Standards Closed-Loop Defensibility
Open architecture standard · CLD-SPEC-v1.0 · CC BY 4.0

Closed-Loop Defensibility

Most healthcare AI governance stops at two places: a checklist before deployment, and a document for the survey. Both are open loops. When a model drifts on a Tuesday, an open loop notices at the next quarterly meeting, if at all, and the record of what happened between is whatever anyone remembers. Closed-Loop Defensibility is the architecture that closes the gap: every anomaly is bound to an automated response and to an accountable human decision, and the whole sequence is preserved as evidence that accumulates with dates rather than being written after the fact.

The thesis, in one line

Static committee charters, model cards, and ethics pledges describe intentions. In an adverse event or an unannounced survey, intentions are not evidence. Governance has to be executed, at runtime, and the execution has to leave a record. A governance loop that is never closed, detection with no bound response, or a response with no recorded human decision, is not partial safety; it is the part a reviewer will ask about first.

The five-stage loop

  1. Credentialing. Before production, each model or agent receives a Model Scope of Practice and a privileging tier. Deployment on IT approval alone is out of conformance.
  2. Runtime surveillance. The system continuously measures what can change: distributional drift, subgroup performance disparity, and the rate at which clinicians override it.
  3. Automated response. A defined threshold breach triggers an automated privilege change, up to removing the system’s ability to act, without waiting for a meeting. This is the Runtime Privileging Circuit Breaker.
  4. Accountable triage. A named human proctor is alerted and owns the decision: override, recalibrate, retrain, or retire. The Governance Decision Latency clock runs from breach to that decision.
  5. Closing the loop. Every step, from baseline to human decision, is written to a Deposition Ledger: an append-only, hash-chained record that cannot be silently altered.

The lexicon

These are the defined terms of CLD-SPEC-v1.0. They are offered CC BY 4.0: use them, cite them, build on them.

$
Closed-Loop Defensibility (CLD)
An operational architecture in which every algorithmic anomaly, statistical drift, data-feed change, or adverse event affecting a clinical AI system is bound to an automated runtime response and to an accountable, timestamped human decision, with the whole sequence preserved as tamper-evident evidence. The loop is closed when the human decision is recorded; governance that stops at detection or documentation is open-loop.
Governance Decision Latency (GDL)
The elapsed time from an automatic suspension of an AI system to the next accountable human decision on it. The one governance number that cannot be produced by writing documents. Defined in full at /standards/decision-latency/.
Model Scope of Practice (MSoP)
The declared clinical boundaries of an AI model or agent: authorized patient populations, encounter types, permitted inputs, contraindications, and permitted outputs. Adapted from hospital medical-staff bylaws, an MSoP makes an out-of-boundary input a rejectable event rather than a silent one. Open template at /standards/model-scope-of-practice/.
Autonomous Agent Privileging (AAP)
The credentialing lifecycle applied to non-deterministic clinical or operational agents: provisional (supervised), conditional (sampled), and full privileges, with surveillance and defined conditions for revocation. The analogue of clinical privileging, applied to software that acts.
Deposition Ledger
An append-only, cryptographically hash-chained record of an AI system’s governance events: baselines, threshold breaches, automated responses, and human decisions, each entry incorporating the digest of the one before it so the history cannot be silently altered. The evidentiary substrate of a closed loop. Implemented in the Institute’s Model Governance Record and reference SDKs (US patent pending).
Runtime Privileging Circuit Breaker (RPCB)
An automated control that changes an AI system’s privileges, up to and including removing its ability to act, when a governance threshold is breached, without waiting for human intervention. The mechanism that makes a loop close in seconds rather than at the next committee meeting.

Conformance requirements

A system conforms to CLD-SPEC-v1.0 if all of the following hold. The specification states what must be true, not how to achieve it; the detection and enforcement methods are the implementer’s to design, and may be proprietary.

  1. C1 — Scoped. Every production model or agent has a recorded Model Scope of Practice naming its authorized populations, inputs, and outputs, and an accountable owner.
  2. C2 — Measured. The system computes, on a stated cadence, at least: a distributional-drift statistic against a sealed baseline, subgroup performance across the populations the MSoP names, and the clinician override rate.
  3. C3 — Bound. Stated, versioned thresholds are bound to automated privilege changes that take effect without human intervention. What the thresholds are, and how they are computed, is implementation-defined and may be proprietary; that they exist, are versioned, and act automatically is required.
  4. C4 — Owned. Every automated response alerts a named human, and the Governance Decision Latency from breach to that human’s recorded decision is measured and reportable.
  5. C5 — Recorded. Every event in C1–C4 is written to an append-only, tamper-evident ledger in which each entry incorporates the digest of its predecessor, such that a third party can verify the history was not altered after the fact.

A conformance claim is a statement about architecture, not about outcomes. Conforming to CLD-SPEC does not certify a system as safe, effective, or compliant with any regulation, and is not a certification issued by the Institute.

How the Institute’s standards fit together

CLD is the architecture; the other open standards are its parts. The Model Scope of Practice is C1. The Model Governance Record is the file format that carries C2 through C5, and its verifier is how a third party checks C5. Governance Decision Latency is the metric of C4. And the Model Governance Rider is how a buyer requires all of it in a contract.

Why this is published, and what is not

The architecture, the lexicon, and the conformance requirements are open because a standard only becomes a standard when others can adopt it without permission. What is deliberately not published here is any particular algorithm for computing a breach or scoring a privilege change: those are implementers’ competitive ground, and some are the subject of the Institute’s pending patents. A good standard draws that line exactly where CLD-SPEC draws it, at the interface, not the engine.

CLD-SPEC-v1.0 is published by The Healthcare AI Institute under CC BY 4.0. It is an engineering and governance specification, not legal, clinical, or regulatory advice, and adopting it does not create any professional relationship. Proposals and implementations: write to us.