Health Tech

Hospitals Are Governing AI With a Process Designed for MRI Machines. The Mismatch Is the Danger.

The typical American hospital now runs AI through the important parts of medicine. Software drafts clinical notes, flags sepsis, screens imaging, processes prior authorizations, and answers patient messages. The adoption is real and much of the benefit is real. The problem is that most health systems are overseeing these tools with a governance process built for a different kind of technology entirely.

The gap between how fast AI changes and how slowly hospitals review it is where patient risk is quietly accumulating.

The mismatch at the center

Consider how a hospital has traditionally approved a major new tool, say an MRI scanner around 2010. A subcommittee convenes. A checklist is completed. A quarterly meeting weighs it. Approval or rejection follows, sometimes six months later. That deliberate pace was appropriate for a machine that, once installed and validated, behaves the same way for a decade.

AI does not behave that way, and that is the crux. An imaging algorithm or a clinical language model is not a fixed object. It updates. Its performance drifts as the patient population shifts, as the data feeding it changes, as the vendor pushes new versions. A tool validated as safe in January can behave differently by June without anyone touching it deliberately, because the world it models moved and the model moved with it. Governing something that changes continuously with a process that reviews periodically is a structural mismatch, and periodic review cannot catch a problem that emerges between meetings.

The measurable evidence that hospitals are not keeping up is stark. Only 22% of hospital leaders surveyed in late 2025 were highly confident they could produce a 30-day AI audit trail for regulators or payers. More than three-quarters of health systems, in other words, could not readily reconstruct what their AI did over a single month. For a technology making decisions that affect care, that is a governance gap wide enough to see through.

Committees without inventories

The more revealing statistic is about the shape of the gap, not just its size. 70% of healthcare organizations have established AI governance committees, yet only 30% maintain an enterprise-wide inventory of the AI they actually use.

Sit with that combination. More than twice as many hospitals have a committee to govern AI as have a list of the AI they are governing. The oversight body exists; the thing it is supposed to oversee has not been fully counted. You cannot govern what you have not inventoried, and the inventory problem is worse than it sounds because of how AI enters a hospital.

Some of it arrives unannounced. AI features get added to existing platforms, the EHR, imaging software, billing systems, through routine vendor updates, so a tool a hospital already approved can acquire new AI capabilities it never separately reviewed. And "shadow AI," tools clinicians or administrators start using on their own, spreads through workflows without any formal sign-off at all. The result is that a hospital's real AI footprint is larger than its official one, and the difference is precisely the part no one is watching. The Censinet CEO's framing is apt: healthcare has built the governance scaffolding for AI without yet having control over what it is meant to hold.

Why this lands on the CEO, not the CIO

The instinct is to treat this as an IT problem, and that instinct is the mistake. The reason is about the nature of the decisions AI is making, and it is worth being precise.

When software flags sepsis or screens imaging, it is participating in clinical judgment, not just processing data. A missed sepsis flag is a patient harm. A biased screening algorithm is a care-quality and equity failure. A prior-authorization model that wrongly denies is both a clinical and a financial harm. These are not IT outcomes; they are the outcomes hospital leadership is accountable for to boards, regulators, and patients. Parking their oversight in IT treats a clinical-governance question as a technical one, and the categories do not match.

There is also a liability trap worth naming, because hospitals keep walking into it. A common assumption is that a vendor contract transfers responsibility for an AI tool's failures to the vendor. It generally does not, at least not in the way that matters clinically. When an AI recommendation contributes to a bad outcome, the accountability for having deployed and relied on it stays with the health system and its clinicians. Assuming the contract absorbed the risk is how an organization ends up responsible for a harm it believed it had outsourced.

The soundest principle in the current guidance follows directly: keep accountability with the human, not the algorithm. As one framework puts it, transparency should include in-line citations to the original patient data, so a clinician can verify the AI's work rather than trust it, keeping the ultimate accountability with the clinician rather than the algorithm. An AI that cannot show its sources cannot be safely trusted, because it cannot be checked, and a clinician told to rely on an output they cannot verify is being asked to accept liability for a black box.

What good governance actually looks like

The encouraging part is that the systems furthest along are not treating this as a documentation exercise. They are redesigning the decision itself, and two contrasting models show there is more than one workable answer.

At CommonSpirit, a 150-hospital system, a 25-member Enterprise Data and Governance Committee spanning technology, clinical, ethics, mission, and finance actually rejects tools, which is the sign of a real gate rather than a rubber stamp. A governance body that has never said no is not governing. Intermountain Health took the opposite structural path: rather than a standalone AI committee, CEO Rob Allen embedded AI accountability into every existing board committee's charter, with cross-functional teams evaluating and approving AI within their domains on a 30-day turnaround.

Those two approaches, centralized gatekeeper versus distributed accountability, differ in form but share the substance that matters. Speed matched to the technology, so review keeps pace with tools that change monthly rather than annually. Cross-functional authority, so clinical, ethical, financial, and technical judgment sit at the same table. And genuine power to reject, so the process can stop a tool, not just document it. The 30-day turnaround is the tell: it is fast enough to be relevant to how AI actually moves, where a six-month cycle guarantees the review is stale before it finishes.

The honest tension

None of this resolves cleanly, and it would be dishonest to pretend the answer is simply "govern harder." There is a real tension between safety and speed, and moving too far in either direction has a cost.

