Skip to content
Use Case Healthcare & Diagnostic AI

EVIDE for Healthcare and Diagnostic AI

Preserving observable evidence at the boundary between clinical data, machine interpretation and operational consequence.

For healthcare providers, hospitals, diagnostic laboratories, medical-device manufacturers, AI developers, research institutions and public authorities evaluating operational or experimental evidentiary workflows.

Section 1

1. Why This Matters Now

Every diagnostic AI system may eventually face an evidentiary question.

When a diagnostic result is challenged or placed under review, whether by a patient, a clinical board or a supervisory authority, the question concerns more than what the system produced. It also concerns what can be independently reconstructed after the event.

The use of artificial intelligence in healthcare diagnostics offers significant opportunities, but it introduces a problem at a specific point: the moment at which the system interprets received content, such as a report, a diagnostic image, structured clinical data, a laboratory result or sensor-generated data. Depending on its declared function, the system may be expected to distinguish, for example, clinical data from operational instructions, and ordinary information from possible manipulation.

Regulatory timelines may be foreseeable. Incidents are not always so.

An incident occurring before an evidentiary procedure has been established does not lose its significance. It may simply leave fewer independently preserved elements available for later reconstruction.

Section 2

2. Why the Evidentiary Boundary Matters in Healthcare

In healthcare, the distinction between clinical data, instruction, metadata and external content can directly affect classifications, priorities, escalations, reports and recommendations. The same content may present:

This is one of the points at which an anomaly, if not observed or preserved, may become partially or wholly unreconstructable.

Section 3

3. The Risk Is Not Limited to Traditional Cybersecurity

Cybersecurity protects systems, networks and access. But an event may also concern the way an AI system interprets content that is formally accessible and legitimate. Three forms of concern should be kept distinct:

Across these forms, the situations of concern include:

These are risk scenarios, not statements that such events have occurred in any particular facility or technology. Which of these forms applies in a given case is not determined by EVIDE.

The domain is broad: diagnostic images, structured clinical data, laboratory results, sensor-generated data, triage systems, telemedicine systems, medical devices containing AI components, and systems producing classifications, priorities, recommendations or escalations, not only textual reports.

Section 4

4. Human-Visible and Machine-Visible Surfaces

The same content may present at least five distinct conditions:

The classification of a surface as human-visible or machine-visible may be declared by the system or participant and, where possible, supported through technical artefacts. EVIDE preserves that distinction and its level of support without presuming that internal visibility has been independently verified.

This distinction connects directly to the declared visibility surfaces already provided for in the EVIDE architecture.

Section 5

5. The Observable Interpretation Boundary

EVIDE does not preserve the model's internal chain of thought. It preserves the observable boundary at which a declared classification, an artefact-supported condition or another externally observable signal was associated with an action, block, escalation or output.

Depending on its declared function, the system may be expected to distinguish, for example, clinical data from instructions, information from commands, trusted content from unverified content, diagnostic output from operational direction, and ordinary processing from a condition requiring escalation.

Where the system is expected to draw such distinctions, they may constitute a genuine evidentiary boundary.

Section 6

6. Instruction Conflict Signature — ICS

An Instruction Conflict Signature is a proposed evidentiary concept under evaluation within the EVIDE framework.

It describes a candidate set of observable signals associated with a possible conflict between the declared task scope and instructions present in an external source. Possible signals:

The presence of an Instruction Conflict Signature may constitute a candidate evidentiary trigger. It is not proof of an attack, error, malicious intent, clinical harm, causation or responsibility.

An ICS is not a clinical standard, a validated function, or a capability already implemented automatically in the platform.

Section 7

7. When an EVIDE Intake May Be Triggered

The declared or observed presence of an ICS does not necessarily activate an intake. It may satisfy a previously defined evidentiary materiality condition and, according to the applicable scope, lead to the proposal or activation of an evidentiary checkpoint. It does not follow a deterministic sequence of the type "ICS detected → automatic intake required."

Conditions that may be relevant:

Section 8

8. What the Intake Can Preserve

The following fields constitute a candidate Minimum Evidentiary Set to be tested and refined for the defined system, boundary and experimental scope. They are not a universal schema already established:

  1. event identifier;
  2. declared source and provenance;
  3. declared origin of the referenced artefact;
  4. declared transfer path;
  5. receipt timestamp;
  6. preservation timestamp;
  7. artefact digest;
  8. custody condition at the intake boundary;
  9. representation actually received;
  10. declared visibility surface;
  11. materially relevant segment;
  12. declared task or objective;
  13. declared or artefact-supported anomaly or conflict condition;
  14. system-declared classification;
  15. proposed or attempted action;
  16. operational consequence;
  17. human intervention or confirmation;
  18. model, policy and tool versions;
  19. external evidence references;
  20. level of independent support for each material assertion;
  21. unresolved signals and any applicable unverifiable condition.
A digest and a receipt or preservation timestamp do not, by themselves, establish authorship, origin, authenticity, creation time or truth of the referenced content.

Section 9

9. Observable Outcomes and Evidentiary States

To avoid ambiguity, "ignored" is not used on its own, as it can carry opposite meanings. Candidate evidentiary outcome labels for this proposed use case may include:

These candidate labels are presented for evaluation and do not necessarily correspond to fields or states already implemented in the EVIDE platform. unresolved and unverifiable can be linked to existing EVIDE capabilities; the rest of the list remains candidate.

