90% of Health Systems Run Third-Party AI. Fewer Than Half Can Prove It's Safe.

Vitea Newsroom
Editorial team
Aug 10, 2026
7 minutes
Editorial team
Physician with tablet showing AI

This week in healthcare AI news: A national survey put hard numbers on how many health systems can actually validate the AI they've already deployed. An accreditor awarded its first certification for responsible AI use. A new state law drew another hard line around clinical AI. A study asked patients what it would take to trust AI in their care. And a survey of the engineers building medical AI found most don't know the rules meant to keep it safe.

Different actors, different angles — but one question sits underneath all of them: whether healthcare organizations can actually prove they're governing AI.

For two years, the story of AI in healthcare has been a story of adoption — how fast, how many tools, how much saved. This week the story shifted. The headlines weren't about deploying more AI; they were about demonstrating control over the AI already in production, to a regulator, an accreditor, a patient, or a health system's own board.  

Adoption is something an organization announces. Governance is something it has to be able to show.  

Here are the five stories worth a health system leader's attention this week.

1. The AI Adoption Gap Finally Has a Number — and It Isn't Reassuring

New research from UPMC's Center for Connected Medicine and KLAS Research, drawn from interviews with more than two dozen health system leaders, found that more than 90% have deployed third-party AI and 92% say they test tools before go-live — yet only 44% have a dedicated environment in which to validate them.  

As Healthcare Innovation and Fierce Healthcare both reported, validation methods ranged from formal vendor test cases to informal pilots, and 63% of leaders described their AI strategy as still developing or ad hoc. Clinical documentation led deployments at 52%, followed by revenue cycle and coding at 36%, and analysts concluded the barriers ahead are as much operational and governance-related as they are technical.

Why it matters: Testing means little when fewer than half of organizations have anywhere to run a tool against their own patient data — and when there's no shared agreement on how to measure whether it worked.  

This is the deployment–governance gap rendered in percentages; adoption is nearly universal, the capacity to validate is not. And validation isn't a one-time gate. A model that passed on launch day can drift, degrade, or start writing plausible errors into the chart months later — which is why seeing every AI tool in the environment has to come before anyone can claim to be testing it.

2. Governance Just Became Something You Can Be Certified For — or Fail

Hackensack Meridian Health became the first health system in the country to earn The Joint Commission's Responsible Use of AI in Healthcare (RUAIH) certification, developed with the nonprofit Coalition for Health AI, Healthcare Innovation reported. The evaluation spanned six domains: governance and oversight, safeguards for patient privacy and data, processes to identify and reduce bias and risk, ongoing monitoring of tool performance, transparency with patients, and staff training.

Why it matters: Until now, AI governance in healthcare has been graded largely on self-report; an organization decided for itself whether its program was good enough. A certification changes the terms.  

The six RUAIH domains read like an operational checklist, and each one describes something an organization must be able to demonstrate on demand rather than assert. That is a meaningful shift for every health system that isn't Hackensack Meridian, because the question is no longer whether to govern AI but whether the program could withstand outside scrutiny.  

The distance between a policy on a shared drive and a control that is provably running is exactly the distance a certification is designed to measure.

3. Another State Drew a Line Around Clinical AI — and the Map Keeps Fragmenting

Colorado's HB26-1195 takes effect August 12, prohibiting AI from independently providing therapy and requiring that clinical treatment and psychotherapy be delivered by a licensed human. As the bill's sponsors announced, the law confines AI to administrative support under licensed oversight, requires disclosure when it is used, and bars chatbots from being marketed as equivalent to a licensed counselor or implying that a conversation carries HIPAA-style confidentiality.  

The sponsors pointed to active lawsuits against major AI companies over chatbots that allegedly encouraged self-harm as part of the impetus.

Why it matters: Colorado isn't acting alone. It follows California's SB 1120 and a growing run of state measures, and the cumulative effect is a compliance map that no longer looks the same from one state to the next.  

For a system operating across borders, that makes a single static AI policy hard to defend; the same behavioral-health tool can be permissible in one jurisdiction and unlawful in the next. Staying inside the lines now depends on knowing where clinical AI is running across the footprint and being able to enforce different rules in different places. The difference between a policy that describes intent and a control that adapts to where the AI is actually operating.

4. Patients Answered a Question the Industry Keeps Avoiding — What Earns AI's Trust

A study published in JAMA Network Open, led by researchers at the University of Queensland, set out to define the "social license" that lets healthcare AI operate with public acceptance rather than mere legal permission.  

As Health Exec reported, workshops with patients surfaced three drivers of that trust: being told when AI is involved in their care, confidence that its performance is reliable, and — notably — the presence of clear, established governance. Participants did not describe governance as a brake on AI. They described it as a precondition for accepting it at all.

Why it matters: Most governance conversations inside a health system are framed around risk: what could go wrong, what a regulator might find. This study reframes it from the outside in. Patients are saying that visible, credible oversight is part of what makes AI in their care tolerable in the first place, which turns governance from a cost of doing business into a condition of adoption.  

Put plainly: without governance patients can see, trust erodes, and without trust, adoption stalls. That makes an enforced oversight program not just a shield against the next lawsuit but an enabler of the AI strategy leaders are trying to scale.

5. The People Building Medical AI Often Don't Know the Rules

A multi-region survey of 122 medical AI developers across Singapore, China, Hong Kong and Britain, published in npj Digital Medicine and covered by ComputerWeekly, found that only 57% were aware of even one relevant regulatory framework — and roughly two-thirds worked for organizations that had adopted none at all.  

The developers largely accepted that they should be held responsible for the tools they build; they simply lacked familiarity with the safeguards meant to keep those tools safe. The researchers, noting developers' unique vantage on data quality, bias and hallucination risk, called for regulation to be built into training and for responsibility to be shared across the chain rather than resting on engineers alone.

Why it matters: When the people writing the models don't know the frameworks, a hospital cannot assume its vendors have governed a tool on its behalf. Responsibility for how AI behaves in care does not transfer with the purchase order — the organization deploying the tool answers for it, to patients and regulators alike.  

That reframes vendor risk as an ongoing oversight function rather than a box checked at procurement, and it raises the same uncomfortable question the rest of the week keeps asking: can a health system actually see, and constrain, what a purchased AI tool is doing once it's live?

Final Thoughts

The era of announcing AI adoption is closing. The era of proving AI governance has begun, and this week, the proof was demanded from four directions at once: the regulator, the accreditor, the patient, and the balance sheet.

That is the shift Vitea was built for. We give health systems the visibility to see every AI tool touching their environment, sanctioned or not; the policy enforcement to control what each one is allowed to do, by use case and by jurisdiction; and the continuous monitoring to prove it keeps performing safely long after go-live.  

The headlines rotate every week. The thing they keep exposing — the gap between saying you govern AI and being able to show it — is the constant, and it's the one we close.

If your organization is asking how much of its AI it could actually account for today, we'd be glad to be a resource. Get in touch with us here.

Follow Vitea on LinkedIn for more of the latest news and views on AI governance in healthcare, including our weekly roundup of the stories healthcare leaders need to know.

Suggested for You

Inspired by what you’ve recently viewed.

Bring AI under control
without slowing innovation.
We're here to help you innovate and transform
Discover every AI in use, including shadow AI
Enforce 100+ out-of-the-box policies in real time
Stop risky AI activity before sensitive data is exposed
Continuously monitor AI performance and prove governance on demand
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.