Thursday, August 27, 2026

 

World-first: AI guides live brain surgery in the UK to save patient's sight

Hani Marcus, neurosurgeon (left) and Rhys Hibbert (right).
Copyright UCLH

By Marta Iraola Iribarren
Published on


A British man has become the first patient in the world to undergo brain surgery guided live by artificial intelligence, in an operation that saved his sight.

A man in England has become the first patient to undergo live AI-assisted brain surgery, which protected his sight during the removal of a brain tumour, the University College London Hospitals announced on Thursday.

Rhys Hibbert, a 48-year-old from Bedfordshire, was diagnosed in December 2024 when he collapsed during a walk and suffered a seizure.

As his symptoms worsened, Hibbert opted for surgery and volunteered to take part in research.

“If patients are not prepared to join research how can doctors ever learn and how can medicine ever progress?” he said.

“Asked if I would be prepared to be the world's first patient to have this technology used live… I said, yes, of course.”

According to Hibbert’s doctors, the tumour would have continued to threaten his sight and could ultimately have led to blindness. The operation successfully removed the growth and protected his vision.

Hibbert said that upon waking from surgery, his vision had dramatically improved: “When I came round… I could see everything in the room clearly.”

The operation was carried out at the National Hospital for Neurology and Neurosurgery (NHNN), part of University College London Hospitals (UCLH), as part of a clinical trial using AI technology developed in-house at University College London and funded by the National Institute for Health and Care Research (NIHR).

During the surgery, the AI analysed the live surgical video feed in real time, rather than using pre-surgery scans, helping the surgical team make more precise decisions by highlighting critical structures at the base of the brain, UCLH explained.

In this part of the brain, the pituitary gland — which is the size of a marble — sits tightly blood vessels and nerves controlling vision. A margin of error of just a millimetre can prove critical, potentially leading to death, blindness or stroke.

The doctors explained that AI supported the surgical team by helping identify risky areas to avoid while removing as much of the tumour as safely possible.

It also has the potential to track surgical instruments and instrument–tissue interactions, with the aim of supporting surgeons during complex procedures and providing feedback.

“This is an example of AI at its best: patients getting care previously deemed unimaginable thanks to the latest groundbreaking technology,” said James Frith, the UK’s Health Innovation Minister.

He added that AI needs proper safeguards and we will always ensure that safety is taken seriously.


Major security weaknesses found in leading open AI models



International research team finds all 21 leading open-weight AI models tested could be modified to bypass safety protections, raising concerns about misuse at scale




University of Waterloo






Safety protections built into some of the world's most widely used artificial intelligence (AI) models can be stripped away with alarming ease, according to a new international study. 

The research team, led by the University of Waterloo and FAR.AI, a non-profit AI security research group, rigorously tested 21 of the most popular open-weight large language models (LLMs) and found they could all be tampered with despite their built-in safeguards. 

The holes in even the best protections currently available raise concerns open-weight models could be used to wage mass disinformation campaigns, create sophisticated email scams or produce step-by-step instructions to make hazardous chemicals. 

“When the safety guardrails are stripped out of a capable model, it can be used at scale for harm in ways a single person could never manage manually,” said Dr. Sirisha Rambhatla, a professor of management science and engineering at Waterloo. 

LLMs are advanced AI systems that can essentially understand and generate human language to perform tasks such as drafting emails, writing computer code and conversing with users. 

Unlike closed proprietary models such as ChatGPT and Gemini, open-weight LLMs are publicly available to be downloaded and fine-tuned for use by everybody from individual software developers to private companies and public organizations like hospitals. 

Rambhatla said the “sobering” results of testing by the team – which included members in Canada, the United States and Switzerland – should serve as a wake-up call to global researchers on the need to develop stronger security systems. 

“The leading open-weight models are often not too far behind the best closed models,” said Rambhatla, director of the Critical Machine Learning Lab at Waterloo. “As they grow more powerful, the potential consequences of someone stripping out their safety features grow with them.” 
 
While the study identified significant vulnerabilities, Rambhatla noted that the weaknesses may not be unique to open models. “Open-weight models remain essential to AI research and accountability,” Rambhatla said. "This openness is part of how we make sure the models people use work for everyone.” 

To test a cross-section of open-weight AI models, the research team first built an open-source tool called TamperBench, a standardized way to simulate a variety of different attacks. The hope is that other researchers will now help refine and improve it. 

“The defences available today don’t yet appear strong enough to guarantee that a publicly released model will remain safe once it’s in the hands of anyone who chooses to modify it,” said Saad Hossain, a researcher in the lab who led the study. 

“And as governments increasingly rely on AI in healthcare, fraud detection, education and other public services, the assessment of models and their procurement must be more rigorous and grounded in evidence.” 

The research team also included members from the Massachusetts Institute of Technology, ETH Zurich and the University of Toronto. 

A paper on its work, TamperBench: Systematically Stress-Testing LLM Safety Under Fine-Tuning and Tampering, was recently presented at the ACM Conference on Knowledge Discovery and Data Mining in South Korea. 

No comments: