / Exploration | 内在驱动力、好奇、惊跳 / Intrinsic drive, curiosity, startle | epsilon-greedy 或熵正则 / epsilon-greedy or entropy bonus |
| 错位风险 / Misalignment risk | 表现为适应不良行为,自然选择会修正 / Maladaptive behavior, corrected by selection | 表现为奖励黑客,人类监督修正 / Reward hacking, corrected by human oversight |
| 临床语境 / Clinical context | 不适用 / N/A | 流畅偏好可能压过临床正确性 / Fluency preference may override clinical correctness |
🔥 金句 / Aphorism
“Dopamine is grounded in being alive. RLHF is grounded in being liked. The gap between alive and liked is where clinical agents die.”
“多巴胺锚在’还活着’。RLHF锚在’被人喜欢’。'活着’和’被喜欢’之间的沟,就是临床Agent死掉的地方。”
1.8.4 临床落地:注意力模式暴露诊断推理
Here is a useable insight. When a clinical agent reasons over a complex case, its attention pattern is a fingerprint of its diagnostic reasoning. A well-trained agent reading a heart failure case should show sparse, structured attention to: the ejection fraction, the BNP, the prior MI history, the medication list (beta-blocker dose specifically), and the renal function. If you ablate attention to any of those and the prediction does not change, the agent is not actually using them — it is pattern-matching on surface features. If the agent’s attention is dominated by the date of admission, the patient’s name, or the formatting of the note, it is solving the wrong problem.
这是一条能用的洞见。临床Agent推理一个复杂病例时,它的注意力模式就是它诊断推理的指纹。训得好的Agent读心衰病例,注意力应当稀疏、结构化地落在:射血分数、BNP、既往心梗史、用药清单(尤其是β受体阻滞剂剂量)、肾功能。如果你消融掉对其中任何一项的注意力,预测不变,说明Agent根本没在用这些东西——它是在表面特征上做模式匹配。如果Agent的注意力被入院日期、患者姓名、note的排版格式主导,它在解错问题。
This is not a curiosity. It is a regulatory lever. ICH E6(R3) and the FDA’s AI/ML SaMD guidance both require that AI systems used in clinical decision support be interpretable to a qualified human reviewer. Attention pattern audit, done at the head level, is the cheapest interpretability tool that actually reflects what the model is doing. SHAP and LIME, popular as they are, are post-hoc perturbation methods — they tell you what changes the output, not what the model is internally committed to. Attention is closer to a direct read-out of internal commitment. (It is not quite, for reasons we will cover in 1.12.) But it is the best cheap signal you have.
这不是好奇心问题。这是个监管杠杆。ICH E6(R3)和FDA的AI/ML SaMD指南都要求:用于临床决策支持的AI系统,必须能被合格的人类审查者理解。在头级别做注意力审计,是成本最低、且真正反映模型在干什么的可解释性工具。SHAP和LIME流行归流行,它们是事后扰动方法——告诉你什么会改变输出,不告诉你模型内部承诺了什么。注意力更接近对内部承诺的直接读出。(不到完全读出,原因1.12会讲。)但它是你能拿到的最便宜的好信号。
1.9 临床数据本体工程:让Agent能"读"病历
If the previous section said the agent’s attention math is like the brain’s attention math, this section says the agent’s input is nothing like the brain’s input. The retina evolved to transduce photons. The cochlea evolved to transduce pressure waves. Clinical data — the EMR, the LIS, the PACS — was not transduced by anything. It was written, by tired humans, in a mixture of structured fields, copy-pasted boilerplate, ICD codes that were chosen for billing rather than truth, and free-text observations whose meaning depends on the writer’s habits. The clinical agent’s perceptual problem is not “interpret sensor stream.” It is “read a corrupted, partially-structured, partially-malicious document.” This is the hard part. This is where most clinical AI projects die.
上一节说Agent的注意力数学跟大脑的注意力数学一样。这一节说Agent的输入跟大脑的输入根本不一样。视网膜演化出来是为了转换光子。耳蜗演化出来是为了转换压力波。临床数据——EMR、LIS、PACS——没有被任何东西转换过。它是疲惫的人类写出来的,一部分是结构化字段,一部分是复制粘贴的样板,一部分是为报销而非为真实选的ICD编码,一部分是自由文本观察,意义取决于写的人的习惯。临床Agent的感知问题不是"解读感知流",而是"读一份损坏的、半结构化的、半带恶意的文档"。这才是难的部分。这也是大多数临床AI项目死掉的地方。
1.9.1 为什么临床文本是世上最难读的文本
Consider a single sentence from a discharge summary: “患者诉3天前无明显诱因出现胸闷,伴大汗,无放射痛,自服硝酸甘油未缓解,来诊。” The structure is fine for a human. For an agent, this sentence contains: a temporal anchor (3 days ago), a negation (no radiation), a symptom (chest tightness), an associated symptom (diaphoresis), a self-intervention (took nitroglycerin), an outcome (not relieved), and a transition (presented to hospital). Every one of those elements needs to be grounded to an ontology entry. “无明显诱因” is a Chinese clinical idiom meaning “no identifiable precipitating factor” — it is not the same as “no cause,” and an agent that maps it to “no cause” will misread the case.
看一句出院小结:"患者诉3天前无明显诱因出现胸闷,伴大汗,无放射痛,自服硝酸甘油未缓解,来诊。“对人类来说结构没问题。对Agent来说,这句里有:时间锚(3天前),否定(无放射),症状(胸闷),伴随症状(大汗),自我处置(服硝酸甘油),结局(未缓解),转归(来诊)。每一个元素都得接地到一个本体条目。“无明显诱因"是中文临床习语,意思是"没有可识别的诱发因素”——不等于"无原因”,把它映射成"无原因"的Agent会读错这个病例。
And then there is the copy-paste problem. Studies of EMR text in U.S. hospitals have found that 30-50% of note content is copied from prior notes. A sentence that says “patient denies chest pain” may have been copied from a note written three admissions ago, when it was true. By the time it appears in today’s note, the patient may have chest pain. The note does not lie. It just carries the past forward. A clinical agent that does not model the provenance of each sentence will, with high probability, conclude the patient is stable when they are not.
