Search all 478 artefacts by title, document ID or content.
Statement | Family 3, Security, Privacy & Trust Disclosures
This is Pensieve Labs's statement of how it thinks about artificial intelligence in a hospital. It is the principles document that produced the two operational documents beside it, and it does not repeat what they say.
This document is the source of truth for: marketing:/legal/ai-principles, marketing:/ai, marketing:/responsible-ai, trust:/ai-principles, trust:/documents/STM-GL-034
Those surfaces render this text from here. They do not keep their own copy, so they cannot drift from it.
Artefacts this one references or cannot be issued without.
Artefacts that would be blocked if this one were missing or out of date.
Nothing in the register depends on this artefact.
STM-GL-034 | Version 1.0.0 | Last Modified On 03 August 2026
This is Pensieve Labs's statement of how it thinks about artificial intelligence in a hospital. It is
the principles document that produced the two operational documents beside it, and it does not repeat what
they say.
| Document | Answers |
|---|---|
| This statement | Why. The principles Pensieve Labs builds to, and the mechanism behind each |
POL-GL-060 Responsible AI Use Policy |
How it may be used: by hospital staff, by Pensieve Labs personnel, and by the Platform |
POL-GL-132 AI Governance and Model Risk Policy |
How Pensieve Labs governs it internally: model inventory, approval, change control, model risk |
DIS-GL-027 AI/ML Feature Disclosure |
What exists: the dated inventory of every capability that uses a model, and its limitations |
A principle that cannot be tested against a control is a slogan. Each principle below is stated with the
mechanism that makes it real and the document that records it. Where Pensieve Labs has a commitment
rather than a control, Section 10 says so plainly rather than dressing an intention as a fact.
The whole of this document reduces to one sentence: in
Pensieve, artificial intelligence assists a person and never replaces one, and it never crosses the clinical boundary inDIS-GL-028. No principle in it is moved by a configuration, an Order Form, a price, or a request from a hospital.
These principles are a property of the software and of how Pensieve Labs builds it, not of where the
software runs. They apply identically in all four deployment models.
DM-1 Dedicated |
DM-2 Shared |
DM-3 Customer Cloud |
DM-4 On-Premise |
|---|---|---|---|
| Yes | Yes | Yes | Yes |
Where a capability requires an external model provider, its availability by deployment model is stated in
DIS-GL-027 Section 6, not here.
Pensieve is a hospital operating system: an administrative and record-management platform. It
is not a medical device, and no capability that uses a model changes that. No capability diagnoses,
triages, calculates a patient-specific dose, computes a clinical risk or early-warning score, interprets an
image or a signal, or recommends treatment. The machine-learning functions in the Platform are
administrative and operational: coding suggestions for billing, denial prediction, demand and stock
forecasting, roster optimisation, document classification, transcription without clinical interpretation,
and search over records a user is already permitted to see.
The boundary, jurisdiction by jurisdiction and with the provision relied on in each, is DIS-GL-028. The
feature-level inventory that stays inside it is DIS-GL-027. This statement adds one thing to both: the
boundary is the first principle, not a caveat to the others. A hospital cannot opt into having
Pensieve make a clinical decision, because that capability is refused at design and is not built
(POL-GL-132 Section 3.1; ADD-GL-005).
Every consequential action, whether clinical, financial, employment-related or otherwise affecting a person, is taken by a named human being who is accountable for it and who can see what the capability suggested and what it drew on. The capability assists; the person decides.
This is enforced, not asserted. For each artificial-intelligence capability a hospital enables, the role
accountable for its outputs is recorded. No auto-approve control and no bulk-accept control is built for any
suggestion class: a coder accepts, edits or rejects each coding suggestion; an unsigned transcription is a
draft, not a record; a ranked queue is shown alongside the unranked list. The operational detail is
POL-GL-060 clause 2. The design rule behind it is simple: a capability that cannot be given a human
decision point is not built.
