Trust Centre
AI safety
Last updated 10 July 2026
AI in AyrisIQ is advisory only. It reads, classifies, compares and drafts. It does not decide, publish, delete or notify — people do.
The dividing line
- AI is used to: classify uploaded documents, extract metadata for your confirmation, detect gaps and contradictions across your governance library, map findings to CQC themes, and draft suggested wording.
- AI may never: publish or change a live governance record without a named human approval; release a document from patient-data quarantine; send patient-identifiable content to any external processor; or trigger actions on its own.
Human review — enforced, not promised
- AI-drafted content moves through a review lifecycle: pending review → reviewed by a named person → (optionally ratified by a second person) → published. Publishing without a named reviewer is impossible.
- The exact content that was reviewed is fingerprinted, so a draft cannot be altered after review and silently published.
- Every published change creates a new version; the previous version is archived, never overwritten.
- A deterministic content-preservation check runs after automated document transformations and blocks publishing if any source content went missing without explicit per-item approval.
- If AI is unavailable, features fall back to deterministic logic — AI is never a hard dependency for your records.
Before anything reaches an AI provider
- Content flagged by the identifier gate is blocked before the configured provider call.
- Staff evidence and complaint/incident AI are disabled by default at the app server and AI gateway. The closed pilot uses structured, de-identified entry and human review instead.
- Outgoing text is scanned for strong identifiers such as checksum-valid NHS numbers and labelled patient details. The scanner has documented limitations and is not represented as an anonymisation service.
- Repository records can show processing status, and database mutations create server-authored audit events. A complete, independently verified per-provider-send ledger is still being built, so we do not claim one today.
The provider receives the minimised content needed for the enabled task, normally extracted text and, for an explicitly enabled vision workflow, rendered page content. Signed provider terms/DPA and retention evidence are required before a real-data pilot.
Our advisory-AI statement
AyrisIQ's AI features produce suggestions, not decisions. AI output may be incomplete or wrong, and is not a substitute for the professional judgement of your practice's staff. Nothing AI-generated becomes part of your governance record until a named member of your team has reviewed and approved it. Responsibility for the content of published policies and records remains with your organisation.
Providers and models
Current configured provider: Amazon Bedrock, London (eu-west-2), direct in-region model. The gateway rejects cross-region Bedrock inference profiles. Provider or model changes must update the processing register and this page before deployment. See data protection for supporting services and open contractual evidence.