None of these labels determines clinical correctness, compliance, causation, fault or responsibility.

Section 10

10. What EVIDE Does Not Do

EVIDE preserves

  • the observable conditions under which a diagnostic or operational outcome was produced, modified, blocked, escalated or transmitted

EVIDE does not

  • diagnose;
  • determine clinical correctness;
  • replace medical professionals;
  • authorise treatments or healthcare decisions;
  • control the device during execution;
  • replace cybersecurity, safety engineering or regulatory validation;
  • acquire or certify the model's internal chain of thought;
  • automatically establish an attack, error, causation, fault or responsibility.

Reconstructability is an evidentiary condition, not a clinical or governance determination.

Section 11

11. Potential Operational Evaluation Path

This is not a clinically validated integration path, nor a solution ready for any healthcare environment. It is a possible evaluation path:

  1. System and boundary identification
  2. Evidentiary materiality conditions
  3. Checkpoint selection
  4. Candidate Minimum Evidentiary Set
  5. External Artifacts linkage
  6. Intake configuration
  7. Reconstruction-sufficiency review
  8. Periodic review of triggers and limitations
No promise is made of clinical certification, diagnostic validity, operational safety or automatic compliance.

Section 12

12. Governance Lab Experimental Path

Controlled experimentation, initially without real health data and using synthetic scenarios, following the Lab's standard sequence:

  1. Registration
  2. Identity confirmation
  3. NDA where required
  4. Scope Draft
  5. Participant-side Profile Freeze
  6. Bilateral Scope Freeze
  7. Experiment start

Possible experiments:

Participation in the Lab does not constitute approval, certification or validation of the participant or of the technology.

Section 13

13. Data Minimisation and Synthetic Testing

Synthetic testing reduces exposure to real health data but does not, by itself, establish clinical validity, operational safety or regulatory compliance.

Section 14

14. Evidentiary Reconstruction After an Incident

In the absence of an evidentiary checkpoint, the final output may remain available while the conditions that produced it disappear.

With EVIDE, reconstruction does not have to depend solely on the final report; it can draw on elements preserved at the checkpoint. Where those elements are available and within the defined scope, an EVIDE-supported reconstruction may include the received input, declared visibility surface, active versions, declared or artefact-supported conflict condition, human intervention, operational consequence and unresolved signals.

Section 15

15. Illustrative Scenarios

The following are illustrative scenarios, not descriptions of real incidents.

Scenario A — An embedded instruction in a report

A system receives a report containing visible clinical text and an embedded instruction that is not immediately visible to the operator. The instruction purports to modify the priority of the case.

Sequence:

  1. Content received
  2. Visibility divergence declared or artefact-supported
  3. Instruction-conflict candidate identified
  4. Action blocked or escalated
  5. Human review requested
  6. Relevant artefacts and states anchored
  7. No automatic conclusion concerning attack, clinical error, causation or responsibility

Scenario B — An agent receives a denial and attempts another path

An AI agent performing a declared task within a healthcare organisation requests access to a resource, which may be patient data, a diagnostic tool or a clinical workflow. The access-control system returns a denial. The agent then makes further attempts, and a later access is declared to have been obtained through a different path.

Where the relevant steps are submitted to EVIDE within the defined scope, a reconstruction may link:

Sequence:

  1. Request
  2. Access decision returned (denial)
  3. Subsequent attempts
  4. Later access through another declared or artefact-supported path
  5. Outcome
  6. Human intervention or confirmation

Where supported by the applicable scope and implementation, related steps may be connected through linked intake records and applicable chain references. The linkage records the relationship between the entries; it does not establish that one caused another.

What this scenario does not establish

  • EVIDE does not grant or deny access;
  • EVIDE does not block the agent in real time;
  • EVIDE does not replace identity and access management, access controls or security monitoring;
  • a later access does not prove circumvention, impropriety or causal connection with the earlier denial;
  • an alternative path may have been legitimate;
  • the absence of a preserved step does not prove that the step did not occur;
  • EVIDE does not establish attack, error, causation, fault or responsibility.

Section 16

16. Who Can Work With EVIDE

Section 17

17. Proposed Research Questions

  1. Which interpretation boundaries carry genuine evidentiary materiality?
  2. What minimum set allows sufficient reconstruction?
  3. Who should define and approve the triggers?
  4. How can an observable deviation be distinguished from a clinical judgement?
  5. When is human review necessary?
  6. How should what remains upstream and unverifiable be documented?
  7. How can sufficient information be preserved without total recording?
  8. How can a denial, subsequent attempts and any access obtained through another path be linked without recording the underlying patient data?

Section 18

18. Closing

Potential Operational Evaluation

For providers and manufacturers interested in evaluating checkpoints, intake and reconstruction sufficiency in a defined system or process.

Discuss an Evidentiary Use Case ↗

Governance Lab Experiment

For organisations interested in a circumscribed, synthetic-first study that is bilaterally frozen before it begins.

Propose a Synthetic Experiment ↗

Contact EVIDE Governance Lab ↗


References