Govern too loosely and unsafe or biased tools reach patients, drift undetected, and accumulate the harms above. Govern too tightly and a slow, risk-averse process blocks tools that would genuinely help, keeps clinicians burning time on documentation AI could absorb, and pushes frustrated staff toward exactly the unsanctioned shadow AI that formal governance was meant to prevent. Overcaution does not eliminate AI risk; it relocates it into the ungoverned corners. The right target is not maximum control but calibrated control, matched to how much a given tool can affect a patient.

That calibration is the practical core. A model that suggests appointment scheduling and one that flags sepsis do not warrant the same scrutiny, and treating them identically wastes oversight on the harmless while under-resourcing the dangerous. Risk-tiering, concentrating the heaviest governance on tools touching diagnosis, treatment, and prior authorization, is what lets a system be both fast and safe, and it depends entirely on having the inventory that most hospitals still lack.

The uncomfortable summary is that AI has already moved into clinical work at most hospitals while the oversight to govern it responsibly has not caught up. The committees exist. The inventories, the audit trails, the speed, and the clear lines of accountability often do not. The systems getting it right treat AI governance as a core clinical-quality function, sitting inside the same oversight as morbidity and mortality review, rather than a compliance chore parked in IT. The ones getting it wrong will likely not discover the gap until a tool fails in a way that reaches a patient, and on current numbers most hospitals could not fully reconstruct what happened if it did.

Further reading

Written by James T.

Do you disagree with any of the medical statements in this article? Email medical_disputes@mavengity.com with your feedback.

A note on sources: the framing that hospital executives, not IT, must own AI governance was argued by the CEO and chief medical officer of Qualified Health, a company that sells AI governance services to health systems, so the argument aligns with their commercial interest. That does not make it wrong, and the supporting data here is drawn from independent surveys and health-system reporting, but readers should weigh the source. This is general information, not legal, clinical, or management advice. Sources: STAT First Opinion, Censinet, Managed Healthcare Executive, American Hospital Association, and Black Book Research. Mavengity is editorially independent.
Keep reading

More from Healthcare & Medical

Women's Health

The Bottleneck in Women's Health Was Never the Drug

Venture capital is pouring into women's health on the promise of a trillion-dollar productivity gap, but endometriosis still takes years to diagnose and most osteoporotic fracture patients never get treated. Both conditions have had effective treatments for decades. The bottleneck was never the molecule; it was the last mile between diagnosis and care.

By James T.·8 min read
Vaccines

The Cleverest Part of the Shingrix Study Is Also Its Ceiling

An Oxford study using the 2017 Shingrix approval date as a natural experiment found 9 percent less cardiovascular disease in recipients versus the older shingles vaccine. The design elegantly removes the usual healthy-vaccinee bias, but it is still an observational study, and a randomized Danish trial of 162,000 people will settle the question in 2027.

By James T.·8 min read
End-of-Life Care

New York's Aid-in-Dying Law Runs on Doctors the State Does Not Have

New York's new medical aid in dying law is the strictest in the country, requiring a recorded oral request, two physicians, a mandatory mental health evaluation, and a five-day wait. Every safeguard answers a real objection, but the process runs on specialists the state's own workforce data says are scarce, and the friction quietly sorts who can complete it.

By James T.·8 min read
Public Health

Measles Disappeared for So Long That Its Danger Became Hard to Believe

Two unvaccinated people died of measles in Lancaster County, Pennsylvania, the state's first measles deaths in over three decades. The outbreak traces to a gap in the herd-immunity shield that worked so quietly for a quarter century that a large share of the public stopped believing the danger behind it was real.

By James T.·8 min read
Cardiology

One in Five People Carries a Heart Risk Their Doctor Never Tested For

New cardiology guidelines now call for testing every adult once for lipoprotein(a), a genetic cholesterol particle absent from the standard lipid panel, even though no approved drug yet lowers it. The measurement is running ahead of the medicine on a deliberate bet that treatment is a year away.

By James T.·8 min read
Public Health Data

Four Years After Dobbs, the Data Refused to Keep Score

Both sides of the abortion debate made confident predictions after Dobbs. Four years of studies later, one prediction held, one reversed, and two dissolved into competing research reading the same numbers in opposite directions. The failure of the scoreboard says more about how policy meets data than about which side was right.

By James T.·8 min read
Patient Care

The Sound in the ICU That Has No Column in the Chart

A physician's essay on grief and whale song points at something the medical record has never measured, that a family's wail carries real physiological information. Crying and whale calls have decades of published science behind them; the sound that fills an ICU when someone dies has no column in any chart.

By James T.·8 min read
Rural Health

Medicaid Cuts Are Closing the Last Mile of Rural Care First

Federal Medicaid reductions are usually measured in coverage lost and dollars cut. In rural Maine, hospitals losing about 1 percent of revenue are dropping birthing units and leaning on a philanthropy-funded air ambulance service, turning a budget line into miles a family must drive at 2 a.m.

By James T.·8 min read
Cancer Screening

In Long-Term Care, the Screening Decision Is Made by Logistics

National cancer screening guidelines stop offering guidance for women past 75, exactly the age long-term care residents have often just entered. In the resulting silence, whether a resident gets screened is decided not by medicine but by who can arrange transportation to an off-site appointment.

By James T.·8 min read