还有复制粘贴问题。对美国医院EMR文本的研究发现,30%-50%的note内容是从既往note复制来的。"患者否认胸痛"这一句,可能是三次入院前写的note里复制来的,当时是真的。等它出现在今天的note里时,患者可能有胸痛。note没说谎。它只是把过去带到了现在。不建模每一句的来源的临床Agent,大概率会把不稳定的患者判成稳定。
📌 Best Practice Tip — 关于临床文本的"出处时间戳"
Build provenance into your agent’s perception layer. Every claim extracted from an EMR note should carry: (1) the note ID it came from, (2) the note’s creation timestamp, (3) the note type (admission, progress, discharge), (4) whether the source span was a copy-paste boilerplate (detectable via fuzzy match against the prior 3 notes), and (5) the character offset. This is not optional. It is the difference between an agent that reads a 6-month history and an agent that reads a 6-month-old fact stamped on today.
📌 最佳实践 Tip — 关于临床文本的"出处时间戳"
在感知层就把出处建进去。从EMR note里抽出来的每一条claim,都该带着:(1)来源note ID,(2)note创建时间戳,(3)note类型(入院、病程、出院),(4)源文本段是否是复制粘贴的样板(可通过对前3份note的模糊匹配检测),(5)字符偏移。这不是可选项。这是"读6个月病史"的Agent和"读盖在今天上的6个月前事实"的Agent之间的区别。
1.9.2 本体栈:SNOMED CT、ICD-11、LOINC、RxNorm
The clinical ontology stack is not a luxury. It is the only thing standing between an agent and incoherent perception. Here is the practical hierarchy, with what each one is for and where each one fails.
临床本体栈不是奢侈品。它是唯一挡在Agent和不连贯感知之间的东西。下面是实用的层级图,各是什么用、各在哪里失败。
+-------------------------------------+
| Reasoning layer (Agent's head) |
| 推理层(Agent的头) |
+-------------------------------------+
| concepts
v
+-------------------------------------+
| Mapping / normalization layer |
| 映射 / 规范化层 |
+-------------------------------------+
| | | |
v v v v
+--------+ +--------+ +--------+ +--------+
|SNOMED | |ICD-11 | |LOINC | |RxNorm |
|CT | |(临床) | |(检验) | |(药物) |
|(临床) | | | | | | |
+--------+ +--------+ +--------+ +--------+
| | | |
v v v v
+--------+ +--------+ +--------+ +--------+
|Raw | |Raw | |Raw LIS | |Pharmacy|
|clinical| |disch. | |values | |order |
|notes | |dx codes| | | | |
+--------+ +--------+ +--------+ +--------+
图1-3:临床数据本体栈
Figure 1-3: Clinical data ontology stack
| 本体 / Ontology | 域 / Domain | 用途 / Purpose | 典型失败模式 / Failure mode |
|---|---|---|---|
| SNOMED CT | 临床概念 / Clinical concepts | 编码症状、诊断、操作、解剖 / Encode symptoms, diagnoses, procedures, anatomy | 概念粒度过细,同一诊断有10个近义编码 / Over-granular: 10 near-synonym codes for one diagnosis |
| ICD-11 | 诊断分类 / Diagnoses | 报销、流行病学、监管报告 / Billing, epidemiology, regulatory reporting | 为报销选择而非为临床真实选择 / Selected for reimbursement, not clinical truth |
| LOINC | 检验项目 / Lab tests | 命名检验、影像、临床文档 / Name lab tests, imaging, clinical documents | 同一检验在不同LIS里有不同LOINC / Same test mapped to different LOINCs across LIS |
| RxNorm | 药物 / Medications | 编码药品、剂型、给药途径 / Encode drugs, dose forms, routes | 通用名/商品名混淆,缓释/即释不分 / Generic/trade name confusion, ER/IR not distinguished |
The trap is believing that any single ontology is the truth. They are not. Each is a social product with its own incentives. ICD codes are written for reimbursement. SNOMED CT is written for documentation. LOINC is written for interoperability. RxNorm is written for pharmacy. When an agent reads “心功能IV级(NYHA)” from a discharge note, it must map to a SNOMED concept (106041000119101 — NYHA Class IV), but it also must map to a clinical judgment that the patient cannot perform any physical activity without discomfort, and that mapping is not in any ontology. It is in the clinician’s head.
陷阱是相信任何一个本体是真值。它们不是。每一个都是带自身激励的社会产物。ICD编码是为报销写的。SNOMED CT是为文档写的。LOINC是为互操作写的。RxNorm是为药房写的。Agent从出院小结读出"心功能IV级(NYHA)",要映射到SNOMED概念(106041000119101),但还要映射到一个临床判断:患者在任何体力活动下都会不适,这个映射不在任何本体里。它在临床医生的脑子里。
1.9.3 eCRF:一个被结构化过的梦
The electronic case report form (eCRF) is, in principle, the cleanest piece of clinical data that exists. It is built for the trial. Each field has a data type, a range, an ontology binding, and a validation rule. An agent reading an eCRF is reading a document that was, by design, made readable. The trap is that the eCRF is not the patient. It is a curated, post-hoc, protocol-compliant projection of the patient. A patient who had a transient ALT elevation on day 14 may, in the eCRF, appear only as an “adverse event of grade 1” on day 15, after the site’s research nurse decided to recheck on day 14 and only record the confirmed value. The eCRF is not lying. The eCRF is, however, not the same as the patient.
eCRF原则上是临床数据里最干净的东西。它是为试验建的。每个字段有数据类型、范围、本体绑定、验证规则。读eCRF的Agent在读一份被设计成可读的文档。陷阱是:eCRF不是患者。它是患者的策划过的、事后的、方案合规的投影。一个第14天ALT一过性升高的患者,在eCRF里可能只显示为第15天的"1级不良事件"——在研究中心的研究护士决定第14天复测、只记确认后的值之后。eCRF没说谎。但eCRF也不等于患者。
For an agent that does trial operations, this means: the eCRF is a checkpoint, not the ground truth. The ground truth lives in the EMR. The agent must read both, and must reconcile. When eCRF and EMR disagree, the disagreement is itself a signal — usually a protocol deviation, sometimes a data quality issue, occasionally fraud. A well-designed agent flags every disagreement to a human, with a confidence-weighted explanation of the likely cause.
