Health sovereignty is usually discussed as a question of privacy. Who holds the record. Who can inspect it. Who profits from its reuse. These are serious matters, but by mid-2026 they no longer describe the sharpest edge of the problem. As machine-learning systems move from back-office triage and workflow support into diagnosis, mental-health monitoring, medication management and longevity-oriented prevention, the more difficult issue is whether a patient can leave. Not leave care altogether, but exit a particular algorithmic regime without losing continuity, intelligibility or practical safety.
This is a less fashionable thesis than familiar arguments about surveillance, yet it is arguably more consequential. A person may technically possess rights over data access and still be trapped inside a clinical stack whose recommendations, alerts, risk scores and care pathways are not portable in any meaningful sense. The decisive issue is not merely who can see the record, but whether a patient can leave a decision system without clinical penalty.
Why exit matters now
In older health IT, lock-in was mostly administrative. Switching providers or software could be cumbersome, expensive and error-prone. In AI medicine, lock-in becomes epistemic. Models infer risk from data patterns, generate summaries, rank likely diagnoses, flag mental-health deterioration, predict adverse events and shape which human decisions appear normal or prudent. If those inferences cannot be translated, audited or challenged across settings, the patient is not simply carrying a file from one institution to another. They are attempting to migrate an entire interpretive layer.
This matters especially in long-horizon care: cancer survivorship, metabolic disease, fertility treatment, neurodegeneration, psychiatry, and the new market for longevity services built around dense monitoring. In these domains, what accumulates over time is not only a list of encounters but a chain of model-mediated judgments. The patient’s future treatment may depend on how previous systems defined adherence, relapse risk, frailty, resilience or biological age.
The sovereign unit is continuity, not the database
Policy discussions often imagine data sovereignty as control over an asset. That frame is too static for medicine. A medical life is a moving process, and its most valuable property is continuity under conditions of uncertainty. For a patient, the practical question is not whether a laboratory result can be downloaded as a file, but whether a new clinician can reconstruct enough context to safely continue treatment without inheriting opaque assumptions from the old system.
The sovereign unit in medicine is not the file but the continuity of care. This is why the right to access records, important though it is, cannot on its own guarantee autonomy. A record export that omits model provenance, threshold settings, confidence intervals, device calibration histories, alert logic, or the rationale for care-plan changes may satisfy a formal requirement while failing the substantive test of safe transfer.
The sovereign unit in medicine is not the file but the continuity of care.
From interoperability to reversibility
The decisive issue is not merely who can see the record, but whether a patient can leave a decision system without clinical penalty.
Health systems have spent years discussing interoperability, and rightly so. The European Health Data Space, OECD work on patient access, the WHO digital health strategy and rules in the United States against information blocking all push in the direction of greater data mobility. Yet interoperability is not identical to reversibility. A system may exchange documents perfectly well while still making departure costly because the receiving side cannot reproduce the sending side’s model-based interpretations.
Reversibility is a stronger standard. It asks whether a patient can stop using one AI-mediated service, or one provider ecosystem, and enter another without dangerous information loss, distorted baselines or hidden behavioural penalties. In practical terms, reversibility requires not just transportable data fields but transportable context: which model version shaped a recommendation, what training limitations were known, when a risk score materially changed, and whether a human overrode the system.
Mental wellness shows the problem in miniature
Mental health is where this issue becomes unusually vivid. Digital phenotyping, passive sensing, chatbot-assisted therapy, suicide-risk flagging and relapse prediction all depend on intimate behavioural traces gathered over long periods. These systems do not simply store what a patient said in a consultation. They create secondary interpretations about sleep irregularity, social withdrawal, linguistic markers, medication adherence or mood volatility.
If a person seeks to withdraw from one monitoring arrangement, perhaps because it feels intrusive or because trust has broken down, the clinical consequences are delicate. A new clinician needs enough information to avoid abrupt discontinuity, but not a sealed black box whose internal categories become unquestioned truth. In psychiatry, categories can harden quickly. A proprietary or institution-specific risk label can follow a person into future care even when its basis is contestable, culturally narrow or stale.
The same difficulty appears in workplace-linked wellness programmes, student mental-health systems and insurer-adjacent preventive services. The nominal service may be therapeutic, but the infrastructure creates dependency on a particular interpretive environment. Once again, the central liberty is not abstraction about data ownership. It is the lived ability to say no, leave, and still remain legible to the next caregiver.
Longevity medicine adds temporal lock-in
Longevity technologies intensify the problem because they stretch medical interpretation across years rather than episodes. Biological age estimates, multi-omic profiles, continuous glucose traces, sleep and activity streams, cardiovascular wearables, imaging archives and consumer biomarker panels can produce elaborate personal baselines. Many are clinically useful in narrow contexts. But once assembled into a personalised prevention regime, they form a cumulative model of the self that is difficult to transfer responsibly.
A patient who leaves one longevity-oriented platform may receive an export of measurements while losing the practical meaning of those measurements inside the originating system. Which trend mattered. Which anomaly was dismissed as artefact. Which interventions were recommended because the model weighted family history over current physiology. Which assumptions underpinned a claim of accelerated ageing. The portability of numbers is not the portability of care.
