ai-native-medicalv0.2.0
← AI-Native Medical
Transmit
Normative terminology · 20 terms

Glossary

Canonical definitions of the terms used in the AI-Native Medical specification: sovereign compute edge node, zero egress, the Tripartite Ownership Model, ambient intelligence, and the acoustic and identity requirements they depend on.

Category

Core concepts

AI-Native Medical

Also written: AI native medical · AI-Native Healthcare · The Exam Room as the Machine

The AI-Native Medical Office Building is a healthcare real estate asset engineered so that the building itself performs clinical inference: a sovereign, on-premises compute edge node in which GPU hardware, acoustic isolation, ambient sensing, and physical identity enforcement are delivered as building infrastructure rather than as a cloud subscription. Protected Health Information is ingested and processed locally within a bounded glass-to-photon latency budget, and no inference payload crosses the property's network boundary. Zero egress operates as a physical and technical control within a defense-in-depth HIPAA Security Architecture pursuant to 45 CFR § 164.312 — narrowing the Business Associate Agreement surface to direct local infrastructure operators and making the control inspectable in the real estate itself, rather than establishing regulatory compliance by locality alone.

This is a vendor-neutral specification describing a class of physical infrastructure, not a software product and not a particular building. Its unit of delivery is a leasable enclave, which makes commercial real estate — rather than the hyperscaler — the vehicle through which regulated enterprises obtain frontier AI capability.

Ambient Clinical AI

Also written: agentic clinic · ambient clinical intelligence · AI clinical agents · ambient documentation

Ambient clinical AI is a software condition in which AI agents operate as persistent participants in care — listening to encounters, drafting documentation, reconciling data across the record, and invoking downstream systems autonomously. The AI-Native Medical specification treats ambient clinical AI as a workload description rather than an architecture: it names what the software does, not where the computation physically occurs or who holds custody of the protected health information.

The distinction is load-bearing. Persistent, autonomous clinical agents generate continuous inference against a covered entity's most sensitive material, which is precisely the access pattern that metered-egress cloud infrastructure prices punitively and that HIPAA-covered institutions cannot lawfully authorize off-premises. Ambient clinical AI is therefore the demand; the AI-Native Medical is the substrate that demand requires.

Ambient Intelligence

Also written: ambient AI · ambient computing · ambient telemetry

Ambient intelligence, in the AI-Native Medical, is machine capability that engages the work without being invoked. Rather than waiting on a prompt typed into a chat interface, the environment continuously perceives the meeting, the document, and the decision as they occur. The specification treats the keyboard as a legacy ingestion bottleneck and the room as a continuous sensory organ that supersedes it.

Intelligence Compounding

Also written: compounding intelligence · institutional memory · the flywheel

Intelligence compounding is the accrual effect the AI-Native Medical is designed to capture: because ambient context is structured and retained inside the tenant's own boundary, each engagement improves the retrieval assets available to the next. The resulting institutional memory is an owned asset rather than a vendor-held one, and it cannot be replicated by a competitor or withdrawn at renewal.

Structural Ceiling

Also written: the structural ceiling · regulated AI ceiling

The structural ceiling is the problem the AI-Native Medical exists to solve: the institutions with the most to gain from frontier AI — banks, law firms, healthcare systems — are the ones least able to adopt it as delivered, because their regulatory obligations forbid the data movement that cloud inference requires. The limit is architectural, not a matter of budget, appetite, or technical sophistication.

Category

Architecture

Sovereign Compute Edge Node

Also written: sovereign compute · sovereign edge node · on-premises inference node

A sovereign compute edge node is the deployable unit of the AI-Native Medical: localized accelerator hardware, storage, and orchestration sited inside a tenant-controlled physical boundary, where the tenant owns the silicon, the inference data, and the model outputs outright. Because inference executes adjacent to the people generating the work, latency is a function of distance measured in meters rather than network topology.

Demarcation Boundary

Also written: tenant boundary · sovereignty boundary · declared boundary

The demarcation boundary is the explicitly declared physical and logical perimeter of an AI-Native Medical deployment, inside which the tenant holds sole custody of data and compute. It is the surface against which the specification's zero-egress requirement is evaluated: a conforming deployment must be able to enumerate every path that crosses the boundary and demonstrate that no inference payload traverses any of them.

Stateless Ingestion

Also written: stateless ingestion layer · ephemeral ingestion

Stateless ingestion is the AI-Native Medical's requirement that the layer converting ambient reality into structured data retain no raw capture. Acoustic and spatial input is transcribed and reduced to lightweight structured records in flight; the raw uncompressed capture is never written to durable storage. The AI-Native Medical adopts this constraint because a durable store of raw ambient recording is both a liability surface and an unnecessary one.

Statelessness is a property of the ingestion layer, not of the system as a whole. The structured artifacts ingestion produces — clinical notes, triage scores, finalized reports, and the audit records evidencing them — are deliberately retained, and become persistent Protected Health Information subject to the full Security Rule safeguard set, the practice's retention schedule, and breach-notification obligations once written or filed to the record.

Localized Orchestration Layer

Also written: orchestration layer · hypervisor for physical space · spatial hypervisor

The localized orchestration layer is the AI-Native Medical's central logic unit: it functions as a hypervisor for physical space, abstracting the room's sensory hardware into resources that software workloads can schedule against. Once ambient input has been routed, transcribed, and structured, the orchestration layer is what evaluates it against policy and triggers autonomous action inside the demarcation boundary.

Model Context Protocol (MCP)

Also written: MCP · MCP server · Model Context Protocol server

The Model Context Protocol is the open standard by which models invoke tools and reach external context, and it is the interface through which agents act inside an AI-Native Medical. The specification's contribution is physical: it requires MCP tool invocation to be gated by zero-trust physical identity, so an agent's authority is bounded by who is verifiably present in the enclave.

