Our FDA comment on AI in early-phase trials
AI GOVERNANCE

AI-native shouldn't mean you bolted on AI. It should mean you can keep it safe as it gets stronger.

The companies that last in AI-enabled care won't be the ones that integrated AI fastest. They'll be the ones built so it stays safe and governed no matter how powerful it gets. That assumption is our foundation, not a feature.

SOC 2 Type II
HIPAA Compliant
FHIR-native
Patent Pending
WHERE THE VALUE GOES

The scarce thing isn't another model. It's the layer that can govern them.

You already feel it. AI is getting more capable faster than anyone planned for, and the bottleneck in care isn't the intelligence, it's whether a hospital can trust it near a patient. As models get stronger, the scarce thing isn't another model. It's the layer that can govern them, keep them safe, and make them deployable in a regulated setting. That layer is where the durable value sits, because it gets more necessary, not less, as AI improves. So the real question for anything you build, your device, your IP, your programs, is whether it sits on a foundation built to govern AI from the start. Build on that, and a stronger model makes you better. Build without it, and a stronger model makes you more exposed.

WHAT AI-NATIVE ACTUALLY MEANS

Not AI as a feature. AI as a force you design to govern.

Built on the assumption.

Built on the assumption that the AI has to be kept safe and usable for the value to hold, no matter how strong it gets. That assumption is our starting point.

Safety as the foundation, not a feature added later.

The envelope endures.

The model is swappable; you will run a better one next year and the year after. What endures is the governed envelope it runs inside.

Models change. The envelope holds.

Bounded authority, by design.

The bounded authority, the policy, the audit. We made that envelope the foundation, so the intelligence can keep improving without the safety having to be rebuilt each time.

Bounded authority is what makes 'agentic' deployable.

The intelligence keeps improving.

Because the safety is structural, you get the upside of stronger AI without re-earning the trust each time a model improves.

A stronger model makes you better, not more exposed.

THE FDA LINE

The line the FDA draws, built into the platform.

The FDA draws a hard line between general wellness and clinical use, and which side you're on turns on intended use and the claims you make. The 2026 General Wellness guidance is specific, and we built that line directly into the platform: an organization defines a compliance policy with two lanes, and every AI output is checked against the lane it's allowed to operate in. The agent can only produce what its lane permits, because the regulatory boundary is enforced on every output, not left to hope.

The policy we built against: FDA, General Wellness: Policy for Low Risk Devices.

THE WELLNESS LANE

A wellness-lane product can encourage someone to see a professional and show general benchmarks, but it cannot issue diagnostic alerts, trigger clinical interventions, or recommend treatment without becoming a regulated device. Wellness-lane output that drifts toward a clinical claim is caught and rewritten or blocked.

THE CLINICAL LANE

The lane for regulated, clinically consequential work. Clinical-lane output that needs a human is surfaced for review, and the clinically consequential decisions surface to your clinical team rather than being made autonomously.

HOW THE GOVERNANCE WORKS · PILLAR 1

PHI-safe model routing.

PHI requests

PHI REQUEST

Heart Rate: 106 bpm

Patient ID: 4287

HIPAA Tier

BAA-Covered Model Providers

HIPAA-compliant

Non-PHI requests

NON PHI REQUEST

Summarize ECG Trends

General Tier

Broader AI Models

No Patient Data

PILLARS 2 + 3

Compliance gates. Bounded authority.

AI OUTPUT

Governance layer

PHI-Safe Model Routing
Human-in-the-Loop Review
LLM Cost and Usage Transparency
Compliance Gates
Agent Types with Scoped Authority
Full Audit Trail
Allow

Meets all criteria. Output delivered as-is.

Rewrite

Clinical claims rewritten to wellness-appropriate language. Both versions preserved.

Block

PHI leak or harmful content. Surfaced for human review.

PILLAR 4 · FULL AUDIT TRAIL

The audit trail is the thing that lets a hospital say yes.

Every run logs what data was seen, which model ran, what was produced, which gate it passed, whether a human approved it, and what action followed. Structural, not bolted on.

AnyBio

Audit Trail · Patient_01

Verified
1.Inputs seen

ECG stream · episode metadata · patient context

source:   ring_0000 · BLE · 250Hz

episode:   ep_0000 · 13:30–14:00

patient:   pt_0000 · PHI tagged

hash:   0000x00 · verified

2.Model called

anyBio-clinical-v2 · HIPAA tier · BAA-covered

14:08:01
3.Output produced

“Resting tachycardia detected. HR sustained above 100 bpm...”

14:09:01
4.Compliance gate

PHI check · scope · confidence · decision: Human Review

14:10:07
5.Human reviewer

dr_JohnDoe · flagged for review · 14:10

14:14:01
6.Final action

FHIR synced · EHR updated · episode closed

14:31:01
FOR AN IP HOLDER

Your model can be the best in its class and still never reach a patient if there's no governed place to run it.

We are that place, and it stays current as models improve.

FOR A PROVIDER

Your team can say yes to AI because legal and security are reviewing one policy, not auditing every tool.

The governance is the same on every agent, so approval is about the policy, not the project.

See the governance in practice.

We'll walk through the compliance policy, the wellness and clinical lanes, the gates, and the audit trail, and show how an agent runs inside the envelope on a real program.

Moving forward together