Health Systems Are Adopting AI Faster Than They Can Govern It: 5 Steps to Build a Real AI Strategy
Health systems are deploying artificial intelligence faster than they are building the structures to manage it. An effective AI strategy must address more than technology selection. It must connect opportunities, data, people, workflow, risk, accountability, and measurable business value.
That gap is becoming harder to ignore. According to a 2025 KLAS Research and CCM report, 93% of health systems have deployed third-party AI. Yet 63% describe their AI strategy as developing or ad hoc, and only 4% report having an advanced strategy.
The message for health system leaders is straightforward: AI adoption is no longer waiting for a perfect enterprise plan. But without a practical strategy, each new deployment can create more fragmentation, risk, and operating complexity.
A real AI strategy is not a vendor list or a long-range technology plan. It is a set of enterprise choices: which problems merit investment, which outcomes define value, what risks are acceptable, what capabilities are required, who owns performance, and what evidence is needed before scale.
AI Strategy Starts With the Work, Not the Tool
Many organizations begin with a vendor conversation. A department identifies a promising product, a budget becomes available, and a pilot moves forward. That approach can produce useful results, but it can also create disconnected tools, inconsistent standards, and unclear ownership.
The more useful question is not, "Where can we use AI?"
It is:
Which clinical, operational, financial, or consumer problems are important enough to justify investment and change?
The most visible AI use case is not always the most valuable one. Ambient documentation may reduce administrative burden. Revenue cycle automation may improve financial performance. Patient access, workforce planning, clinical operations, and consumer engagement may offer greater strategic value depending on the system's priorities.
Leaders should create a focused portfolio of use cases tied to current business objectives. Each candidate should have an accountable executive, a defined workflow, a baseline measure, an expected outcome, and a clear reason why AI is the appropriate intervention.
Step 1: Assess the Opportunity
Start with an enterprise view of where AI could improve performance. Review the full operating environment, including clinical care, revenue cycle, workforce management, patient access, supply chain, contact centers, marketing, analytics, and administrative functions.
The goal is not to identify the largest possible number of ideas. It is to identify the few opportunities with the strongest combination of business value, organizational readiness, and manageable risk.
For each potential use case, ask:
- What problem are we solving?
- Who experiences the problem today?
- What does the current process cost in time, money, capacity, quality, or experience?
- What outcome would justify the investment?
- What decision or workflow would change if the tool works?
- What could go wrong if the tool performs poorly?
- How will we know whether the result is actually better?
This assessment should include input from the people who own and use the workflow. A tool that appears attractive at the enterprise level may fail when it reaches a busy clinical team, a contact center, or a revenue cycle operation.
Rank opportunities using a simple scorecard:
| Criterion | Core question |
|---|---|
| Strategic alignment | Does this solve a priority enterprise problem? |
| Measurable value | Is there a credible baseline and target outcome? |
| Workflow readiness | Can users adopt it without creating new friction? |
| Data readiness | Are local data, integration, access, and monitoring adequate? |
| Risk profile | What happens if the output is wrong, biased, unavailable, or misused? |
| Accountable ownership | Who owns the workflow, decision, outcome, and escalation path? |
The first deployment should not simply be the easiest. It should build confidence and useful organizational capability without exposing the system to unnecessary risk.
Step 2: Establish the Value Case
AI projects often lose momentum because the business case is too general. "Improved efficiency" is not enough. Executives need to understand what will improve, for whom, by how much, and over what period.
Set a baseline before implementation. Depending on the use case, this may include:
- Documentation time per encounter
- Call abandonment and average speed of answer
- Appointment conversion and time to appointment
- Denial rates and days in accounts receivable
- Length of stay and discharge delays
- Staff productivity and overtime
- Patient experience and digital engagement
- Clinical process, quality, or safety measures
The baseline does not need to be perfect, but it must be credible enough to support a decision.
Value should also include the full cost of adoption. A business case that includes only licensing fees will understate the investment. Account for integration, workflow redesign, training, change management, governance, monitoring, support, vendor management, and the time required from clinical and operational leaders.
The right question is not whether the technology performs well in isolation. It is whether the entire process performs better after the technology is introduced.
A disciplined value case gives leadership a basis for making three decisions:
- Proceed
- Redesign the use case
- Stop the initiative
That level of clarity is more useful than a long list of pilots with no defined path to scale.
Step 3: Assess Capabilities and Data
A health system cannot build a durable AI program on disconnected data, unclear ownership, and informal technical support. Before scaling AI, leaders need an honest view of the capabilities already in place.
Review the organization across four areas.
Data and Infrastructure
Assess data quality, interoperability, access controls, integration patterns, analytics environments, cybersecurity, model monitoring, and the technical ability to support AI-enabled workflows over time.
Data quality deserves particular attention. An AI system can produce a technically accurate output that is still unsuitable for local use if the underlying data is incomplete, poorly defined, biased, or materially different from the population used to develop the model.
People and Expertise
Identify the clinical sponsors, operational owners, informatics leaders, data and analytics resources, privacy and security teams, legal counsel, procurement partners, finance leaders, and change-management capacity required to support the work.
AI cannot be assigned exclusively to IT, innovation, or an individual department. It requires coordinated ownership across the people accountable for technology, workflow, safety, business performance, and user adoption.
Workflow Readiness
Evaluate process stability, current-state variation, decision rights, user capacity, training needs, escalation processes, and the organization's ability to redesign work around the technology.