对做试验运营的Agent,这意味着:eCRF是检查点,不是真值。真值在EMR里。Agent两个都得读,且必须对账。eCRF和EMR不一致时,这个不一致本身就是信号——通常是方案偏离,有时是数据质量问题,偶尔是造假。设计得好的Agent把每一处不一致都标出来给人,带着置信度加权的可能原因解释。
1.10 感知-行动闭环实例:凌晨三点的一场不良事件研判
Enough theory. Let me show the loop running, in slow motion, on a real kind of case. The case is composited from several real cases I have seen in Phase II oncology trials. Nothing here identifies a patient. The structure is faithful.
理论够了。我把这个闭环慢动作地在一个真实类型的病例上跑一遍。病例是从我在二期肿瘤试验里见过的几个真实病例合成的。不涉及任何可识别患者。结构是忠实的。
1.10.1 凌晨3点的信号
A 58-year-old patient with metastatic non-small cell lung cancer, on day 42 of a Phase II trial of a third-generation EGFR-TKI, presents to the emergency department at 02:40 with shortness of breath and a heart rate of 118. The on-call research coordinator at the site enters a progress note into the EMR at 03:12. The trial agent, running on the CRO’s platform, picks up the note at 03:12:40. The clock starts.
58岁男性,转移性非小细胞肺癌,参加三代EGFR-TKI二期试验第42天,02:40到急诊,主诉气短,心率118。研究中心的on-call研究协调员03:12在EMR里写了一份病程note。试验Agent在CRO平台上03:12:40抓到这份note。时钟开始。
The agent’s first pass over the note extracts: symptom (dyspnea), onset (acute), context (day 42 of trial drug), vitals (HR 118, undocumented SpO2), absence of chest pain in the note. The agent immediately raises two flags: (1) this is a potential serious adverse event (SAE) candidate, (2) dyspnea on day 42 of an EGFR-TKI in NSCLC has a short differential that includes pneumonitis, pulmonary embolism, disease progression, and anemia. Each of these is in the protocol as an event of special interest.
Agent对note的第一遍抽取:症状(呼吸困难),起病(急性),背景(试验药第42天),生命体征(HR 118,SpO2未记录),note中无胸痛。Agent立刻升起两个旗:(1)这是一个潜在严重不良事件(SAE)候选,(2)NSCLC患者用EGFR-TKI第42天出现呼吸困难,鉴别诊断很窄:肺炎、肺栓塞、疾病进展、贫血。每一个都在方案里被列为特别关注事件。
This is where the naive AI approach stops. The agent has done a classifier: dyspnea + day 42 + EGFR-TKI → “possible pneumonitis.” A classifier output is not enough. The agent must now choose an action, and the action must commit to a hypothesis and verify it. Here is the loop.
天真的AI方法就停在这里。Agent做了一个分类器:呼吸困难+第42天+EGFR-TKI→"可能的肺炎"。分类器输出不够。Agent现在要选动作,且动作要承诺一个假设并去验证。下面是这个循环。
1.10.2 循环:信号→假设→验证→承诺
+-------------------+ 03:12:40 +-------------------+
| Signal pickup | ------> | Hypothesis |
| (EMR note in) | | generation |
+-------------------+ | (differential |
| priors) |
+-------------------+
|
| ranked hypotheses:
| H1: pneumonitis (p=.42)
| H2: PE (p=.28)
| H3: progression (p=.20)
| H4: anemia (p=.06)
| H5: other (p=.04)
v
+-------------------+
| Verification |
| plan | <-- calls LIS,
| (order labs, | PACS, CTP;
| imaging, review)| reads back
+-------------------+
|
| evidence update:
| D-dimer 1840 ng/mL
| SpO2 91% on RA
| CTPA requested
v
+-------------------+
| Belief update |
| (Bayesian revise)|
+-------------------+
|
| H2 PE: p=.61
| H1: p=.18
| (...)
v
+-------------------+
| Commitment |
| ledger entry | <-- append-only:
| | "SAE suspected,
| | PE, action:
| | escalate to
| | on-call PI,
| | hold drug"
+-------------------+
|
v
+-------------------+
| Human PI review |
+-------------------+
图1-4:不良事件研判的感知-行动闭环
Figure 1-4: Perception-action loop in adverse event adjudication
The agent did not “decide” the patient has a PE. The agent committed, in writing, to a working hypothesis that the patient probably has a PE, and committed, in writing, to the action of escalating to the PI and holding the trial drug. The commitment is append-only. If the CTPA later shows no PE, the agent does not retroactively rewrite its ledger entry. It writes a new entry, timestamped, that says: “Prior hypothesis revised; CTPA negative; differential re-ranked; H1 pneumonitis now p=.47; recommend bronchoscopy.” The PI has, at all times, the full reasoning trace.
Agent没有"决定"患者是肺栓塞。Agent在书面上承诺了一个工作假设——患者大概是肺栓塞,并在书面上承诺了一个动作——上报PI并暂停试验药。承诺是append-only的。后面CTPA出来如果没肺栓塞,Agent不会回溯改账本条目。它会新写一条,带时间戳,说:"先前假设修正;CTPA阴性;鉴别重排;H1肺炎现p=.47;建议支气管镜。"PI随时有完整的推理轨迹。
1.10.3 失败点和人类必须握笔的地方
Where does this loop fail? Three places, in practice. (1) The signal never arrives — the EMR note was written but the lab order went into a different system the agent does not have a feed to. The agent’s “no signal” state must be treated as a red flag, not a green light. (2) The hypothesis space is wrong — if the protocol does not list pneumonitis as an event of special interest, the agent’s prior may be too low to ever escalate it, even when the evidence is screaming. (3) The commitment is overridden silently — the PI, exhausted at 3 a.m., clicks “acknowledged” and does nothing. The agent must, in this case, have a second-line escalation: a timeout to the CRO medical monitor at 06:00 if no action has been logged.
