Safety is a paramount concern in clinical chatbot applications, where inaccurate or harmful responses can lead to serious consequences. Existing methods--such as guardrails and tool calling--often fall short in addressing the nuanced demands of the clinical domain. In this paper, we introduce TACOS (TAxonomy of COmprehensive Safety for Clinical Agents), a fine-grained, 21-class taxonomy that integrates safety filtering and tool selection into a single user intent classification step. TACOS is a taxonomy that can cover a wide spectrum of clinical and non-clinical queries, explicitly modeling varying safety thresholds and external tool dependencies. To validate our taxonomy, we curate a TACOS-annotated dataset and perform extensive experiments. Our results demonstrate the value of a new taxonomy specialized for clinical agent settings, and reveal useful insights about train data distribution and pretrained knowledge of base models.
@article{arxiv.2509.22041,
title = {Taxonomy of Comprehensive Safety for Clinical Agents},
author = {Jean Seo and Hyunkyung Lee and Gibaeg Kim and Wooseok Han and Jaehyo Yoo and Seungseop Lim and Kihun Shin and Eunho Yang},
journal= {arXiv preprint arXiv:2509.22041},
year = {2025}
}