Executive Summary
Healthcare organizations have largely moved beyond asking whether they need AI governance. Today, the bigger challenge is turning governance into an operational capability that supports responsible AI adoption across the enterprise.
As artificial intelligence becomes embedded in clinical care, administrative operations, cybersecurity, and business workflows, organizations need practical processes for evaluating AI, managing risk, assigning ownership, and monitoring AI systems throughout their lifecycle. Policies and governance committees are important starting points, but they must be supported by repeatable processes that become part of everyday operations.
In the fourth session of Clearwater’s 2026 Healthcare AI Executive Summer Series, Dave Bailey, Vice President of Consulting Solutions & Strategy at Clearwater, and Cate Ciccolone, Associate Director of Commercial Health IT Advisory at Guidehouse, discuss what operational AI governance looks like in practice. Drawing on their experience advising healthcare organizations, they explore governance structures, AI inventories, risk prioritization, change management, and strategies for integrating AI governance into existing organizational processes.
The discussion reinforces that effective governance should enable responsible innovation. Organizations that operationalize governance early will be better prepared to scale AI adoption while maintaining accountability, transparency, and enterprise-wide risk management.
Why This Conversation Matters
Many healthcare organizations have already developed AI principles or formed governance committees. Those are important first steps, but governance cannot remain a strategic exercise.
Healthcare leaders now face practical questions:
- How do we govern hundreds of AI use cases?
- Who approves new AI technologies?
- How do we know where AI already exists?
- How do we prioritize governance efforts?
- How do we avoid slowing innovation?
Dave Bailey and Cate Ciccolone explain that organizations should stop thinking about governance as a standalone initiative and begin embedding it into existing business processes.
AI governance becomes sustainable when it is integrated into procurement, cybersecurity, compliance, enterprise risk management, privacy, clinical operations, and organizational decision-making.
Key Insights from the Discussion
Governance Must Become Operational
The conversation begins with a simple observation: most healthcare organizations understand the importance of AI governance.
The difficult part is execution.
Policies alone do not govern AI. Governance becomes effective when organizations establish repeatable processes that guide every stage of the AI lifecycle, from evaluating vendors to approving implementations, monitoring performance, and reassessing risk over time.
Dave Bailey explains that governance should become part of the way organizations naturally make decisions, not an additional process employees try to avoid.
Operational governance creates consistency, accountability, and confidence as AI adoption expands.
You Cannot Govern What You Cannot See
One of the strongest themes throughout the discussion is visibility.
Many healthcare organizations underestimate how much AI already exists within their environments.
AI is no longer limited to standalone applications. It is increasingly embedded within electronic health records, cybersecurity platforms, imaging solutions, revenue cycle technologies, productivity software, and countless third-party vendor products.
Without understanding where AI is being used, organizations cannot effectively assess risk or assign ownership.
Cate Ciccolone: “You can’t govern what you don’t know you have.”
The speakers encourage organizations to develop an enterprise AI inventory that documents AI-enabled technologies, identifies responsible business owners, and establishes a foundation for ongoing governance.
Risk Should Drive Governance
Not every AI system requires the same level of oversight.
Throughout the discussion, the speakers recommend adopting a risk-based governance model.
Organizations should evaluate AI according to factors such as:
- Patient safety
- Clinical impact
- Data sensitivity
- Business criticality
- Regulatory requirements
- Level of autonomy
An internal productivity tool presents different governance considerations than an AI application supporting clinical decisions.
Risk-based governance allows organizations to focus oversight where it provides the greatest value while avoiding unnecessary bureaucracy for lower-risk use cases.
Build on Existing Governance Structures
Healthcare organizations often assume AI requires entirely new governance programs.
Dave Bailey challenges this assumption.
Most organizations already maintain governance structures for:
- Enterprise risk management
- Cybersecurity
- Privacy
- Compliance
- Vendor management
- Quality improvement
- Change management
Instead of creating separate AI governance silos, organizations can extend these existing processes to include AI-specific considerations.
This approach improves adoption because employees already understand how existing governance processes work.
AI simply becomes another factor considered during organizational decision-making.
Governance Is a Team Sport
No single department possesses all of the expertise necessary to govern AI effectively.
Technology leaders understand system architecture and cybersecurity.
Compliance professionals evaluate regulatory obligations.
Privacy teams assess data protection.
Clinical leaders understand patient safety and workflow implications.
Legal teams review contracts and liability.
Executive leadership aligns AI initiatives with organizational priorities.
The speakers explain that successful governance depends on bringing these perspectives together through structured collaboration.
Cross-functional governance produces stronger decisions because it reduces organizational blind spots while improving accountability.
Change Management Is Often Overlooked
Technology is only one part of successful AI implementation.
Organizations must also help employees understand:
- Why governance exists
- How governance supports innovation
- Who is responsible for decisions
- When governance processes should be followed
Without effective communication and organizational engagement, governance can easily be perceived as an obstacle instead of an enabler.
The panel emphasizes that change management should receive as much attention as governance documentation itself.
Organizations that build governance into their culture are far more likely to sustain responsible AI adoption over time.
Governance Is Never Finished
The session concludes by emphasizing that AI governance is not a one-time project.
AI capabilities continue evolving.
Vendors introduce new features.
Regulatory expectations change.
Organizational priorities shift.
Governance programs must evolve accordingly.
Organizations should continuously monitor AI systems, reassess risks, update inventories, review governance processes, and refine policies as new technologies emerge.
Operational governance becomes an ongoing organizational capability that grows alongside AI adoption.
Practical Recommendations for Healthcare Leaders
The discussion highlights several practical actions organizations can begin implementing immediately:
- Create and maintain an enterprise AI inventory.
- Assign a business owner for every AI implementation.
- Prioritize governance according to organizational risk.
- Extend existing governance processes instead of creating entirely new structures.
- Include compliance, cybersecurity, privacy, legal, clinical, and executive stakeholders in governance decisions.
- Review AI systems regularly as technologies and risks evolve.
- Treat governance as an operational discipline rather than a project.
These recommendations help organizations establish governance programs that support innovation while maintaining accountability across the enterprise.
Notable Quotes
Cate Ciccolone: “You can’t govern what you don’t know you have.”
Dave Bailey: Effective AI governance becomes part of everyday operations rather than a separate initiative.
Questions This Discussion Answers
- How do healthcare organizations operationalize AI governance?
- What should an enterprise AI inventory include?
- How should organizations prioritize AI risk?
- How can AI governance be integrated into existing governance processes?
- Why is cross-functional leadership essential for AI governance?
- How does change management support successful AI adoption?
- What does mature AI governance look like in practice?
- How should governance evolve as AI technologies continue changing?
About This Webinar
This webinar is the fourth session of Clearwater’s 2026 Healthcare AI Executive Summer Series. Dave Bailey and Cate Ciccolone examine what it takes to move AI governance from strategy to execution. Drawing on practical experience helping healthcare organizations implement governance programs, they discuss how to establish AI inventories, prioritize risk, integrate governance into existing organizational processes, and create governance models that scale with AI adoption. The discussion provides healthcare executives, governance committees, risk leaders, and technology professionals with practical guidance for operationalizing AI governance while supporting responsible innovation across the enterprise.
