Method

My Personal AI Health Rules: A Simple Governance Policy

How to create a simple, two-page policy for using AI in your health. A clear system of rules keeps you safe and the output useful.

By Sabin · Wellness & AI8 min read
AI & Health
My Personal AI Health Rules

Personal AI health rules are a simple policy you create for yourself to govern how you use large language models for health research. A good policy has three parts: a clear statement of intent and limits, a method for reviewing and recording outputs, and a schedule for auditing your system.

The Goal: A System, Not a Subscription

It seems every company in health wants to sell you a subscription to their proprietary AI model. The pitch is always the same: their closed system is safer, more accurate, and more personalized. But this misses the point of using AI for your health in the first place.

The goal is not to become dependent on another app. The goal is to build your own capability. By using the powerful, general-purpose AI tools you likely already have access to, you can learn to do your own research, manage your own data, and design your own protocols. This is about agency, not just answers.

This requires a system. A personal set of rules gives you a clear, repeatable process for using AI safely. It prevents you from outsourcing your thinking or accepting advice without verification. It’s your personal governance document for staying in control.

Page 1: Intent and Limits

The first page of your policy defines the job description for your AI assistant. It sets the boundaries. It should be simple enough to fit on a single page. Mine has two parts: what the AI is for, and what it is never for.

Part 1: Statement of Intent

Start by defining the AI's role. My statement is direct: 'My AI assistant is a research accelerator and a data-structuring tool.' That's it. It’s not a doctor, not a coach, and not a decision-maker. Its job is to speed up the first layer of the Wellness & AI method: Research. It helps me find studies, summarize findings, and extract key data points. It also helps in the second layer, the Ledger, by turning my messy notes and data into clean, structured formats.

Defining the intent prevents 'scope creep,' where you start asking the AI for opinions, diagnoses, or reassurance. Its role is mechanical: find, summarize, structure. This keeps the interaction clean and reduces the risk of relying on it for things it cannot do.

Part 2: Statement of Limits

Next, define what you will never ask the AI to do. These are your non-negotiable red lines. My list is just as direct:

  • The AI will never be asked for a diagnosis or to interpret symptoms.
  • The AI will never be asked to create a treatment plan or recommend specific dosages.
  • The AI will not be used as a substitute for consultation with a qualified clinician.
  • The AI will not be given personally identifiable health information (PHI) unless it is running locally on my own hardware.

These limits are critical for safety. Public-facing models are not secure environments for your private data. More importantly, they are not qualified to give medical advice. A 2023 study in the Journal of Medical Internet Research evaluated chatbot responses to public health questions and found that while they could be helpful, they also had the potential to provide inaccurate or biased information. Your rules are the fence that keeps you from wandering into that territory.

Page 2: Review, Record, and Audit

The second page of your policy outlines your process for handling the AI's output. How do you check its work, where do you store the results, and how do you periodically review your system?

Part 3: Review and Record

Every output from an AI requires verification. My rule is: 'All claims, summaries, and data points must be traced to a primary source.' If the AI summarizes a study, I need the link to the PubMed entry or the DOI. I then check the source to confirm the AI's summary is accurate. I never trust the output on its own.

Once verified, the information goes into my personal health Ledger. This is a simple, structured document—a spreadsheet or a personal database—where I track my research, self-tracked data, and clinical test results. The key is that information only enters the Ledger *after* it has been fact-checked. The AI helps generate the raw material; I do the verification and integration.

Part 4: The Quarterly Audit

Technology and evidence change quickly. A policy that is useful today might be outdated in six months. That's why the final part of my policy is a scheduled review. Once a quarter, I set aside an hour to audit my system.

The audit answers three questions:

  1. Is my Intent & Limits statement still correct and am I following it?
  2. Is my Review & Record process working, or is unverified information slipping through?
  3. Have any new tools, research, or security concerns emerged that require me to update my rules?

For example, the increasing availability of open-source models that can run locally has changed my rule on personal data. I now have a clause that allows me to use PHI with a local model, something I would never do with a public web interface. This audit ensures your personal AI health rules remain a living document, adapting to the tools and your needs.

Common Questions

Is a two-page policy really necessary?

Yes. It's not about bureaucracy; it's about clarity. The act of writing down your rules forces you to think clearly about how you're using a powerful but fallible technology. It takes less than an hour to create and transforms your process from ad-hoc and risky to structured and safe.

Can't I just use a specialized health AI app?

Three things to read next.

See all →

Suggested for you

Based on what you've been reading — always learning.

See all →