Vendor and Product Reality

Viz.ai's clinical footprint is anchored by FDA-cleared algorithms operating on imaging acquired in the emergency department workflow. Viz LVO, the original 2018 De Novo clearance for AI-based notification in stroke, analyzes CT angiograms and pushes a notification to the neurointervention team when an LVO is suspected. Viz CTP performs CT perfusion analysis and provides quantitative maps that are used to support thrombectomy decisions under DAWN/DEFUSE-3 criteria. Viz ICH detects suspected intracranial hemorrhage on non-contrast CT. The Viz Aortic, Viz PE, Viz HCM, and Viz Subdural products extend the same detect-and-notify pattern into adjacent diagnoses.

ContaCT is the communication substrate that makes the clinical value real. A positive AI finding triggers a HIPAA-compliant alert to a defined care team, with the relevant images and the model output viewable on a mobile device within seconds. The combination of fast detection and fast communication is what changes door-to-puncture times in stroke programs and is the basis of the clinical evidence Viz.ai has accumulated.

The architectural model is, in essence, model-output-as-notification. Each algorithm produces a binary or scored finding; ContaCT translates positive findings into pages and chat messages; the receiving clinician views the imaging and decides. This model is appropriate for FDA's Computer-Aided Triage and Notification (CADt) regulatory category and has been the basis of Viz.ai's clearances. It is scoped to notification rather than to downstream automated execution, and Viz.ai has been disciplined about staying within that scope.

The Architectural Axis

The model-output-as-notification architecture places confidence in the output rather than in the execution pathway. Confidence is reported as a score attached to a finding, and that score is carried separately from the imaging quality conditions under which it was produced, the patient-context features that modulate it, and the workflow-state preconditions bearing on whether the finding is actionable. Downstream use of the score therefore locates admissibility with the receiving clinician or system.

The consequences are the familiar, category-level failure modes of any scored-notification system in clinical imaging, and they are not unique to any one vendor: alert fatigue tends to grow as a platform's footprint expands across diagnoses, false positives in low-prevalence settings erode trust, and a gap between what a model emits and what the clinical context warrants can drive both over-triage and under-triage. As a detect-and-notify platform expands into workflows that touch order entry, transfer coordination, and care-pathway automation, an architectural confidence-governance layer becomes the structural element that bounds what is automated.

What the disclosure adds is not a model or a notification interface. It is a primitive in which confidence is a composite, decision-grade object, derived from model output, input quality, patient context, and workflow state, and in which downstream execution is structurally gated on that composite rather than on a raw model score.

What Confidence Governance Provides

Confidence Governance, as disclosed in the confidence governor of United States Patent Application 19/647,395, treats execution as a revocable permission rather than a default assumption. Execution is not the resting state that failure interrupts; it is a conditional privilege that must be continuously earned and can be withdrawn at any moment the conditions that warranted it no longer hold. That is a structural inversion of the triage-and-notify arrangement, in which a notification is emitted once, on a scored finding, and everything downstream re-derives whether to act.

The governor makes confidence a first-class computed state variable, not a heuristic score or a metadata annotation. It is written to a designated field, computed by a deterministic evaluation function over agent-state and task-state inputs, and recorded in lineage so its trajectory is auditable. The spec is explicit that this is a composite determination: the confidence governor, together with the integrity engine and the capability envelope, operates as a composite admissibility evaluator that requires concurrent satisfaction of confidence sufficiency, integrity compliance, and capability confirmation before a proposed action is admitted. Admissibility is not reduced to any single dimension.

Crucially, the governor is a hard gate, not an advisory module. When it withdraws authorization, execution ceases; in the described embodiments the agent does not override the withdrawal through self-assessment, affective escalation, or policy reinterpretation. The prohibition is enforced as a structural decoupling of the execution output pathway rather than a flag the execution subsystem may check and respect. This locates the determination differently than a scored notification does: a raw model score is consumed by whatever reads it, while a governed gate holds the execution pathway itself.

The governor also projects trajectory. It does not wait for confidence to cross a threshold before responding; an adverse rate of change can trigger preemptive suspension into a non-executing cognitive mode, where cognition and planning continue but action does not. Authorization resolves into three states the spec names directly: authorized (above threshold, normal operation), suspended (below threshold or preemptively halted, execution prohibited while cognition continues), and locked (a governance-mandated halt requiring external review). Recovery from suspended to authorized requires the confidence value to exceed the threshold by a configurable hysteresis margin, so the system does not oscillate at the boundary.

