Documentation

Last reviewed: May 2026

AI Model Governance & Change Control

This page explains how Widgi AI changes are approved, released and communicated. It covers model updates, release controls, customer notification, and the choices your organisation has for larger changes. It summarises our internal clinical-safety policy.

In short

Every AI change requires approval from our Clinical Safety Officer (CSO), and release is blocked if approval is not recorded. Critical safety updates are applied automatically. Larger capability changes are released as optional agents or major upgrades that your organisation can trial, enable or disable.

What we run today: the Corpus Agent

Widgi AI is delivered through named agents. Today we run one agent: the Corpus Agent. It is a retrieval-augmented assistant built on Amazon Nova and hosted in the UK in the AWS London region.

The Corpus Agent answers only from your organisation's approved content. Before processing, it scans every prompt for patient-identifiable information. It uses no third-party model such as OpenAI.

1. How updates are approved

We manage AI changes through two tracks. Both require CSO sign-off before release.

  • Critical/safety updates — small, iterative changes that keep the service safe and current, with little or no change to the user experience. These updates are reviewed by the CSO and applied automatically to every organisation.
  • Optional updates — larger capability changes released as a new agent or a major agent upgrade. These changes are also CSO-approved, but adoption is optional. We publish them alongside the existing agent, which remains available, so your organisation can trial them and turn them on or off.

CSO approval is technically enforced. The release process blocks an AI change unless approval from a named CSO has been recorded.

Two change tracks

  • Critical/safety → CSO-reviewed and applied automatically to every organisation.
  • Optional/larger → CSO-approved, published in parallel, and controlled by your organisation.

2. Our release and change-control process

  1. An AI change is raised for review.
  2. An automated release gate checks whether a named CSO has approved the change.
  3. If CSO approval has not been recorded, the release is blocked.
  4. The CSO reviews the clinical-safety impact and records approval.
  5. On release, we record the change in an internal change log and in a public, plain-language change log. The public entry explains what changed, the considerations applied, and the approving CSO.
  6. Critical/safety updates are applied automatically. Optional updates are published for organisations to adopt at their discretion.
  7. Retired versions are deprecated on a notified 90-day schedule, with a managed roll-forward. We do not use silent cutoffs.

Every AI response is stamped with the exact model and pipeline versions that produced it. This gives full traceability for audit and investigation.

3. How we notify you about material AI changes

  • Public change log — every change, large or small, is published for organisations and users. Each entry states what changed, the considerations applied, and the CSO approval.
  • Direct notification — material changes trigger a customer notification under the material-change and sub-processor clause in our Data Processing Agreement. Optional agents are not enabled for your organisation unless you choose to turn them on.

Your control

Your organisation's clinical-safety lead can trial an optional agent, enable it, or disable it at any time. The base Corpus Agent remains available and receives automatic, CSO-approved safety updates.