Healthcare used to be the industry that arrived late to every technology wave. Electronic records, cloud, mobile: each one landed in healthcare years after it landed everywhere else.
That reputation is now out of date. Healthcare didn't just catch up on AI. It overtook almost everyone.
The problem is that the rules for using it responsibly did not move at the same speed. And that gap between what organisations are doing and what they can actually account for is where the risk sits.
First, what data governance actually means
Data governance sounds like a compliance word. It's simpler than that.
It's the set of rules an organisation uses to answer five questions about any piece of information it holds:
- Where did this come from?
- What does it actually represent?
- Can we trust it?
- Who is allowed to use it?
- Is it the right data for the decision we're about to make?
In healthcare that might mean rules for protecting patient records, controlling who can see claims data, or documenting where a data set originated and what it can legally be used for.
AI doesn't replace those questions. It makes them harder and more urgent, because an AI model is only as good as the data it learned from.
Here's the classic failure. A hospital builds a model to flag patients at high risk of readmission. The training data mostly covers one demographic group. The model works well for that group and quietly underperforms for everyone else. Nobody set out to build a biased tool. There was simply no process checking whether the data represented the people it would be used on.
That's not an AI problem. That's a governance problem wearing an AI costume.
How fast adoption actually moved
The numbers are genuinely striking.
According to Menlo Ventures' research, based on a survey of more than 700 healthcare executives, 22% of healthcare organisations have now deployed domain-specific AI tools. Two years earlier that figure was around 3%. That's roughly a sevenfold increase over 2024 and tenfold over 2023.
Meanwhile, only 9% of companies across the rest of the economy have implemented AI, and most of those are using general-purpose tools rather than anything purpose-built. Healthcare is now adopting AI at about 2.2 times the rate of the broader economy.
The adoption is not evenly spread, and this part matters if you sell into the market:
| Segment | Adoption of domain-specific AI |
|---|---|
| Health systems | 27% |
| Outpatient providers | 18% |
| Payers | 14% |
Spending followed. Healthcare AI spend reached roughly $1.4 billion in 2025, close to triple the previous year, and around 85% of it went to startups rather than established platform vendors.
Individual clinicians moved just as fast. The American Medical Association surveyed 1,692 physicians in early 2026 and found 81% now use AI professionally, up from 66% in 2024 and just 38% in 2023. The average number of ways each physician uses it roughly doubled, from 1.1 use cases to 2.3.
Talk to Intent.Health →Now the governance side
This is where the picture changes.
A January 2026 MGMA poll of medical group leaders (328 responses) asked whether their organisation had AI governance or a formal policy on AI use.
Only 20% said yes. Another 22% said they were working on developing one. That's the 42% figure you'll see quoted, but it's worth separating the two, because "we have a policy" and "we've started thinking about a policy" are not the same thing. Meanwhile 56% said they had neither, and 2% weren't sure.
There is real progress here. Research from MGMA and Humana in late 2024 found that 73% of organisations had no formal AI governance structure at all. So things are moving. They're just moving slower than deployment.
Put the two data sets side by side and the shape of the problem is clear: 81% of physicians are using AI, and one in five organisations has a written policy about it.
What goes wrong in that gap
Shadow AI. When there's no approved tool and no clear policy, people use whatever is convenient. That often means pasting sensitive or proprietary information into a free public chatbot, not out of recklessness but because there's no sanctioned alternative and the work still needs doing. Every one of those pastes is a potential privacy incident.
Unexplainable outputs. If you can't trace a result back to the data behind it, you can't check whether it was right. Errors and biases don't get caught, they get repeated.
Adoption without benefit. This one gets overlooked. An MGMA poll found 71% of practice leaders reported using AI in patient visits, but when asked whether it had reduced staff workload, 44% said it hadn't and only 39% said it had. Using a tool and getting value from it are different things, and without measurement you can't tell which one you're doing.
Clinician trust erodes quietly. The AMA survey found 88% of physicians worry about losing clinical skills through over-reliance on AI, and 85% want a say in how AI gets adopted in their practice. Those aren't anti-AI numbers. They're a request to be involved. Organisations that roll out tools without a visible governance process tend to burn that goodwill fast.
Talk to Intent.Health →What a governance framework needs to cover
You don't have to invent this from nothing. Four areas cover most of it.
1. Clear principles. Start with a written statement of what responsible AI use means in your organisation: patient safety, privacy, transparency, managing bias, human oversight, approved data use. A commitment to transparency, for instance, might mean every AI system has documented data sources, intended users, known limitations, and an approval history. A commitment to human oversight means defining which outputs a person must review before they influence a decision.
2. A consistent way to assess tools. Every proposed tool should be evaluated the same way, starting with the use case. What is it for, who uses it, what decisions does it touch, and what happens if it's wrong? A tool that summarises internal meeting notes needs less scrutiny than one that supports diagnosis or coverage decisions. A standard assessment tells you which is which before the tool is everywhere.
3. Governance across the whole lifecycle. Approval is not a one-time gate. Define the problem first and check whether AI is even the right answer. At procurement, evaluate whether the tool is built on accurate, diverse, appropriately licensed data, and review vendor terms on data use, incident response, and security. After launch, keep monitoring, because model performance drifts.
4. Someone actually accountable. A committee or review board with real authority to set standards, evaluate high-risk uses, settle disputes, and switch something off. Staff it across departments, not just IT.
The frameworks worth knowing
Most articles point to the general-purpose ones: the NIST AI Risk Management Framework, the EU AI Act, and ISO/IEC 42001. All useful, none written specifically for healthcare.
