TwinEthosRequest access

Standard or framework

WHO AI-for-Health (LMM) Guidance

World Health Organization · Everywhere (*) · 2 provisions encoded · verified against the official source as of 2026-09-04.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Official text: www.who.int.

Standard / soft law

Health AI/LMMs should keep a clinician accountable with oversight and redress (WHO)

WHO LMM Guidance (2024) — Human oversight & accountability recommendation · official text · Soft law or guidance (not binding law)

Per the WHO Guidance on AI for Health (LMMs), under the consensus principles 'foster responsibility and accountability' and 'protect autonomy', AI/LMMs used in health care must be subject to human oversight — a health-care provider or clinician remains accountable for clinical decisions and must be able to review, override, and take responsibility for AI outputs — with clear assignment of responsibility and mechanisms for redress for individuals harmed by an AI-informed decision. Detect a health-AI decision path with no clinician oversight/override or no accountability/redress mechanism.

Who it applies to

  • Duty falls on: developer, deployer
  • Systems covered: automated decision, high risk
  • Sectors: healthcare
  • Developers, providers, and deployers of AI/LMMs used for health care, medical, or public-health purposes. Voluntary WHO guidance; governments have primary responsibility to set standards. Globally influential health-AI baseline.
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Hold AI-generated clinical output as a draft until an accountable clinician reviews and signs it, and record who approved it before it reaches the chart or the patient.

A clinician sign-off step between the model call and every clinical sink: AI-drafted notes, summaries, diagnostic suggestions, triage levels, and treatment plans are stored as drafts (FHIR DocumentReference.docStatus 'preliminary', DiagnosticReport.status 'preliminary', CarePlan.status 'draft') and become final, active, or visible to the patient only through an action by an authorized clinician that records reviewed_by and reviewed_at. Configuration flags that auto-sign or auto-finalize AI-drafted records stay false, and provenance shows the AI as a contributing device and the clinician as verifier. The deployment also names who is accountable for AI-assisted decisions and gives patients a complaint or redress route.

Where it goes: 1 application source code, 2 data models, 9 AI output handling, 3 config and feature flags.

Example (Python + OpenAI SDK + FHIR REST), before:

note = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
requests.post(f'{FHIR_BASE}/DocumentReference', json=doc_ref(patient_id, note, doc_status='final'))

After:

note = client.chat.completions.create(model=MODEL, messages=msgs).choices[0].message.content
requests.post(f'{FHIR_BASE}/DocumentReference',
              json=doc_ref(patient_id, note, doc_status='preliminary'))   # AI draft

def practitioner_review_and_sign(doc_id, practitioner):   # only path to 'final'
    doc = requests.get(f'{FHIR_BASE}/DocumentReference/{doc_id}').json()
    doc['docStatus'] = 'final'
    doc['authenticator'] = {'reference': f'Practitioner/{practitioner.id}'}
    requests.put(f'{FHIR_BASE}/DocumentReference/{doc_id}', json=doc)
    audit.record(doc_id, reviewed_by=practitioner.id, reviewed_at=utcnow())

Control: Health AI without clinician oversight/accountability + redress. The same guard addresses 3 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id who-health-ai.clinician-oversight-accountability · review status: primary source derived

Standard / soft law

Health AI/LMMs should be transparent and documented before deployment (WHO)

WHO Ethics and Governance of AI for Health (LMMs, 2024) — Six Consensus Principles · official text · Soft law or guidance (not binding law)

Per the WHO Guidance principle 'ensure transparency, explainability and intelligibility', sufficient information must be published or documented before the design or deployment of a health-AI technology, and outputs should be explainable/intelligible to users (clinicians and patients). Developers should transparently design LMMs, document training-data provenance, and disclose limitations. Detect a health-AI deployment with no pre-deployment documentation (intended use, data, limitations) or explainability provision.

Who it applies to

  • Duty falls on: developer, deployer
  • Systems covered: high risk
  • Sectors: healthcare
  • Developers and deployers of AI/LMMs for health care. Voluntary WHO guidance; globally influential.

The guard to add

Organizational artifact to keep (not verifiable from code); the guard is the record, its owner and its upkeep.

Send each adverse AI-assisted decision with its main reasons and the AI's role, plus a way to correct data and appeal to a human who can change the outcome.

Where model output becomes an adverse status (denied, declined, rejected, ineligible), the decision service stores reason codes or principal reasons, the model id and version, and an input snapshot or hash with the decision. The notice to the person (letter, email, portal response) says AI was involved and what role it played, lists the main factors, and links to data correction and to an appeal that creates a human-review task with authority to change the outcome. An explanation endpoint returns the stored record on request, so the deployer can explain a decision long after the model has changed.

Where it goes: 2 data models, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • Before design or deployment, publish or document the health-AI system's intended use, training-data provenance and limitations, and make outputs intelligible to clinicians and patients.

Example (Python + OpenAI SDK + Pydantic), before:

resp = client.chat.completions.create(model=MODEL, messages=msgs)
if 'deny' in resp.choices[0].message.content.lower():
    application.status = 'denied'
    send_email(applicant.email, 'Your application was declined.')

After:

a = Assessment.model_validate_json(resp.choices[0].message.content)   # decision, reason_codes
if a.decision == 'deny':
    decisions.insert(app_id=application.id, status='denied', reason_codes=a.reason_codes,
                     model=resp.model, input_hash=hashlib.sha256(payload).hexdigest())
    send_email(applicant.email, render('adverse_action_notice.txt',
        reasons=a.reason_codes,
        role_of_ai='An AI model assessed your application; a reviewer can change the outcome.',
        correct_data_url='/profile/data', appeal_url=f'/appeals/new?decision={application.id}'))

Control: Adverse AI decision without explanation/appeal. The same guard addresses 6 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

  • UnitedHealth nH Predict claim-denial litigation (2023-11; alleged (not proven)). A class action filed in November 2023 alleges that UnitedHealth's nH Predict model had a 90% error rate, measured by denials reversed on appeal, while only about 0.2% of members appealed. UnitedHealth disputes the allegations; the litigation is ongoing. Source: STAT News · evidence grade: primary · cited by Explain adverse AI-assisted decisions and offer a way to contest them — everywhere

Rule id who-health-ai.transparency-documentation · review status: primary source derived