top of page


The Patient & Community AI License (PCAL)
A framework for earning — not just claiming — the right to deploy AI in care. The Core Idea Responsible AI (RAI) answers one question: can we use this AI responsibly? It's the discipline of governance, testing, documentation, and oversight — and it's necessary. But it isn't the question patients, clinicians, and communities are actually asking when a new AI system shows up in their care. Their question is different: should this AI be used on me, and do I believe the people de
Corey Mercy
Aug 314 min read


Why North Carolina Doesn't Need OneTrust — And What It Needs Instead
A sequenced approach to privacy maturity in state government Every few months, another "Best Data Privacy Platforms" listicle circulates with the same cast: OneTrust, BigID, TrustArc, Securiti. They're built for a specific problem — a company with a website, a data broker relationship, and a CCPA or GDPR obligation that generates a steady stream of consumer deletion requests. State government doesn't have that problem. Not because privacy doesn't matter in the public sector —
Corey Mercy
Aug 256 min read


The Servant Leadership Impersonators: How to Spot the Difference Between Language and Practice
Servant leadership has become one of the most cited — and most misapplied — leadership philosophies in modern organizations. It is in the keynote slides, the annual strategy decks, and nearly every executive interview. Nearly every leader, at some point, claims to practice it. Far fewer actually do. The issue rarely starts with malice. It starts with misaligned incentives. Saying you are a servant leader costs nothing. It sounds humble in an all-hands meeting, checks a cultu
Corey Mercy
Aug 233 min read


Part 9: Naming the Acceptance Layer — Introducing PCAL
Final Part in the Responsible AI and Social/Cultural Acceptance series Everything in this series points to the same gap: we have well-developed language and frameworks for the "can we use AI responsibly" question, and comparatively little for the "should we, and have we earned the right to" question. That gap is worth naming rather than leaving implicit. In healthcare specifically, I've started using a framework I call the Patient & Community AI License (PCAL); a deliberate o
Corey Mercy
Aug 133 min read


Part 8: The Autonomy Question
Responsible AI and Social/Cultural Acceptance As AI moves from generating content to reasoning, planning, using tools, and acting with less human intervention, a new question moves to the center: how much authority should we give AI? It helps to think of this as a progression, where each step increases both usefulness and risk: AI tells me what to do → AI recommends what I should do → AI prepares the action for me → AI takes the action with my approval → AI takes the action a
Corey Mercy
Aug 131 min read


Part 7: Does the NIST AI RMF Adequately Address All of This?
Responsible AI and Social/Cultural Acceptance Short answer: it's a strong, well-designed foundation for the Responsible AI side, and it was never intended to single-handedly answer the acceptance question; that was outside its scope by design, not by oversight. What it does well: The four functions — Govern, Map, Measure, Manage — give a flexible, outcome-oriented structure that scales from a startup to a multinational, and NIST explicitly frames trustworthiness characteristi
Corey Mercy
Aug 122 min read


Part 6: One Framework, Many Implementations
Responsible AI and Social/Cultural Acceptance: A Series A single monolithic AI framework applied uniformly fails in both directions . It overburdens low-risk applications (a meeting summarizer doesn't need the same governance as a sepsis prediction model) and under protects high-risk ones, because generic controls rarely capture the specific failure modes of a given domain. A more defensible model has three layers: Universal principles that apply regardless of industry: human
Corey Mercy
Aug 122 min read


Part 5: What Government Agencies Should Be Considering
Responsible AI and Social/Cultural Acceptance: A Series Government carries a heavier acceptance burden than private companies, for a structural reason: government doesn't just provide services, it exercises authority, and when it makes a consequential decision, the individual often has nowhere else to go. That changes the ethical equation and adds a dimension private companies don't carry to the same degree: legitimacy. A government system can be internally compliant with eve
Corey Mercy
Aug 112 min read


