Skip to content

Novartis · Kesimpta / DELCI

A bounded-response system routes supported questions, refusals and human escalation.

The guide had to operate inside an approved information boundary, defined before release rather than after an incident.

Challenge

A general-purpose assistant placed in front of healthcare professionals can answer outside its intended use case, draw on information that was never approved, or imply clinical guidance the system holds no authority to give. The danger is not that it fails loudly. A plausible answer from outside the boundary looks exactly like one from inside it.

Action

The governing decision was to fix the boundary in advance and make refusal a designed behavior rather than a gap. Supported question types were aligned to approved resources, so what the system was competent to answer and what it was permitted to answer were the same set. Everything outside it got an explicit path: refuse, or escalate to a person with the authority to respond. The AI Risk and Control Matrix held the mapping between question class, eligible source, expected behavior, and the human who owned the outcome. Controls were tested and approval authority signed before release, with residual risk accepted explicitly rather than left unstated.

Result

DELCI gave healthcare professionals structured access to approved knowledge without extending the system past its authorized content domain. What it would answer, what it would refuse, where it would escalate, and who held approval authority were settled in advance and visible in the record, so the boundary could be audited rather than inferred from behavior.

Mapping supported questions, refusals and escalation