All case studies
AI Governance

Healthcare network moves AI from pilot to production with enforced guardrails

Healthcare · ~1,200 employees, highly regulated · Switzerland / EU · On-premises deployment in 5 weeks; 7 pilots in production within 2 quarters

Short answer

A ~1,200-employee healthcare provider network moved seven blocked AI pilots into production within two quarters by deploying bluebill on-premises with runtime PII redaction, prompt-injection defence and complete audit logging mapped to EU AI Act and ISO/IEC 42001 requirements.

7

blocked pilots moved into production

5 weeks

to on-premises deployment

0

requests leaving the network boundary

100%

of model traffic covered by logged guardrail decisions

The challenge

  • Seven AI pilots had passed clinical usefulness review but failed data-protection review.
  • Patient data could not leave the network, ruling out unmediated use of public model APIs.
  • There was no runtime enforcement — policies existed as documents, not as controls.
  • Audit preparation was a manual exercise nobody wanted to repeat quarterly.

What bluebill did

  • Deployed the control plane on-premises so no request or log leaves the network boundary.
  • Enforced guardrails at four layers: input validation, data redaction, output checks and tool/action limits.
  • Redacted patient identifiers before any model call, with the redaction decision itself logged.
  • Scoped agent permissions to explicit tool allow-lists with budget ceilings per use case.
  • Mapped every logged control to EU AI Act and ISO/IEC 42001 evidence requirements so audit export is a query, not a project.
The pilots were never the hard part. Proving what happens to the data was.

CISO, anonymised healthcare provider network

What changed afterwards

  • Data-protection review moved from a blocker to a checklist, because the controls are demonstrable at runtime.
  • New AI use cases are approved against an existing control set instead of starting a fresh review each time.
  • Audit evidence is exported on demand rather than reconstructed quarterly.

Environment: On-premises / air-gapped deployment · Self-hosted open models · Existing IAM · Audit log export

Questions this engagement answers

Can AI governance work in an air-gapped environment?

Yes. This network runs the control plane on-premises with self-hosted models, so no request, prompt or log leaves the boundary while guardrails and audit logging still apply in full.

What evidence does an AI audit actually need?

A model inventory, retention-bounded prompt and response logs, guardrail decisions including what was redacted or blocked, and an approval history for model changes. Producing these as a by-product of normal traffic is what removed the quarterly manual effort here.

Client names are withheld by agreement. Engagement profiles are anonymised; figures are the measured results of the engagement described and are consistent with bluebill's aggregate programme results. Individual results vary with environment, scale and starting maturity.

Curious what this looks like for you?

Talk To An Expert