Healthy AIClinical safety protocol / Builder reference

Readiness before authorization

Bound the use, trace the evidence, require a qualified decision.

A bounded builder checklist for intended use, release contraindications, evidence traceability, risk controls, monitoring, and qualified human authorization before a health AI prototype advances.

Mandatory hold conditions

Do not advance while a release contraindication remains open.

H01

Intended users, setting, and excluded uses are not explicit.

H02

The system can influence diagnosis, treatment, dosing, or emergency decisions without qualified review.

H03

Known failure modes lack detection, escalation, containment, or recovery controls.

H04

Claims about performance or safety cannot be traced to current, applicable evidence.

H05

Protected health information boundaries, retention, access, and deletion are unresolved.

H06

No qualified person is authorized to accept residual clinical risk.

Six-part readiness protocol

1. Intended use boundary

Describe who uses the system, for which task, in what setting, on which population, and for what decision. List excluded uses with equal precision. Marketing language and technical capability must not silently expand the intended use.

2. Clinical consequence map

Identify credible failure modes, affected people, severity, time to harm, reversibility, and existing safeguards. Include omission, delay, hallucination, automation bias, subgroup performance, workflow disruption, and escalation failure.

3. Evidence record

Connect every material claim to a source, dataset, evaluation, reviewer, date, population, and limitation. Distinguish internal prototype testing from evidence suitable for a clinical or regulatory decision.

4. Human factors and workflow

Test whether users understand limitations, notice uncertainty, verify consequential outputs, resist automation bias, and can escalate safely. A technically accurate output can still be unsafe in a poorly designed workflow.

5. Operational controls

Define access, logging, privacy, monitoring, incident response, rollback, model and prompt change control, and evidence retention. Assign owners and response deadlines before release.

6. Qualified authorization

Prepare a handoff that states intended use, excluded use, evidence status, unresolved risks, mitigations, monitoring, and the decision required. Authorization must be named, bounded, dated, and revocable.

Reviewer handoff

Make the authorization question answerable.

The handoff should include intended and excluded use, workflow, affected population, performance claims, evidence limitations, known failures, risk controls, privacy and security boundaries, monitoring, incident response, and every unresolved decision.