A HUMAN IS ALWAYS THE DESTINATION

AI Safety

Bliss builds AI Twins trained on individual licensed practitioners. This page explains what they do, what they refuse to do, what happens when someone is at risk, and who is accountable when something goes wrong.

It is written against the WHO expert recommendations on responsible AI for mental health, published in March 2026.

Last updated 17 August 2026

Seven rules we build against

1

The twin supports care, it does not deliver it.

An AI Twin never diagnoses, never prescribes, and never makes a clinical decision. This is built into the base model, not added as a filter on top.

2

Nobody speaks in a practitioner's name without their sanction.

Every twin is trained, reviewed, tested and activated by the licensed practitioner it belongs to. They can switch it off at any moment.

3

Risk goes to a human, and we keep going until a human answers.

Escalation is not a notification that sits unread. It repeats until someone acknowledges it.

4

The twin moves people towards human care, never away from it.

Usage limits, session prompts and routing are designed so the twin is a bridge to a practitioner, not a replacement for one.

5

Care that does not fit the person is not safe care.

Language, culture and context are clinical safety factors, not preferences. A twin that misreads what a phrase means in someone's culture misreads the person.

6

The person owns their data, and the practitioner owns their expertise.

Nothing is used to train models without explicit consent. Practitioners keep their content and their voice.

7

We say what we have not finished.

Where a control is planned rather than live, we say so on this page.

The hard limits

  • Never diagnoses a condition.
  • Never prescribes or advises on medication.
  • Never makes or implies a clinical decision.
  • Never claims to be a human being.
  • Never claims to be the practitioner it was trained on.
  • Never discourages someone from booking a live session.
  • Never answers from sources the practitioner has not reviewed.
  • Never handles a crisis without alerting a named human.
  • Never continues after a practitioner deactivates it.
  • Never operates for anyone under 18.

Bliss AI Twins are for adults. WHO's expert group identified young people as the group most exposed to untested generative AI for emotional support, and we do not serve minors while the evidence base and the safeguards for that group are still being built.

What happens when someone is at risk

Every conversation is continuously classified against three levels of risk. Emergency resources are surfaced based on the person's own location and time zone, not on where our servers sit.

Level 1, low risk

Support, reflection and psychoeducation

The twin works as trained. The conversation is logged and included in the practitioner's daily summary.

Level 2, moderate risk

Holding responses, clinician notified

Triggered by implicit or explicit references to self harm, or by any phrase on the practitioner's own alert list. The twin moves into holding responses, and the responsible clinician is notified within 24 hours.

Level 3, high risk

Crisis protocol, human contact committed

The conversation is redirected to local emergency resources and the crisis protocol activates. The care team is paged every hour until a human acknowledges the alert. A human makes contact with the person within 24 hours, followed by a scheduled morning check in. The twin stays present in the conversation and continues to recheck the person's safety rather than ending the exchange.

Escalation routes are agreed with each clinic or hospital before deployment, so alerts arrive inside the on call structure your team already runs.

WHO's expert group identified the absence of agreed crisis referral frameworks as one of the urgent open problems in this field. We have published ours in full above rather than describing it in general terms, and we will share the underlying protocol with any clinical body, research group or regulator working towards a common standard.

The practitioner is in the loop, not behind glass

Full visibility. Practitioners can read every conversation their twin has, and receive a daily summary before their first appointment.

Correction. Any response can be rated up or down. Corrections change how the twin answers next time.

Limits set by the clinician. Daily usage caps per client, defined by the practitioner. Current clinical guidance is two short conversations a day.

Review before anything goes live. Every change to a twin's knowledge or behaviour passes a review and approval step. Nothing enters a twin unchecked.

An off switch that works immediately. Activation is optional and reversible. Deactivation takes effect at once.

Dual consent. A twin only becomes available to a client once both the practitioner and the client have consented. Clients are told clearly that they are talking to an AI Twin, before the first message.

Built by the people it was built for

Bliss did not start with a market. It started with a founder who moved country at 16 and could not find anyone who could hear her in her own language.