| # | Principle | The mechanism that makes it real | Recorded in |
|---|---|---|---|
| P1 | A person decides; the capability assists | A recorded accountable role per capability; no auto-approve or bulk-accept control is built | POL-GL-060 clause 2 |
| P2 | No clinical decision, ever | Every proposed capability is assessed against DIS-GL-028 at a design gate before it is built; clinical-purpose vocabulary is banned in product, documentation and sales copy |
DIS-GL-028; POL-GL-132 Section 3.1 |
| P3 | It is always visible that a machine produced it | The output carries a label naming the capability, the model version and the time; no configuration removes it | POL-GL-060 clause 1.3 |
| P4 | What a model saw and produced can be reconstructed | Every invocation touching personal data is logged with the user, the record, the capability and the model version | DIS-GL-013; DIS-GL-027 |
| P5 | The hospital's data trains nothing for anyone else | A contractual undertaking, with no aggregation and no de-identified reuse | DIS-GL-027 Section 4; DPA-GL-001 |
| P6 | Optional and reversible | Off until the hospital enables it, per capability, and disableable without losing unrelated function | DIS-GL-027 Section 7 |
| P7 | Published before it ships | The public inventory is updated, and the design gate recorded, before any hospital can use a capability | DIS-GL-027 Section 2 |
| P8 | Honest claims | No accuracy, validation or certification figure that Pensieve Labs has not evidenced appears in any published material |
DIS-GL-028 Section 8; POL-GL-132 Section 6 |
Sections 4 to 7 expand the four principles a hospital's data-protection and clinical-governance functions test hardest.
This is P4 in full. Every invocation of a model-assisted capability that touches personal data is logged:
who invoked it, when, on which record, which capability, and which model version produced the output. A
suggestion that influenced a person's decision can be reconstructed afterwards from the audit trail
(DIS-GL-013). This is what makes the machine-generated label in P3 more than cosmetic: the label tells a
user in the moment, and the log tells an investigator later. Where a change to a model, a prompt or a
threshold alters a capability's behaviour, that change is a release with a change record, so the version
named in the log is meaningful rather than approximate.
Pensieve does not use a hospital's data to train, fine-tune or improve any model offered to
another hospital, or to Edsol Edtech Pvt. Ltd. itself. This holds whether the data is identified,
de-identified or aggregated, and it is not relaxed by permission. It is a contractual undertaking in
DPA-GL-001, and the full position, including the treatment of any external model provider, is
DIS-GL-027 Section 4 and Section 5. A model available to one hospital does not see, learn from, or produce
an output influenced by another hospital's data, in any deployment model.
Pensieve Labs adds one undertaking of conduct to the contract: no Pensieve Labs employee may ask a
hospital to relax this as part of a commercial negotiation (POL-GL-060 clause 1.4).
There is a second, independent reason for the commitment. Using hospital data to develop or validate a
model is biomedical research under the applicable Indian ethical guidance, which would require
ethics-committee review and, in most framings, participant consent. That reasoning sits alongside the
data-protection analysis and is recorded in DIS-GL-027 Section 8. Pensieve Labs does not do it.
Indian care is multilingual and served across a wide range of literacy. A model trained mainly on English
text, or on one population, under-serves patients who speak another language or read at a lower level, and a
model trained on operational data reflects the patterns in that data. Pensieve Labs does not treat a
capability validated in one language or one population as validated everywhere.
The clinical boundary in Section 1 is what keeps the consequence of this proportionate. Because every
capability that uses a model is administrative, the failure mode of a biased model is an inaccurate billing
code, a wrong forecast or a misrouted document, corrected by the person who decides and logged either way.
It is not a clinical harm. That is a deliberate design choice, not an accident of scope: keeping artificial
intelligence away from clinical decisions keeps the equity failure mode financial and operational rather
than clinical (DIS-GL-027 Section 9.5).
Pensieve Labs applies, voluntarily, the algorithmic due-diligence discipline that Indian law places on
a significant data fiduciary, although Pensieve Labs is not so designated: every capability is assessed
for whether its output could disadvantage a person, and the assessment is recorded (DIS-GL-027
Section 8). The non-discrimination and equity commitment this rests on is POL-GL-069. Stated honestly,
Pensieve Labs does not yet publish bias-testing results for these capabilities. Section 10 records that
as a commitment to be met with the accuracy figures, not as a control in place today.
