About
The short version
I build AI prototypes and translate them into the governance a hospital, a regulator, and a legal team can each act on, for high-risk medical and regulatory contexts. I am an AI PhD (The University of Hong Kong), R&D Manager and Functional Lab Lead at the HKU-Avnet Joint AI Laboratory, where I drive the development and governance of a patient-facing medical digital twin, covering model design, cross-party coordination, deployment planning, clinical risk considerations, and responsible AI documentation.
The capability is high-stakes AI governance; medical AI is where I prove it, because it is the domain with the least room for an ungoverned system. The discipline itself, deciding what a system may claim, who is accountable when it fails, and where the audit trail lives, transfers to any setting where AI carries real consequences: financial, regulatory, and public-sector.
Following technology into governance
I did not start in governance. I started in AI research, working on three-dimensional perception and automatic annotation, where a model is only as good as the data behind it and the evaluation around it. That work taught me how AI systems are actually built, where they quietly fail, and why “reliable” means something more than a high score on a benchmark.
When I moved into leading a patient-facing medical digital twin, I expected the hard part to be the modelling. It was not. The decisive questions were about deployment: what the system is allowed to claim, who is responsible when it is wrong, what evidence a patient should have before they see an output, and who has the authority to stop it. These are governance questions, and in medical AI they are not optional.
So I began translating my own project into governance: intended-use boundaries, stakeholder and decision-rights maps, risk registers, deployment-readiness criteria, and a growing casebook of medical AI governance analyses. Following the technology into governance was not a step away from engineering. It was following the technology to the point where it either becomes trustworthy or does not.
That boundary is now where I choose to stand. I understand the capability limits of AI systems because I build them, and I understand the risks of medical settings because I work in one. It lets me translate technical risk into governance rules, and governance goals back into requirements a team can actually build against. In short, I try to govern what I build.
What I work with
- Regulatory literacy: EU AI Act, NIST AI RMF, ISO/IEC 42001, WHO guidance on AI for health, FDA guidance for AI-enabled device software (including predetermined change control plans), Hong Kong TR-008.
- Technical risk literacy: validation and external validation, calibration, subgroup performance, model drift, LLM failure modes, human-in-the-loop failure, post-market monitoring.
- Clinical workflow literacy: where an AI output enters a care pathway, who acts on it, what over-reliance looks like, and when escalation to a clinician is mandatory.
- Audit evidence literacy: risk registers, model cards, validation reports, incident logs, change control plans, override logs, monitoring reports.
- Operational handoff literacy: designing governed AI workflows with human-in-the-loop controls, auditability, and a transition plan so a system can be owned and run by an operating team, not just its builder.
- Policy writing: turning all of the above into language that hospital leadership, regulators, and legal teams can act on.
Where I am going
The conviction under all of it is easy to say and hard to deliver: advanced AI should be governed where it actually operates, in real applications, not only in policy documents. I work to make responsible governance something a deployed system does, not something a paper promises, and I work at it from the side that builds.
My aim is to work where medical AI meets rules: research on health AI governance and regulatory science, governance and responsible AI roles in health systems and industry, and, over time, policy-facing and standards-facing work. If you are building or overseeing patient-facing medical AI and want a governance perspective grounded in real system-building, I would like to hear from you.
The core of that work is patient-facing, but the governance questions do not stop at the individual. As frontier AI moves into areas like biosecurity, the same discipline has to protect people who are nowhere near the system, which changes which safeguards count. I read that boundary from the side I know, for example in a note on dual-use and the geometry of accountability.
I am currently looking for: (1) senior collaborators willing to co-author or advise on the governance research line, and (2) opportunities to pilot governance instruments with real medical AI deployments.
Contact
Email: qianxy10@connect.hku.hk · xyqian@eee.hku.hk
Profiles: Google Scholar · LinkedIn · ORCID