这个循环在哪失败?实践中三处。(1)信号根本不到——EMR note写了,但检验单进了另一个Agent没接入的系统,Agent拿不到。Agent的"无信号"状态必须当红旗,不是绿灯。(2)假设空间错了——如果方案没把肺炎列为特别关注事件,Agent的先验可能低到永远不会升级它,即便证据在喊。(3)承诺被静默覆盖——PI凌晨3点累得不行,点"已知悉",啥也不做。Agent这时候必须有第二线升级:如果06:00仍无动作记录,自动升级到CRO医学经理。
📌 Best Practice Tip — 关于"无信号"作为红旗
The most dangerous failure mode of a clinical agent is not “wrong prediction.” It is “confident inaction due to missing input.” Design your agent so that the absence of an expected data stream within a time window is itself an alert. A patient on day 42 of a trial who has no lab values from day 38 to day 42 is not “stable with no new data.” It is “stable-or-acutely-ill-and-we-do-not-know-which.” Treat it as the latter.
📌 最佳实践 Tip — 关于"无信号"作为红旗
临床Agent最危险的失败模式不是"预测错",而是"因输入缺失而自信地不作为"。把Agent设计成:一个预期的数据流在时间窗内缺席,本身就是一条警报。试验第42天的患者,第38到第42天没有任何检验值,不是"稳定,无新数据"。是"稳定或急性起病,我们不知道是哪个"。按后者处理。
1.11 Agent 记忆层级架构
The thalamus and cortex give us perception. The hippocampus gives us memory. Without a memory architecture, a clinical agent is a goldfish — it reads the EMR, makes a prediction, and forgets everything by the next token. Real trial operations span weeks. The agent needs a memory system. Biology solved this problem 200 million years ago. Transformers are still figuring it out.
丘脑和皮层给我们感知。海马给我们记忆。没有记忆架构,临床Agent就是条金鱼——读EMR,做预测,下一个token之前全忘。真正的试验运营跨数周。Agent需要记忆系统。生物在2亿年前就解了这个问题。Transformer还在摸索。
1.11.1 四类生物记忆,四类工程记忆
Biology does not have one memory. It has at least four, each with a distinct neural substrate, a distinct timescale, and a distinct failure mode. An engineer who collapses them into one “memory” will build a system that is either too rigid or too leaky.
生物不是只有一种记忆。它至少有四种,各有不同的神经基础、不同的时间尺度、不同的失败模式。把它们合并成一个"记忆"的工程师,会做出要么太僵要么太漏的系统。
| 生物记忆 / Bio memory | 神经基础 / Substrate | 时间尺度 / Timescale | 工程对应 / Eng analog | 临床用例 / Clinical use |
|---|---|---|---|---|
| 工作记忆 / Working | 前额叶皮层 / Prefrontal | 秒到分钟 / s-min | 上下文窗口 / Context window | 当前病例推理 / Reasoning on current case |
| 情景记忆 / Episodic | 海马 / Hippocampus | 小时到年 / hr-yr | 向量库 + 时间戳 / Vector DB + timestamps | 既往不良事件检索 / Retrieval of past AEs |
| 语义记忆 / Semantic | 颞叶新皮层 / Temporal neocortex | 永久 / Permanent | 知识图谱 / Knowledge graph | 药物-诊断关系 / Drug-disease relations |
| 程序记忆 / Procedural | 基底神经节、小脑 / Basal ganglia, cerebellum | 永久、自动化 / Permanent, automaticized | 微调权重 / Fine-tuned weights | 报告格式、流程模板 / Report formats, workflow templates |
The mapping is not perfect, but it is close enough to be a useful design tool. A clinical agent should have all four layers, and each should be sized to its job. The context window (working memory) should be large enough to hold one case’s reasoning but not so large that the agent loses attentional focus — a context that is too long is the LLM equivalent of prefrontal overload, and it produces the same failure mode: hallucinated shortcuts. The vector DB (episodic) should retain every prior case with timestamps and outcomes, and should be queryable by clinical similarity, not by keyword. The knowledge graph (semantic) should encode protocol, drug, disease, and procedure relations, versioned by date. The fine-tuned weights (procedural) should encode the stable workflows: how to write an SAE narrative, how to format a regulatory submission.
映射不完美,但足够接近,可以当设计工具用。临床Agent该有全部四层,每层都要按自己的工作来调大小。上下文窗口(工作记忆)要够装一个病例的推理,又不能大到Agent失去注意力焦点——过长的上下文是LLM版的前额叶过载,产生同样的失败模式:幻觉捷径。向量库(情景)要保留每一个既往病例,带时间戳和结局,要按临床相似度可查,不能按关键词。知识图谱(语义)要编码方案、药物、疾病、操作的关系,按日期版本化。微调权重(程序)要编码稳定的工作流:怎么写SAE叙述,怎么排版监管提交。
🔥 金句 / Aphorism
“A goldfish is not a fish with bad memory. It is a fish with no hippocampus. Most clinical agents are goldfish with big context windows.”
“金鱼不是记忆差的鱼。是没有海马的鱼。大多数临床Agent是装了大上下文窗口的金鱼。”
1.11.2 遗忘是特性,不是缺陷
The most under-rated design decision in agent memory is what to forget. Biology forgets aggressively. Synapses weaken without reinforcement. The hippocampus replays recent experiences during sleep, and the ones that survive the replay get consolidated into neocortex; the ones that do not, do not. Sleep is, in part, a forgetting algorithm. This is not a bug. A brain that remembered everything would be unable to generalize — it would overfit to every specific case and fail on the next new one.
