Healthcare AI Governance: Why It Must Evolve With AI

Why healthcare organizations need governance that can adapt as AI capabilities, authority, and risk change
Healthcare organizations are moving quickly to establish policies for artificial intelligence. That is necessary, but a policy written today cannot anticipate every capability an AI system may have six months or a year from now. A tool that begins as a documentation assistant may later generate recommendations, access additional data, interact with other applications, or initiate actions through an agentic workflow. The organization may still think of it as the same technology, while the risk associated with using it has materially changed.
After more than four decades working in healthcare compliance, auditing, coding, revenue integrity, and regulatory risk, I have seen this pattern many times. Effective compliance has never depended on writing a policy and assuming the risk is therefore controlled. Organizations assess risk, establish controls, educate their workforce, audit performance, monitor activity, investigate problems, implement corrective action, and reassess when circumstances change. AI governance needs to follow that same discipline, with one important difference: AI can change much faster than a traditional policy-review cycle.
A Policy Is Only the Starting Point
An AI policy has an important role. It establishes expectations and defines organizational requirements, but it does not demonstrate that those requirements are being followed. It also cannot anticipate capabilities that did not exist when the policy was approved.
Consider an AI platform initially approved for administrative use. At implementation, it may retrieve information, summarize documents, or help an employee draft content. A later vendor update may allow the system to analyze records, make recommendations, connect with another application, or initiate a workflow. The original approval may have been appropriate when the system was evaluated, but the technology being used by the organization has now changed.
That is where governance has to move beyond the policy. The organization needs a way to recognize meaningful changes in AI capability and determine whether the original risk assessment and controls still apply. The policy remains part of the framework, but the real work happens through risk assessment, controls, monitoring, change management, accountability, and reassessment.
This is why I believe healthcare organizations need to think about AI governance as an operating capability rather than a document that is reviewed periodically and placed back on the shelf.
Build the Brakes Before You Need Them
One principle I return to repeatedly in my AI governance work is simple: build the brakes before you need them.
Before an organization gives AI meaningful authority within a healthcare workflow, it should establish appropriate boundaries, human oversight, escalation pathways, approval requirements, auditability, monitoring, and the ability to intervene or stop a process when necessary.
But the brakes themselves need to be evaluated as the technology changes.
A control that was appropriate when AI was simply assisting an employee may not be adequate when the system begins making recommendations. A review process designed for recommendations may not be sufficient when an AI agent can execute an action. As capability and authority increase, the organization needs to determine whether its controls can still prevent, detect, and correct unwanted outcomes.
I think about this through a progression I call Assist → Recommend → Decide → Act. At the Assist level, AI may retrieve information, organize data, summarize documentation, or help someone complete a task. At the Recommend level, AI begins influencing professional judgment by identifying a potential code, flagging a compliance issue, prioritizing a case, or suggesting an action. At the Decide level, the system may determine an outcome within defined parameters. At the Act level, agentic AI may execute a decision, initiate a workflow, communicate with another party, or interact with another system.
Those are fundamentally different risk environments. As AI moves toward decision-making and action, questions of authority, accountability, traceability, reversibility, and human intervention become more important. The organization needs to know not only what the system can do, but what it is authorized to do.
Capability is not authority. That distinction becomes especially important in healthcare because the consequences of an incorrect recommendation or action can extend well beyond the technology itself. A system may be capable of taking an action, but that does not mean the organization should permit it to do so without appropriate review, approval, or controls.
The Risk Changes as AI Changes
Consider coding. An AI system may begin by retrieving applicable coding guidance for a professional. It may then analyze documentation and recommend a code. A more advanced system could determine a code within established parameters, while an increasingly autonomous workflow could potentially modify information or move a claim toward submission.
Each step creates a different compliance concern. At the first level, the primary question may be whether the information being retrieved is accurate and current. At the recommendation level, the organization needs validation, professional review, and source traceability. At the decision or action level, additional controls may be needed around authority, approval, audit trails, error correction, and the ability to stop or reverse the process.
The same progression can occur in compliance monitoring. AI may initially monitor CMS, OIG, state agencies, or payer guidance and summarize relevant changes. It may later identify potential organizational impact, prioritize issues, or recommend corrective action. An agentic system could eventually initiate portions of a corrective workflow.
The value may increase as the capability increases. So does the consequence of failure. The question cannot simply be, “Can AI do this?” The organization also needs to ask, “Are we prepared to govern AI doing this?”
That question becomes even more important when the change comes from a vendor rather than from the organization itself.
