Healthcare doesn’t need more AI governance — It needs better AI governance

Advertisement

As healthcare organizations deploy more artificial intelligence, the natural response is to add more governance. More committees. More reviews. More policies. More approval steps.

But more governance does not necessarily mean better governance. Too little governance can expose organizations to clinical, operational, financial, privacy and reputational risks. Too much can create months of review, unclear accountability and unnecessary friction for relatively low-risk applications.

The challenge is therefore not simply to govern more; it is to govern better. Better governance does not mean less oversight. It means applying the right oversight to the right risk at the right point in the AI lifecycle. The goal should be proportional governance — enough oversight to manage risk without creating unnecessary friction.

Governance should enable responsible scale

AI governance is sometimes treated as a checkpoint. A team develops or purchases an AI solution. Privacy, security, legal, clinical and technology stakeholders review it. A committee approves it. The system goes into production. Governance is considered complete.

But AI does not stop changing after approval.

Data changes. Patient populations change. Workflows evolve. Models are updated. Vendor platforms change. Users find new ways to interact with systems. And increasingly, AI is moving beyond predicting or generating information toward taking actions.

Governance therefore cannot simply be a gate that AI passes through on its way to production. It needs to be a lifecycle capability.

A practical governance model should create a repeatable path:

Risk → Decide → Deploy → Monitor → Learn

Governance may appear to be one stage of an AI operating model, but in practice it spans the entire lifecycle — from deciding what deserves investment to determining whether a deployed system should remain in use.

The objective is not to remove oversight; it is to make oversight proportional, continuous and increasingly effective as the organization learns.

Five principles of better AI governance

Healthcare organizations will structure governance differently depending on their size, risk profile, technology environment and clinical scope.

But five principles should guide an effective enterprise AI governance model.

1. Govern according to risk, not technology

Not every AI application creates the same level of risk. An administrative tool that summarizes internal information should not necessarily require the same review process as an AI system influencing diagnosis, treatment or another consequential clinical decision.

Yet organizations can unintentionally create governance processes in which very different applications travel through similar review pathways simply because they all contain AI.

The better starting point is not, “Does this use AI?”

It is, “What could go wrong, who could be affected and how consequential would the failure be?”

Another question is becoming increasingly important: “Can the action be reversed?”

Those questions allow organizations to establish risk tiers and match governance intensity to potential consequences.

Lower-risk applications may move through streamlined review pathways with established controls. Higher-risk applications may require additional clinical validation, security assessment, human oversight, monitoring or executive approval.

As AI becomes more autonomous, governance should also consider how much authority is being delegated to the system. A useful way to think about governance intensity is through three dimensions:

Impact. Autonomy. Reversibility.

How consequential is the decision? How much authority does the AI have? And if something goes wrong, can the action be reversed?

The level of governance should reflect those risks rather than simply the sophistication of the underlying technology. This does not weaken governance. It concentrates governance where it matters most.

2. Governance needs decision rights, not just committees

A governance committee does not necessarily create governance. Governance is not a committee. It is a system of decision rights, accountability and controls. Committees may be part of that system. But bringing the right stakeholders together is not enough if nobody knows who has authority to make the decision.

Effective AI governance should answer several questions: Who can approve an AI application? Who can reject it? Who can require additional validation? Who accepts the residual risk? Who can pause a system after deployment? Who has authority to retire it?

Good governance should clarify who can say yes, who can say no and who remains accountable after the decision. This is particularly important in healthcare because AI decisions often span multiple organizational boundaries. A clinical AI system may involve clinicians, data scientists, IT, cybersecurity, privacy, legal, compliance, operations and executive leadership. Everyone may have an important perspective, but shared participation should not mean ambiguous accountability. The purpose of governance is not simply to bring stakeholders into the room. It is to create a repeatable mechanism for making responsible decisions.

Organizations should also consider expected decision timelines for different risk tiers. A clearly defined, lower-risk application should not necessarily sit in the same review queue for the same length of time as a high-consequence clinical system. In that sense, governance needs both a risk standard and a service standard.

3. Governance should continue after go-live

Go-live should not mark the end of AI governance; it should mark the beginning of lifecycle governance. Traditional governance processes often concentrate significant attention before deployment. But many of the most important questions emerge only after AI enters a real-world workflow. Are people actually using it? Is performance changing? Are there differences across patient populations or locations? Has the workflow changed? Are users relying on the system differently than expected? Is the solution still producing the clinical, operational or financial outcome that justified its deployment?

Every production AI system therefore needs ongoing technical, operational and value ownership. The lifecycle should look more like:

Approve → Deploy → Monitor → Revalidate → Improve → Retire

The intensity of monitoring should again depend on risk. But every production system should have someone responsible for determining whether it continues to perform as intended and whether the assumptions underlying its original approval remain valid. Without that ownership, organizations can accumulate what might be called governance debt: AI applications remain in production without clear monitoring requirements, revalidation triggers, ownership or retirement criteria.

Each individual gap may appear manageable. But as the AI portfolio grows, the accumulated ambiguity becomes increasingly difficult to manage. An AI system should not remain in production indefinitely simply because nobody owns the decision to stop it.

Retirement is part of governance too.

4. Governance must evolve as AI moves from recommending to acting

AI governance becomes more consequential as systems gain greater autonomy. Predictive AI typically estimates risk, recommends or prioritizes. Generative AI can summarize, synthesize and create content.