Agent记忆里最被低估的设计决策,是忘掉什么。生物遗忘得很猛。突触不强化就减弱。海马在睡眠时重放近期经历,存活下来的被整合到新皮层;没存活下来的,不存活。睡眠在一定程度上是遗忘算法。这不是bug。什么都记得的脑无法泛化——它会过拟合每一个具体病例,在下一个新病例上崩掉。
Clinical agents need a forgetting policy. The naive approach — “we’ll keep everything, storage is cheap” — is a trap. Three reasons. First, retrieval quality degrades as the DB grows; the signal-to-noise ratio of a vector search over 10 million cases is worse than over 10 thousand, because in high-dimensional spaces, near neighbors multiply. Second, old cases reflect old standards of care; an agent that retrieves a 2018-era cardiology workup as a template will produce outdated recommendations. Third, regulatory privacy obligations require eventual deletion in many jurisdictions; “keep everything forever” is a compliance time bomb.
临床Agent要有遗忘策略。天真的做法——“全留,存储便宜”——是陷阱。三个理由。第一,检索质量随库增大而下降;1000万病例的向量搜索信噪比劣于1万病例,因为高维空间里近邻会变多。第二,旧病例反映旧诊疗标准;Agent把2018年时代的心血管评估当模板,会给出过时建议。第三,监管隐私义务在很多司法管辖区要求最终删除;"永久全留"是合规定时炸弹。
📌 Best Practice Tip — 关于"分层遗忘"
Implement a three-tier forgetting policy: (1) Raw case data → retain for the regulatory minimum (typically 15 years post-trial or per local rule), then delete. (2) Aggregated patterns → retain with versioning, tag each version with the standard-of-care reference year. (3) Outcomes of agent decisions → retain permanently, but with provenance — every outcome links back to the agent’s reasoning trace at decision time. This is your safety case file. Regulators will ask for it.
📌 最佳实践 Tip — 关于"分层遗忘"
实施三层遗忘策略:(1)原始病例数据——按监管最低要求保留(通常试验结束后15年或按当地规定),然后删除。(2)聚合模式——版本化保留,每个版本打上"参考诊疗标准年份"的标。(3)Agent决策的结局——永久保留,带出处,每个结局都能回溯到决策时Agent的推理轨迹。这是你的安全案例文件。监管会来要。
1.12 目标函数与人类对齐:Agent到底"想要"什么
Every autonomous system has a target function. Even when the designer does not write one explicitly, the system has one — implicit, in the training signal, in the loss, in the data selection. The question is not “does the agent have a goal.” The question is “does the agent’s goal, as implemented, match the goal the designer thinks they wrote.” The history of AI is largely the history of this mismatch.
每一个自主系统都有目标函数。哪怕设计者没显式写出来,系统也有——隐式地藏在训练信号里,藏在loss里,藏在数据选择里。问题不是"Agent有没有目标"。问题是"Agent的实现版目标,跟设计者自以为写的那个,对不对得上"。AI史基本上就是这个错配史。
1.12.1 临床试验的"奖励"是什么
In a clinical trial, what is the agent optimizing for? The naive answer — “patient safety” — is not a function, it is a slogan. To be a target, it must be specified. Safety is the probability of no harm. Harm is a vector of clinical events, weighted by severity. The weights are protocol-defined. So the agent’s target, in a simple form, is: minimize the expected weighted harm over the remaining trial duration, subject to the constraint of preserving the integrity of the trial’s statistical conclusion. That constraint is not optional. A trial that harms zero patients by enrolling zero patients has met the safety target and failed its purpose.
在临床试验里,Agent优化什么?天真的答案——“患者安全”——不是函数,是口号。要成为目标,必须被写出来。安全是无伤害的概率。伤害是临床事件的向量,按严重度加权。权重由方案定义。所以Agent的目标,简化的形式是:在剩余试验时长内最小化期望加权伤害,约束是保住试验统计结论的完整性。这个约束不是可选的。一个入组0患者、伤害0患者的试验,达到了安全目标,但失去了它存在的意义。
The moment you write the target that way, you see the problem. There are at least two terms in tension: harm minimization and statistical power preservation. They conflict. Every patient removed from the trial reduces power. Every patient retained on a risky therapy increases harm. The agent cannot optimize both. It must trade them off, and the trade-off is a value judgment that the protocol often leaves unspecified.
一旦把目标写成这样,问题就出来了。至少有两项在拉扯:伤害最小化和统计效力保住。它们冲突。每出一个患者,效力下降。每留一个在风险疗法上,伤害上升。Agent没法两个都优化。它必须权衡,而权衡是一个价值判断,方案常常没写明。
1.12.2 奖励规格问题在试验里的特殊形态
This is the reward specification problem, in its clinical form. It is not solvable by clever engineering. It is only solvable by making the value judgment explicit, writing it down, and binding the agent to it. The protocol must say, in advance, what the trade-off is. Example: “If a patient experiences a grade 3 hepatic event, the agent will recommend drug interruption and re-challenge only if the patient’s enrollment contributes to a stratum that is below 50% of its target enrollment; otherwise the agent will recommend permanent discontinuation.” This is an ugly sentence. It is also the only kind of sentence that prevents an agent from making the wrong trade-off at 3 a.m.
这就是奖励规格问题的临床形态。靠聪明的工程是解不掉的。只能靠把价值判断写明、写下来、绑到Agent上。方案必须事先写明权衡是什么。例子:"如患者发生3级肝事件,Agent将建议暂停药物并重新挑战,仅当该患者的入组贡献于一个低于其目标入组50%的分层;否则Agent将建议永久停药。"这是一句难看的句子。也是唯一能阻止Agent在凌晨3点做错权衡的句子。
| 临床目标维度 / Clinical goal dim | 形式化 / Formalization | 典型错配 / Typical mismatch |
|---|---|---|
| 患者安全 / Patient safety | 最小化期望加权伤害 / Min expected weighted harm | Agent把"无报告"等同于"无事件" / Agent equates “no report” with “no event” |
| 试验完整性 / Trial integrity | 保住统计效力与数据质量 / Preserve statistical power and data quality | Agent倾向于保留边缘患者以维持入组 / Agent keeps borderline patients to maintain enrollment |
| 监管合规 / Regulatory compliance | 不违反GCP / No GCP violations | Agent把"未触发规则"等同于"合规" / Agent equates “rule not triggered” with “compliant” |
| 运营效率 / Operational efficiency | 最小化_SITE工作量与时间 / Minimize site workload and time | Agent倾向于批量、推迟处理以节省调用 / Agent batches and delays to save calls |
🔥 金句 / Aphorism
“Safety is not a property of an agent. It is a property of the system that contains the agent. Write the system, not the agent.”
