Clinical AI safety for the agentic era β deterministic boundaries for probabilistic systems, before and after they act.
Physician-researcher: MD/PhD, 6+ years in pharmacovigilance & drug safety, now applying that discipline to autonomous AI agents. I call this frame AI Vigilance β pharmacovigilance logic for runtime agent behavior. As AI moved from chat models to autonomous agents, the safety question moved from "what did the model say?" to "what is this agent allowed to do, and on what evidence?" Drug safety solved a structurally similar problem decades ago: never trust a claim of safety β demand observed evidence, per case, with an audit trail.
- EBAC-T4 β Deterministic Trace-Bound Authorization for High-Risk EHR Writes β authorization gate for high-risk EHR writes: execution authority per evidence cycle, ALLOW / DOWNGRADE / HALT with reason codes, HITL approval bound to exact payloads.
- Clinical Verifiable Gates β medical verifier kernel: extractor contracts, UNKNOWN-by-default fields, deterministic PASS / BLOCK / ABSTAIN, Silence gate against fabricated slot-filling.
- CASEF β Clinical AI Safety Evaluation Framework β reproducible, artifact-based qualification of LLM behavior under explicit constraints. Generation is cheap. Qualification is not.
- Space Model Lab v3 β case study of governed multi-agent development: a browser-based physics sandbox built by a provider-diverse AI team (architect, PM/auditor, gated single-writer executor) under human PI approval, with a full decision log and commit-hash receipts.
- LLM / World-Model / Hybrid Decision Frame β architecture decision protocol for choosing system design under risk, latency, and verification constraints.
- Modular Reasoning Framework (MRF) β earlier research: external reasoning orchestration for fast language models; a predecessor of the governed-orchestration ideas above.
- Pre-action authorization & deterministic safety gates β execution authority granted per evidence cycle, not by role or prompt; deterministic ALLOW / DOWNGRADE / HALT and PASS / BLOCK / ABSTAIN gates for state-changing steps; evidence model: traces + constraints + audit artifacts (natural-language claims alone aren't evidence).
- Qualification under pressure & behavior stability β reproducible crash-tests for role drift; auditable FAIL artifacts; omission-aware evaluation: in clinical settings, missed critical actions β not only wrong ones β are the dominant harm mode.
- Governed humanβagent development (PI-led) β provider-diverse specialist roles under one human PI; decision logs, per-action write gates, receipts with observed validation results; CLAIMED vs OBSERVED discipline: an audit without a commit hash is a claim, not an observation. Demonstrated end-to-end in Space Model Lab v3.
- Architecture selection under hard constraints β decision protocols for LLM-only vs world-model vs hybrid approaches; hard tradeoffs: latency budgets, verification independence, cost-of-error.
- Method sanity checks: framing, assumptions, failure modes; independent cross-checking
- Engineering discipline: prototypes β documented, testable artifacts; stable interfaces; minimal reproducible examples
- Adversarial QA: stress tests for unsafe behavior, hallucinated actions, and format brittleness; definition-of-done gates
Open to open-source collaboration, research discussion, peer review, and unpaid writing/speaking where appropriate.
π« smorev.research@gmail.com
All of the above is personal, independent, non-commercial open-source research, done in my own time with my own resources. My current employment is in transportation & logistics (New Brunswick, Canada) and is unrelated to this research. I do not offer commercial or paid services through these projects.