A model's output is not explainable line by line. Where a capability suggests a code or flags a claim,
Pensieve shows the evidence the capability drew on, but it does not produce a formal account of
the model's internal reasoning, and Pensieve Labs does not claim otherwise. This is precisely why every
capability has a human decision point rather than an explainability guarantee: the person can see the source
and the suggestion and decide, which is a stronger control than a claim of full transparency the technology
cannot honestly support (DIS-GL-027 Section 9.2).
Pensieve Labs states its regulatory position so a hospital's legal function does not have to
reconstruct it. Two sentences frame it. India has no binding, horizontal artificial-intelligence statute as
at 03 August 2026. Pensieve, because it takes no clinical decision, sits outside the
high-risk and medical-device regimes that would otherwise apply.
Governance runs through existing law, the Information Technology Act, 2000 and the Digital Personal Data
Protection Act, 2023, together with voluntary guidance. The Ministry of Electronics and Information
Technology published the India AI Governance Guidelines on 05 November 2025, setting out seven guiding
principles and a largely voluntary, graded approach; NITI Aayog's Responsible AI principles (2021) are also
voluntary. Pensieve Labs aligns to these as principles, not as binding law, and does not describe them
as obligations they are not.
The DPDP Act regulates the personal data an artificial-intelligence system uses, not the automated decision
as such. It contains no right equivalent to a right against solely automated decisions; its nearest
provision is Section 8(3), under which a Data Fiduciary must keep personal data that is likely to be used to
make a decision affecting a person complete, accurate and consistent. The Digital Personal Data Protection
Rules, 2025 commence in phases, and the data-principal rights and Board enforcement commence in the third
phase, expected in 2027 [UNVERIFIED: the exact third-phase commencement date is not settled in the sources, which place it in 2027]. Throughout, the hospital is the Data Fiduciary and Pensieve Labs is
its Data Processor: the hospital holds these duties and Pensieve Labs assists it (DPA-GL-001;
POL-GL-053).
One point is stated to head off a common overstatement. The labelling duty for synthetically generated
content in the 2026 amendments to the Information Technology intermediary rules binds intermediaries and the
users who post such content publicly, not a business-to-business hospital-software processor.
Pensieve labels machine-generated output at the point of use as a matter of principle (P3), not
because that rule compels it to.
The reason Pensieve stays outside medical-device regulation in every market is intended purpose:
it performs no diagnostic, monitoring, scoring or treatment function on an individual patient. The Indian
position under the Central Drugs Standard Control Organisation, the European position under Regulation (EU)
2017/745 Rule 11, and the equivalents in Australia and the United Arab Emirates, are set out with the named
provision in each in DIS-GL-028. This statement does not restate them. It records that the clinical
boundary in Section 1 is what keeps every one of those positions true.
Under the EU Artificial Intelligence Act, Regulation (EU) 2024/1689, an artificial-intelligence system
becomes high-risk only in one of two ways: it is, or is a safety component of, a product that must undergo
third-party conformity assessment as a medical device (Article 6(1) with Annex I), or it performs a use
listed in Annex III, which in healthcare means chiefly determining eligibility for healthcare services or
emergency patient triage. Pensieve does neither. Being used in a hospital does not, by itself,
make a system high-risk, and Pensieve Labs does not describe its Platform as high-risk artificial
intelligence.
The Act's transparency duties in Article 50 apply from 02 August 2026, and the labelling in P3 already meets
their intent for the administrative outputs Pensieve produces. The high-risk obligations were
deferred by the Digital Omnibus on artificial intelligence, in force 27 July 2026: standalone Annex III
high-risk systems now apply from 02 December 2027, and product-embedded high-risk systems from 02 August
2028. Pensieve Labs notes the deferral so that no reader mistakes the general application date of the
Act for the date its high-risk rules take effect.
Pensieve Labs takes as reference pointsPensieve Labs is informed by the following instruments. It is aligned to them as reference points; it
does not claim to be compliant with, or certified or conformity-assessed against, any of them.