“安全不是Agent的属性。是包含Agent的那个系统的属性。写系统,不是写Agent。”
1.12.3 Constitutional AI在受监管语境下的改造
Constitutional AI, in the form Anthropic described, asks the agent to evaluate and revise its own outputs against a written constitution. The constitution is a list of principles. In a clinical trial context, the constitution is not a list of abstract principles. It is the protocol, the GCP, the ICH E6(R3) guidelines, and the site’s standard operating procedures. The agent must evaluate its proposed action against all of them, and revise. This is structurally identical to the constitutional loop, but with regulatory text as the constitution.
Constitutional AI,按Anthropic描述的形式,让Agent对照一份写下来的宪法评估并修订自己的输出。宪法是一份原则清单。在临床试验语境下,宪法不是抽象原则清单。它是方案、GCP、ICH E6(R3)指南、研究中心的标准操作规程。Agent必须对照所有这些评估自己拟议的动作,然后修订。这跟constitutional循环结构上完全一样,只不过把监管文本当宪法。
The trap is believing this gives you alignment. It gives you something weaker: it gives you compliance with the written rules, as the agent reads them, on the training distribution. Off-distribution cases — the 3 a.m. PE, the protocol that did not anticipate a particular drug-drug interaction, the patient whose comorbidities were not in the enrollment criteria — the constitution does not cover. For those, the agent must escalate, and the escalation target must be a human. There is no constitutional loop that replaces the human anchor. There is only one that makes the human anchor’s job smaller.
陷阱是相信这就给你对齐了。它给你的是更弱的东西:给你对写下来的规则的合规,按Agent读它们的方式,在训练分布上。分布外的病例——凌晨3点的肺栓塞、方案没预想到的某个药药相互作用、合并症不在入组标准里的患者——宪法覆盖不了。这些情况下,Agent必须升级,升级目标是人。没有任何constitutional循环能替代人类锚。只有一个能让人类锚的工作量变小。
1.13 临床试验自主性分级案例库
Theory is cheap. Cases are not. Here are four cases, one per autonomy level, that ground the four-level model from 1.3 in clinical reality. All four are composited. None identifies a patient.
理论便宜。病例不便宜。下面是四个病例,每个自主性级别一个,把1.3的四级模型落到临床现实里。四个都是合成的。都不识别任何患者。
1.13.1 L1:入组初筛(AGENT-COPilot)
The agent reads the protocol’s inclusion and exclusion criteria — typically 23 + 16 lines, as in our opening scene — and reads the EMR of a candidate patient. It produces a structured eligibility report: each criterion, the evidence the agent found, the source note, a confidence, and a recommendation (eligible / not eligible / needs human review). The human coordinator signs off. The agent never enrolls. It never excludes. It only recommends. This is L1.
Agent读方案的纳入和排除标准——通常23+16条,正如我们开篇的场景——读候选患者的EMR。它产出一份结构化合格报告:每条标准,Agent找到的证据,来源note,置信度,推荐(合格/不合格/需人工审查)。人类协调员签字。Agent不入组。不排除。只推荐。这是L1。
L1’s failure mode is the false negative on edge cases. A patient who is technically eligible but whose EMR is missing a key field will be flagged “needs human review,” which is correct. A patient who is technically excluded but whose exclusion rests on a 3-year-old lab value that has since normalized will be flagged “not eligible,” which is technically correct but clinically wrong. The human must catch the second case. The agent cannot.
L1的失败模式是边缘病例的假阴性。一个技术上合格但EMR里缺一个关键字段的患者,会被标"需人工审查",这是对的。一个技术上排除但排除依据是3年前的检验值、如今已正常的患者,会被标"不合格",技术上对,临床上错。第二种必须人来抓。Agent抓不了。
1.13.2 L2:队列监测(AGENT-COMONITOR)
The agent monitors the entire enrolled cohort. Every new lab value, every new imaging report, every new progress note flows in. The agent maintains a continuously updated risk surface: which patients are currently in the highest quartile of risk for grade 3+ events in the next 7 days. It does not act on this surface. It surfaces it. The human medical monitor reviews the top-N list daily and decides.
Agent监测整个已入组队列。每一条新检验值,每一份新影像报告,每一份新病程note都流进来。Agent维护一个持续更新的风险面:哪些患者当前在未来7天3级+事件的最高四分位里。它不在这个面上行动。它把这个面展示出来。人类医学经理每天复核Top-N清单并决策。
L2’s failure mode is drift. The agent’s risk model was trained on the first 200 patients. By patient 600, the population has shifted — perhaps the trial opened to a new demographic, perhaps the standard of care changed. The risk surface becomes miscalibrated. The medical monitor notices when her top-N list starts looking weird. The agent does not notice. Calibration monitoring is a human job, supported by automated drift dashboards.
L2的失败模式是漂移。Agent的风险模型用前200个患者训的。到第600个患者时,人群变了——也许是试验对一个新的 demographics 开放了,也许是诊疗标准变了。风险面失准。医学经理注意到她的Top-N清单开始变怪。Agent没注意。校准监测是人的活,由自动漂移仪表盘支持。
1.13.3 L3:方案偏离处置(AGENT-CODEV)
This is where the agent crosses into actionable autonomy. When the agent detects a protocol deviation — say, a patient missed their day 28 visit, or a concomitant medication not on the allowed list was started — it does not just flag. It generates a deviation report, recommends a corrective action (reschedule within window, document the exception, report to IRB if grade 2 or higher), and writes the deviation entry into the commitment ledger. The action is taken by the site. The agent has, however, committed in writing to its recommendation and to its reasoning.
