Last reviewed: May 2026
AI Model Governance & Change Control
This page explains how Widgi AI changes are approved, released and communicated. It covers model updates, release controls, customer notification, and the choices your organisation has for larger changes. It summarises our internal clinical-safety policy.
In short
What we run today: the Corpus Agent
Widgi AI is delivered through named agents. Today we run one agent: the Corpus Agent. It is a retrieval-augmented assistant built on Amazon Nova and hosted in the UK in the AWS London region.
The Corpus Agent answers only from your organisation's approved content. Before processing, it scans every prompt for patient-identifiable information. It uses no third-party model such as OpenAI.
1. How updates are approved
We manage AI changes through two tracks. Both require CSO sign-off before release.
- Critical/safety updates — small, iterative changes that keep the service safe and current, with little or no change to the user experience. These updates are reviewed by the CSO and applied automatically to every organisation.
- Optional updates — larger capability changes released as a new agent or a major agent upgrade. These changes are also CSO-approved, but adoption is optional. We publish them alongside the existing agent, which remains available, so your organisation can trial them and turn them on or off.
CSO approval is technically enforced. The release process blocks an AI change unless approval from a named CSO has been recorded.
Two change tracks
- Critical/safety → CSO-reviewed and applied automatically to every organisation.
- Optional/larger → CSO-approved, published in parallel, and controlled by your organisation.
2. Our release and change-control process
- An AI change is raised for review.
- An automated release gate checks whether a named CSO has approved the change.
- If CSO approval has not been recorded, the release is blocked.
- The CSO reviews the clinical-safety impact and records approval.
- On release, we record the change in an internal change log and in a public, plain-language change log. The public entry explains what changed, the considerations applied, and the approving CSO.
- Critical/safety updates are applied automatically. Optional updates are published for organisations to adopt at their discretion.
- Retired versions are deprecated on a notified 90-day schedule, with a managed roll-forward. We do not use silent cutoffs.
Every AI response is stamped with the exact model and pipeline versions that produced it. This gives full traceability for audit and investigation.
3. How we notify you about material AI changes
- Public change log — every change, large or small, is published for organisations and users. Each entry states what changed, the considerations applied, and the CSO approval.
- Direct notification — material changes trigger a customer notification under the material-change and sub-processor clause in our Data Processing Agreement. Optional agents are not enabled for your organisation unless you choose to turn them on.
Your control