Edsol Edtech Pvt. Ltd. holds no artificial-intelligence certification of any kind (POL-GL-132
Section 6.3).
| Framework | Status | The principle in this statement it informs |
|---|---|---|
| OECD AI Principles (2019, updated 03 May 2024) | Soft-law recommendation, not certifiable | Transparency and explainability (P3, Section 7); accountability (P1) |
| NIST AI Risk Management Framework 1.0 (January 2023) | Voluntary framework; four functions: Govern, Map, Measure and Manage | The pre-ship gates (P7) and model risk in POL-GL-132 |
| ISO/IEC 42001:2023 | AI management-system standard; certifiable via an accredited body. Pensieve Labs is not certified and has not committed to certify |
The management-system structure behind POL-GL-132 |
| WHO Ethics and Governance of AI for Health (2021) | Guidance, not certifiable | The clinical-boundary and human-oversight emphasis (Sections 1 and 2); inclusiveness and equity (Section 6) |
Citing a framework is not conformity. Pensieve Labs writes "informed by" and "aligned to", and reserves
"certified" and "compliant" for a certificate that exists (WPR-GL-005 Section 6).
The honest division between what a control enforces now and what remains a commitment.
| Principle or claim | Enforced by a control today | The control, or the commitment |
|---|---|---|
| A person decides (P1) | Yes | No auto-approve or bulk-accept control exists; accountable role recorded per capability |
| No clinical decision (P2) | Yes | Design gate against DIS-GL-028 before build; clinical-purpose vocabulary banned |
| Machine-generated label (P3) | Yes | Label at the point of use; no configuration removes it |
| Provenance and audit (P4) | Yes | Per-invocation logging under DIS-GL-013 |
| No cross-customer training (P5) | Yes | Contractual in DPA-GL-001; DIS-GL-027 Section 4 |
| Opt-in and reversible (P6) | Yes | Per-hospital, per-capability enablement (DIS-GL-027 Section 7) |
| Published before shipped (P7) | Yes | Inventory updated before enablement (DIS-GL-027 Section 2) |
| Data protection impact assessment where processing is new | Yes | REP-GL-020 on the pre-ship gate |
| Accuracy figures published | No | Commitment: published per capability once measured; no date committed |
| Bias-testing results published | No | Commitment: with the accuracy figures (DIS-GL-027 Section 9.5) |
| Independent assessment of these capabilities | No | Commitment: included in the scope of the first independent assessment |
| AI-specific certification | No, and not sought | Pensieve Labs holds none and has not committed to seek one (POL-GL-060 clause 7) |
A change that would weaken P1, P2 or P5 is not a change to this statement; it would be a change to what
Pensieve Labs is, and it would be published, with its reasoning, before it took effect.
A person may complain about an artificial-intelligence capability directly to
info@pensievelabs.org, whether or not they are a Pensieve Labs customer. The Grievance
Redressal Policy (POL-GL-066) governs how the complaint is received, investigated and answered. Where the
person is a patient, the hospital is the Data Fiduciary and the request is made to the hospital, which
Pensieve Labs assists under DPA-GL-001.
| Question | Document |
|---|---|
| What may and may not be done with an AI capability | POL-GL-060 Responsible AI Use Policy |
How Pensieve Labs governs models internally |
POL-GL-132 AI Governance and Model Risk Policy |
| The dated inventory of capabilities that use a model | DIS-GL-027 AI/ML Feature Disclosure |
Why Pensieve is not a medical device |
DIS-GL-028 Clinical Safety Boundary Statement |
| The contractual instrument where a capability is enabled | ADD-GL-006 AI and Automated Processing Addendum |
| Contractual use restrictions and prohibited uses | ADD-GL-005 Use Case Restrictions and Prohibited Uses |
| The no-training commitment in contract | DPA-GL-001 Data Processing Agreement |
| The pre-ship data protection impact assessment | REP-GL-020 Data Protection Impact Assessment |
| Non-discrimination and equity | POL-GL-069 Human Rights Policy |
| Complaints and the Grievance Officer | POL-GL-066 Grievance Redressal Policy |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 2026-08-03 | Founder / Pensieve Labs | First issue. States the principles behind POL-GL-060 and POL-GL-132 without restating them: the clinical boundary first, human accountability, eight principles each with its enforcing mechanism, provenance and traceability, the no-cross-customer-training commitment, fairness in a multilingual setting, honest explainability limits, the India and EU regulatory horizon, the frameworks taken as reference points with no claim of certification, and a maturity table dividing controls in place from commitments. |
STM-GL-034 v1.0.0 | Last Modified On 03 August 2026 | Review due
03 February 2027 | Published at https://trust.pensievelabs.org