White paper The Insurability Problem in Healthcare AI

AI’s zero trust moment

Manage AI risk with every action.

Glacis gives teams continuous visibility, customer-defined controls and verifiable evidence for AI in production. A managed runtime governance layer holds every action to those controls and signs a record of each decision, one that buyers, auditors and insurers can check without trusting a dashboard.

Managed runtime governance

Placed, agreed and run for you.

We place the layer wherever your AI acts, between the application and the models it calls, agree the controls with your team, and run it from there: policy, approvals, signing, retention and the reviewer’s view. You ship. The record keeps itself.

Integration
One call at the point of action, inside your own environment. Payloads stay where they are. The record carries hashes.
Controls
Written with you as policy and enforced on every action: approvals, guardrails, consent checks.
Records
Every decision signed and kept in an open format, readable by the people who sign off.

Why now

AI assurance is becoming a market. We build the part that can be checked.

AI is acting inside real businesses, and the people who sign off on it want more than a policy and a dashboard. This summer showed why: agents inside a frontier lab’s own evaluation forged their tool calls, and the transcript said one thing while the action did another. Glacis closes that gap at runtime, with a record nobody has to take on faith.

Where we fit

Observability, guardrails, GRC. None of them shows which controls ran.

Observability shows what the model did. Guardrails try to stop what it shouldn’t. Governance, risk and compliance answers for it on paper. Even with all three in place, the gaps between them stay open, because nothing joins them at the action. Glacis sits in the path of the action and produces the one thing none of them does alone: a signed record of which controls ran and what they decided. One control and evidence layer, whether the AI is an agent using tools, an ambient scribe in a clinic or a model inside an enterprise workflow.

Risk you can’t evidence stays yours. A record signed at the time and checkable after is what an auditor can review, a regulator can examine and an insurer can weigh.

Fig. I. The accountability overlap Three overlapping circles: observability, which shows what the model did; guardrails, which try to stop what it should not; and GRC, governance, risk and compliance, which answers for it on paper. Where only two overlap the gap reads stopped but not signed, governed but not seen, or logged but not enforced. Glacis sits where all three meet, in the path of the action, and records which controls ran.
Fig. IThe accountability overlap. Any two of the three leave a gap. Glacis sits where all three meet, in the path of the action, and records which controls ran.

How it works

Every action gated, every decision signed, every record open to inspection.

Every action passes through the layer, and every one is on the record. All of them, not a sample. That’s the denominator when an auditor or an underwriter asks how often a control ran.

The gate

Every action is held to the agreed controls before it runs: allowed, constrained, held for a person, or denied.

The signature

Each decision leaves a signed record: what was asked, which controls ran, what was decided, and when. Hashes, not the payload.

The check

Anyone holding a record can verify it against the open standard. No Glacis account, no dashboard, nothing from the application or its logs.

Ambient clinical documentation

Where AI already acts on a patient’s behalf.

nVoq builds ambient documentation for clinicians. Its head of product, on what Glacis adds to that workflow:

“Glacis enables proactive AI trust and assurance, embedding consent validation, human‑in‑the‑loop oversight, and robust guardrails directly into ambient workflows.”
Chad Hiner Chad HinerSenior Vice President of Product, nVoq nVoq
Working with
  • PACT AI
  • Digital Medicine Society
  • Coalition for Health AI
  • ScaleHealth
  • EisnerAmper
  • Cloudflare

The primitive

Underneath it all, one record.

Every decision Glacis makes is written in OVERT, an open format we published so nobody has to trust us to read it. One record is one governed action. Not a token, not a request, not a seat.

This is a real one. It verifies in this browser, and it stays verifiable whether or not you’re still a customer.

OVERT 1.1, published 11 June 2026 under a royalty‑free patent covenant.

Demonstration sample OVERT 1.1
Workflow
ambient-scribe-draft-note
Rule
PHI egress check
Control
14 rules evaluated, 0 triggered
Decision
allow, policy mode enforce
Record ID
glc_receip…f135
Recorded
2026-06-11 09:14:02 UTC
Output hash
157cf56f01…a161
Operator key
9c8eb1b83a…23d8
Witness key
7c038b40b8…39a5

    Open the full verifier

    Allow Constrain Hold Deny

    Let’s start where the questions are.

    What is it doing? What can it reach? Did the controls run? Can you prove it? For one team that’s organization-wide monitoring, to see every AI action before deciding what to gate. For another it’s one high-risk use case that needs an audit trail a regulator will accept. Any action can be instrumented, the scope is yours, and the layer is managed either way. We take on a small number of managed deployments each quarter and reply within a business day.

    Platform·For agent teams·Healthcare