AIAH Health Limited uses artificial intelligence to help women understand, contextualise and act on their own health information. AI extends — it never replaces — the judgment of healthcare professionals. This Policy sets out the principles, controls and accountability we apply to every AI feature we build or deploy.
1. Purpose and scope
This Policy applies to all AI features in the AIAH.Health Service, whether built in-house, fine-tuned by us, or accessed through a third-party model provider. It applies at every stage from feasibility through decommissioning.
2. Ethical principles
- Beneficence — AI is deployed to advance women's health outcomes and autonomy.
- Non-maleficence — we do not deploy AI where the potential harms outweigh the benefits.
- Justice — we design to reduce, not amplify, disparities in women's health.
- Autonomy — users remain in control of their data and their decisions.
- Transparency — users know when AI is involved and what its limitations are.
3. Human oversight
We do not deploy solely automated decision-making with legal or similarly significant effects under Article 22 UK GDPR. Humans — either the user or our clinical/support team — remain in the loop for consequential decisions. Each AI feature has a designated feature owner accountable for its behaviour.
4. Transparency and explainability
- AI-generated content is clearly labelled in the interface.
- We publish plain-language explanations of what each AI feature does, what data it uses and what it does not do.
- Where practicable we provide the source signals behind an AI output so users can interrogate it.
- Our public model cards describe purpose, training approach, evaluation and known limitations.
5. Data minimisation and privacy
- Inputs are limited to what is necessary for the feature.
- Personal data is not used to train third-party foundation models unless the user gives explicit informed consent and the vendor contract prohibits reuse.
- We prefer providers with zero-data-retention or short retention configurations.
- Prompts and outputs used for safety monitoring are pseudonymised where possible.
6. Bias mitigation
- We evaluate features across relevant demographic dimensions (age, life stage, ethnicity where data is available).
- We actively identify and correct for known women's-health data gaps in third-party models.
- Bias findings are logged, prioritised and remediated before launch or as high-priority defects.
7. Clinical safety
- AI features are risk-assessed against clinical safety principles inspired by DCB0129/0160.
- Features that could influence medical decisions include explicit non-medical-advice disclaimers, safety guardrails and, where appropriate, escalation pathways to seek professional care.
- Emergency red-flag content is never handled by AI alone — it triggers signposting to urgent care.
8. Model lifecycle
- Every model or provider has a security and privacy review before use.
- We record model versions, prompts and configuration in change control.
- Model updates are tested against a regression suite covering safety, bias and accuracy.
- We monitor for drift, harmful outputs and user-reported issues.
- Decommissioning removes prompts, keys and any residual training data.
9. AI limitations
AI outputs may be inaccurate, incomplete or out of date. They must not be used for diagnosis, treatment, medication management, allergen avoidance or any other safety-critical decision. Users are told this clearly at the point of use.
10. Continuous monitoring and incident response
We monitor AI features in production for safety, accuracy and abuse. AI safety incidents are handled under our Data Breach Response Plan and, where relevant, our clinical safety incident procedure. Users can report AI issues in-app or by email.
11. Regulatory compliance
- We track applicable UK regulation, ICO guidance on AI and data protection, and MHRA guidance on software as a medical device.
- We assess whether each feature falls within the UK MDR 2002 (as amended) definition of a medical device and act accordingly.
- We monitor developments in the EU AI Act where our services reach EU users.
12. Governance and review
This Policy is owned by the DPO in partnership with the Head of Engineering and the Clinical Lead. It is reviewed at least annually and on any material change in law, guidance or the AI features we operate.