Health Tech

Hospitals Are Governing AI With a Process Designed for MRI Machines. The Mismatch Is the Danger.

The typical American hospital now runs AI through the important parts of medicine. Software drafts clinical notes, flags sepsis, screens imaging, processes prior authorizations, and answers patient messages. The adoption is real and much of the benefit is real. The problem is that most health systems are overseeing these tools with a governance process built for a different kind of technology entirely.

The gap between how fast AI changes and how slowly hospitals review it is where patient risk is quietly accumulating.

The mismatch at the center

Consider how a hospital has traditionally approved a major new tool, say an MRI scanner around 2010. A subcommittee convenes. A checklist is completed. A quarterly meeting weighs it. Approval or rejection follows, sometimes six months later. That deliberate pace was appropriate for a machine that, once installed and validated, behaves the same way for a decade.

AI does not behave that way, and that is the crux. An imaging algorithm or a clinical language model is not a fixed object. It updates. Its performance drifts as the patient population shifts, as the data feeding it changes, as the vendor pushes new versions. A tool validated as safe in January can behave differently by June without anyone touching it deliberately, because the world it models moved and the model moved with it. Governing something that changes continuously with a process that reviews periodically is a structural mismatch, and periodic review cannot catch a problem that emerges between meetings.

The measurable evidence that hospitals are not keeping up is stark. Only 22% of hospital leaders surveyed in late 2025 were highly confident they could produce a 30-day AI audit trail for regulators or payers. More than three-quarters of health systems, in other words, could not readily reconstruct what their AI did over a single month. For a technology making decisions that affect care, that is a governance gap wide enough to see through.

Committees without inventories

The more revealing statistic is about the shape of the gap, not just its size. 70% of healthcare organizations have established AI governance committees, yet only 30% maintain an enterprise-wide inventory of the AI they actually use.

Sit with that combination. More than twice as many hospitals have a committee to govern AI as have a list of the AI they are governing. The oversight body exists; the thing it is supposed to oversee has not been fully counted. You cannot govern what you have not inventoried, and the inventory problem is worse than it sounds because of how AI enters a hospital.

Some of it arrives unannounced. AI features get added to existing platforms, the EHR, imaging software, billing systems, through routine vendor updates, so a tool a hospital already approved can acquire new AI capabilities it never separately reviewed. And "shadow AI," tools clinicians or administrators start using on their own, spreads through workflows without any formal sign-off at all. The result is that a hospital's real AI footprint is larger than its official one, and the difference is precisely the part no one is watching. The Censinet CEO's framing is apt: healthcare has built the governance scaffolding for AI without yet having control over what it is meant to hold.

Why this lands on the CEO, not the CIO

The instinct is to treat this as an IT problem, and that instinct is the mistake. The reason is about the nature of the decisions AI is making, and it is worth being precise.

When software flags sepsis or screens imaging, it is participating in clinical judgment, not just processing data. A missed sepsis flag is a patient harm. A biased screening algorithm is a care-quality and equity failure. A prior-authorization model that wrongly denies is both a clinical and a financial harm. These are not IT outcomes; they are the outcomes hospital leadership is accountable for to boards, regulators, and patients. Parking their oversight in IT treats a clinical-governance question as a technical one, and the categories do not match.

There is also a liability trap worth naming, because hospitals keep walking into it. A common assumption is that a vendor contract transfers responsibility for an AI tool's failures to the vendor. It generally does not, at least not in the way that matters clinically. When an AI recommendation contributes to a bad outcome, the accountability for having deployed and relied on it stays with the health system and its clinicians. Assuming the contract absorbed the risk is how an organization ends up responsible for a harm it believed it had outsourced.

The soundest principle in the current guidance follows directly: keep accountability with the human, not the algorithm. As one framework puts it, transparency should include in-line citations to the original patient data, so a clinician can verify the AI's work rather than trust it, keeping the ultimate accountability with the clinician rather than the algorithm. An AI that cannot show its sources cannot be safely trusted, because it cannot be checked, and a clinician told to rely on an output they cannot verify is being asked to accept liability for a black box.

What good governance actually looks like

The encouraging part is that the systems furthest along are not treating this as a documentation exercise. They are redesigning the decision itself, and two contrasting models show there is more than one workable answer.

At CommonSpirit, a 150-hospital system, a 25-member Enterprise Data and Governance Committee spanning technology, clinical, ethics, mission, and finance actually rejects tools, which is the sign of a real gate rather than a rubber stamp. A governance body that has never said no is not governing. Intermountain Health took the opposite structural path: rather than a standalone AI committee, CEO Rob Allen embedded AI accountability into every existing board committee's charter, with cross-functional teams evaluating and approving AI within their domains on a 30-day turnaround.

Those two approaches, centralized gatekeeper versus distributed accountability, differ in form but share the substance that matters. Speed matched to the technology, so review keeps pace with tools that change monthly rather than annually. Cross-functional authority, so clinical, ethical, financial, and technical judgment sit at the same table. And genuine power to reject, so the process can stop a tool, not just document it. The 30-day turnaround is the tell: it is fast enough to be relevant to how AI actually moves, where a six-month cycle guarantees the review is stale before it finishes.