Applied to a medical-imaging context, an embodiment can compose the governor's inputs from the domain's own signals. A Viz LVO finding stops being simply "positive at score 0.92" and becomes admissible only when the composite holds: the model output, an input-quality condition (for a CT angiogram, acquisition parameters such as contrast timing and slice thickness), patient-context features the clinical pathway requires, and a workflow-state predicate that the receiving action is genuinely ready. Each downstream action declares the threshold it requires; a notification, an order suggestion, and a transfer initiation can carry different thresholds, calibrated to the action's consequences and reversibility. The governor does not change the underlying model; it changes what the model output is structurally permitted to do, and it records that decision in an auditable lineage rather than reconstructing it after the fact.

Composition Pathway

A skilled implementer can build the governor as a layer above a detect-and-notify platform without touching the cleared algorithms. In one embodiment, the governor sits at the boundary between model output and the ContaCT notification layer. Each algorithm's output (Viz LVO, Viz CTP, Viz ICH, and adjacent products) becomes an input to the composite evaluator: the existing model score as one dimension, an input-quality condition derived from DICOM acquisition metadata as another, patient-context features drawn from the EHR through standard FHIR integrations as a third, and a workflow-state predicate derived from the receiving team's on-call state as a fourth. The confidence value is computed by a deterministic evaluation function over those inputs and written to a governed, lineage-tracked field.

Outbound, notifications fire only when the governor holds the pathway in the authorized state. Compositions that fail admissibility land in the suspended state: the finding is not discarded but held in a non-executing mode, deferred or routed to a quality-review queue rather than paged into the on-call workflow, with recovery to authorized requiring the hysteresis margin so a marginal case does not flicker on and off. The clinical experience for the receiving team is fewer, higher-confidence alerts, and every suppression is recorded rather than silent.

For care-pathway automation, the workflows where a detect-and-notify vendor would expand beyond pure CADt, the per-action threshold model applies: order suggestions, transfer initiations, and care-team assembly each declare the threshold they require, and the hard gate enforces it before the action can fire. The disclosure is not limited to this deployment. Enumerated embodiments and variations include: composition above other medical-imaging pipelines and non-imaging clinical models; the input-quality dimension instantiated from any acquisition or sensor-fidelity signal, not only CT parameters; trajectory-based preemptive suspension driven by rate-of-change as well as absolute threshold; the locked state reserved for governance-mandated halts pending external authorization; and per-action thresholds calibrated to reversibility, spanning notification, order entry, transfer, and autonomous execution. A regulatory posture aligned with notification is preserved in the CADt embodiment because the cleared model is unchanged; what is added is the governance layer above it.

Commercial and Licensing Implication

Confidence Governance, disclosed in United States Patent Application 19/647,395, describes confidence-governed execution as an architectural mechanism: execution as a revocable permission, a first-class computed confidence state, a hard gate that cannot be overridden, preemptive trajectory-based suspension, and the three authorization states. A triage-and-notify platform implements model-output-as-notification with high clinical fidelity, which is a different and legitimate design point; the disclosed architecture is organized instead around downstream execution as a continuously revocable, hard-gated permission. The regulatory pathway under which CADt clearances are granted is aligned with notification, not with governed execution, which is precisely why the notification posture is a good fit for detection and a poor fit for automation.

The comparison is scoped to that axis and no further. Nothing here asserts a defect in Viz.ai's cleared detection performance, its clinical evidence, or its regulatory standing, all of which are strong within the CADt category. The observation is architectural: the move from detect-and-notify into care-pathway automation is gated by exactly the property the confidence governor supplies. A governance layer of this kind gives a detection vendor a substrate for governed execution compatible with an existing notification posture, and for a deploying health system the practical consequence is automation that can be defended to QA, to payers, and to regulators because each admissibility decision is structural and recorded rather than reconstructed after the fact.

Disclosure Scope

The technology described here, Confidence Governance and its confidence governor, is disclosed in United States Patent Application 19/647,395: execution as a revocable permission, confidence as a first-class computed state variable, the composite admissibility evaluator (confidence, integrity, capability), the hard gate that cannot be overridden by self-assessment or affect, trajectory-based preemptive suspension into a non-executing cognitive mode, the three authorization states (authorized, suspended, locked), and hysteresis on recovery. This article is a dated public disclosure of that subject matter and its application, enabling a skilled implementer to build the described approach across the enumerated embodiments and variations.

References to Viz.ai and its products (Viz LVO, Viz CTP, Viz ICH, ContaCT, and adjacent offerings), to the FDA Computer-Aided Triage and Notification pathway, and to any other third party or market are provided as external context to situate the invention. They are described to the best available public understanding, are not claims of United States Patent Application 19/647,395, and are not assertions of any deficiency in those products beyond the specific architectural axis discussed. Named products are the property of their respective owners.