Skip to content

[ Field Notes ]

The Missing Layer in Healthcare AI: Governance That Actually Ships

70% of hospital AI pilots never make it past limited deployment. The problem isn't the technology — it's the missing governance layer between 'this model works' and 'we trust it enough for patients.'

All field notes

· Jonathon Carlson · 7 min read

By Jonathon Carlson | Atlas Thread Digital

Here's a number that should make every hospital CIO uncomfortable: in a recent survey of roughly 650 U.S. hospital leaders, 70% reported at least one AI pilot that never made it past limited deployment. The reasons weren't technical. The models worked fine in the sandbox. What killed them was everything around the model: unclear ownership, no audit trail, workflow misalignment, and nobody who could answer the question "who approved this for clinical use?" That's not an AI problem. That's a governance problem.

Healthcare has spent the last two years racing to adopt AI. And the race has produced real results: predictive sepsis models, ambient documentation tools, imaging analysis that catches things human eyes miss. But for every tool that made it to production, a dozen others are sitting in pilot purgatory, technically functional but organizationally stuck. The bottleneck isn't the technology. It's the missing governance layer that sits between "this model works" and "we trust this model enough to use it on patients."

The Governance Gap by the Numbers

The numbers tell a clear story. Only 23% of health systems have established formal AI governance structures, yet 78% plan to deploy clinical AI within the next 24 months. Think about what that means in practice: three out of four hospitals are planning to roll out AI tools with no formal process for evaluating, approving, or monitoring them. Only 29% of hospitals have implemented and enforced policies covering AI model inventory, lineage, and sign-offs. Nearly half, 48%, are still drafting those policies. And when asked whether they could produce a complete AI audit trail within 30 days for a regulator or payer, only 22% said yes with confidence. Among small hospitals, that number drops to 15%.

The budget picture tells the same story. The median share of 2026 IT and quality budgets allocated to AI governance is 4.2%. Large systems are spending 6.8%; small hospitals are at 2.3%. For context, many of these same organizations are spending orders of magnitude more on the AI tools themselves. It's like buying a fleet of cars and budgeting nothing for insurance, maintenance, or driver training.

Why Pilots Die

The conventional explanation for failed AI pilots is that the technology wasn't ready, or the use case wasn't right. Sometimes that's true. But the more common story, the one I keep hearing from healthcare IT leaders, is more mundane. A department champion gets excited about a tool. They run a proof of concept. It shows promise. Then it hits the wall: who owns this in production? Who monitors for drift? What happens when the vendor pushes an update? Who's accountable if the model starts performing differently across patient populations? If nobody has built the organizational scaffolding to answer those questions, the pilot just... sits there. It doesn't fail dramatically. It fades out.

Eighty percent of hospital leaders surveyed said it was difficult to verify vendors' AI claims without formal governance in place. Vendors show up with impressive accuracy numbers from controlled studies. But without a governance process that includes independent validation, bias assessment, and clinical workflow integration testing, hospitals have no way to confirm those claims hold up in their specific environment, with their patient population, and their existing systems. According to the AHA, while the majority of U.S. hospitals employ predictive AI models, only half assess them for bias and two-thirds for accuracy. That gap between adoption and verification is where the real risk lives.

The Regulatory Pressure Is Real and Getting Worse

If the operational arguments don't move the needle, the regulatory ones might. In 2025, 47 states introduced over 250 bills touching healthcare AI regulation, and 33 of those bills became law across 21 states. In 2026, Manatt is already tracking roughly 200 more state-level AI bills. The themes keep recurring: patient disclosure and consent for AI-assisted decisions, restrictions on payer use of AI for coverage determinations, requirements that AI tools not present as clinical providers, and special rules around mental health chatbots.

The EU AI Act is also tightening. High-risk AI obligations covering medical devices and in vitro diagnostics take effect in August 2026, and there are currently only 12 Notified Bodies designated to perform conformity assessments for AI medical devices, which means bottlenecks of six to twelve months for certification. For U.S. organizations doing any work across borders or with global vendors, this matters. And domestically, the FDA has shifted its framing to emphasize post-market surveillance for AI systems that learn and adapt over time, placing the burden on provider institutions alongside manufacturers to maintain performance documentation and track changes.