The honest tension

None of this resolves cleanly, and it would be dishonest to pretend the answer is simply "govern harder." There is a real tension between safety and speed, and moving too far in either direction has a cost.

Govern too loosely and unsafe or biased tools reach patients, drift undetected, and accumulate the harms above. Govern too tightly and a slow, risk-averse process blocks tools that would genuinely help, keeps clinicians burning time on documentation AI could absorb, and pushes frustrated staff toward exactly the unsanctioned shadow AI that formal governance was meant to prevent. Overcaution does not eliminate AI risk; it relocates it into the ungoverned corners. The right target is not maximum control but calibrated control, matched to how much a given tool can affect a patient.

That calibration is the practical core. A model that suggests appointment scheduling and one that flags sepsis do not warrant the same scrutiny, and treating them identically wastes oversight on the harmless while under-resourcing the dangerous. Risk-tiering, concentrating the heaviest governance on tools touching diagnosis, treatment, and prior authorization, is what lets a system be both fast and safe, and it depends entirely on having the inventory that most hospitals still lack.

The uncomfortable summary is that AI has already moved into clinical work at most hospitals while the oversight to govern it responsibly has not caught up. The committees exist. The inventories, the audit trails, the speed, and the clear lines of accountability often do not. The systems getting it right treat AI governance as a core clinical-quality function, sitting inside the same oversight as morbidity and mortality review, rather than a compliance chore parked in IT. The ones getting it wrong will likely not discover the gap until a tool fails in a way that reaches a patient, and on current numbers most hospitals could not fully reconstruct what happened if it did.

Further reading

Written by James T.

Do you disagree with any of the medical statements in this article? Email [email protected] with your feedback.

A note on sources: the framing that hospital executives, not IT, must own AI governance was argued by the CEO and chief medical officer of Qualified Health, a company that sells AI governance services to health systems, so the argument aligns with their commercial interest. That does not make it wrong, and the supporting data here is drawn from independent surveys and health-system reporting, but readers should weigh the source. This is general information, not legal, clinical, or management advice. Sources: STAT First Opinion, Censinet, Managed Healthcare Executive, American Hospital Association, and Black Book Research. Mavengity is editorially independent.
Keep reading

More from Healthcare & Medical

growth disorders

A Growth Drug Passed Its Pivotal Test in a Second Bone Condition

Detailed Phase III results for Voxzogo in hypochondroplasia showed a 2.33 centimeter annual growth velocity advantage, published in NEJM Evidence.

By James T.·September 9, 2026·7 min read
angioedema

An Oral Drug Cut HAE Attacks by 83 Percent in a Pivotal Trial

Pharvaris' deucrictibant extended-release tablets met the primary endpoint of the CHAPTER-3 study, including in the HAE subgroup with no dedicated prophylactic option.

By James T.·September 9, 2026·7 min read
lung cancer

The First Survival Win for a BiTE Drug Arrives in Small Cell Lung Cancer

AstraZeneca and Amgen's DeLLphi-305 trial showed Imfinzi plus Imdelltra improved overall survival in extensive-stage small cell lung cancer.

By James T.·September 9, 2026·7 min read
rare disease

The $12 Billion Muscle Drug Missed Its Big Test

Novartis' del-desiran failed its Phase III endpoint in myotonic dystrophy type 1, a setback for the centerpiece of the Avidity Biosciences acquisition.

By James T.·September 9, 2026·7 min read
Drug Development

Europe's Biotech Act Promises Faster Trials the EU Has Never Managed

The European Commission wants clinical trial authorization cut from about 106 days to 75. The EU's first progress report on its 2030 trial targets shows why the Act exists: the continent's trial machine is running behind its own goals.

By James T.·September 8, 2026·8 min read
Mental Health

California Draws the Line Between an AI Assistant and a Therapist

California's pending SB 903 would ban unlicensed AI therapy and restrict how licensed professionals use AI with patients. The bill's principle is that what matters is the conduct, not what the app calls itself.

By James T.·September 8, 2026·8 min read
Data Privacy

One Compromised Account Cost a French Hospital 727,000 Patient Records

France's data regulator fined a Saint-Étienne private hospital €500,000 after an attacker used a single doctor's account to drain its patient record system, and the findings read like a checklist the sector has ignored for years.

By James T.·7 min read
Clinical Trials

The Lp(a) Hypothesis Just Lost Its First Big Test

Novartis reported that pelacarsen failed its cardiovascular outcomes trial, the first major test of whether lowering lipoprotein(a) prevents heart attacks and strokes. The class is not dead, but the theory now needs a new proof.

By James T.·8 min read
Public Health

Iowa's Opioid Settlement Money Moved. The First $1.6 Million Shows Where

The state's first wave of opioid settlement grants funds jail re-entry, peer support, a homeless shelter, youth prevention and a drug incinerator, and the list is a map of how Iowa intends to spend $365 million.

By James T.·7 min read