This is the point at which the AI-Native Medical and the agentic office meet concretely. MCP describes what an agent may call; the AI-Native Medical constrains where that call may execute and whose presence authorizes it. Because a model ingesting ambient clinical dialogue is ingesting untrusted input, the specification requires a Policy & Authorization Engine — Open Policy Agent or equivalent, over mTLS with fine-grained role-based access control — to sit between the agent and the MCP server and adjudicate every tool call under default-deny policy, which is what bounds prompt injection and privilege escalation to a decision the enclave makes rather than one the model makes.

GraphRAG

Also written: graph retrieval augmented generation · graph RAG · knowledge graph retrieval

GraphRAG is retrieval-augmented generation over an explicit knowledge graph rather than over flat vector similarity alone, and it is the retrieval strategy the AI-Native Medical uses to exploit ambient context. Because the AI-Native Medical observes who met with whom, about what, and in what sequence, it can build typed relationships between people, documents, and decisions that similarity search alone cannot recover.

Category

Data & economics

Zero Egress

Also written: zero-egress architecture · no data egress · egress-free inference

Zero egress is the defining data-movement property of the AI-Native Medical: no inference payload, no ambient telemetry, and no derived artifact crosses the tenant's demarcation boundary during normal operation. Because sensitive material never transits a third-party network, the AI-Native Medical removes the vendor-trust dependency that procedural cloud compliance is built to manage, and eliminates per-gigabyte egress billing entirely.

Zero egress is stated as an architectural constraint, not a configuration setting or a contractual promise. In the AI-Native Medical there is no supported path by which inference data leaves the premises. It functions as a physical and technical control within a defense-in-depth HIPAA Security Architecture under 45 CFR § 164.312 — narrowing the Business Associate Agreement surface to direct local operators — and does not by itself discharge the administrative, physical, and technical safeguards the Security Rule requires.

Egress Asymmetry

Also written: asymmetric egress pricing · data gravity · egress economics

Egress asymmetry is the hyperscaler pricing structure the AI-Native Medical is designed to escape: inbound data transfer is free or subsidized while outbound transfer is metered and billed. The asymmetry is not incidental. It makes accumulated corporate data progressively more expensive to relocate the more of it exists, converting a storage relationship into a structural dependency the specification refers to as data gravity.

Category

Physical environment

Acoustic Enclave

Also written: the enclave · acoustic isolation · sovereign enclave

The acoustic enclave is the engineered room in which an AI-Native Medical deployment operates. Because continuous ambient capture is only defensible if the captured field is contained, the specification treats acoustic isolation as a security control rather than a comfort amenity, and specifies it against measurable confidential-speech-privacy criteria: STC-55 assemblies engineered to a Privacy Index above 95% and an Articulation Index below 0.05, verified by ASTM E1130 field testing of the constructed room.

STC 55

Also written: Sound Transmission Class 55 · STC rating · STC-55 partition

STC 55 is the Sound Transmission Class rating the AI-Native Medical specifies for enclave partitions. Sound Transmission Class measures how effectively an assembly attenuates airborne sound in a laboratory setting. The AI-Native Medical adopts STC 55 as a numeric floor, then requires the delivered room to demonstrate confidential speech privacy in the field — a Privacy Index above 95% and an Articulation Index below 0.05 under ASTM E1130 — because a laboratory rating is not by itself a statement about speech intelligibility at the boundary.

Category

Governance & compliance

Tripartite Ownership Model

Also written: tripartite ownership · three-party ownership model

The Tripartite Ownership Model is the AI-Native Medical's governance architecture, separating a deployment into three parties with strictly disjoint holdings: the property owner, who provides the shell and physical infrastructure; the tenant, who owns the compute hardware, the inference data, and all outputs; and the software operator, who maintains orchestration inside the boundary. No party holds access to what belongs to another.

The Tripartite Ownership Model is what makes the AI-Native Medical commercially deliverable through a lease. It lets a landlord finance and install sovereign infrastructure without ever acquiring rights to tenant data, and it lets a software operator maintain the stack without custody of what it operates on.

Physical Sovereignty

Also written: data sovereignty · sovereignty by architecture

Physical sovereignty is the AI-Native Medical's claim that control over data follows from physical custody of the hardware processing it. Where cloud sovereignty is asserted through contract, jurisdiction, and vendor attestation, the AI-Native Medical grounds it in a locked room containing tenant-owned silicon — a control an auditor can walk into, inspect, and verify without relying on a third party's representation.

Zero-Trust Physical Identity

Also written: physical identity · physical access identity · zero trust physical layer

Zero-trust physical identity is the AI-Native Medical's requirement that entry to the enclave be treated as an authentication event of equal standing to a software credential. A sovereign compute environment is only as strong as its physical access log, so the specification binds identity at the door to identity in the inference session — presence in the room is itself an authorization fact, recorded and auditable.

Compliance Moat

Also written: architecture as compliance · structural compliance

The compliance moat is the competitive position the AI-Native Medical creates by making its central control structural rather than procedural. Cloud compliance rests on access controls and audit logs maintained by a third party whose interests are not identical to the customer's; the AI-Native Medical instead makes third-party data movement physically unavailable, so that control is demonstrated by inspection rather than attested by process. The moat is the durability of that one control, not a claim that the architecture completes a compliance program.

Software Integrator

Also written: software operator · integration layer

The software integrator is the third party in the AI-Native Medical's Tripartite Ownership Model: the operator that deploys, configures, observes, and updates the orchestration stack inside the tenant's demarcation boundary. The role is defined by what it does not hold — the software integrator has no ownership of tenant data, policies, evaluations, routing logic, or retrieval assets, only responsibility for the machinery acting on them.