Exact Disclosure Binding for Persistent Writes in Longitudinal Health AI: The GLHS Governance Contract
This article has been Reviewed by the following groups
Listed in
- Evaluated articles (PREreview)
Abstract
Purpose. Persistent health AI may produce a proposed write from an authorized longitudinal-health disclosure and attempt to persist that proposal after clinical state, consent, role, or policy has changed. Rechecking only the current record and current authorization does not establish which exact governed disclosure supplied the evidence and governance context used during inference. We evaluate whether that disclosure can remain a verifiable dependency of later write admission. Methods. GLHS implements a disclosure-to-commit contract. A Task-Bounded Health State Snapshot (THSS) persists the actor-, purpose-, task-, temporal-, consent-, and evidence-scoped disclosure supplied to inference. A Governed State Transition (GST) admits a persistent proposal only after revalidating the bound disclosure and current state/governance. Primary evidence comprises a deterministic conformance matrix, a matched exact-binding ablation over 320 frozen logical schedules, 12 governance/state time-of-check-to-time-of-use (TOCTOU) schedules repeated with jitter, and a profile-global versus entity-partitioned versioning contention check. Model-context utility is secondary and is evaluated in prospectively frozen synthetic cohorts. Results. In the matched ablation, an otherwise governed arm without exact disclosure binding admitted all 256 binding-specific invalid schedules, whereas the exact-binding arm rejected all 256 and admitted all 64 clean controls. This result is interpreted as deterministic mechanism/conformance evidence on the frozen attack families, not as an estimate of real-world attack prevalence. Across 600 repetitions of 12 governance-writer schedules, no forbidden commit was observed; 10/12 logical schedules matched their frozen classifications in every repetition and two retained classification mismatches. Entity-partitioned versions eliminated the tested false-stale mechanism for disjoint partitions through 128 synchronized writers. In a later 384-subject synthetic comparison, Strict THSS versus full authorized history differed by $-0.781$ percentage points (95% bootstrap CI $[-6.77,+5.21]$), which does not establish the prespecified $\pm2$ percentage-point equivalence margin. Mean prompt tokens decreased from 3,280 to 412; measured provider latency also decreased, but that latency effect is benchmark-specific rather than a controlled systems-speedup estimate. Conclusions. The strongest supported claim is a software-governance property: on the evaluated snapshot-bound path, accepted persistent proposals remain tied to a specific persisted governed disclosure while current state and governance are rechecked. The experiments do not establish clinical benefit, regulatory compliance, optimality of the THSS representation, correctness for arbitrary unbounded schedules, or universal downgrade resistance across every downstream workflow.
Article activity feed
-
This Zenodo record is a permanently preserved version of a PREreview. You can view the complete PREreview at https://prereview.org/reviews/23089251.
Peer Review: Structural Governance and Temporal Latency in Automated State Architectures
Preprint Reviewed: GLHS: A Co-Versioned Disclosure-to-Commit Governance Contract for Longitudinal Health AI (Nguyen Ngoc Thien, Preprints.org, DOI: 10.20944/preprints202609.2193.v1)
Summary & Technical Core
The author isolates a major vulnerability in model-mediated enterprise architectures: the read-to-write temporal interval. When a model evaluates a snapshot and returns a write proposal minutes or hours later, the underlying data, policy, or consent state often shifts. Executing an unverified write against a drifted state causes silent error propagation and compliance failure.
The GLHS framework …
This Zenodo record is a permanently preserved version of a PREreview. You can view the complete PREreview at https://prereview.org/reviews/23089251.
Peer Review: Structural Governance and Temporal Latency in Automated State Architectures
Preprint Reviewed: GLHS: A Co-Versioned Disclosure-to-Commit Governance Contract for Longitudinal Health AI (Nguyen Ngoc Thien, Preprints.org, DOI: 10.20944/preprints202609.2193.v1)
Summary & Technical Core
The author isolates a major vulnerability in model-mediated enterprise architectures: the read-to-write temporal interval. When a model evaluates a snapshot and returns a write proposal minutes or hours later, the underlying data, policy, or consent state often shifts. Executing an unverified write against a drifted state causes silent error propagation and compliance failure.
The GLHS framework addresses this by inserting pre-commit verification mechanics (THSS snapshot bounding and GST pre-commit state checks). This shifts AI governance from post-hoc output inspection to active pre-commit execution control.
Key Strengths & Framework Alignment
State-Version Latency vs. Model Error: The paper correctly identifies that algorithmic failures frequently stem from asynchronous state drift rather than raw model hallucination. In my work on Systemic Intent Shadows (SIS) and The Sunglasses Protocol, I define this as regulatory and state latency—where temporal gaps between evaluation and execution simulate operational non-compliance or error. GLHS provides a direct technical contract to enforce boundaries across these latency windows.
Concurrency Mechanics Over Output Ethics: The PostgreSQL state-version experiments clearly show how coarse, profile-global version counters cause false-stale write rejections during concurrent operations. This provides hard technical evidence for the Zero-Defect Paradox: overly rigid automated controls create systemic friction that degrades operational throughput.
Enforcing Non-Deference: By requiring a database-level commit check before state mutation occurs, GLHS acts as a functional Systemic Disclosure Architecture. It stops human operators and downstream databases from exhibiting blind algorithmic deference to stale model outputs.
Direct Recommendations for Revision
Decouple Version Counters: Coarse profile-global counters trigger false-stale rejections on unrelated metadata writes. The author should implement attribute-level or domain-scoped version vectors so only state changes altering the model's actual inference context invalidate the write window.
Stress-Test Latency: Expand the synthetic test harness to simulate explicit network and administrative latency, testing the GST verification layer under heavy operational load.
Conclusion
Solid, highly practical work. It proves that AI governance is fundamentally a structural problem of data architecture, concurrency control, and state versioning. Highly recommended for formal publication.
References & Related Frameworks for the Author's Consideration:
1. Rodriguez, J., Jr. (2026). The Systemic Intent Shadow: Mapping Organizational Collapse and Regulatory Friction in the Era of AI-Driven Governance. Zenodo. https://doi.org/10.5281/zenodo.22304608
2. Rodriguez, J., Jr. (2026). The Sunglasses Protocol: A Procedural Framework for Temporal Normalization and Algorithmic Contrast in Automated Regulatory Environments. Zenodo. https://orcid.org/0009-0007-9332-0140
3. Rodriguez, J., Jr. (2026). The Illusion of Completeness: Systemic Disclosure Architecture and the Mitigation of Algorithmic Deference in Institutional Healthcare. Zenodo. https://doi.org/10.5281/zenodo.23022219
Reviewer:
Julián Rodríguez, Jr., FRSA, MRES, M.ISRM
Managing Principal, Julian Rodriguez & Associates
ORCID: 0009-0007-9332-0140
Competing interests
The author declares that they have no competing interests.
Use of Artificial Intelligence (AI)
The author declares that they used generative AI to come up with new ideas for their review.
-
-