Healthcare organizations are accustomed to treating software updates as technology events. With AI, a vendor update can also be a governance event. A new model may change system behavior. A new integration may expand the information available to the system. A new feature may move the technology from generating information to initiating an action. Any of those changes can alter the organization's risk profile.
The organization does not need to reassess every minor software change. It does need a process for identifying material changes and determining when they require review. That review should consider whether the system's intended use has changed, whether access to data or systems has expanded, whether its level of autonomy has increased, whether new workflows or integrations have been introduced, and whether existing human-review requirements are still appropriate.
Without that process, an organization can remain technically current while its risk assessment and controls quietly fall behind.
Monitoring Has to Be Part of the Model
This is where healthcare compliance professionals have an important role. We already understand that a control must be tested to determine whether it is working. AI should be treated the same way.
Monitoring should be appropriate to the use case, the level of risk, and the authority given to the system. Depending on the workflow, that may include output accuracy, source integrity, unexpected results, exceptions, human overrides, escalations, system performance, vendor changes, incidents, and near misses. The measures should be tied to the actual risk rather than created simply because a dashboard is available.
Scale is particularly important. One incorrect AI recommendation may be an isolated event. The same error repeated across thousands of transactions can become a significant compliance, financial, operational, or patient-impact issue before anyone recognizes the pattern.
Scale changes the consequence of error.
Monitoring should therefore provide enough evidence to determine whether the technology is operating within its approved boundaries and whether the controls around it are still working. When something meaningful changes, the organization should be prepared to reassess the risk rather than waiting for an incident to force the issue.
I think about that process as Inventory → Risk-Tier → Control → Monitor → Detect Change → Reassess → Adapt. The organization first needs to know where AI is being used and what role it plays within each workflow. It can then establish controls appropriate to the risk and monitor whether those controls remain effective. When the technology, data, vendor, workflow, model, integration, or organizational use changes in a meaningful way, the assessment begins again.
That is what makes AI governance adaptive. Change should trigger attention.
When AI Fails, Look Beyond the Output
When monitoring identifies an AI-related problem, organizations should resist the temptation to conclude simply that “the AI got it wrong.” That describes the result, but not the cause.
Was the source outdated? Was the data incomplete? Did the underlying model change? Did the workflow expand beyond its approved purpose? Did an integration introduce unexpected information? Did a user over-rely on the recommendation? Did an escalation threshold fail? Was the control itself poorly designed?
These are familiar compliance questions because they are the foundation of root-cause analysis. Once the organization understands the underlying cause, it can develop a Corrective Action Plan, implement the necessary changes, and monitor again to determine whether the corrective action worked.
AI does not make these disciplines less relevant. It makes them more important because an AI-related problem can be repeated at scale before the organization recognizes the pattern. The goal is not simply to correct an incorrect output. It is to determine why the control environment allowed the failure to occur and whether the same failure could happen again.
Build Governance That Can Adapt
Healthcare organizations should not respond to AI risk by creating a governance process so complicated that responsible use becomes impractical. A process that requires months of review for every low-risk use case will not necessarily create better oversight. It may simply encourage workarounds and shadow AI use.
The better approach is proportional. A low-risk administrative use may require basic approval, appropriate data protections, and workforce guidance. AI influencing coding, reimbursement, clinical decisions, compliance determinations, or other consequential processes should require substantially stronger controls, monitoring, human authority, and documentation.
Organizations do not need to solve every future AI scenario before they begin. They need a structure capable of learning from experience and adapting as the technology changes.
That brings me back to the question I believe healthcare leaders should be asking. Not simply, “Do we have an AI policy?” but, “Do we know where AI is operating, what authority it has, how that authority is controlled, and what happens when the technology changes?”
Leaders should be able to determine whether consequential AI-supported decisions can be reconstructed, whether someone can intervene when necessary, whether system performance is being monitored, and whether there is evidence that the controls are actually working.
The policy establishes expectations. The operating model puts those expectations into practice through risk assessment, controls, monitoring, accountability, escalation, corrective action, and reassessment. That is how an organization keeps its governance connected to the technology it is actually using.
Healthcare has spent decades developing these compliance disciplines. We now need to apply them to artificial intelligence in a way that recognizes the technology's ability to change rapidly and operate at scale.
Don't wait for perfection. But don't scale chaos.
Build the brakes before you need them. Then test them, monitor them, and strengthen them as the technology evolves.
Your AI policy may become outdated. Your governance model should be designed to adapt.