The healthcare-specific work is newer and matters more, and it's moving quickly:
In September 2025, the Joint Commission and the Coalition for Health AI (CHAI) released joint guidance on responsible AI use in healthcare. It's voluntary, and it covers seven areas including AI policies, governance structures, privacy and transparency, data security, quality monitoring, safety event reporting, and bias assessment.
In May 2026, CHAI followed with detailed governance playbooks, built with input from more than 100 healthcare organisations of different sizes and settings.
CHAI also maintains model cards, a standard template documenting an AI model's intended use and known risks, plus a registry where organisations can look them up.
And here's the part with teeth: the Joint Commission is developing a voluntary AI certification based on those playbooks, which it plans to open to its 22,000-plus accredited organisations.
Once AI governance becomes something you can be certified on, it stops being a nice-to-have and starts becoming a procurement question. That shift is close.
Talk to Intent.Health →Why this matters if you sell into healthcare
Governance maturity is a qualification signal. An organisation with a functioning AI committee and a written policy can actually buy something. One without either will stall in review no matter how good your product is. That's not a small distinction, it's the difference between a two-month cycle and a twelve-month one.
The gap is the opportunity. Fifty-six percent of medical groups have no policy and no plan for one. If your product touches AI, data, or clinical decisions, you will be asked governance questions you can answer better than your buyer can. Coming to that conversation with documentation ready, model cards, data provenance, licensing terms, is a genuine differentiator right now.
Segment adoption rates tell you where to aim. Health systems at 27%, outpatient at 18%, payers at 14%. Those aren't just interesting figures, they're a sequencing decision about where your early adopters actually live.
Certification is a timing signal. Organisations preparing for a Joint Commission AI certification will be reassessing vendors, documentation, and contracts. That's a buying window, and it's opening now rather than later.
And know who owns the decision. AI governance rarely sits with one person. It spans clinical leadership, IT, compliance, and legal, and at an IDN or corporate owner the policy may be set at the parent level rather than the individual facility. Working out which entity decides, and who inside it is accountable when something goes wrong, is usually the difference between a meeting and a deal. That's what we work on at Intent.Health, but the principle holds whatever tools you use.
The short version
Adoption is a solved problem in healthcare. Nobody needs convincing that AI is useful any more.
What's unsolved is proof: showing where the data came from, why the output can be trusted, who approved the tool, and how anyone would know if it stopped working. Organisations that can answer those questions will keep deploying. The ones that can't will eventually get stopped, either by an incident or by an auditor.
Talk to Intent.Health →Quick answers
What is data governance? The rules an organisation uses to manage its data responsibly: where it came from, what it represents, whether it can be trusted, who may use it, and whether it suits the decision at hand.
Why does AI make governance harder? Because a model is only as good as its training data. Poor or unrepresentative data produces unreliable or biased outputs, and without governance nobody catches it.
How fast is healthcare adopting AI? Around 22% of healthcare organisations have deployed domain-specific AI tools, up from roughly 3% two years earlier. That's about 2.2 times the adoption rate of the broader economy, where the figure is 9%.
Which parts of healthcare are furthest ahead? Health systems at 27%, outpatient providers at 18%, and payers at 14%.
How many physicians use AI? 81% reported professional use in the AMA's 2026 survey of 1,692 physicians, up from 66% in 2024 and 38% in 2023.
How many organisations have an AI policy? Only 20% of medical groups surveyed by MGMA in January 2026 had one in place, with another 22% developing one. 56% had neither.
What is shadow AI? Employees using AI tools that were never formally reviewed or approved, usually because no sanctioned option exists. It raises the risk of privacy breaches and data leaks.
Are physicians worried about AI? Broadly positive but not uncritical. More than three-quarters think AI improves their ability to care for patients, yet 88% worry about losing clinical skills and 85% want input into how it's adopted.
Which frameworks should we look at? Generally: the NIST AI Risk Management Framework, the EU AI Act, and ISO/IEC 42001. For healthcare specifically: the Joint Commission and CHAI guidance from September 2025 and CHAI's governance playbooks from May 2026.
Is AI governance going to be regulated or certified? The Joint Commission is developing a voluntary AI certification based on the CHAI playbooks, to be offered to its 22,000-plus accredited organisations.
What are the four building blocks of a governance framework? Written ethical principles, a consistent method for assessing tools, governance across the full lifecycle rather than a one-time approval, and a cross-functional body with real authority to oversee it.
Why should commercial teams care? Governance maturity predicts whether an account can actually buy. It tells you which prospects will move quickly, which will stall in review, and which are about to reassess their vendors.
This post is a general overview and isn't legal or compliance advice. Frameworks and guidance in this area are changing quickly, so check the primary sources for current requirements.
Sources
- Menlo Ventures, "2025: The State of AI in Healthcare"
- American Medical Association, "AI usage among doctors doubles as confidence in technology grows"
- American Medical Association, "More than 80% of physicians use AI professionally"
- MGMA, "AI governance in medical group practices: Rules for the humans in the loop"
- MGMA, "Most practices use some form of AI, but is it actually reducing staff workloads?"
- Joint Commission, "Joint Commission and CHAI Release Initial Guidance to Support Responsible AI Adoption"
- CHAI, "CHAI Releases Comprehensive Governance Playbooks to Streamline AI Implementation for Health Systems"
- Healthcare Dive, "CHAI releases AI governance guidance for health systems"
- Fenwick, "Joint Commission and CHAI Release Guidance on Responsible Use of AI in Healthcare"
- NIST, "AI Risk Management Framework"
- Forbes, "AI Adoption In Healthcare Is Surging: What A New Report Reveals"