There is also a political dimension. Longitudinal preventive medicine may become the most data-intensive layer of healthcare while remaining only partially embedded in public institutions. If exit rights are weak here, a parallel medicine emerges in which individuals can technically access their own readings but cannot realistically escape the analytical framework that turned those readings into life advice.
A health system that cannot be exited is not merely inconvenient; it is politically and medically brittle.
The legal architecture is necessary but incomplete
Europe has moved furthest in articulating a public framework for health data sharing and high-risk AI obligations. The European Health Data Space aims to make primary use of health data easier for patients and secondary use more structured across the Union. The AI Act imposes duties on certain high-risk systems around risk management, documentation and human oversight. The Data Governance Act seeks trusted conditions for data re-use. Together, these are substantial steps.
But none fully resolves the exit problem because law can mandate access more readily than intelligible transfer. A patient may gain electronic access to records and still lack the metadata necessary to re-establish care under a different analytical regime. Similarly, transparency obligations may explain a system in general terms while leaving the individual migration path obscure. The right to obtain one’s data is not yet the right to depart with one’s clinically relevant context intact.
American policy offers a parallel lesson. Anti-information-blocking rules and application programming interfaces have improved data access. Yet easier retrieval does not by itself produce substitutability between algorithmic services. In economic terms, the barrier is not only switching cost but translation cost: the difficulty of re-encoding one institution’s AI-shaped patient narrative into another’s clinical grammar.
A health system that cannot be exited is not merely inconvenient; it is politically and medically brittle.
What an exit right would contain
An exit right in AI medicine would be more demanding than a download button. It would include at least five elements. First, data portability in structured, widely used clinical formats. Second, provenance records showing where crucial outputs came from: model version, input window, device source, update date, and whether the result was generated automatically or after human review. Third, clinically meaningful summaries written for receiving professionals, not just machine exchange. Fourth, disclosure of unresolved uncertainty, including known performance limitations across populations. Fifth, the ability to pause or terminate monitoring without forfeiting access to prior records or being silently downgraded in future service eligibility.
None of this requires revealing trade secrets in the simplistic sense sometimes invoked in these debates. It requires separating legitimate protection of intellectual work from illegitimate dependence created by opacity. The standard should be functional: can another competent clinician or service continue care safely and critically, without blind deference to the previous system’s outputs.
Explainability is not enough
The literature on explanation in algorithmic decision-making has shown that the demand for a single neat explanation is often misplaced. In medicine, this is doubly true. A patient seldom needs a philosophical account of model internals. What is needed is transferability of consequence. Which findings altered the treatment path. Which alerts were ignored and why. Which inputs are likely to have been noisy. Which recommendations rested on population-level correlations rather than patient-specific causal evidence.
The sovereign unit in medicine is not the file but the continuity of care.
In this sense, exit is a more operational concept than explanation. It tests whether the informational environment around a patient has been documented well enough to support independent continuation of care. A system can be superficially explainable and still impossible to leave. Conversely, a technically complex model may be compatible with sovereignty if its outputs are carefully contextualised for migration and review.
Why this matters for public resilience
Exit rights are not only about individual liberty. They are also about system resilience. Health infrastructures fail, vendors disappear, standards drift, public procurement changes, cyber incidents occur and institutions merge. In mental-health services, social care and ageing populations, patients may depend on long-lived digital records whose analytic wrappers outlast the organisations that created them. A system built on non-reversible dependencies accumulates clinical fragility over time.
This has strategic implications for states seeking to reduce overdependence on concentrated digital intermediaries. Sovereignty in health cannot mean simply hosting data within a jurisdiction while accepting that clinical meaning remains non-transferable across tools and institutions. Public capacity requires the ability to unwind and replace components without compromising care. That is as true for regional hospitals as for national data spaces.
The quiet ethics of refusal
There is also an underappreciated moral question. Patients do not only need rights when they consent. They need rights when they refuse. Someone may reject continuous mood tracking, decline a predictive frailty score, or wish to discontinue a longevity subscription built on incessant measurement. If exit brings medical suspicion, administrative friction or a degradation of future care quality, then consent was never fully free.
This is particularly salient in behavioural and preventive medicine, where the rhetoric of empowerment can mask a shift toward perpetual observability. Refusal should not require becoming clinically invisible. A humane digital health order would preserve care pathways for those who opt out of intensive inference while still enabling their records to travel and their histories to remain coherent.
A different metric for progress
For the past decade, health AI progress has often been measured by adoption, accuracy and scale. Those are incomplete metrics. A mature system should also be judged by how gracefully a patient can disengage from it. Can the individual carry forward not only documents, but medically relevant meaning. Can a new professional reassess prior machine judgments rather than simply inherit them. Can care continue when trust in a specific platform ends.
These are not marginal governance details. They cut to the political economy of future medicine. If predictive healthcare, mental-wellness monitoring and longevity management become inescapable analytical environments, then personal health data sovereignty will have failed on its own terms. A person does not become sovereign because a portal allows export of thousands of measurements. Sovereignty exists when departure is possible, comprehensible and safe.
That is the harder standard now coming into view. In AI medicine, the right to be informed and the right to access matter greatly. But the right that may ultimately determine whether digital healthcare remains compatible with autonomy is the right to exit with one’s continuity intact.



