Somerville, Mass.-based Mass General Brigham has spent the past three years building out how it governs AI, and the system’s technology chief said the arrival of agentic AI — tools capable of acting rather than just generating text — is pushing her toward a more restrictive stance sooner than she expected.
Mass General Brigham Chief Information and Digital Officer Jane Moran discussed the shift in an interview with Becker’s at the World Medical Innovation Forum in Boston, minutes after appearing on a panel about agentic AI alongside executives from Bank of America and Philips.
The panel conversation started out “a little doom and gloom,” Ms. Moran said, because the last year in healthcare AI has moved “like a hockey stick” in terms of how urgently organizations are trying to prevent bad outcomes. Stopping every risk, she said, is “almost nearly impossible.”
Still, she and her fellow panelists converged on the same prescription: Break problems down by risk profile, and keep educating employees under an assumption of positive intent.
“We need to do AI at scale at MGB, and so how do we enable people to use AI in a safe and secure way?” Ms. Moran said.
That governance has moved through overlapping phases. Mass General Brigham had no formal AI governance three years ago, Ms. Moran said. What she calls “governance 1.0” began in 2024 and centered on standards — which tools employees could use, and how. That gave way to risk frameworks, or “2.0.” The system is now in what she calls “3.0,” a more strategic phase focused on where to concentrate AI investment rather than letting adoption spread unchecked.
“Not 1,000 flowers blooming,” she said, “but shouldn’t we … converge in all different areas.” Those areas could include clinical operations, research or business operations, she said, adding: “Shouldn’t we really start to look and prioritize those things that would give us more benefit to the organization and really support our goals?”
Mass General Brigham has already put pieces of that strategy in place publicly. The system created a slate of new AI-focused roles over the past year, including a director of AI governance and literacy.
Asked what she would prioritize if she could make only one AI investment, Ms. Moran gave the same answer as her fellow panelists: people, then platforms. Point solutions, she said, aren’t working. Organizations instead need to lean into working with platform companies that understand what peers across other industries are already doing.
That platform-first instinct is shaping how far Mass General Brigham lets AI agents operate. The system allows employees to use two versions of OpenAI’s tools and recently signed an agreement with OpenEvidence. It has Anthropic’s Claude Cowork in a pilot, but ring-fenced inside the system’s own environment and data rather than open to the broader internet. Under Mass General Brigham’s responsible-use agreement, employees can use outside large language models only if they aren’t entering protected health information or other restricted data; anything touching patient data has to stay inside systems the organization controls, including an internally managed Microsoft Copilot deployment.
That caution extends to how AI agents interact with each other. Ms. Moran described a scenario in which one agent is given a narrow task — password resets, for example — and another agent elsewhere in the system recognizes that role and could, in theory, request access across systems on its own.
“So right now we’re not allowing autonomous AI across different platforms,” she said.
The restriction traces partly to a CrowdStrike outage two years ago that exposed gaps in the system’s own visibility into its network. “We didn’t have all of our systems in our configuration management database,” Ms. Moran said. Devices were connected to the network that the IT team could see by IP address but couldn’t fully identify. Mass General Brigham has since used AI tools to map what is actually running across its environment and moved toward a zero-trust model: no device gets on the network without the right credentials, and some systems require a human in the loop rather than multifactor authentication alone.
Ms. Moran said she expects the system will eventually trust AI agents enough to grant them something closer to employee-level autonomy — helping onboard new staff, for instance. Agents won’t be making decisions in the operating room anytime soon, she said, and any expansion will depend on the risk profile of the task at hand.
“I don’t think you can rely on any single company,” she said of managing that risk.
Mass General Brigham’s chief information security officer meets regularly with roughly a dozen counterparts at other academic health systems to trade notes on how each is approaching AI security, Ms. Moran said — a dynamic she said contrasts with her earlier career in banking.
“That was very competitive,” she said. “This is a very collegial environment, and people are trying to understand just how we can use these tools to make life better.”