Agentic systems increasingly have the potential to interact with tools, execute multistep workflows and take actions, but the most important governance issue is not simply which category of AI is being used. It is, what authority are we willing to delegate to AI?

As AI becomes more autonomous, governance increasingly becomes a question of delegated authority. What can the AI see? What can it recommend? What can it change? What can it execute? Which actions require human approval? What should it never be permitted to do?

Organizations will also need to determine how actions are logged, audited, interrupted and, where possible, reversed. Human oversight should therefore not be treated as a generic requirement. The important question is where human judgment is necessary.

A low-consequence action may require limited intervention. A consequential clinical, financial or operational action may require explicit human authorization. The level of human oversight should follow the consequence of the action, not simply the sophistication of the model. As AI moves from recommending to generating to acting, governance must increasingly address not only model risk, but also authority, permissions and accountability.

5. Measure whether governance is working

Governance itself should be measured. Organizations often know how many AI applications have been reviewed or approved. Those numbers describe activity, not necessarily effectiveness. Better questions include, how long does an appropriate AI application take to move from submission to decision? Are higher-risk applications receiving greater scrutiny than lower-risk ones? Are deployed systems actually being monitored and revalidated? Are previous governance decisions making similar future decisions easier?

That last question is particularly important.

If every new AI use case requires governance to start from scratch, the organization has a governance process. It has not yet built a governance capability. Over time, decisions should create reusable risk classifications, validation approaches, monitoring standards, architectural patterns and approval pathways. Governance should become more precise and efficient as the organization learns.

From governance process to governance capability

The two most common governance failures sit at opposite ends of the spectrum. At one extreme, governance becomes bureaucracy. Nearly every application follows the same process. Committees multiply. Decision rights remain unclear. Reviews take months. Teams learn to view governance as an obstacle they need to navigate.

At the other extreme, governance becomes a checkbox. A system is reviewed, approved and deployed, but ownership and monitoring become less clear after go-live. Neither model is sufficient for enterprise AI.

Better governance should have three characteristics: Proportional before deployment; the intensity of review should reflect the risk; and continuous after deployment.

Monitoring and accountability should continue for as long as the AI remains in use and is reusable across deployments. Previous decisions should create standards and patterns that make comparable future decisions faster and more consistent.

Imagine that a health system reviews its first generative AI application. The organization develops standards for approved data, privacy, security, evaluation, human oversight and monitoring. The next comparable application should not require every question to be answered from the beginning.

The organization should be able to reuse what it learned. The same principle applies to predictive models, vendor solutions and emerging agentic systems.

Each governance decision should leave behind something useful: a standard, risk tier, validation method, monitoring requirement, architectural pattern or clearer decision right. The progression should become:

Decide → Monitor → Learn → Standardize → Reuse

The next comparable decision should become faster and more consistent — not because scrutiny has been reduced, but because the organization has learned.

That is the difference between having a governance process and building a governance capability.

Governance is part of the AI operating model

In my previous Becker’s articles, I have explored several parts of the enterprise AI journey. The first focused on workflow: AI creates value when it changes how work gets done. The second described the AI value gap between successful pilots and repeatable enterprise value. The third focused on the AI operating model required to turn AI into an organizational capability.

Governance connects all three. It determines which risks are acceptable, who has authority to make decisions, how AI is monitored after deployment and whether lessons from one implementation improve the next.

But governance should not become the objective itself; the objective is responsible value creation. Healthcare organizations should therefore resist two assumptions: that faster innovation requires weaker governance, or that stronger governance requires more friction.

That is a false tradeoff. Poor governance can slow innovation. But weak governance can also prevent AI from scaling because clinicians, executives and patients may be less willing to trust systems whose risks, controls and accountability are unclear.

Good governance is not the price organizations pay for responsible AI. It is part of the infrastructure that makes responsible scale possible. As AI becomes more capable and increasingly autonomous, this balance will become even more important. The question healthcare leaders should ask is no longer simply, “Do we have AI governance?” It should be, “Is our governance making responsible AI easier to scale?”

If the answer is yes, governance has stopped being a checkpoint; it has become an enterprise capability.

Executive takeaways

  • More governance does not necessarily mean better governance. Better governance applies the right oversight to the right risk at the right point in the AI lifecycle.
  • Govern according to risk, not technology. Consider the potential impact of a failure, the autonomy delegated to AI and whether its actions can be reversed.
  • Governance is not a committee. It is a system of decision rights, accountability and controls that clarifies who can approve, reject, pause and retire AI.
  • Go-live begins lifecycle governance. Production AI requires ongoing monitoring, revalidation, ownership and, when appropriate, retirement.
  • As AI moves from recommending to generating to acting, governance increasingly becomes a question of delegated authority, permissions and human oversight.
  • Better governance should be proportional before deployment, continuous after deployment and reusable across deployments.
  • Measure governance as an organizational capability. Each governance decision should make comparable future decisions faster and more consistent without weakening oversight.

Dr. Yapalparvi is an executive leader in artificial intelligence, machine learning, and healthcare analytics with more than 15 years of experience leading enterprise AI strategy and production-scale AI initiatives across payer and provider organizations. He has led multidisciplinary teams and initiatives spanning payment integrity, hospital-at-home, remote patient monitoring, clinical and operational decision support, revenue cycle analytics, MLOps, and generative AI.

Advertisement

Next Up in Health IT

Advertisement