Presents an IEEE 11073 Service-Oriented Device Connection integration with MCP that enforces deterministic constraints for safe AI-agent interaction with medical devices.
A Safety-Bounded SDC-to-MCP Gateway is a research prototype by Bennet Gerlach and Stefan Fischer (published September 25, 2026) that integrates IEEE 11073 Service-Oriented Device Connectivity (SDC) with the Model Context Protocol (MCP) to enable safe AI-agent interaction with medical devices.
The gateway enforces a no-execution boundary, exposing device metrics, alarms, and context as read-only MCP resources while representing action affordances as policy-validated dry-run tools that do not dispatch actual SDC device operations. This architecture ensures that AI agents can gain situational awareness and propose actions without having direct control over device parameters, addressing the challenge of grounding language-model reasoning in current system state without granting non-deterministic models authority over device operation.
Key features include: SDC-MIE Metadata: An explicit mapping system that makes codes, handles, units, and policy metadata transparent, preventing silent interpretation of unmapped medical concepts. Deterministic Constraints: The system uses structured validation for proposals, ensuring that invalid, stale, or unauthorized requests are rejected visibly while maintaining a strict separation between agent interpretation and device state. * Safety Isolation: The gateway confines MCP interactions to same-host subprocesses via standard input/output, protecting device-state integrity and ensuring that agent-facing requests cannot bypass policy checks or trigger device writes.
This material describes a safety-bounded gateway that connects the IEEE 11073 Service-Oriented Device Connection (SDC) standard to the Model Context Protocol (MCP), enabling AI agents to interact with medical devices through a controlled, protocol-aware interface. Rather than exposing raw device services directly to an autonomous agent, the gateway acts as an intermediary that translates device capabilities into MCP-compatible tools, resources, or commands while enforcing deterministic constraints. In effect, it provides a structured boundary between the probabilistic behavior of AI agents and the deterministic, clinically regulated expectations of medical device systems.
A key contribution is the emphasis on bounded, auditable, and policy-enforced interaction. The gateway appears to constrain what an agent can request, how often, under what conditions, and with what validation, reducing the risk that an LLM-driven agent issues malformed, out-of-scope, or unsafe device commands. This is especially important in healthcare settings, where device interactions may affect monitoring, alarms, or therapeutic functions. By mapping IEEE 11073 device semantics into MCP with explicit safety limits, the work offers a practical pattern for integrating emerging agent architectures into clinically relevant device ecosystems without abandoning standards-based interoperability.
The work matters because it addresses a concrete gap in the deployment of medical AI agents: safe interoperability. MCP is becoming a common protocol for giving agents access to external tools and context, while IEEE 11073 remains an important standard for medical device service orientation. A gateway that bridges the two with deterministic safeguards could make it easier to build explainable, testable, and clinically deployable agent systems. More broadly, it points toward a design principle for medical AI: agents should not directly control devices, but should operate through a constrained, standards-aware layer that enforces safety, traceability, and predictable behavior.