NOXBlog
AI Safety

How Leo Works

Illustration for How Leo Works

Leo is Nox’s medical-safety guardian. It screens health conversations for acute clinical red flags before an AI-generated answer appears, so potentially urgent guidance can be shown first. Leo is a safety net, not a diagnosis tool or a guarantee that every emergency will be identified.

What is Leo in Nox?

Leo is the user-facing name for Nox’s layered medical-safety system. Its job is to look for signs that a message may describe an acute emergency or urgent health concern, rather than leaving that judgment entirely to a conversational AI response.

This matters because people do not always describe serious symptoms in neat, clinical language. They may use slang, describe a change indirectly, write in another language, or mention several symptoms across a conversation. Leo is designed to screen those messages before Nox responds with regular health information.

For a closer look at the kinds of concerns involved, see What Are Medical Red Flags?.

How does Leo screen a health conversation?

Leo begins with an independent, deterministic detection layer. “Deterministic” means it uses fixed rules: given the same message, the same applicable rule produces the same result. This first screen runs before any AI model is called.

The deterministic layer includes more than 100 rules across over 70 acute red-flag categories, with multilingual coverage. Categories include stroke signs, chest pain and cardiac symptoms, severe breathing difficulty, severe allergic reactions, trauma and severe bleeding, mental-health crisis, pregnancy warning signs, concerning symptoms in children, environmental emergencies, and toxicology or overdose.

When a rule is triggered, Nox shows a clear emergency or urgent-care banner before any AI-generated content. The sequence is intentional: the safety guidance is not an afterthought added at the end of an answer, nor does it depend on an AI response deciding to mention it.

Leo does not diagnose the cause of a symptom. It identifies language that may warrant immediate attention and surfaces guidance to seek appropriate care. If you think you or someone else may be experiencing an emergency, contact local emergency services right away.

What happens when the first screen finds a red flag?

When Leo’s deterministic screen recognizes a possible acute red flag, Nox places the safety guidance ahead of the normal conversational response. That gives the person reading the chat an immediate, visible signal that the situation may need urgent or emergency care.

If a region has been set in Nox’s settings, Leo’s banner displays the relevant local emergency number. If the region is unknown, Nox falls back to universal emergency numbers—911, 999, or 112—so the guidance is not left blank.

This design is meant to make urgent direction clear even when someone is stressed, rushed, or uncertain how to describe what is happening. It is still important not to wait for any app when a situation seems life-threatening: contact local emergency services.

You can read more about the response sequence in What Happens When Leo Detects an Emergency?.

Why does Leo have an AI backstop?

Fixed rules are useful because they are consistent and measurable, but people do not always use the exact words a rule anticipates. A person might use an older disease name, informal phrasing, an indirect description, or another language.

When the deterministic layer finds no match, a lightweight AI classifier can re-read recent messages in the background to look for dangerous descriptions that fixed patterns may miss. If it recognizes a likely emergency, Nox presents the same type of seek-care guidance that a deterministic pattern match would trigger.

The order and limits here are important. The AI backstop can add a safety note, but it cannot remove, weaken, or soften a warning already produced by the deterministic layer. Its results are also kept separate from the published deterministic-detector metrics because it is not deterministic.

This is one reason health AI safety is more than getting an answer that sounds plausible. Why High Model Accuracy Is Not Enough for Health AI explores the difference between a broadly capable answer and a system designed to recognize when an answer should not come first.

Can you choose how strict Leo is?

Yes. Leo’s screening level can be selected from a control in the chat box, and the choice is available on every plan. The three levels run from least to most protective: Relaxed, Standard, and Strict.

Relaxed warns about clear emergencies only. Standard also warns about concerns that may be urgent. Strict adds the AI backstop that reviews recent messages for dangerous descriptions expressed indirectly or in another language.

No matter which level you choose, Leo continues to screen for true emergencies. The level changes how many optional safety layers run in addition to that core emergency screening. Agent and voice conversations always use the strictest setting.

The purpose of this control is not to ask users to make a medical judgment for themselves. It gives them a way to decide how broadly they want Leo to flag possible concerns while preserving emergency screening in every setting.

How is Leo’s performance measured?

Nox measures the deterministic detector’s overall recall and false-positive rate against a maintained test set. A high-level summary of those results is published on the Nox Trust & Transparency page.

Recall describes how often a system identifies relevant cases within the test set. A false-positive rate describes how often it flags something that does not meet the test set’s red-flag criteria. Both matter in a safety system: missing a serious concern can be harmful, while unnecessary alarms can also create stress and confusion.

Published metrics do not turn Leo into a guarantee. No automated system catches every emergency, and Nox does not claim that Leo does. If symptoms are severe, sudden, worsening, or concerning to you, seek guidance from a qualified clinician; for a possible emergency, contact local emergency services.

Why Leo shows guidance instead of diagnosing

A health conversation can be useful for explaining terms, helping someone organize questions, or clarifying when professional care may be appropriate. But it cannot replace an in-person assessment, emergency services, or a clinician’s judgment.

Leo is designed around that boundary. When it recognizes language associated with an acute red flag, its role is to surface urgent direction before the conversation continues—not to identify a condition, predict an outcome, or tell someone what treatment they need.

That distinction is central to a safer approach to health AI. Learn more in Why Health AI Should Escalate Instead of Diagnose.

Common questions

Does Leo read every message before Nox answers?

Leo’s deterministic red-flag screen checks messages before any AI model is called. Depending on the selected safety level, additional screening layers may also run.

Can Leo understand slang or another language?

The deterministic layer has multilingual coverage. On Strict, an additional AI classifier can review recent messages for indirect wording, slang, older disease names, or descriptions in another language that fixed patterns may not catch.

Does Leo always show the correct emergency number?

When you set your region in Nox’s settings, Leo shows that region’s local emergency number. If no region is known, it uses universal fallback numbers: 911, 999, or 112.

Is Leo a replacement for emergency care?

No. Leo is a safety feature within an educational health companion, not emergency care or a clinical diagnosis system. If you believe there may be an emergency, contact local emergency services immediately.

A note from the Nox team: This article is for education and general understanding only — not medical advice. Wearable metrics vary between individuals. For questions about your own health, please talk to a qualified clinician. If you think you may be experiencing an emergency, contact your local emergency services immediately.
Have a question about your own data?
Ask Nox — it reads your trends and explains them in plain language.
Open Nox