Part 4: What Companies Owe the People They Affect
Responsible AI and Social/Cultural Acceptance: A Series Companies need two different muscles: the RAI discipline (governance structure, bias testing, transparency, human oversight, incident response…table stakes at this point) and a genuinely separate acceptance-building practice. A few concrete, often-skipped pieces of the second muscle: Build an AI operating model, not just an AI policy. Ownership needs to be explicit: who approves high-risk use cases, who monitors deployed
Corey Mercy
Aug 92 min read


Part 3: What Individuals Should Be Weighing
Responsible AI and Social/Cultural Acceptance Individuals aren't passive recipients of AI governance — as users, employees, patients, and citizens, they carry their own responsibilities: Become AI-literate, not AI-dependent. AI literacy is becoming as basic as digital literacy. People don't need to become ML engineers, but they should internalize that AI can be confidently wrong, can reproduce biases baked into its training data, and that convenience is not the same thing as
Corey Mercy
Aug 61 min read


Stop Asking "Is This AI?" — Ask "What Happens If It's Wrong?"
Part 2 in Responsible AI and Social/Cultural Acceptance: A Series A lot of AI governance conversation gets stuck on the wrong question. "Is this AI?" tells you almost nothing useful. The better question is: what happens if this AI system fails, is misused, is biased, or behaves differently than expected? That reframe leads somewhere more useful than "is AI safe?”…because safe is not a single, fixed condition. The more precise questions are: Safe for whom? Safe for what purpos
Corey Mercy
Aug 32 min read


Responsible AI and Social/Cultural Acceptance: A Series
Why "doing AI right" and "getting people to trust AI" are related but not the same problem — and what individuals, companies, and government agencies each need to do about it. Part 1: Two Conversations Wearing One Name Ask ten people to define "Responsible AI" and you'll get ten answers that all sound reasonable and don't quite match. That's because we're usually collapsing two distinct conversations into one term. Responsible AI (RAI) asks: can we use AI responsibly? It's th
Corey Mercy
Aug 22 min read


Leading Through the AI Fog: Why Trust Trumps Technology
It was September when an advertisement for the Atari 2600 first sparked my lifelong curiosity in technology. From that early moment learning BASIC in a junior high school library to overseeing complex cloud migrations and critical public health infrastructure, I have always believed in the ways technology drives transformation across the human experience. Yet, the current wave of Artificial Intelligence feels distinctly different. Throughout my career in health IT and public
Corey Mercy
Jul 123 min read


Scaling Beyond the Sandbox: A Pragmatic Blueprint for AI in Healthcare (Part 2)
It is relatively easy to make an artificial intelligence tool look like a miracle worker inside a controlled environment. When you are operating within a dedicated clinical innovation hub, utilizing isolated, de-identified datasets, the integration challenges are minimized, the stakes are managed, and the outcomes feel predictable. But as any veteran technology executive knows, the real test begins when you pull down the partition walls and attempt to hook that algorithm into
Corey Mercy
Jul 83 min read


Moving Fast Without Breaking Things: A Pragmatic Blueprint for AI in Healthcare (Part 1)
There is a profound difference between reading about artificial intelligence and actually being responsible for deploying it within a complex health system. When you are the one sitting in the leadership seat, the questions carry an immense weight. Which tool do you choose when the market shifts every single week? How do you absolutely guarantee that patient data isn't exposed to unnecessary risk? And even if you manage to solve the technical riddles, how do you get exhausted
Corey Mercy
Jul 22 min read


The Sustainability Cliff: 3 Strategic Anchors for Rural Health Funding
Federal funding injections for rural health transformation programs are a lifeline, but they come with a clock. Far too often, when the grant cycle expires, the innovations built upon them risk fading away. As technology leaders and public health strategists, our mandate cannot simply be to deploy capital—it must be to anchor that capital into infrastructure that thrives long after the federal runway ends. True transformation happens when we shift our perspective from tempora
Corey Mercy
Jun 303 min read
bottom of page