
AI is beginning to coordinate care between clinical encounters — scheduling follow-ups, monitoring recovery, supporting discharge. The question hospitals now face is not whether AI is capable, but whether every AI-mediated action is authorised, consented, risk-tiered, escalated and evidenced — at the point of use.
“We did not start by asking how to build another AI assistant. We started with a different question: why do patients spend 99% of their lives outside healthcare, yet every clinical encounter begins as though their story has been forgotten?”
That gap — between the continuous life of a patient and the episodic memory of the system — is where care breaks down: at discharge, across handovers, between the hospital and the home, between one multidisciplinary team and the next. Information is lost, questions are re-asked, and the patient carries the burden of remembering.
Operational AI Governance — and the Runtime Governance Infrastructure behind it — emerged from solving that continuity problem. Once AI begins acting between encounters, continuity can only be safe if every action is governed: who authorised it, whether consent held, what risk it carried, when it should escalate, and what evidence it left behind.
Helping every patient feel known.
Continuity of care · continuity of knowledge · continuity of each person's health context. Our hypothesis is simple: continuity compounds.
Every hospital now has access to the same frontier models. Capability is no longer the differentiator — yet AI projects keep stalling before they touch a care transition. They stall on the same wall.
None of the items on the left solve a single item on the right.
The agentic shift removed the technical ceiling and exposed the organisational one. A capable agent dropped into an ungoverned care workflow does not improve continuity — it accelerates whatever was already broken: unclear authority becomes faster unclear authority; assumed consent becomes automated assumed consent. Operational AI Governance is the missing layer that lets the 70% — people, authority and how care actually moves — finally have infrastructure beneath it.
1 The 10/20/70 framing is drawn from AI-implementation practitioner Andreas Horn's publicly shared 2026 lessons, cited as independent validation of a direction PatientCentricCare.AI reached through healthcare deployment — not as its intellectual source.
Everyone understands a care pathway; few understand a governance diagram. So we start where care actually happens — with the path a real interaction travels, from the patient to the evidence and back. Governance is the mechanism. Continuity is the outcome.
Every hospital sits somewhere on this ladder. The value is not in reaching the top fastest — it is in never letting autonomy outrun governance, so continuity never depends on an unaccountable action.
Hospitals do not buy governance. They buy outcomes — the results that keep patients safe and staff confident as care moves between people and settings.
Governance is the mechanism. Continuity is the outcome. Operational AI Governance is the discipline of ensuring every AI-mediated action in care is authorised, consented, risk-tiered, escalated and evidenced — at the point of use — so that a follow-up, an escalation or a handover can be trusted across every care transition.
A decade ago, few hospital boards discussed cybersecurity as core infrastructure. Today none would deploy a clinical system without it. Operational AI Governance is following the same curve for AI-enabled care: first a differentiator, soon an expectation, ultimately a precondition for deployment.
And it answers the five questions no ungoverned AI can: Who authorised this action? Was consent valid at this moment? Who holds authority now? Is escalation required? And when something goes wrong — why was execution permitted?
A hospital executive needs these five principles — not the software beneath them. Together they keep continuity safe as care moves between people, teams and settings.
Operational AI Governance is made possible by Runtime Governance Infrastructure (RGI) — a domain-agnostic architecture that evaluates the five principles at the point of execution, in milliseconds, before an AI-mediated action reaches a patient.
Runtime Governance is to AI what Air Traffic Control is to aviation. ATC does not fly the aircraft — it governs the safe execution of flight. Aircraft, pilots and airlines differ; ATC is the common layer that keeps the system safe. RGI does not replace AI models, EHRs or clinical workflows. It governs the safe execution of AI-mediated actions between them.
HCP-as-Pilot™ is the healthcare framework built on RGI, following the principle proven in aviation: autopilot may execute, but authority remains with the pilot. AI may assist, recommend and coordinate; authority over patient-impacting actions remains human. RGI is a new infrastructure category — healthcare is its first implementation.
Regulatory inevitability creates a window for first movers: hospitals that build Operational AI Governance today will hold the evidence and institutional trust required when it becomes mandatory.
Indicative market-development scenario — projection, not sourced regulatory fact
| Framework | Reference | Alignment |
|---|---|---|
| EU AI Act | Art. 12, 14, 16 | Generates runtime evidence for human-oversight, record-keeping and post-market monitoring obligations. |
| Singapore AIHGle 2.0 | MOH/HSA 2026 | Independent convergence: mandates human oversight for clinical AI; flags home-care AI as needing added governance. |
| UK MHRA | SaMD Roadmap | Phased architecture aligns with the MHRA's progressive AI-oversight framework for software as a medical device. |
| FDA SaMD / PCCP | 2019 / 2023 | Phase III maps to Predetermined Change Control Plan requirements for adaptive AI medical devices. |
Phase I (Home Companion™) is an early-access usability deployment with senior users across Switzerland and the UK — non-medical, non-SaMD, governed end to end.
A governed runtime event is a single AI-mediated action evaluated for consent, authority, risk and escalation before it executes. Figures describe a usability deployment, not a clinical study; hospital-pilot recruitment is now underway.
Every hospital now has access to intelligence. The differentiator is the capability to govern it — to trust, scale, audit, improve and certify AI acting between clinical encounters. Hospitals that can do this will adopt AI faster, protect continuity of care, and earn greater confidence from patients, clinicians and regulators.
“She made me laugh speaking in Luzern Swiss German dialect from my childhood.”
— Senior & cancer survivor, 86, Basel“I love that I can suggest personalised memories for my mum to discuss. It makes her smile.”
— Caregiver, 62, Allschwil“I care for multiple seniors, and Home Companion keeps the status of each organised for me.”
— Care-home assistant, 42, BaselStart where the risk is bounded — one care transition, one virtual ward, one discharge pathway. Prove Operational AI Governance there, then expand autonomy only where the evidence earns it.
The question is not whether AI can participate in care.
It is how AI is governed — at the point of use, in service of continuity.
Hospital readers can stop at the five principles. This appendix is for technical evaluation and procurement due diligence: the components of PCC-SafetyOS™ that implement Operational AI Governance using Runtime Governance Infrastructure — each stated as one function and one governance consequence.
Inventories every AI-involved decision and assigns one named human owner.
→ A decision not inventoried cannot be automated. · Authority
Defines the boundaries AI may act within — and who holds authority when it cannot.
→ AI never operates outside authorised boundaries. · Authority
Validates consent at the moment of every AI-mediated action.
→ No consent, no action; ambiguity defaults conservatively. · Consent
Classifies every action into a risk tier in real time.
→ Higher risk demands human confirmation or authority. · Risk
Routes to caregiver or clinician by urgency and availability.
→ Escalation is governed, not improvised. · Escalation
Records why each action was permitted — not just what happened.
→ Every governed decision is reconstructable; append-only. · Evidence
Structures governance artefacts for internal review, quality assurance and regulatory assessment.
→ Everyday operation becomes defensible evidence. · Evidence