Every person who works on Bliss has lived some version of that: leaving a country, arriving somewhere the words do not quite fit, trying to explain something that only makes sense inside a culture you are no longer standing in. That is not a founding story we tell in pitches, it is why decisions get made the way they do. It is the reason the twin escalates rather than reassures, the reason it holds a boundary instead of being endlessly available, and the reason it works in 30 languages rather than translating from one.

Our clinical committee are practising psychotherapists and psychologists. Our practitioners test their own twins and correct them in daily use. And the people designing the system are the people who needed it.

WHO's expert group asks for tools co-designed with mental health experts and with people who have lived experience. We are describing both sides of that sentence, and we are continuing to widen it: design partner cohorts include service users alongside clinicians, and their feedback is treated as clinical evidence, not as product feedback.

A twin that cannot hear you cannot keep you safe

Risk does not sound the same in every language. Distress gets expressed through the body in some cultures and through mood in others. Shame around mental health changes what a person will say out loud, and to whom. A system trained on one culture's way of asking for help will miss the others.

Every Bliss twin works in the languages its practitioner works in, and inherits that practitioner's cultural frame rather than a default one. Risk classification is applied to the language the person is actually using, not to a translation of it. Emergency resources are the ones that exist where the person lives, in the language they will be answered in.

This is why Bliss matches on culture and language before anything else. It began as an access problem. It is also a safety one.

Designed against overuse, and measured for it

The risk with a supportive system available at every hour is that people lean on it instead of moving forward. WHO's expert group names emotional dependence as one of the long term outcomes the field is failing to measure. We treat it as a safety signal, not a usage metric, and we would rather lose engagement than create reliance.

Limits. Daily conversation caps are set by the practitioner. Current clinical guidance is two short conversations a day.

Boundaries that match the clinician's. The twin surfaces the practitioner's own boundaries rather than inventing softer ones.

Signals we watch. Rising conversation frequency, sessions that cluster at night, declining live session attendance alongside rising twin use, and language that positions the twin as the person's main source of support.

Where the signal goes. Straight into the practitioner's daily summary, so a clinician can act on it in the next session rather than discovering it months later.

Direction of travel. The twin routes towards booking a human session and never positions itself as the endpoint of care.

Six steps, four of them clinical

  1. 1

    Credentials. Licence and registration verified before any twin can be created.

  2. 2

    Clinical preferences. Modality, orientation, session structure and frameworks, set by the practitioner.

  3. 3

    An alert list. Words and phrases the twin must never use, and phrases that trigger an alert if a client raises them.

  4. 4

    Reviewed knowledge. Papers, protocols and materials uploaded by the practitioner, each reviewed before it goes live, and checked against the evidence base for that modality rather than accepted on upload.

  5. 5

    Testing by the practitioner. They talk to their own twin and correct it before any client can reach it.

  6. 6

    Activation, by choice. The twin becomes available only when the practitioner decides it sounds like them.

Your data, and what we do not do with it

Minimal collection. We collect what is needed to deliver care, and no more.

No training without consent. Conversations are not used to train models unless the person has explicitly agreed.

Residency by location. Data is stored according to the user's location, on Google Cloud infrastructure.

Export and deletion. Users can export their data or delete their account and its contents from within the product.

Practitioner ownership. A practitioner's frameworks, materials and voice remain theirs. If they leave Bliss, the twin does not stay behind.

Underlying models

Bliss twins run on Google's Gemini models through Vertex AI, configured for European data residency. We do not send conversation data to consumer AI products.

Measuring outcomes, not engagement

Most AI products in this space report usage. Usage tells you nothing about whether someone got better, and a rising number can mean the opposite.

Every Bliss design partner deployment is set up with outcome measures agreed before it starts: validated clinical measures appropriate to the setting, time from referral to first meaningful contact, attendance at live sessions, escalation frequency and how each escalation resolved, and the dependency signals described above. We agree what we are measuring before we can be tempted by what the data says.

We publish what we find, including where the twin did not help. Where a partner is a research or academic institution, we support independent analysis of their own data rather than reporting on ourselves.

Our regulatory position

GDPR. Compliant by design, with a documented data governance policy, processing records, and export and deletion tooling in the product.

