Skip to content

Regulatory baselines

The second leg of the healthcare wedge: regulators have already forced healthcare AI to write down what its systems are supposed to do. That documented “supposed to” is exactly the raw material a declared behavioral baseline is made from.

The Control Platform attests every inference against a baseline declared at deployment. In an unregulated sector, getting a vendor to declare that baseline is a negotiation. In healthcare it is largely already done, because three regimes require documented intended use and controls GROUNDED · Brochure:

Regime What it contributes to the baseline
FDA (US) Intended-use definitions, change-control expectations (the PCCP vocabulary buyers actually use), post-market duties for AI-enabled devices. STABLE
MHRA (UK) Parallel device-regulation baseline; the UK regulatory sandbox track is where Glacis is active (VERIFY current program status — draft bio material).
EU AI Act High-risk system obligations: logging, record-keeping, human oversight, post-market monitoring — duties that read like a specification for runtime evidence. STABLE

The pitch-level summary: compliance documentation is a promise; the evidence layer turns the promised baseline into an attested fact. The regulator defines what to declare; the attestation chain proves it was enforced.

The draft’s formulation is worth memorizing: “The sector determines what the baseline is declared against; the evidence infrastructure is the same.” GROUNDED · Brochure A clinical-scribe deployment declares consent gates and PHI controls; a credit-decisioning deployment declares fairness and adverse-action controls. Same Arbiter, same receipts, same OVERT record shape — different declared scope. That is why the expansion table in 00 Why healthcare first is credible: nothing sector- specific lives in the evidence layer itself.

Both sides of the trade are regulated — don’t confuse them

Section titled “Both sides of the trade are regulated — don’t confuse them”

Volume 1 taught the insurance-side regime: the NAIC AI Model Bulletin and the evaluation tool govern how insurers use AI. This page is about the insured-side regime: FDA, MHRA, and the EU AI Act govern the AI vendor’s system. STABLE

Keep the two straight in a conversation:

  • Selling to a carrier or MGA: the NAIC bulletin is the pressure — their own AI underwriting and claims processes need audit-grade evidence, and Glacis-as-software serves that (Volume 1’s stream 1).
  • Selling to a healthcare-AI vendor: FDA/MHRA/EU-AI-Act obligations are the pressure — their documented baseline is sunk cost, and runtime attestation makes it pay twice: once for the regulator, once for the underwriter.

The same evidence stream satisfies both audiences — that reuse is the economic point, and it is assertable because it is a property of the record format, not a promise about outcomes. GROUNDED · Labs

02 The composite case study

Drill this page →13 bank questions stand behind what you just read. Check it while it’s warm.