Related on The Signal Room: Privacy and AI Governance Insights with Andre Samokish. Related from HDSC: Responsible AI in Healthcare.During the previous three years, healthcare and AI discussions have primarily focused on capabilities. What models are the best performers? What use cases provide the best return on investment? What vendors have the most advanced platforms? This conversation has led to progress, including the creation of many AI resources being integrated into healthcare systems. From the other side of the ledger, there are insufficient institutional infrastructures to manage these resources. As we look towards 2026, the focus of the conversation is changing. Users of AI systems are asking, "what is the institutional and regulatory structure to manage the activities AI systems are performing for us? This is the first of many questions, and whether there is one or multiple answers is at the heart of the rapidly evolving AI systems landscape."

The rapid evolution of the AI systems landscape is informing this document and applies to the regulatory and institutional systems of the last 18 months. There are notable changes in the posture towards the management of AI systems. Federal authorities, state legislatures, professional bodies, and the healthcare system at large, are all moving towards a more integrated AI oversight framework. Institutions that adapt to the changes first will be the leaders; those that fail to recognize the changes will be lagging behind after the regulatory and oversight changes have been implemented.

Federal Landscape

The FDA continues to broaden its framework for medical devices incorporating AI/ML (Artificial Intelligence/Machine Learning). The FDA has authorized over 900 AI-integrated devices, and it plans to heighten post-market surveillance for these devices. The predetermined change control plan from earlier drafts has become a pillar of the regulation, necessitating manufacturers to document how models will be modified and validated over time.

Furthermore, the Office of the National Coordinator for Health IT stated new interoperability policies, including AI-related clinical data components. The policies impose requirements on documentation of AI-generated clinical data in electronic health records, as well as the availability of AI-generated data to patients through authorized access. Consequently, health care institutions can no longer view AI-generated clinical data as internal documents. Such data will be incorporated into patient records and health care institutions will be subject to strict regulations.

Concurrently, the Centers for Medicare and Medicaid Services has begun to incorporate AI in its participation and quality reporting frameworks. For the first time, the CMS stated it will examine the application of AI in clinical decision-making, which will be integrated into the survey and certification process and will effectively regulate the clinical process and documentation requirements related to AI adoption.

Acceleration at the State Level

At the state level, legislative action about AI in healthcare has grown materially. In 2025, over 20 states proposed AI-related bills concerning healthcare, and several of them have since become laws. These laws impose new restrictions upon health systems operating in those states.

Colorado has new laws requiring the high-risk AI systems vendors to perform impact assessments and notify people about the automated decisions made about them. AI used in healthcare to make decisions about coverage, classification of risk, or clinical recommendations is also included. California has added to its privacy laws specific provisions regarding automated decision-making in health.

The National Association of Insurance Commissioners has issued model bulletins pertaining to health insurers use of AI which specify testing, documentation, and oversight of algorithms used in coverage and claims decisions. These model bulletins are being adopted by state insurance departments in varying forms, resulting in a dispersed regulatory environment that health systems and insurance companies must individually monitor and comply with.

Professional and Institutional Momentum

The American Medical Association AI clinical policy includes recommendations for a framework of institutional oversight of AI, clinician education on AI, and patient consent frameworks for AI care. These AMA policies are becoming standards for many health systems.

At the same time, the National Academy of Medicine has issued multiple reports regarding the role of AI in healthcare. The reports include recommendations around AI preparedness, institutional cross-disciplinary review structures, workforce AI rapid development, and more. The reports serve as a starting point for adaptive healthcare organizational frameworks.

There are reports about an increasing gap within the health system between the AI deployment velocity and the AI management capability. There are reports about the AI management capability gap across healthcare institutions. KLAS has reported this gap, and the reports translate the oversight gap that 2026 will pose.

What This Means for Health System Leaders

Health system leaders will experience and come face to face with the consequences of lack of AI oversight for the first time in 2026. The recommendations will no longer be in the federal regulations; they will be enforced. The state regulations will create new AI oversight and management protocols. There will be professional expectations that move the AI management capability from rudimentary to intermediate. The internal institutional pressure to develop and implement AI will only increase.

Healthcare institutions that will be most successful will be those with management systems that are enterprise level for AI, including role definition, review system standardization, centralized management systems, and systems for control and review. Institutions that wait will have management systems based on poorly constructed regulations that will result in abortions of management constructs that are more rational, more effective, and less disruptive.

The closing window for voluntary measures means regulatory mandates, legal liability, and reputational risk which will make oversight of AI in healthcare a regulatory requirement instead of a business strategy.

Relevant Context and Citations

The FDA has approved more than 900 AI devices and is entrenching post-market surveillance. ONC has proposed new interoperability rules with AI-related provisions. CMS is including AI in participation criteria. 2025 has seen more than 20 states introducing regulations for AI. Colorado and California have AI oversight laws. The NAIC has proposed AI-related model bulletins in insurance. The AMA has published AI policy for clinical practice. The National Academy of Medicine has issued a report on institutional readiness. KLAS has documented the AI deployment and management gap. This edition links to the themes of regulation and institutional readiness in Editions Z, W, and Y of this newsletter.

Christopher Hutchins
Founder & CEO, Hutchins Data Strategy Consultants

Recommended for you