EU AI Act. Bliss AI Twins are classified in the limited risk category, with transparency obligations met: users are told they are interacting with an AI system before they use it. We voluntarily apply several obligations that apply to higher risk categories, including human oversight, logging and post market monitoring.

Not a medical device. AI Twins do not diagnose, treat, prevent or monitor disease, and are not placed on the market as a medical device. Clinical decisions remain with licensed practitioners.

HIPAA. Our practices align with HIPAA requirements today. Formal certification is expected in 2027.

Professional regulation. Every practitioner on Bliss holds a valid licence in their own jurisdiction, and remains bound by their professional body's code of conduct. A twin does not change what its practitioner is licensed to do.

The WHO recommendations, and what we do about each one

In March 2026, WHO published the conclusions of an expert workshop convened by the Delft Digital Ethics Centre at TU Delft, the first WHO Collaborating Centre on AI for health governance. Three recommendations came out of it. They are not a certification scheme, and nobody can claim to be certified against them. They are the clearest statement so far of what responsible AI in mental health should look like, so we build against them and we report against them here.

Recommendation one: treat generative AI use as a public mental health concern, across all generative AI tools and not only those built for mental health.

Response: The concern behind this recommendation is people turning to general purpose AI, built and tested for other things, in moments of real distress. Bliss exists as the alternative to that. Every twin belongs to a licensed practitioner, is built on a clinical base model that refuses to diagnose or prescribe, and escalates to a named human. We also accept the wider point: this is a public health matter and not a product category, which is why we publish our escalation protocol openly rather than treating it as intellectual property.

Recommendation two: build mental health into impact assessment and monitoring, covering short term measures and long term outcomes such as emotional dependence.

Response: Every deployment carries agreed outcome measures, set before launch. Emotional dependence is monitored explicitly, with defined signals routed to the responsible clinician. We publish findings, including negative ones, and we support independent analysis where partners can run it. Where this work is still being built out, it is listed in the open items below.

Recommendation three: co-design with mental health experts and people with lived experience including youth, ground the tool in the best available evidence, and tailor it to cultural, linguistic and contextual factors.

Response: Co-design with experts: clinical governance sits with our clinical committee of practising psychotherapists and psychologists, and every twin is built and corrected by the licensed practitioner who owns it. Co-design with lived experience: the team building Bliss are people who needed it, and design partner cohorts include service users. Evidence: uploaded knowledge is reviewed against the evidence base for that modality before it goes live. Culture and language: twins operate in the practitioner's own languages and cultural frame, risk is classified in the language the person actually used, and emergency resources are local to them. Youth: Bliss AI Twins are not available to anyone under 18.

Read the WHO summary of the recommendations.

Clinical team

Clinical governance at Bliss is led by our clinical committee, senior licensed psychotherapists and psychologists who own the AI Protocol covering the clinical, ethical and practical rules every twin operates under. Escalation design, risk classification and the review process all sit with the clinical team, not with engineering.

What we do before anything reaches a patient

Every practitioner tests their own twin before activation. All development happens in a separate environment from live care. Escalation and crisis flows are tested manually by our clinical team, because those paths cannot be validated with synthetic data. Conversations are reviewed continuously by the practitioners who own them, and every rating and correction feeds our monitoring.

Open items

We would rather list these and be transparent.

  • HIPAA certification is in progress, expected in 2027.
  • Formal EU AI Act conformity documentation is being completed with external review.
  • Independent evaluation of clinical outcomes. Our measurement framework is defined and running with design partners. Independent analysis by an external research partner is not yet in place, and we are seeking one.
  • The AI Twin is in clinical testing with design partners and is not yet generally available.
  • Voice and text are supported today. Avatar interaction is on the roadmap and will go through the same clinical review before release.

This page is updated as each item closes.

If something goes wrong, tell us

If you are a practitioner, a client, or a clinical partner and you believe a twin has responded unsafely, inaccurately or outside its limits, contact us at info@bliss.al. We acknowledge every report and tell you what we did about it.

If you or someone else is in immediate danger, contact your local emergency services.