League publishes AI applied model card in partnership with Coalition for Health AI (CHAI), advances comprehensive responsible AI posture

Coalition for Health AI (CHAI) logo on a light lilac background.

Today, League announced a further suite of additional responsible AI and compliance milestones that reflect the company’s continued commitment to the NIST AI Risk Management Framework, and building trustworthy AI, transparently, accountably, and in partnership with the standards bodies shaping the industry.

At the center of today’s announcement is the publication of League’s first applied model card, developed using CHAI’s framework, for its Health Coach agent. Often called an AI “nutrition label,” the CHAI model card provides health plan members, employers, and enterprise buyers with clear, standardized disclosure of how League’s AI works: what data it uses, how it performs, where it has limitations, and how it is evaluated. It is available publicly on the League Trust Center.

The announcement comes as League simultaneously achieves a set of complementary milestones across data privacy, global AI governance, and public sector readiness, forming one of the most comprehensive responsible AI postures in healthcare technology.

Milestone highlights

1. Applied Model Card — published with CHAI framework

League has published its first AI Applied Model Card using the template developed by CHAI, a leading non-profit founded by clinicians to advance responsible health AI. The model card covers League’s Health Coach feature, the platform’s conversational AI capability that guides health plan members through their wellness journeys with easy access to trusted information from their plan.

The CHAI-aligned model card includes:

  • Intended use and target population
  • Testing data descriptions and privacy controls
  • Performance benchmarks and known limitations
  • Bias evaluation and fairness considerations
  • Human oversight of the feature and guardrail design and performance

League intends to publish applied model cards for additional features — including Benefits Navigator and Care Navigator — as part of an ongoing AI evaluation and disclosure program.

“Health systems need clear, consistent information to understand how an AI solution was developed, how it performs, and where its limitations lie before they can determine whether it is appropriate for their patients and care environments,” said Brian Anderson, M.D., CEO of the Coalition for Health AI. “By publishing a model card, League is helping put that information into a standardized, accessible format that can support more informed evaluation and governance. This kind of transparency from solution providers is essential to building trust and giving healthcare organizations the information they need to adopt AI responsibly.”

“Every healthcare organization we work with is being asked by their own board and regulators: how do you know your AI is safe?” said Leo Espindle, VP of Compliance, League. “A model card is a real answer. We built ours with CHAI because we wanted a standard the whole industry could hold us to.”

2. OECD Hiroshima AI Reporting Framework

League has submitted its responsible AI disclosure to the OECD’s Hiroshima AI Transparency Reporting Framework, a voluntary global initiative through which leading AI organizations publicly account for their AI governance practices. The initiative, aligned with the G7 Hiroshima AI Process, counts Amazon, Google, Microsoft, OpenAI, Telus, and Anthropic among its reporting organizations. 

League’s submission, among the earliest leveraging the updated HAIP 2.0 reporting format, covers its enterprise AI governance practices, human oversight mechanisms, safety testing protocols, and commitments to ongoing transparency. The report will appear on the OECD AI Policy Observatory portal upon publication, pending the OECD’s standard review timeline.

3. Renewed EU-US Data Privacy Framework certification

League has renewed its certification under the Data Privacy Framework program, administered by the US Department of Commerce, which enables lawful personal data transfers from the European Union, United Kingdom, and Switzerland to the United States. The program provides a legal mechanism for US organizations to self-certify their compliance with applicable data protection requirements, including the EU GDPR, UK GDPR, and Swiss Federal Act on Data Protection.

This renewal expands League’s coverage to include Switzerland for the first time, adding the Swiss-US DPF alongside the existing EU-US DPF and UK Extension certifications, and reinforces the company’s ability to serve global health plan clients with operations across European and international markets.

4. Canadian government procurement readiness

League has completed preparation of a full suite of procurement artifacts required for Canadian federal and provincial government contracting. The artifacts address key Canadian public-sector requirements including:

  • ITSG-33 / PBMM (Protected B) control equivalence via League’s HITRUST r2 certification, and SOC 2 Type 2 and NIST 800-53 compliance reports
  • Canadian data residency compliance per Treasury Board’s ITPIN No. 2017-02 direction
  • CPCSC Level 1 cyber security self-assessment (valid through June 2027)
  • Provincial health privacy law alignment across all major Canadian jurisdictions (PHIPA, FOIPPA, PHIA, HIA, and others)
  • ISO/IEC 27001:2022 certification (valid through January 2029)

While formal procurement submissions and other actions may be triggered by active RFP processes, League is now positioned to move rapidly in response to federal or provincial opportunities, a readiness posture that supports the growing adoption of AI-driven health engagement platforms across Canada’s public health system.

The full picture: League Trust Centre

All compliance artifacts, certifications, and the published applied model card are available at league.com/league-trust-centre/. League’s Trust Centre serves as a live disclosure resource for enterprise buyers, health plan partners, and regulators evaluating League’s data privacy, security, and AI governance posture.

About League

Founded in 2014, League is an AI technology company powering the next generation of healthcare consumer experiences. Payers and providers build on the League platform to deliver personalized, agent-powered experiences that safely coordinate and complete care at scale. League builds security, privacy, and AI guardrails into its platform by design, meeting HIPAA, HITRUST, SOC 2 Type II, ISO 27001, and GDPR standards, and applying the NIST AI RMF to guide responsible AI use. Millions of people around the world use League to access, navigate, and manage their health every day. Learn more at league.com.

About CHAI

CHAI was started by clinicians. The coalition’s mission is to build the broadest possible consensus across the health ecosystem to help ensure health AI is trusted, secure and safe. The CHAI membership is open and rapidly expanding. Today, we consist of more than 3,000 members including health systems, patient advocacy groups, academia, and a wide range of industry start-ups and incumbents. CHAI is committed to convening and dialogue to achieve consensus. There are no limits to who can join and participate. Learn more about CHAI membership at chai.org/membership.

Intelligent care—in your inbox

Subscribe now to receive product updates and insights from League.