Sovereign AI at the Front Door of Care: A Physically Unidirectional Architecture for Secure Clinical Intelligence

arXiv cs.AI / 3/27/2026

💬 OpinionIdeas & Deep AnalysisModels & Research

Key Points

  • The paper proposes a “Sovereign AI” clinical triage architecture where all model inference happens on-device, eliminating reliance on external inference services.
  • Patient data is delivered through a physically unidirectional channel using receive-only broadcast infrastructure or certified hardware data diodes, with no network return path.
  • The authors argue this removes the network-mediated attack surface by design, rather than relying primarily on software security controls.
  • The system supports conversational symptom intake, integrates device-captured vitals, and outputs structured, triage-aligned clinical records at the point of care.
  • The work formalizes security properties of receiver-side unidirectionality and analyzes threat models and deployment configurations, showing transport-agnostic operation across broadcast vs diode enforcement.

Abstract

We present a Sovereign AI architecture for clinical triage in which all inference is performed on-device and inbound data is delivered via a physically unidirectional channel, implemented using receive-only broadcast infrastructure or certified hardware data diodes, with no return path to any external network. This design removes the network-mediated attack surface by construction, rather than attempting to secure it through software controls. The system performs conversational symptom intake, integrates device-captured vitals, and produces structured, triage-aligned clinical records at the point of care. We formalize the security properties of receiver-side unidirectionality and show that the architecture is transport-agnostic across broadcast and diode-enforced deployments. We further analyze threat models, enforcement mechanisms, and deployment configurations, demonstrating how physical one-way data flow enables high-assurance operation in both resource-constrained and high-risk environments. This work positions physically unidirectional channels as a foundational primitive for sovereign, on-device clinical intelligence at the front door of care.

Sovereign AI at the Front Door of Care: A Physically Unidirectional Architecture for Secure Clinical Intelligence | AI Navigate