Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Keeping control of AI at scale: Runtime Governa...

Avatar for Marketing OGZ Marketing OGZ PRO
September 18, 2026
1

Keeping control of AI at scale: Runtime Governance at Healthtech myTomorrows

Avatar for Marketing OGZ

Marketing OGZ PRO

September 18, 2026

More Decks by Marketing OGZ

Transcript

  1. Keeping control of AI at scale. Runtime governance at healthtech

    myTomorrows. Janiek Meppelink Maarten Stolk General Counsel CEO myTomorrows Deeploy
  2. INTRODUCTIONS Who is speaking. Janiek Meppelink Maarten Stolk General Counsel,

    myTomorrows CEO, Deeploy Leads legal and compliance at myTomorrows, where healthcare regulation, data protection and AI governance meet in the same product decisions. Deeploy — AI governance software for regulated industries. Enjins — AI engineering consultancy. The Stack — Amsterdam hub for European AI startups. I believe AI is a game changer to how we will work. Building better, more efficient systems to do good has been a consistent theme throughout my career. AI has huge potential for society. I’ve seen too many projects and companies fail to deliver on their promises. It has been my drive throughout my career to build things that last.
  3. WHAT YOU NEED Governance is a hard requirement. ➔ The

    AI Act indirectly forces you to govern high risk AI, and keep registry of others ➔ For Pharma and healthcare orgs, requirements go often further (MDR / GxP) ➔ Customers demand proof of compliance. It’s your license to operate. 02
  4. THE REALITY A jungle of AI systems AI is used

    everywhere across the org. There is no central overview of AI use cases. Governance is just paperwerk, not enforced at runtime. 02
  5. THE OPERATIONAL LAYER 5 steps to govern AI 01 Discover

    and register. Every AI system, model and agent is discovered and registered in one inventory 02 Assess and document. One intake and review route, so the board reviews consistent, comparable cases 03 Assign controls. Your framework, the EU AI Act, ISO 42001 or NIST, translated into controls with owners. 04 Monitor in production. Risks, performance, drift and alerts on the systems that are actually live. 05 Collect evidence. Decisions, approvals and checks recorded as the work happens. 03
  6. INTRODUCING MYTOMORROWS Finding treatment options beyond standard care. Information about

    clinical trials and pre-approval programmes is spread across registries, protocols and clinical networks. Finding the right option is still manual. FOR PATIENTS When standard care runs out, there is no single reliable place to see what is available. FOR PHYSICIANS AND SITES Searching every registry takes time physicians do not have, so recruitment stalls. FOR BIOPHARMA No clear view of the recruitment funnel, so timelines stretch and costs rise. 09
  7. THE CASE IN ONE VIEW Why we use AI in

    our intakes WHY AI HERE HOW IT WORKS WHAT RUNS UNDERNEATH A phone call is the only way in. Validate first, AI second, human last. Guardrails at the routing layer. Today, sharing your medical situation means booking a call with a Patient Navigator. For someone with ALS that call may not be possible - so people who could be eligible never enter the funnel at all. The patient answers in their own words. Every answer is checked against our database before the model is called, the AI drafts at most five follow-ups, and a Navigator reviews before any trial option is shared. Every call passes through our LiteLLM proxy, where content and PII guardrails already run. That is the same layer Deeploy plugs into, so evidence for each control lands in one place.
  8. THE CASE The steps AI takes AI Medical Intake, one

    of the AI use cases at myTomorrows, piloted with ALS patients. THE BARRIER Today, sharing your medical situation means booking a call with a Patient Navigator. For someone with ALS, a phone call may simply not be possible. THE DESIGN 1 Patient answers in their own words, or via speech-to-text 2 We validate first answer checked against guardrails before the AI ever sees it That's not a UX gap, it's people who can't get acces our services at all. 3 AI drafts one follow-up max five per question, via a sanitized, server-built prompt 4 A Navigator reviews everything before any clinical trial options are shared
  9. THE GOVERNANCE CHALLENGES What makes this hard. We’re dealing with

    extremely confidential patient data. ➔ Our policies were existing on paper, not at runtime. Forcing AI to behave within boundaries is crucial to comply and use AI safe. ➔ Oversight and transparency into (external) model performance was lacking. High-level metrics is not enough. ➔ Transparency: User guidance for careful and thorough design on where and how to apply AI is a hard requirement.
  10. FIRST THING: GETTING OVERVIEW Every AI systems is detected. No

    shadow AI. AI PROJECTS Integrations AGENTS MCP / Hooks VENDORS GRC / IT repo
  11. THREE OPERATIONAL LAYERS Logs & traces feeding our evidence Logs

    & traces are collected Monitoring behaviour Collecting evidence Traces are collected real-time: Integrations Deeploy as a proxy Through MCP & Hooks The logs and traces are used to monitor the AI systems in real-time, and flag alerts when the model violates policies Over time, evidence is collected to proof that compliance.. 02
  12. TWO DIFFERENT WAYS OF ENFORCING OUR POLICIES Enforcing the policies

    as guardrails… Every AI follow-up question passes through this exact path, no shortcuts. Patient Frontend Our Platform LiteLLM Proxy Cloud AI browser holds session validates first guardrails run here Gemini / Claude follow-up question returns to patient (max 5 loops) Deeploy is being wired in here reads evidence from the same layer the guardrails run at + Patient Navigator reviews before any trial match
  13. TWO DIFFERENT WAYS OF ENFORCING OUR POLICIES …Or using the

    Governance Harness Deeploy is enforced on agents, using its governance harness
  14. THE VALUE The value for myTomorrows. BEFORE DEEPLOY WITH DEEPLOY

    ➔ No central overview of AI systems. Registration depended on the discipline of people. ➔ A complete AI register, kept current by the platform rather than by individual discipline. ➔ Nothing was traced or tracked. No rules or policies enforced, and no guardrails on AI. ➔ Evidence for controls is collected based on logs and traces. Alerts are triggered at non-compliance ➔ Higher risk of non-compliance, and almost no way to prove compliance to customers. ➔ Compliance can be enforced on model level, to make sure AI complies to its control framework. 15
  15. THANK YOU Thank you. Thanks to Data Expo and to

    everyone in the room. Questions now, or find us at the Deeploy stand afterwards! deeploy.ai → Scan for the whitepaper AI governance in regulated industries 18