The bottom line: compliance is no longer a federal-only conversation. Organizations need state-level playbooks, regular audits, and a living inventory of every AI system in use. Most hospitals I talk to don't have any of those things, and the ones that do are still patching gaps.

What Governance That Ships Actually Looks Like

Healthcare team meeting to discuss AI governance planning and implementation framework

So what does practical AI governance look like for a health system that doesn't have a dedicated AI ethics team or a seven-figure compliance budget? It starts smaller than you'd think, and it starts with knowing what you have. The first step is an AI system inventory. This sounds basic, but almost every organization that does one discovers they have two to three times more AI and algorithmic tools in use than leadership realized. That includes everything from clinical decision support built into their EHR to third-party tools purchased by individual departments to generative AI apps that clinicians adopted on their own. You can't govern what you can't see, and shadow AI is a real problem in health systems where individual departments have purchasing authority.

From there, the governance framework needs to cover three things: intake (how do new AI tools get evaluated and approved), monitoring (how do you track performance, drift, and bias in production), and accountability (who owns the tool lifecycle, and what happens when something goes wrong). This doesn't require a massive committee structure. At Atlas Thread Digital, when we do healthcare AI gap analyses for organizations, we often find that the governance infrastructure can be surprisingly lightweight if it's designed well. A clear intake checklist, a quarterly review cadence, defined escalation paths, and an owner for each deployed model. The goal is a system that's rigorous enough to satisfy regulators and practical enough that clinical teams actually follow it.

The organizations getting this right are treating governance as a design requirement, not a compliance afterthought. At HIMSS26 this year, the consensus among attendees was that the industry is moving beyond the hype cycle and into a phase where integration into existing clinical workflows, especially within the EHR, is the priority. Governance fits naturally into that shift. If you're already thinking about how an AI tool fits into a clinician's workflow, you're already halfway to thinking about how it gets monitored and maintained.

Small and Mid-Size Systems Can't Afford to Wait

There's a temptation for smaller organizations to treat governance as something the big academic medical centers worry about. That's a mistake. The regulatory environment doesn't care about your bed count. A 150-bed community hospital deploying an AI-powered coding tool faces the same state disclosure requirements as a 2,000-bed system. And the data shows that small hospitals are the least prepared: lower governance budgets, lower confidence in audit readiness, and fewer dedicated resources.

The good news is that governance doesn't have to be expensive or bureaucratic. It needs to be intentional. A small system with a well-designed intake checklist, a simple model registry, and a designated AI governance lead can be more compliant and more effective than a large system with a sprawling committee that meets quarterly and produces reports nobody reads. The advantage of being smaller is that you can move faster and keep things simple. The disadvantage is that you're more likely to have zero governance infrastructure today, which means the gap between where you are and where you need to be might feel larger even though the actual work is smaller.

The Year Governance Becomes Table Stakes

2026 is shaping up to be the year that healthcare AI governance stops being optional. The regulatory pressure is mounting from every direction. The pilot failure rates are forcing organizations to confront the fact that technology alone doesn't create value. And the organizations that figured out governance early are starting to pull ahead, turning stalled pilots into production deployments while their peers are still drafting policies.

The pattern I keep seeing is that governance isn't the thing that slows AI adoption down. It's the thing that speeds it up. Clinical teams move faster when they trust the approval process. Regulatory reviews go smoother when there's a visible audit trail. And vendors get more honest about their claims when they know you have a real evaluation framework waiting for them. Governance is the infrastructure that turns AI experiments into AI operations. And for healthcare, where the stakes are patient safety and the regulators are paying close attention, that infrastructure isn't a nice-to-have. It's the missing layer that determines whether your AI investments actually pay off.

Jonathon Carlson is the founder of Atlas Thread Digital, where he builds custom AI solutions, MCP servers, and intelligent automation systems for organizations ready to move beyond the chatbot. Reach him at jcarlson@atlasthreaddigital.com.