A proposed framework for underwriting healthcare AI risk.
Jennifer Shannon and Sarah Gebauer connect medical-device standards, healthcare validation, and operational evidence in a research framework for insurer review.

Our CMO Jennifer Shannon, MD and Sarah Gebauer, MD published “The Insurability Problem in Healthcare AI”, a proposed standards-based framework for underwriting risk assessment. The paper is research: it does not represent insurer adoption, available coverage, or an underwriting commitment.
The conversation that started this
Healthcare AI can create a difficult underwriting problem. The technology may be useful while its failure modes, deployment context, and responsibility boundaries remain hard to translate into conventional insurance evidence.
Depending on the facts and jurisdiction, one clinical AI failure may implicate product, professional, and enterprise liability. The paper asks what evidence could help an underwriter examine those overlapping exposures without pretending they are one legal question.
Claims history for many clinical AI uses is still limited, and product behavior can change after deployment. That can lead to narrower terms, exclusions, additional diligence, or a decision not to quote. Those outcomes vary by insurer, product, insured, and jurisdiction.
Jennifer and Sarah asked a different question: what if we don’t need to wait for the claims data?
What the paper proposes
The core proposal is to reuse artifacts generated while implementing standards such as ISO 14971 for risk management, IEC 62304 for software lifecycle, and ISO 13485 for quality management. Those artifacts can describe process, risk, and lifecycle controls; they do not by themselves establish product quality, regulatory clearance, insurability, or coverage. The Standards-Proof framework proposes organizing them as one input to underwriting diligence.
Three layers, each mapping to a distinct liability domain:
- Layer 1: Foundation. Product liability. How deeply has the vendor implemented risk management standards? Not binary pass/fail, but scored implementation depth across ISO 14971, IEC 62304, and ISO 13485.
- Layer 2: Healthcare-specific validation. Professional liability. Validation stratified by risk tier: clinical decision support gets prospective studies with subgroup analysis; prior authorization and documentation tools get harm-pathway-matched validation.
- Layer 3: Continuous operational assurance. Runtime evidence relevant across liability domains: pre-deployment adversarial stress testing plus post-deployment tamper-evident records of what configured safety controls reported. Routing, testing, and coverage evidence remain necessary to establish whether those controls mediated the relevant action and worked effectively.
That third layer is where Glacis lives. And it’s where the paper gets most interesting.
Four illustrative composite cases
The paper states that its four case studies are illustrative composites constructed from the authors’ professional experience. They are not descriptions of named companies, products, customers, or underwriting engagements. Their numbers are scenario inputs used to demonstrate the framework, not market statistics.
A patient-facing triage chatbot scenario starts with a reported aggregate routing rate, then uses subgroup and adversarial testing to expose risks hidden by that measure. The example shows the question an underwriter should ask; it does not report a Glacis customer result.
A prior-authorization scenario shows why an “administrative” label does not settle clinical or fairness risk when the output may affect access to care. The composite uses subgroup analysis to demonstrate how a disparity could be missed.
A clinical-documentation scenario translates an aggregate accuracy claim into error types and operational volume. It illustrates why an underwriter may care more about clinically consequential error categories than one top-line percentage.
The point is bounded: aggregate metrics can obscure where risk concentrates. The framework proposes questions and evidence that could make that concentration easier to examine; it does not establish that a particular system is insurable.
Why this matters for what we’re building
When I read the paper in draft, the thing that struck me was how precisely the three-layer framework maps to what we’ve built at GLACIS. Not because we designed it that way (we didn’t have the paper when we started) but because the same structural analysis leads to the same conclusions.
Glacis connects an intended rule to an operational control that can allow, block, or escalate a consequential action, then leaves a signed record of what the control decided. OVERT defines the portable evidence format and verification boundary. That can supply evidence for diligence; it does not determine coverage, compliance, clinical safety, or claim outcome.
What Jennifer and Sarah have done is connect the technical infrastructure we’ve built to the insurance and legal frameworks that will ultimately determine whether healthcare AI scales or stalls. The Standards-Proof framework isn’t just an academic exercise. It’s a bridge between the people building AI governance tools and the people who need to price the risk those tools are designed to manage.
The path forward
The regulatory timeline has changed since the paper was published, but the evidence question remains: what does the deployed system’s record report, which control was declared in scope, and which properties can an outside reviewer check? The framework offers one research proposal for organizing that inquiry alongside trusted execution and coverage evidence and existing standards.
The paper also explores a possible parametric structure in which a defined, measurable threshold could trigger a predetermined response. This is a design hypothesis, not a Glacis insurance product or evidence that an insurer has agreed to offer such coverage.
If you’re building healthcare AI, underwriting AI risk, running a health system that’s deploying AI tools, or advising on clinical AI liability, read this paper. It’s 36 pages, four case studies, and a concrete framework. The executive summary is available without sign-up if you want to start there.
I’m proud to work with Jennifer and Sarah. This is the kind of work that makes hard problems tractable.
Read the paper
Discuss the evidence an insurer would need.
Start where AI already acts: map the intended controls, the operational evidence available, and the questions an underwriter would still need to resolve. Coverage remains the insurer’s decision.
Start where AI already acts