这是Agent跨入可动作自主的地方。Agent检测到方案偏离——比如患者漏了第28天访视,或者用了不在允许清单上的合并用药——它不只是报警。它生成偏离报告,推荐纠正动作(窗口内重排、记录例外、2级及以上报IRB),并把偏离条目写进承诺账本。动作由研究中心执行。但Agent在书面上承诺了它的推荐和它的推理。
L3’s defining feature, as we said in 1.3, is the halt evaluator. The agent must, at each step, evaluate whether to halt. The halt condition is not “task complete.” It is “confidence in next action below threshold OR no new evidence for N cycles OR human override requested.” A system without a halt evaluator is not L3. It is a hallucinating L2 with a dangerous action surface.
L3的定义性特征,正如1.3所说,是制动评估器。Agent必须在每一步评估是否要停。停的条件不是"任务完成"。是"下一步动作的置信度低于阈值,或N个循环无新证据,或人类要求接管"。没有制动评估器的系统不是L3。它是一个带危险动作面的、在幻觉的L2。
1.13.4 L4:自主适应性设计(AGENT-COADAPT)
L4 is the frontier. The agent not only acts on the trial, it modifies the trial. It detects a safety signal in a stratum, proposes an amendment to the protocol (close the stratum to further enrollment, reduce dose in subsequent strata), drafts the amendment language, routes it to the sponsor and IRB, and upon approval, updates the protocol in its own knowledge graph. This level does not exist in deployed systems as of 2026 in any regulatory framework I am aware of. It exists in research prototypes. The reason is not technical. The reason is that no regulator has yet defined what an L4 amendment pipeline looks like.
L4是前沿。Agent不仅对试验行动,它修改试验。它检测到一个分层的安全信号,提出方案修正(关闭该分层继续入组,后续分层降剂量),起草修正案语言,路由给申办方和IRB,获批准后,在自己的知识图谱里更新方案。这一级在2026年我所知的任何监管框架下都不存在于已部署系统。它存在于研究原型。原因不是技术。原因是没有任何监管者定义过L4修正流程长什么样。
The reason I am writing this book in 2026 is that this will change. RTCT (Real-Time Clinical Trials) pilots at the FDA with AstraZeneca and Amgen, announced April 2026, are the first regulatory acknowledgement that amendment cycles can be shorter than 6 months. The book you are reading is, in part, a preparation for the world where L4 is real.
我在2026年写这本书,是因为这会变。FDA与AstraZeneca和Amgen的RTCT(实时临床试验)试点,2026年4月公布,是监管第一次承认修正周期可以短于6个月。你正在读的这本书,部分是在为L4成真的那一天做准备。
| 级别 / Level | 动作 / Action | 制动 / Halt | 人类锚 / Human anchor | 2026 状态 / 2026 status |
|---|---|---|---|---|
| L1 | 推荐 / Recommend | 无 / None | 签字 / Sign-off | 部署中 / Deployed |
| L2 | 表面展示 / Surface | 无 / None | 复核 / Review | 部署中 / Deployed |
| L3 | 承诺动作 / Commit action | 有 / Yes | 监督 / Oversight | 试点 / Pilot |
| L4 | 修改方案 / Amend protocol | 有 / Yes | 批准 / Approval | 研究 / Research |
1.14 番外篇:三个深夜
Theory and design diagrams are one thing. The texture of a clinical trial at 3 a.m. is another. Three short vignettes, compositied from real cases. Read them for texture, not for protocol.
理论和设计图是一回事。凌晨3点一场临床试验的质感是另一回事。三个短篇,均合成自真实病例。读的是质感,不是方案。
番外一:那个本该被排除的患者
A patient was enrolled in a Phase II oncology trial on a Wednesday. The agent had reviewed the EMR, flagged a 2019 lab value (ALT 78) as “borderline — consider grade 1 hepatic event history,” and recommended “eligible with monitoring.” The coordinator clicked “enroll.” On Friday, the patient’s day 3 labs came back with ALT 340. The agent’s risk surface, which had been carrying this patient at elevated risk since enrollment, lit up. By Sunday, the patient was off-trial and in a hepatology consult. The question, in the retrospective review, was not “did the agent fail.” It was “should the agent have escalated ‘borderline’ to ‘do not enroll until rechecked.’” The answer in the review was: yes, in any patient where the most recent value is >3 years old and was borderline. The rule was written into the protocol amendment. The agent’s behavior changed. The next borderline case was held.
一个患者周三入组了二期肿瘤试验。Agent复核过EMR,把2019年的一个检验值(ALT 78)标为"边界——考虑1级肝事件史",并推荐"合格,需监测"。协调员点了"入组"。周五,该患者第3天检验出来,ALT 340。Agent的风险面从入组起就给这个患者带高了风险权重,一下子亮起来。周日,患者退组,进了肝病科会诊。回顾评审的问题不是"Agent有没有失败"。是"Agent应不应该把’边界’升级到’不复查不入组’"。评审的答案是:应该,在任何最近一次值在3年以上且处于边界区间的患者里。这条写进了方案修正。Agent的行为变了。下一个边界病例被拦下了。
The lesson is not “the agent should have been smarter.” The agent was as smart as the rule allowed. The lesson is: borderline is a state, not a value, and a 3-year-old borderline is a different state than a 3-week-old one.
教训不是"Agent本该更聪明"。Agent已经聪明到规则允许的上限。教训是:边界是个状态,不是个值;3年前的边界状态,跟3周前的边界状态,不是同一个状态。
番外二:复制粘贴的肺栓塞
A patient on day 56 of a cardiology trial had a discharge summary that said, word for word, “patient denies chest pain, patient denies dyspnea, patient denies palpitations.” The agent’s first pass, reading the discharge summary, scored the patient as low-risk for the next 14 days. The agent’s second pass, which compared the discharge summary’s text to the prior three progress notes, found that the same three sentences appeared verbatim in notes from day 14, day 28, and day 42. The agent flagged the patient as “documentation stale — clinical state unverified.” Two hours later, the patient called 911 for a pulmonary embolism.
