<?xml version="1.0"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.2 20190208//EN" "JATS-journalpublishing1.dtd"[]>
<article xml:lang="en" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" dtd-version="1.2" article-type="research-article">
<front>
<journal-meta>
<journal-id journal-id-type="publisher-id">IJPDS</journal-id>
<journal-title-group>
<journal-title>International Journal of Population Data Science</journal-title>
<abbrev-journal-title>IJPDS</abbrev-journal-title>
</journal-title-group>
<issn pub-type="epub">2399-4908</issn>
<publisher>
<publisher-name>Swansea University</publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="doi">10.23889/ijpds.v11i5.3646</article-id>
<article-id pub-id-type="publisher-id">11:5:3646</article-id>
<article-id pub-id-type="pii">S2399490821036466</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Population Data Science</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>How to safely RELEASE-AI models: a lifecycle framework for Trusted Research Environments</article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author"><name><surname>Crespi-Boixader</surname><given-names initials="A">Alba</given-names></name><xref ref-type="aff" rid="affil-1"><sup>1</sup></xref></contrib>
<contrib contrib-type="author"><name><surname>Li</surname><given-names initials="S">Simon</given-names></name><xref ref-type="aff" rid="affil-1"><sup>1</sup></xref></contrib>
<contrib contrib-type="author"><name><surname>Liley</surname><given-names initials="J">James</given-names></name><xref ref-type="aff" rid="affil-2"><sup>2</sup></xref></contrib>
<contrib contrib-type="author"><name><surname>Ward</surname><given-names initials="L">Laura</given-names></name><xref ref-type="aff" rid="affil-1"><sup>1</sup></xref></contrib>
<contrib contrib-type="author"><name><surname>Cole</surname><given-names initials="C">Christian</given-names></name><xref ref-type="aff" rid="affil-1"><sup>1</sup></xref></contrib>
<contrib contrib-type="author"><name><surname>Smith</surname><given-names initials="J">Jim</given-names></name><xref ref-type="aff" rid="affil-3"><sup>3</sup></xref></contrib>
<aff id="affil-1"><label>1</label><institution>University of Dundee, Dundee, United Kingdom</institution></aff>
<aff id="affil-2"><label>2</label><institution>University of Durham, Durham, United Kingdom</institution></aff>
<aff id="affil-3"><label>3</label><institution>University of the West of England, Bristol, United Kingdom</institution></aff>
</contrib-group>
<pub-date date-type="pub" publication-format="electronic"><day></day><month></month><year></year></pub-date>
<pub-date date-type="collection" publication-format="electronic"><year></year></pub-date>
<volume>11</volume>
<issue>5</issue>
<elocation-id>3646</elocation-id>
<permissions>
<license license-type="open-access" xlink:href="https://creativecommons.org/licenses/by-nc-nd/4.0/">
<license-p>This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.</license-p>
</license>
</permissions>
<self-uri xlink:href="https://ijpds.org/article/view/3646">This article is available from the IJPDS website at: https://ijpds.org/article/view/3646</self-uri>
<abstract>
<p>Trusted Research Environments (TREs) enable approved researchers to securely analyse personal data, including Electronic Health Records (EHRs), under strict governance. The accelerating use of Artificial Intelligence and Machine Learning in research with sensitive data, however, introduces novel privacy and disclosure risks that traditional statistical disclosure control methods cannot adequately address. This work presents a comprehensive framework for managing these risks throughout the full AI/ML project lifecycle within TREs. Organised across six phases—design, governance, development, evaluation, disclosure control, and release—the framework provides clear, phase-specific guidance and assigns explicit responsibilities to all involved parties: researchers, project teams, output checkers, data controllers, and TRE staff. The RELEASE-AI contains 28 practical statements, each allocated to a responsible role (e.g., researcher, TRE operator) and prioritised using a modified MoSCoW model (Must, Should, Could). This prioritisation enables proportionate implementation according to risk and resource constraints. The framework promotes early risk identification, proportionate mitigations, and good AI/ML practices, including robust code and documentation standards, privacy-enhancing techniques (e.g., differential privacy), restricted model access via secure query systems, licensing agreements, and pre-release adversarial testing. It emphasises role-specific training to ensure effective implementation. A novel tiering system for disclosure control is proposed, categorising AI projects based on the likelihood of attack and the severity of potential sensitive data leakage. By integrating a lifecycle-focused risk management process with this scalable disclosure control tiering system, the framework enables innovative AI research while maintaining rigorous data protection standards and sustaining public trust in the use of sensitive personal information.</p>
</abstract>
</article-meta>
</front>
</article>