top of page

Part 9: Naming the Acceptance Layer — Introducing PCAL

Writer: Corey Mercy
Corey Mercy
Aug 13
3 min read

Final Part in the Responsible AI and Social/Cultural Acceptance series



Everything in this series points to the same gap: we have well-developed language and frameworks for the "can we use AI responsibly" question, and comparatively little for the "should we, and have we earned the right to" question. That gap is worth naming rather than leaving implicit.


In healthcare specifically, I've started using a framework I call the Patient & Community AI License (PCAL); a deliberate operationalization of the broader "AI social license" concept, scoped to the people health systems, payers, public health agencies, and vendors actually answer to: patients, families, clinicians, and the communities they serve.


PCAL isn't a replacement for Responsible AI. It's the companion layer that sits alongside it. RAI is the engineering and governance discipline, PCAL is the trust and legitimacy discipline. It rests on four pillars:


  • Transparency — patients and communities can find out when AI is involved in their care and what it's influencing.

  • Participation — affected patients, clinicians, and communities get a real voice before deployment, not a notification after.

  • Contestability — a real, accountable human path exists to challenge and correct an AI-influenced decision.

  • Earned track record — trust compounds through consistently equitable, well-explained outcomes over time, not a one-time approval.


Because acceptance is a relationship rather than a checkbox, PCAL status also isn't binary. It moves through stages…not licensed provisional earned renewed…and it can move backward as easily as forward. An organization that treats "earned" as a permanent state, rather than something re-tested on an ongoing basis, is exactly the kind of organization this series has been warning about throughout: well-governed on paper, and still capable of being blindsided by a legitimacy failure it never saw coming.


The point of naming it isn't to add another acronym to an already crowded field. It's to make the acceptance question as concrete, discussable, and actionable as the responsibility question has become. So that "did we earn this?" gets asked with the same rigor as "did we build this safely?"


Closing: How to Actually Think About This as AI Accelerates


A few synthesizing points to carry forward:


  1. Stop treating "Responsible AI" and "trusted AI" as synonyms. Build the RAI discipline as your operational floor. Treat acceptance and legitimacy as a separate, ongoing relationship-building effort that starts before deployment and never really finishes.

  2. Match governance intensity to actual risk and actual sector, not a generic template. Universal principles, risk-based classification, sector-specific controls. This is exactly where NIST, the EU AI Act, and serious sector regulators are converging.

  3. Invest disproportionately in appeal and redress. Across individuals, companies, and government alike, the single highest-leverage trust investment is a real, accessible, human path to challenge and correct an AI-driven outcome.

  4. Govern capability and autonomy, not just applications, and define autonomy boundaries before you need them, not after something goes wrong.

  5. Build a culture and an ecosystem comfortable saying "we shouldn't build this," or "not yet," or "not this way." Zero risk doesn't exist; the discipline is in deciding, transparently, which risks are acceptable and which aren't, and being willing to redesign or stop when that answer changes.

  6. Expect the frameworks to keep moving faster than your policies. Build internal governance to be adaptable by design…a living, continuously reassessed process, not a document you finalize once.

  7. Remember legitimacy is earned slowly and lost quickly. The organizations and agencies that navigate the next several years of rapid AI advancement well are the ones treating trust-building as a long-term investment now, not a communications task bolted on after the system is already built.


The technology will keep moving fast. The deeper question isn't whether AI will change society… it will. The question is whether we shape that change intentionally, or simply react to it. Responsible AI gives us a foundation. Risk management gives us discipline. Regulation gives us boundaries. But social and cultural acceptance gives us legitimacy. And legitimacy may ultimately determine whether the AI revolution succeeds on the terms we'd actually want it to. Frameworks like PCAL are one attempt to make that legitimacy question as tractable as the responsibility question… not the only one, and likely not the last one, but a starting point for asking it on purpose.


 
 
 

Comments


bottom of page