<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD with MathML3 v1.3 20210610//EN" "JATS-archivearticle1-3-mathml3.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink"
  dtd-version="1.3" xml:lang="en" article-type="research-article">
  <?DTDIdentifier.IdentifierValue -//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.2 20190208//EN?>
  <?DTDIdentifier.IdentifierType public?>
  <?SourceDTD.DTDName JATS-journalpublishing1.dtd?>
  <?SourceDTD.Version 1.2?>
  <?ConverterInfo.XSLTName jats2jats3.xsl?>
  <?ConverterInfo.Version 1?>
  <?properties open_access?>
  <front>
    <journal-meta>
      <journal-id journal-id-type="iso-abbrev">Arch Pharm Pract</journal-id>
      <journal-id journal-id-type="publisher-id">archivepp.com</journal-id>
      <journal-id journal-id-type="publisher-id">Arch Pharm Pract</journal-id>
      <journal-title-group>
        <journal-title>Archives of Pharmacy Practice</journal-title>
      </journal-title-group>
      <issn pub-type="epub">2320-5210</issn>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="publisher-id">archivepp.com-1276</article-id>
      <article-id pub-id-type="doi">10.51847/MSRqgiNB22</article-id>
      <article-categories>
        <subj-group subj-group-type="heading">
          <subject>Original research</subject>
        </subj-group>
      </article-categories>
      <title-group>
        <article-title>Designing Large Language Models That Refuse Unsafe Medication Questions Well</article-title>
      </title-group>
                    <contrib-group>
                      <contrib contrib-type="author">
              <name>
                <surname>Costa</surname>
                <given-names>Gabriel</given-names>
              </name>
                              <xref rid="aff1" ref-type="aff">1</xref>
                                                            <xref rid="cor1" ref-type="corresp" />
                          </contrib>
                      <contrib contrib-type="author">
              <name>
                <surname>Ribeiro</surname>
                <given-names>Lucas</given-names>
              </name>
                              <xref rid="aff1" ref-type="aff">1</xref>
                                        </contrib>
                      <contrib contrib-type="author">
              <name>
                <surname>Alves</surname>
                <given-names>Ricardo</given-names>
              </name>
                              <xref rid="aff2" ref-type="aff">2</xref>
                                        </contrib>
                      <contrib contrib-type="author">
              <name>
                <surname>Lopes</surname>
                <given-names>Mariana</given-names>
              </name>
                              <xref rid="aff3" ref-type="aff">3</xref>
                                        </contrib>
                  </contrib-group>
                  <aff id="aff1">
            <label>1</label>Department of LLM Safety and Medication Questions, Faculty of Pharmacy, Federal University of Minas Gerais, Belo Horizonte, Brazil.
          </aff>
                  <aff id="aff2">
            <label>2</label>Department of AI Refusal Mechanisms in Pharmacy, Faculty of Pharmacy, University of Coimbra, Coimbra, Portugal.
          </aff>
                  <aff id="aff3">
            <label>3</label>Department of Safe LLM Design for Pharmacy, Faculty of Pharmacy, University of São Paulo, São Paulo, Brazil.
          </aff>
                          <author-notes>
            <corresp id="cor1">
              <bold>Address for correspondence:</bold> Prof. Wael Abu Dayyih, Department of
              Pharmaceutical Chemistry, Faculty of Pharmacy, Mutah University, Al-Karak 61710, Jordan.
                              E-mail: <email xlink:href="gabriel.costa@ufmg.br">gabriel.costa@ufmg.br</email>
                          </corresp>
          </author-notes>
                    <pub-date pub-type="epub">
        <day>30</day>
        <month>03</month>
        <year>2026</year>
      </pub-date>
      <volume>17</volume>
      <issue>1</issue>
      <fpage>77</fpage>
      <lpage>84</lpage>
      <permissions>
        <copyright-statement>
          Copyright: &#x000a9; 2026 Archives of Pharmacy Practice
        </copyright-statement>
        <copyright-year>2026</copyright-year>
        <license>
          <ali:license_ref xmlns:ali="http://www.niso.org/schemas/ali/1.0/"
            specific-use="textmining" content-type="ccbyncsalicense">
            https://creativecommons.org/licenses/by-nc-sa/4.0/</ali:license_ref>
          <license-p>This is an open access journal, and articles are distributed under the terms of
            the Creative Commons Attribution-NonCommercial-ShareAlike 4.0 License, which allows
            others to remix, tweak, and build upon the work non-commercially, as long as appropriate
            credit is given and the new creations are licensed under the identical terms.</license-p>
        </license>
      </permissions>
      <abstract>
        <title>A<sc>BSTRACT</sc></title>
        <p>Large language models can produce fluent medication information while remaining vulnerable to factual error, missing context, unsafe personalization, adversarial manipulation, and misleading confidence. Refusal is therefore not merely a conversational limitation; when appropriately designed, it may function as a medication-safety control. This article develops a proposed Pharmacy Refusal-Safety Framework for determining when a model should answer, qualify, redirect, or refuse a medication question. The framework combines a multi-axial taxonomy of unsafe and unanswerable questions, a layered risk-interpretation architecture, an action-selection boundary, a non-abandonment response contract, and lifecycle governance. Questions are characterized according to potential harm, urgency, personalization, context sufficiency, epistemic answerability, premise validity, misuse potential, vulnerability, and professional-authority requirements. The selected action is constrained by the consequences of error rather than linguistic confidence alone. A safe refusal should state the relevant boundary, avoid covert individualized advice, preserve appropriate general information, identify missing context, direct the user toward a feasible next action, and provide urgent safety-net guidance when danger is plausible. Evaluation requires realistic safety-critical cases, expert adjudication, subgroup analysis, adversarial testing, user-comprehension assessment, workflow simulation, and prospective monitoring. The framework is an original non-empirical synthesis rather than a validated clinical algorithm or deployment standard. Its categories and transitions may behave differently across models, medicines, languages, users, jurisdictions, and care settings. Empirical validation is therefore required before clinical or pharmacy implementation.</p>
      </abstract>
      <kwd-group>
                <kwd>Digital pharmacy</kwd>
                <kwd>Artificial intelligence</kwd>
                <kwd>Pharmacy practice</kwd>
                <kwd>Medication safety</kwd>
                <kwd>Human–AI collaboration</kwd>
                <kwd>Clinical decision support</kwd>
              </kwd-group>
    </article-meta>
  </front>
</article>