top of page

The Patient & Community AI License (PCAL)

Writer: Corey Mercy
Corey Mercy
Aug 31
4 min read

A framework for earning — not just claiming — the right to deploy AI in care.


The Core Idea


Responsible AI (RAI) answers one question: can we use this AI responsibly? It's the discipline of governance, testing, documentation, and oversight — and it's necessary. But it isn't the question patients, clinicians, and communities are actually asking when a new AI system shows up in their care.


Their question is different: should this AI be used on me, and do I believe the people deploying it have earned the right to make that call?


The Patient & Community AI License (PCAL) is a framework for answering that second question deliberately, instead of assuming it gets answered automatically by passing an RAI checklist. It treats social and cultural acceptance as something a health system, payer, or vendor has to actively earn from the people it affects — patients, families, clinicians, and their communities — not something granted by default because a system is technically compliant.


PCAL isn't a replacement for Responsible AI. It's the layer that sits alongside it. RAI is the engineering and governance discipline. PCAL is the trust and legitimacy discipline. Health AI needs both, and an organization that only builds one will eventually be surprised by the failure of the other.


A system can pass every RAI checkpoint and still fail PCAL. Picture a triage algorithm that's been rigorously validated, bias-tested, and documented — and still has no real path for a patient to challenge its output. It's responsible by every technical measure. It hasn't earned the right to be trusted.


The Four Pillars


1. Transparency. Patients, families, and communities can find out when AI is being used in their care and what it's influencing — without having to dig for it. Is AI involved in this recommendation, this scheduling decision, this risk score, this denial? Transparency is a floor, not a finish line: knowing AI is involved is the precondition for everything else in this framework, not the end of the obligation.


2. Participation. Affected patients, clinicians, and communities get a real voice before a system is deployed, not a notification after it's live — advisory input from the people who will actually experience the system, not just the executives approving the budget. Done well, participation changes what gets built or how it's rolled out. Done poorly, it's a listening session that changes nothing — and quietly teaches the community its input doesn't matter.


3. Contestability. If an AI system meaningfully influences a decision about someone's care, coverage, or access, there has to be a real, accountable human path to challenge that outcome — not "the algorithm flagged you" as a final answer, but an actual person with the authority, information, and time to review and, if warranted, override it.


This is the highest-leverage pillar. Contestability is where people find out whether an organization's promises about human oversight are real — which is why it earns disproportionate trust relative to the effort it takes to build.


4. Earned track record. Trust compounds. An organization that has consistently produced equitable, well-explained, contestable outcomes over time earns benefit of the doubt that a first-time deployer hasn't — and that history has to predate the AI system itself. An organization with a poor track record on data stewardship or equity doesn't get to reset it by publishing a new AI policy. PCAL status isn't permanent, either: a system that was earning trust can lose it if outcomes degrade, if a failure goes unaddressed, or if the organization stops listening.


A Maturity Model


RAI compliance is binary — you pass the audit or you don't. Social and cultural acceptance isn't; it's a relationship that matures or erodes over time.


Stage

Status

What's true

1 — Not licensed

Compliance, not acceptance

Minimal transparency, no meaningful participation, no real contestability path, no track record. May be legal — hasn't been earned.

2 — Provisional

Cautious, conditional trust

Basic mechanics exist: people can learn AI is involved, some structured stakeholder input happened pre-launch, a contestability path exists on paper. Trust is often bounded — a pilot population, a defined use case, a trial period.

3 — Earned

Trust grounded in behavior

A demonstrated history: outcomes monitored and shown equitable, the contestability path actually used and actually changed decisions, participation visibly shaping how the system evolved.

4 — Renewed

Ongoing discipline, not a finish line

Models change, data drifts, populations shift. Stage 4 means re-earning the license on a regular cadence — reassessing outcomes, re-engaging stakeholders, and being willing to admit when something has slipped back toward Stage 2.


The through-line across all four stages: PCAL status is observed, not declared. An organization can't self-certify its way to Stage 3 — the community and the track record decide that. That's exactly what distinguishes it from a compliance framework you can complete internally and file away.


How PCAL relates to RAI, in one line


RAI reduces the risk of harm. PCAL builds the legitimacy to actually deploy despite the risk that remains. You need the first to responsibly attempt the second — but the first alone will never get you there.



 
 
 

Comments


bottom of page