Position: Privacy Claims in Ambient Health AI Require Evidence of Data Flows
Abstract
Local inference does not establish that an ambient health AI system keeps data on the device. Model loaders, supporting services, and retained records can introduce data flows that an architectural description does not capture. We argue that reports making deployment privacy claims should include an egress statement: permitted data flows, controls, observation scope, measurement methods, findings, and unresolved risks. Each claim should be classified as supported within the stated coverage, contradicted, or not assessed. A wearable augmentative and alternative communication (AAC) prototype illustrates why this is needed. External endpoints were observed in all six hub-enabled server sessions and none of twelve sessions configured offline. A separate trace of one cached model start recorded 32 requests to the model hub, each with an authorization header. These observations establish network activity, not transmission of captured speech or images. Configuration and observer failures further showed why both controls and measurements need validation. An illustrative review of six AAC systems and three ambient scribes found no runtime network measurement in the materials examined. The proposed statement makes the evidence and its limits explicit for both local and cloud deployments.