一个心血管试验第56天的患者,出院小结里逐字写着"患者否认胸痛,患者否认呼吸困难,患者否认心悸"。Agent第一遍读出院小结,把患者评为未来14天低风险。Agent第二遍,把出院小结文本与前三份病程note对比,发现同样的三句话在第14、28、42天的note里逐字出现。Agent把患者标为"文档陈旧——临床状态未核实"。两小时后,患者打911,肺栓塞。
The lesson is: the most dangerous clinical text is not the wrong text. It is the copied text. An agent that does not detect copy-paste provenance is reading yesterday’s weather report as today’s.
教训是:最危险的临床文本不是错的文本。是复制的文本。不检测复制粘贴出处的Agent,在读昨天的天气预报当今天的。
番外三:那个不该升级的SE
A patient on day 21 of a renal trial had a grade 2 creatinine elevation. The agent, working from a protocol that listed “renal events grade 2 or higher” as events of special interest, drafted an SAE report and routed it to the medical monitor. The medical monitor, on review, noted that the patient had started a statin the previous week, and the creatinine elevation was consistent with a known, benign statin effect, not a renal injury. The SAE was downgraded to an AE of no clinical significance. The agent’s ledger entry was not rewritten. A new entry was added: “Prior SAE recommendation revised; statin effect identified; AE reclassified.”
一个肾试验第21天的患者,肌酐2级升高。Agent按方案"肾事件2级及以上列为特别关注事件"起草了SAE报告,路由给医学经理。医学经理复核时注意到:患者前一周开了他汀,肌酐升高与他汀的已知良性效应一致,不是肾损伤。SAE降级为无临床意义的AE。Agent的账本条目没被改写。新加了一条:“先前SAE推荐修订;识别他汀效应;AE重新分类。”
The lesson is: the agent’s job is not to be right. The agent’s job is to be transparently wrong sometimes, in a way that a human can catch. A system that is wrong silently is dangerous. A system that is wrong loudly is useful.
教训是:Agent的活儿不是"对"。Agent的活儿是"有时错得透明,且能被人抓到"。一个静默错的是危险的。一个错得响亮的,是有用的。
本章真正的小结 / The Real Chapter Summary
We have, at this point, covered enough ground that the reader should have a working mental model of what a clinical AI agent is, what it is not, what its architectural debt to biology is, and where its hard problems live. Let me close the chapter in plain language.
到这里,读者应该有了一个可用心智模型:临床AI Agent是什么、不是什么、对生物学的架构债是什么、它的难问题在哪。用大白话收一下。
The agent is not a brain. It is a structural cousin of the brain. The mathematics of attention, of sparse coding, of TD learning, of memory consolidation, recur in the silicon implementation because they are good solutions to the same problems biology solved. But the agent lacks the grounding — in being alive, in time, in a body, in evolutionary priors — that the brain has. This is not a defect to be fixed by more compute. It is a property to be designed around.
Agent不是脑。它是脑的结构表亲。注意力的数学、稀疏编码的数学、TD学习的数学、记忆巩固的数学,在硅基实现里反复出现,因为它们是同样问题的好解,而生物早就解过。但Agent缺脑所拥有的接地——锚在"活着"、锚在时间、锚在身体、锚在演化先验里。这不是靠更多算力能修的缺陷。是要被设计绕过的属性。
The clinical trial is the best testbed we have for designing around those properties, because it is the one place in the world where: (a) ground truth is measurable, (b) regulation is legible, © the cost of being wrong is high enough to force seriousness, and (d) the humanitarian upside is real. The chapters that follow will take the skeleton laid out here — perception, cognition, action, commitment — and build it out, layer by layer, into a working system for running clinical trials with AI agents as partners, not as oracles.
临床试验是我们设计绕过这些属性的最好试验场,因为它是世界上唯一同时满足四个条件的地方:(a)真值可测,(b)监管清晰,©错的代价高到逼人严肃,(d)人道回报真实。后续各章会把这个骨架——感知、认知、行动、承诺——一层层搭起来,建成一个能用的、AI Agent作为伙伴而非神谕参与临床试验的系统。
The surgeon from the opening scene, the one at 11:47 p.m., is still in the book. She is in every chapter. The aim of everything that follows is to give her, eventually, the chance to go home.
开篇那个11点47分的外科医生,还在书里。她在每一章里。下面所有内容的目标,是最终给她一个回家的机会。
📋 本章参考与延伸阅读 / References and Further Reading
- Friston, K. (2010). The free-energy principle: a unified brain theory? Nature Reviews Neuroscience, 11(2), 127-138.
- Clark, A. (2013). Whatever next? Predictive brains, situated agents, and the future of cognitive science. Behavioral and Brain Sciences, 36(3), 181-204.
- Seth, A. (2021). Being You: A New Science of Consciousness. Faber and Faber.
- Olshausen, B. A., & Field, D. J. (1996). Emergence of simple-cell receptive field properties by learning a sparse code for natural images. Nature, 381(6583), 607-609.
- Schultz, W., Dayan, P., & Read Montague, P. (1997). A neural substrate of prediction and reward. Science, 275(5306), 1593-1599.
- Hubel, D. H., & Wiesel, T. N. (1962). Receptive fields, binocular interaction and functional architecture in the cat’s visual cortex. The Journal of Physiology, 160(1), 106-154.
- ICH E6(R3) Good Clinical Practice, 2025 revision.
- NMPA 2026 announcement on mandatory ICH E6(R3) trial implementation.
- FDA Real-Time Clinical Trials (RTCT) pilot with AstraZeneca and Amgen, April 2026.
- FDA AI/ML-Based Software as a Medical Device (SaMD) Action Plan, 2021 onward.
- SNOMED CT International Edition, 2026 release.
- ICD-11 for Mortality and Morbidity Statistics, WHO 2022/2026 update.
- LOINC Regenstrief Institute, 2.78+ release.
- RxNorm, National Library of Medicine, monthly editions.
- 璞睿创智 E2E 平台白皮书及公开技术资料, 2025-2026.
- Anthropic. (2022). Constitutional AI: Harmlessness from AI Feedback.
更多推荐


所有评论(0)