Committees without inventories
The more revealing statistic is about the shape of the gap, not just its size. 70% of healthcare organizations have established AI governance committees, yet only 30% maintain an enterprise-wide inventory of the AI they actually use.
Sit with that combination. More than twice as many hospitals have a committee to govern AI as have a list of the AI they are governing. The oversight body exists; the thing it is supposed to oversee has not been fully counted. You cannot govern what you have not inventoried, and the inventory problem is worse than it sounds because of how AI enters a hospital.
Some of it arrives unannounced. AI features get added to existing platforms, the EHR, imaging software, billing systems, through routine vendor updates, so a tool a hospital already approved can acquire new AI capabilities it never separately reviewed. And "shadow AI," tools clinicians or administrators start using on their own, spreads through workflows without any formal sign-off at all. The result is that a hospital's real AI footprint is larger than its official one, and the difference is precisely the part no one is watching. The Censinet CEO's framing is apt: healthcare has built the governance scaffolding for AI without yet having control over what it is meant to hold.
Why this lands on the CEO, not the CIO
The instinct is to treat this as an IT problem, and that instinct is the mistake. The reason is about the nature of the decisions AI is making, and it is worth being precise.
When software flags sepsis or screens imaging, it is participating in clinical judgment, not just processing data. A missed sepsis flag is a patient harm. A biased screening algorithm is a care-quality and equity failure. A prior-authorization model that wrongly denies is both a clinical and a financial harm. These are not IT outcomes; they are the outcomes hospital leadership is accountable for to boards, regulators, and patients. Parking their oversight in IT treats a clinical-governance question as a technical one, and the categories do not match.
There is also a liability trap worth naming, because hospitals keep walking into it. A common assumption is that a vendor contract transfers responsibility for an AI tool's failures to the vendor. It generally does not, at least not in the way that matters clinically. When an AI recommendation contributes to a bad outcome, the accountability for having deployed and relied on it stays with the health system and its clinicians. Assuming the contract absorbed the risk is how an organization ends up responsible for a harm it believed it had outsourced.
The soundest principle in the current guidance follows directly: keep accountability with the human, not the algorithm. As one framework puts it, transparency should include in-line citations to the original patient data, so a clinician can verify the AI's work rather than trust it, keeping the ultimate accountability with the clinician rather than the algorithm. An AI that cannot show its sources cannot be safely trusted, because it cannot be checked, and a clinician told to rely on an output they cannot verify is being asked to accept liability for a black box.
What good governance actually looks like
The encouraging part is that the systems furthest along are not treating this as a documentation exercise. They are redesigning the decision itself, and two contrasting models show there is more than one workable answer.
At CommonSpirit, a 150-hospital system, a 25-member Enterprise Data and Governance Committee spanning technology, clinical, ethics, mission, and finance actually rejects tools, which is the sign of a real gate rather than a rubber stamp. A governance body that has never said no is not governing. Intermountain Health took the opposite structural path: rather than a standalone AI committee, CEO Rob Allen embedded AI accountability into every existing board committee's charter, with cross-functional teams evaluating and approving AI within their domains on a 30-day turnaround.
Those two approaches, centralized gatekeeper versus distributed accountability, differ in form but share the substance that matters. Speed matched to the technology, so review keeps pace with tools that change monthly rather than annually. Cross-functional authority, so clinical, ethical, financial, and technical judgment sit at the same table. And genuine power to reject, so the process can stop a tool, not just document it. The 30-day turnaround is the tell: it is fast enough to be relevant to how AI actually moves, where a six-month cycle guarantees the review is stale before it finishes.
The honest tension
None of this resolves cleanly, and it would be dishonest to pretend the answer is simply "govern harder." There is a real tension between safety and speed, and moving too far in either direction has a cost.
Govern too loosely and unsafe or biased tools reach patients, drift undetected, and accumulate the harms above. Govern too tightly and a slow, risk-averse process blocks tools that would genuinely help, keeps clinicians burning time on documentation AI could absorb, and pushes frustrated staff toward exactly the unsanctioned shadow AI that formal governance was meant to prevent. Overcaution does not eliminate AI risk; it relocates it into the ungoverned corners. The right target is not maximum control but calibrated control, matched to how much a given tool can affect a patient.
That calibration is the practical core. A model that suggests appointment scheduling and one that flags sepsis do not warrant the same scrutiny, and treating them identically wastes oversight on the harmless while under-resourcing the dangerous. Risk-tiering, concentrating the heaviest governance on tools touching diagnosis, treatment, and prior authorization, is what lets a system be both fast and safe, and it depends entirely on having the inventory that most hospitals still lack.
The uncomfortable summary is that AI has already moved into clinical work at most hospitals while the oversight to govern it responsibly has not caught up. The committees exist. The inventories, the audit trails, the speed, and the clear lines of accountability often do not. The systems getting it right treat AI governance as a core clinical-quality function, sitting inside the same oversight as morbidity and mortality review, rather than a compliance chore parked in IT. The ones getting it wrong will likely not discover the gap until a tool fails in a way that reaches a patient, and on current numbers most hospitals could not fully reconstruct what happened if it did.
Further reading
A note on sources: the framing that hospital executives, not IT, must own AI governance was argued by the CEO and chief medical officer of Qualified Health, a company that sells AI governance services to health systems, so the argument aligns with their commercial interest. That does not make it wrong, and the supporting data here is drawn from independent surveys and health-system reporting, but readers should weigh the source. This is general information, not legal, clinical, or management advice. Sources: STAT First Opinion, Censinet, Managed Healthcare Executive, American Hospital Association, and Black Book Research. Mavengity is editorially independent.