
AI Governance Policy
Last updated: May 2026
1. Purpose
This AI Governance Policy explains how AskHEMI uses artificial intelligence responsibly to support users in understanding their health, managing conditions, and making better lifestyle decisions. It covers both the core AskHEMI AI and the Personalised Intelligence feature, which enables the AI to provide contextualised guidance based on health profile data voluntarily provided by users.
Our goal is to ensure that AI is used safely, transparently, ethically, and in a way that supports, not replaces, professional healthcare advice.
2. Role of AskHEMI AI
AskHEMI is designed as an AI health companion that provides:
-
General health information and evidence-based lifestyle guidance.
-
Personalised health context, where the user has provided health profile data through Personalised Intelligence.
-
Support between clinic visits and during everyday health decision-making.
-
Assistance in understanding medical conditions, medications, and treatment concepts.
-
Educational insights to improve health literacy.
-
Proactive risk flagging where a user's health profile suggests elevated risk for certain conditions.
AskHEMI does not replace doctors or healthcare professionals and must not be used as a substitute for medical consultation, diagnosis, or emergency care.
3. Personalised Intelligence: Governance Principles
The Personalised Intelligence feature introduces additional responsibilities. The following principles govern its design and operation:
3.1 Voluntary Participation
All health profile data submitted through Personalised Intelligence is provided voluntarily. Users may choose not to participate, may provide partial data, and may delete any or all of their health profile at any time. The quality of personalisation scales with the data provided, but no data submission is required to use the App.
3.2 Contextualisation, Not Diagnosis
Personalised responses are contextualised guidance informed by the user's health profile. They do not constitute a diagnosis, clinical assessment, or treatment recommendation. AskHEMI uses profile data to improve the relevance and safety of its responses, such as adjusting advice for users with known conditions or medications, and flagging when a symptom may warrant earlier clinical attention given a user's risk profile.
3.3 Data Confidence Handling
AskHEMI recognises that self-reported health data may be incomplete, out of date, or imprecise. The AI is designed to:
-
Treat self-reported data as indicative, not definitive.
-
Apply appropriate uncertainty where data quality is unknown.
-
Prompt users to verify key data points (e.g. recent blood pressure readings) where clinical accuracy matters.
-
Never extrapolate beyond what the available data reasonably supports.
3.4 Escalation Pathways
As personalisation increases the specificity of guidance, clear escalation pathways become more critical. AskHEMI will recommend professional consultation when:
-
A symptom pattern, in the context of the user's health profile, suggests elevated clinical risk.
-
The user's health profile includes conditions or medications that require clinical oversight.
-
A user's reported data has changed significantly over time in ways that warrant assessment.
-
The question asked falls outside the scope of safe AI guidance.
4. Human-Centred Healthcare
AskHEMI follows a human-in-the-loop approach to digital health. This means:
-
AI is designed to support patients and healthcare systems, not replace clinicians.
-
Medical decisions must always be confirmed with qualified healthcare professionals.
-
Users are encouraged to share their AskHEMI health profile summary with their doctor to enrich clinical consultations.
-
AskHEMI does not make autonomous clinical decisions.
For emergencies, users should contact local emergency services or healthcare providers immediately. AskHEMI is not a crisis response platform.
5. Safety and Responsible Use
AskHEMI is designed with safeguards to minimise risk and misinformation across both general and personalised use cases.
5.1 Medical Safety
-
AI responses are intended for educational and informational purposes only.
-
AskHEMI avoids providing definitive diagnoses or treatment prescriptions.
-
Personalised responses are calibrated to be more specific, not more authoritative.
5.2 Risk Awareness
AskHEMI may advise users to seek medical care when:
-
Symptoms may indicate a serious or time-sensitive condition.
-
The user's health profile indicates elevated risk warranting clinical review.
-
A clinical assessment or diagnostic test is necessary to determine appropriate care.
5.3 Content Monitoring
We continuously monitor and review AI outputs to ensure responses remain accurate, safe, and appropriate. Personalised responses are subject to the same quality and safety standards as general responses, with additional review for outputs involving high-risk health conditions.
6. Transparency
We believe users should understand how the AI works and what it does with their data.
