Executive Summary
Artificial intelligence is evolving rapidly, and healthcare organizations are beginning to adopt a new generation of technologies known as agentic AI. Unlike traditional generative AI tools that respond to prompts, agentic AI systems can reason, plan, and complete multi-step tasks with increasing levels of autonomy. These capabilities have the potential to transform healthcare operations, but they also introduce new legal, regulatory, privacy, and governance challenges.
In the second session of Clearwater’s 2026 Healthcare AI Executive Summer Series, Dawn Morgenstern, Chief Privacy Officer and Senior Principal Consultant at Clearwater, joins Adam Greene, Partner at Davis Wright Tremaine LLP, to examine the evolving regulatory landscape surrounding healthcare AI. Together, they discuss what healthcare organizations should do today while federal agencies, state governments, and industry organizations continue to develop AI guidance and oversight.
One message remains consistent throughout the discussion: organizations should not wait for regulatory certainty before establishing AI governance. Existing privacy, cybersecurity, compliance, and enterprise risk management practices provide a strong foundation for governing AI responsibly while remaining flexible enough to adapt as expectations continue to evolve.
Why This Conversation Matters
Healthcare leaders are navigating an environment where AI innovation is moving faster than regulation.
Federal agencies are publishing guidance. States are introducing AI legislation. Industry organizations are developing governance frameworks. At the same time, healthcare organizations are being asked to evaluate new AI technologies that promise greater efficiency, improved patient experiences, and operational transformation.
This creates an understandable challenge.
Should organizations wait until regulations become clearer before deploying AI?
According to the panel, the answer is no.
Waiting for complete regulatory certainty is neither practical nor necessary. Organizations already have many of the governance tools they need. The priority should be building flexible governance programs that can evolve alongside technology and regulation.
Adam Greene: “The regulations will continue to evolve, but organizations still need governance today.”
Key Insights from the Discussion
Agentic AI Introduces New Governance Questions
The conversation begins by defining what makes agentic AI different from earlier generations of artificial intelligence.
Traditional generative AI typically produces text, images, or other outputs in response to user prompts. Agentic AI goes a step further by completing tasks, interacting with multiple systems, making decisions, and executing workflows with less direct human involvement.
These capabilities create significant opportunities for healthcare organizations, but they also increase the importance of governance.
Organizations must understand not only what an AI system produces, but also what actions it can take, what data it can access, and what safeguards exist to prevent unintended outcomes.
As AI becomes more autonomous, governance must become more intentional.
Existing Regulations Still Apply
A major theme throughout the discussion is that healthcare organizations should avoid thinking of AI as existing outside established regulatory frameworks.
HIPAA requirements remain in place.
Privacy obligations remain in place.
Cybersecurity expectations remain in place.
Vendor oversight responsibilities remain in place.
Rather than replacing existing compliance programs, AI governance should build upon them.
Dawn Morgenstern: “Many of the principles we already use still apply.”
The speakers encourage organizations to view AI as another technology that must be evaluated through existing governance, privacy, and enterprise risk management processes.
Governance Should Be Built Around Risk
Not every AI application introduces the same level of organizational risk.
The panel recommends adopting a risk-based governance model that considers factors such as:
- Clinical impact
- Patient safety
- Data sensitivity
- Level of autonomy
- Operational complexity
- Regulatory implications
For example, an AI chatbot answering scheduling questions requires a different level of oversight than an AI system supporting clinical decision-making.
Matching governance to organizational risk allows healthcare leaders to allocate resources effectively while avoiding unnecessary barriers to innovation.
Human Accountability Remains Essential
As AI systems become more capable, organizations may be tempted to rely more heavily on automation.
The speakers caution against this approach.
AI can support decision-making, but accountability always remains with people.
Organizations should establish clear expectations for human oversight, escalation processes, monitoring, and governance throughout the AI lifecycle.
This becomes even more important as agentic AI systems begin making increasingly complex decisions or interacting with multiple technologies without direct human input.
Responsible AI depends on maintaining meaningful human involvement in high-impact decisions.
Organizations Should Prepare Before Regulations Mature
Healthcare leaders frequently ask whether they should delay governance investments until regulators publish more detailed requirements.
The discussion argues that waiting creates unnecessary organizational risk.
Instead, organizations should begin developing governance capabilities today, including:
- AI governance committees
- AI inventories
- Vendor evaluation processes
- Risk assessment methodologies
- AI policies and procedures
- Executive oversight structures
These foundational governance capabilities will remain valuable regardless of how future regulations evolve.
Organizations that begin building governance now will be better prepared to adapt as expectations continue changing.
Governance Should Support Innovation
One of the strongest messages throughout the webinar is that governance is not intended to slow AI adoption.
Healthcare organizations face growing pressure to improve operational efficiency, reduce administrative burden, enhance patient experiences, and support clinicians with better technology.
AI offers meaningful opportunities to address these challenges.
Effective governance creates the confidence organizations need to innovate responsibly while managing legal, privacy, cybersecurity, and operational risks.
The goal is not to prevent innovation.
The goal is to make innovation sustainable.
Practical Recommendations for Healthcare Leaders
The discussion offers several practical recommendations for organizations beginning or maturing their AI governance programs:
- Begin governance before AI technologies are implemented.
- Build on existing compliance, privacy, cybersecurity, and enterprise risk management programs.
- Evaluate AI solutions according to organizational risk.
- Maintain meaningful human oversight for higher-risk AI applications.
- Monitor regulatory developments while avoiding unnecessary delays in governance.
- Design governance processes that can evolve alongside technology.
These recommendations provide a practical roadmap for organizations navigating one of healthcare’s fastest-changing technology landscapes.
Notable Quotes
Adam Greene: “The regulations will continue to evolve, but organizations still need governance today.”
Dawn Morgenstern: “Many of the principles we already use still apply.”
Questions This Discussion Answers
- What is agentic AI?
- How is agentic AI different from generative AI?
- How should healthcare organizations govern agentic AI?
- Does HIPAA still apply when organizations use AI?
- How are FDA guidance, HHS priorities, and state AI laws shaping healthcare governance?
- Should organizations wait for AI regulations before implementing governance?
- How can healthcare organizations balance innovation with regulatory uncertainty?
- Why is human oversight still essential for AI?
About This Webinar
This webinar is the second session of Clearwater’s 2026 Healthcare AI Executive Summer Series. Dawn Morgenstern and Adam Greene explore one of healthcare’s most pressing AI challenges: governing increasingly autonomous AI technologies while regulatory expectations continue to evolve. Drawing on expertise in healthcare privacy, compliance, and healthcare law, they explain how organizations can establish durable governance programs using existing risk management principles instead of waiting for perfect regulatory clarity. The session provides practical guidance for healthcare executives, privacy officers, compliance leaders, legal counsel, and technology professionals responsible for adopting AI responsibly while preparing for the future of healthcare regulation.