A poorly designed or unstable workflow does not become effective simply because an AI layer is added to it.
Financial and Portfolio Discipline
Establish funding expectations, prioritization criteria, procurement standards, vendor-management practices, and a process for reviewing investments across the portfolio.
This is also where vendor diligence becomes important. Ask vendors for information about training data, validation methods, known limitations, performance by relevant populations, security posture, update processes, audit access, and the organization's ability to monitor the tool after deployment.
Do not assume vendor validation is the same as local validation. The tool must work in your environment, with your workflows, data, patient population, staffing model, and escalation processes.
Step 4: Define Risk and Governance
Governance should not be treated as a committee that reviews AI after the purchase decision has already been made. It should be built into the process from the beginning.
A practical governance model starts with an inventory of every AI-enabled tool in use or under consideration. Include enterprise applications, EHR-embedded tools, vendor platforms, departmental pilots, internally developed models, and informal tools being used by employees. Many organizations discover that their actual AI footprint is larger than their approved portfolio.
Next, classify tools according to risk. A patient-facing clinical decision-support tool should not follow the same approval path as an internal administrative assistant. Risk classification can consider patient impact, degree of automation, data sensitivity, potential for bias, explainability, workflow dependence, human review requirements, and the consequences of error.
For higher-risk systems, governance should address:
- Executive ownership and clinical accountability
- Privacy, security, and data-use controls
- Pre-deployment validation and workflow testing
- Performance, safety, and equity monitoring
- Human review, escalation, and override expectations
- Incident reporting and response
- Vendor obligations and audit rights
- Criteria for modification, suspension, or retirement
The National Institute of Standards and Technology AI Risk Management Framework provides a useful structure through its Govern, Map, Measure, and Manage functions. The World Health Organization's guidance on ethics and governance of AI for health reinforces the importance of safety, accountability, transparency, inclusion, and protection of human rights.
These frameworks do not replace operational judgment. They provide a structure for making that judgment consistently.
Step 5: Build the Operating Model
Strategy fails when responsibility is spread across IT, clinical leadership, compliance, finance, and individual departments without a clear owner or decision process.
The operating model should define:
- Who sets enterprise priorities
- Who approves use cases and funding
- Who reviews clinical, operational, technical, legal, privacy, and security risks
- Who validates performance before and after launch
- Who manages vendor relationships and contract obligations
- Who monitors live systems
- Who owns incidents and escalation
- Who has authority to pause or stop a deployment
A central AI steering group may be appropriate for enterprise prioritization, investment decisions, and risk appetite. Separate clinical, technical, operational, privacy, or security review may be necessary depending on the use case.
The exact structure will vary by organization. Accountability, however, cannot remain implied.
A practical first-year roadmap could look like this:
| Timing | Focus |
|---|---|
| First 90 days | Inventory AI tools, identify priority problems, assess capability gaps, establish executive sponsorship, and define initial governance principles |
| Months 4-6 | Standardize intake, use-case scoring, risk review, procurement, vendor diligence, measurement, and approval templates |
| Months 7-9 | Apply the model to a small number of high-value use cases and document what needs to change before scale |
| Months 10-12 | Decide what to scale, redesign, pause, or retire; refine the operating model and expand it to the broader portfolio |
The roadmap should be connected to the broader digital and operating agenda. AI should not become another technology program running beside digital transformation, consumer experience, access, workforce, financial improvement, or clinical improvement initiatives.
Governance Is Part of Adoption
The most effective governance programs are not designed to slow progress. They help organizations move faster with fewer avoidable mistakes.
When standards are clear, leaders can make decisions more quickly. When risk categories are defined, teams know which reviews are required. When measurement is established before launch, the organization can distinguish between a useful deployment and an expensive demonstration.
Governance also improves trust. Clinicians need to understand where a tool fits into their work, what it can and cannot do, and where their judgment remains essential. Patients and communities need appropriate transparency about how their information, experience, and care may be affected. Boards and executives need visibility into the organization's exposure, investment, and progress.
AI maturity is not measured by how many tools a health system has deployed. It is measured by how consistently the organization can decide, implement, monitor, and scale the tools that matter.
Where to Start
Choose one important problem this quarter and evaluate it through all five steps:
- Assess the opportunity.
- Establish the value case.
- Review capabilities and data.
- Define risk and governance.
- Assign ownership and build the operating model.
Do not begin with a broad list of tools. Begin with a clear decision about the work that needs to improve and the conditions required for responsible scale.
If your organization has multiple AI tools in market, pilots underway, or departments pursuing vendors independently, the next step may not be another pilot. It may be a focused AI readiness and portfolio review that clarifies priorities, ownership, risk, value measures, and the path to scale.
BreckenReese Ventures works with health systems and enterprise teams on AI readiness, digital transformation, consumer experience, governance, operating model design, and roadmap development. Our advisory practice provides senior operator capacity shaped around the problem, not a fixed package. Share where you are headed and what is in the way, and we can bring a practical perspective to the next decision.
This article provides strategic and operational guidance and is not legal, regulatory, privacy, security, or clinical advice.
Sources
- KLAS Research and CCM. Healthcare AI Update 2025: What Use Cases Are Adopted the Most? Subscription access may be required.
- National Institute of Standards and Technology, AI Risk Management Framework
- World Health Organization, Ethics and Governance of Artificial Intelligence for Health