-
Users are informed that they are interacting with AI-generated responses.
-
AskHEMI discloses when a response has been personalised based on the user's health profile.
-
Users can view the health profile data currently informing their personalised responses at any time through their profile settings.
-
AskHEMI explains the basis for significant guidance where appropriate (e.g. "Based on your reported blood pressure and age, you may have a higher risk of...").
-
AI responses may not always be perfect and should be verified with trusted healthcare sources or professionals.
7. Privacy and Data Protection
Protecting user health data is a core principle of AskHEMI. The AI Governance framework is built on the following data protection standards:
-
Compliance with Malaysia PDPA 2010, Indonesia PDP Law 2022, and UK GDPR / DPA 2018.
-
Health profile data is classified as sensitive personal data and subject to enhanced security measures.
-
Data minimisation: only data relevant to personalisation is collected and used.
-
Purpose limitation: health profile data is used only to personalise the user's own experience and is not used for advertising, profiling for third parties, or sold.
-
User control: users can view, update, and delete their health profile at any time
8. Responsible AI Development
AskHEMI is developed with responsible AI principles across all features, including Personalised Intelligence:
8.1 Fairness
Efforts are made to minimise bias and ensure the AI serves diverse populations equitably, including across age, gender, ethnicity, and health condition. Personalisation must not amplify existing health inequities.
8.2 Accuracy
The system is continuously improved through updates, monitoring, and quality assurance. Personalised responses undergo additional validation to ensure profile-informed guidance meets clinical safety standards.
8.3 Accountability
MedPlanner maintains governance oversight of AskHEMI's AI systems. The Personalised Intelligence feature is subject to a dedicated review cycle covering clinical safety, data quality, and user outcome monitoring.
8.4 Continuous Improvement
AI models and knowledge sources are periodically updated to reflect evolving healthcare evidence and technology. User feedback on personalised responses is actively incorporated into quality improvement cycles.
9. Limitations of AI
Users should understand that AI systems have limitations. AskHEMI:
-
May occasionally produce incomplete or incorrect information, including in personalised responses.
-
Personalises responses based only on the data the user has provided, which may not represent the user's full clinical picture.
-
Cannot replace clinical judgment, physical examination, diagnostic testing, or professional diagnosis.
-
Does not have access to external medical records or healthcare system data unless explicitly integrated.
Users should use AskHEMI as a supportive tool, not as the sole basis for health decisions. The more complete your health profile, the more relevant the guidance, but AskHEMI always operates within the boundaries of informational support.
10. Ethical Use of AskHEMI
Users agree not to misuse the platform. Examples of prohibited use include:
-
Submitting false health data with the intent to obtain specific AI outputs.
-
Attempting to generate harmful medical instructions or treatment protocols.
-
Submitting another person's health data without their explicit consent.
-
Misrepresenting AskHEMI as a licensed healthcare provider or diagnostic tool.
-
Using the system for illegal or unethical purposes.
MedPlanner reserves the right to monitor and limit misuse of the platform, including where submitted data patterns suggest misuse of the Personalised Intelligence feature.
11. Governance and Oversight
AskHEMI's AI governance is overseen by MedPlanner's AI Governance and Product Development team. Governance structures include:
-
A responsible AI development framework covering both general and personalised AI functions.
-
A dedicated Personalised Intelligence review process covering clinical safety, data quality, and user outcome monitoring.
-
Continuous system monitoring and automated safety flagging.
-
User feedback mechanisms embedded in the App.
-
Compliance monitoring aligned with emerging healthcare AI regulations in Malaysia, Indonesia, and the UK.
12. Updates to This Policy
As AI capabilities, healthcare regulations, and the Personalised Intelligence feature evolve, this AI Governance Policy will be updated accordingly. The latest version will always be available on the AskHEMI website. Material changes will be communicated to users through the App.
13. Contact
For questions about AskHEMI's AI governance or the Personalised Intelligence feature, please contact:
AskHEMI Team
Email: ask@askhemi.ai
MedPlanner Sdn Bhd
B-09-01, Tower B, Menara UOA Bangsar
5, Jalan Bangsar Utama 1, Bangsar
59000 Kuala Lumpur, Malaysia