A trail of small squares rising from the lower left and resolving into a single document marked with a check.

Company news

Why Utah now requires a signed record each time a clinical AI safeguard runs.

Utah’s Office of Artificial Intelligence Policy will require vendors it designates in its AI Learning Laboratory to produce a cryptographically signed record for every covered inference or control evaluation.

5 min read
Joe Braidwood outside the Lloyd’s building in London, with its exterior pipework and stair towers rising behind him.
Outside Lloyd’s on the first day of Lloyd’s Lab cohort 17.

I am writing this from Lloyd’s in London, on the first day of Lloyd’s Lab cohort 17. The underwriters here and the regulators in Salt Lake City are asking the same question about AI in healthcare. They want to know whether the safeguards a vendor describes are actually running when patients use the product.

Today Utah’s Office of Artificial Intelligence Policy gave one answer to that question. Under an agreement with Glacis Technologies, announced today, vendors the Office designates in its AI Learning Laboratory must generate and deliver a cryptographically signed receipt for every covered AI inference or control evaluation. The receipt is a condition of joining the sandbox and of staying in it.

I · The requirementWhat the agreement requires

The receipts conform to OVERT, an open technical standard for verifiable evidence of AI operations, created by Glacis Technologies. OVERT stands for Observable Verification Evidence for Runtime Trust. It is available under a royalty-free patent covenant.

The Office decides which vendors, systems and events are covered. It writes the requirement into each vendor’s own agreement with the state. Glacis provides receipt issuance, verification materials and onboarding. Other evidence can sit alongside a receipt. It cannot replace one.

The agreement does not require vendors to hand over model weights, raw prompts, raw outputs or patient data. A receipt can be bound to an event with a hash or another identifier that carries no content.

This is the first time a regulator has written OVERT into a participation requirement.

II · The mechanismWhat a receipt is

Take a common safeguard. A clinical assistant is configured to hand certain requests to a clinician instead of answering them. Today, a regulator checking that safeguard usually reads a policy document and a statement from the vendor. Neither shows what happened to a specific request on a specific day.

A receipt records the control’s decision on that request and the time it was made. It is signed at the moment of the event. Anyone with the verification materials can check that the record has not been altered and that it came from the expected signing key. They do not need to take the vendor’s word for it, or ours.

The closest analogy I know is a circuit breaker with a trip log. An electrician does not sign off a building by reading the breaker’s specification sheet. They check that the breakers are installed. After a fault, they read which breaker tripped and when. Clinical AI has had the specification sheet for years. It has not had the trip log.

III · The boundaryWhat a receipt does not prove

A verified receipt proves that a control ran, that it reported a decision, and that the record was not changed afterward. It does not prove the decision was right. It does not show that the referral reached a clinician or that the patient received appropriate care. It does not certify safety, effectiveness or legal compliance. The agreement says this in plain terms, and I agree with it.

That is why Utah built the program in layers. CHAI will convene independent evaluators under a separate agreement, and the Office has recognized evaluators who test systems before admission and audit them in operation. Their work is to judge whether a system is safe and effective. A receipt gives them a signed record to examine, in place of a summary the vendor wrote about itself.

IV · The standardWhy the standard is open

We wrote OVERT at Glacis, and we could have kept it proprietary. We published it because a requirement that names one company’s private format is weaker than one that names an open standard. A regulator should be able to verify a receipt without depending on the company that issued it. Other organizations should be able to implement the standard and be held to the same test.

A framework announced in September provides for future joint stewardship of OVERT by CHAI and the AIGovOps Foundation, with Glacis as a nonvoting technical editor. The specification and governance materials are published at overt.is.

V · AheadWhat comes next

Utah’s requirement applies inside the sandbox. The systems in it are meant to go on to work in health systems. Those health systems will face the same question the regulator asked, and so will the insurers that cover them.

Sandbox participants must be underwritten or self-insured, which is part of why I am at Lloyd’s this week. An underwriter pricing clinical AI risk needs the same evidence a regulator does. A policy document describes the intended control. A receipt shows whether it ran on the event in question.

If you deploy AI in a clinical workflow, there is a test you can run today. Pick one patient interaction from last week. Ask whether you could produce a signed record showing which safeguard evaluated it and what that safeguard decided. If you cannot, your evidence for that safeguard is a policy document, and that is the gap a regulator or an underwriter will look at first.

A policy document describes the intended control. A signed record shows whether it ran.