To label AI-generated content and preserve output provenance in ABA, show people where AI materially shaped a draft, recommendation, message, or action and what human review occurred. Retain a durable chain from input and source evidence through model, prompt, retrieval, output, edits, approval, final record, and downstream use. Design labels for the audience and decision; metadata alone cannot prove truth, authorship, consent, or safety.
Define which involvement is material
Quinn distinguishes spellcheck and formatting from generated facts, summaries, reasoning, recommendations, translations, images, extracted values, or automated actions. The practice defines when AI involvement could change a person's understanding, a professional judgment, a record, a payer submission, a claim, or another consequential outcome. Labels should answer the user's real question: what the system did, what evidence it used, who reviewed it, and who owns the final decision.
Use audience-specific labels
A clinician may need model and source details; a family may need plain language explaining that a draft used AI and a named professional reviewed it; an auditor may need versioned provenance. Put the label where the output is read or acted upon; a distant policy is insufficient. Preserve accessible display, language support, and a correction or question route. Do not use a label to transfer responsibility to the client or to imply that human review occurred when it did not.
Preserve the provenance chain
Record use-case ID, purpose, target person and record, requester, input references, retrieved sources and versions, vendor, model, configuration, prompt template, tool calls, timestamp, raw output, uncertainty or abstention, reviewer identity and role, edits, approval, final artifact, downstream transaction, correction, and incident link. Store only the sensitive content needed for the approved purpose, with access and retention controls. A hash can show that an artifact stayed unchanged; it cannot prove the artifact was correct or authorized.
Protect provenance records as sensitive evidence
A provenance log can reveal PHI, prompts, clinical facts, reviewer identity, vendor details, security controls, and incident history. Include it in the practice's ePHI risk analysis when HIPAA applies, restrict fields and access to the approved purpose, and set retention by the actual record and authority. An audit need does not justify copying every raw prompt forever. Preserve enough evidence to reconstruct the material action while minimizing secondary exposure.
Understand technical provenance limits
NIST AI 100-4 reviews techniques such as content authentication and provenance tracking and explains that metadata can be removed, altered, or falsified. Signed metadata can help show who attested to information and whether it changed, yet it does not establish factual accuracy, consent, clinical validity, or lawful use. Use technical signals with source evidence, identity, access, human review, and audit controls.
Keep authorship and approval explicit
A clinician who uses AI in documentation remains responsible for the permitted clinical record within scope. Coding, billing, payer, privacy, security, workforce, finance, and legal owners decide their respective actions. The log distinguishes generated text, human edits, and the signed or approved final artifact. AI provenance does not replace required signatures, late-entry or correction rules, representative authority, informed consent, assent, or payer evidence.
Prevent label loss downstream
Test copy and paste, PDF export, print, API transfer, portal display, email, data warehouse, claim attachment, and record amendment. Decide which provenance travels with the artifact and which remains in a secure internal log. When an external format cannot carry the full history, preserve a durable reference and provide the audience-appropriate disclosure. A summary created from another AI output should link both generations, not reset the chain.
Work through an output inventory
Quinn locks 40 fictional AI-assisted outputs across records, payer work, staff tools, and family messages. Thirty-one retain the required label, sources, versions, raw output, human edits, approval, final artifact, and downstream reference: 31 of 40, or 77.5%. Three labels disappear on export, two outputs lose source versions, one log cannot distinguish human edits, one message claims review that did not occur, and two downstream copies have no durable reference.
Audit provenance quality
Report material outputs due, labeled, source-linked, version-linked, reviewer-linked, downstream-linked, corrected, and unresolved. Sample whether labels are visible and understandable to their audience. Test whether staff can reconstruct a final artifact after a complaint, incident, payer question, or model change. The NIST Generative AI Profile discusses confabulation and content-provenance risks, but this practice-specific chain still needs deployed verification.
Use these design questions
- Which AI contribution can change a decision or person's understanding?
- What must the reader know at the point of use?
- Can the practice reconstruct source, model, prompt, edits, and approval?
- What provenance survives export and copying?
- Who owns correction when a label or source is wrong?
- Which evidence is retained without over-collecting PHI?
Carry provenance through ordinary exports
Test copy and paste, PDF export, portal display, email, fax, API transfer, print, screenshot, and downstream editing. Decide which provenance fields must remain visible to the recipient and which sensitive technical details belong in a restricted audit record. A short disclosure may explain that AI assisted a draft, while the internal chain preserves model, configuration, sources, reviewer, edits, approval, and final action.
Use durable identifiers to link the visible artifact with its provenance record. If a user removes the label, the system should either prevent the action for that workflow, warn and record it, or route the output to a different approved state. Avoid relying on color, icons, or metadata that common export routes strip without notice.
Respond when provenance is incomplete
Missing provenance produces a specific hold or review state. Determine whether the output can be reconstructed from logs and source records, whether a qualified person can independently verify it, and which downstream recipients or decisions may be affected. Do not infer authorship, source support, or approval from the text's quality or from a filename.
If the artifact must be retained, mark the provenance limitation and the corrective action. If it influenced a signed record, claim, message, or other consequential work, reconcile that use under the governing process. Close the finding only after the practice has addressed both the missing evidence and the downstream effect.
Separate disclosure from accountability
A label tells a reader that AI had a role; it does not transfer responsibility to the model or vendor. The qualified author and approver remain attributable for the final clinical, business, payer, privacy, employment, or legal action. State which portions were generated, transformed, summarized, or merely checked so the disclosure is informative rather than a blanket disclaimer.
Test whether intended readers understand the label and can reach the source or correction route they need. Include screen-reader output, print, mobile display, translated content, and exported files. Ask users what they believe the label says about accuracy, authorship, approval, and recourse. Revise wording that implies a guarantee or leaves people unsure who is responsible for the final record or action.
Related resources
- Route ABA AI Work Across Models and Providers Safely
- Validate Speech-to-Text and AI Transcription for ABA Operations
- Control ABA AI Cost, Token, Quota, and Capacity Risk
- Validate AI Document Extraction and OCR for ABA Intake and Payer Work
Sources
- Council of Autism Service Providers, Organizational Guidelines public overview
- National Institute of Standards and Technology, AI Risk Management Framework
- National Institute of Standards and Technology, Generative AI Profile
- National Institute of Standards and Technology, Reducing Risks Posed by Synthetic Content
- U.S. Department of Health and Human Services, Guidance on Risk Analysis