AI Governance for Healthcare and Regulated Companies
Your staff are already using AI tools on regulated data. The question is who owns that, and what you do about it.
The failure everyone expects is the AI pilot that dies in review: legal will not sign, security sends a ninety-question assessment, and the thing quietly stops. That happens. It is not the failure worth worrying about.
The one worth worrying about is the opposite. Adoption that succeeded completely, with no governance around it whatsoever. Staff opened a browser tab, the tools worked, and nobody wrote down which ones are approved, what data may go into them, or who decides. Nobody has an inventory, and nobody could answer a customer or a regulator asking what happens to their data. The answer exists. It is just that nobody in the building knows it.
What AI governance actually involves
Shadow AI discovery
What is actually in use, which is always more than the list anybody can produce from memory. Expense and subscription records, identity and sign-in logs, browser and network telemetry where it exists, and asking people directly in a way that does not make it a disciplinary conversation.
An acceptable use policy people will follow
Which tools are approved, which categories of data may go into each, what may never go into any of them, and who to ask when it is unclear. Short enough to be read, specific enough to be actionable, and written against the tools staff are actually using.
Data protection for AI tools
Keeping regulated data out of the places it must not go: tenant and account configuration, retention and training settings, data loss prevention rules aimed at the paste-into-a-chat-box path, and the controls that make the sanctioned route the easy one.
Vendor agreements and processing terms
Business associate agreements where protected health information is involved, data processing terms, what the contract says about using your data for model training, and which product tiers the agreement actually covers. Consumer tiers are generally not the tier under contract.
Reaching models under paper you already hold
A large share of AI projects that look blocked on legal are blocked on a contract that already exists somewhere in the building. Managed model services from the major clouds often let you reach the same class of models under an agreement your organization has already signed and already had reviewed.
A route to approving use cases
Someone proposes using a tool for something. There has to be a way to say yes that takes days rather than a quarter, with the questions asked once and written down: what data, which tool, who reviews the output, and who is accountable for it.
Human review designed in, not bolted on
Review at the point where the work is already happening rather than in a separate approval queue nobody has time for. Done properly it improves the product and the data quality, and the compliance benefit is a side effect.
A named owner
A policy nobody owns is not a control. One person accountable for the inventory, the policy and the approval route, with enough authority to say no and enough credibility to be asked before rather than after.
Governance that lets adoption continue
The instinct when shadow AI surfaces is to ban it until a policy exists. That is the one move guaranteed to make the problem invisible rather than smaller. A ban does not stop the activity; it moves the same activity onto personal accounts and personal devices, where you can neither see it nor govern it, and where the data protection you were worried about is now certainly absent.
The work is making the sanctioned route good enough that nobody needs the unsanctioned one. That means approved tools that are actually useful, a way to get a new use case approved in days, and a policy that answers questions rather than only forbidding things. People adopted these tools because they help, and any governance that ignores that gets routed around, which is the real compliance risk.
The longer version of this argument, including why most of what gets asked for is not AI at all, is in deploying AI in regulated environments.
Fractional Chief AI Officer, and what that means here
Some companies call this role a fractional Chief AI Officer, or a fractional CAIO. The label is fine and the scope behind it varies a lot, so it is worth being specific about which half of it this is.
This page covers the governance and risk half. Who is accountable, what is in use, what data may go where, which vendors are approved and on what terms, how a use case gets approved, and how you answer a customer or a regulator who asks. That work sits naturally inside the security program, which is why it belongs to the fractional CISO side of the practice.
Where a Chief AI Officer role also covers deciding what to build and then building it, the architecture and build-versus-buy half of that is a fractional CTO conversation, and plenty of companies need both.
What is out of scope
I do not do model development, machine learning research, or data science. Not as a matter of positioning: those are different disciplines with different people, and hiring me for them would be a mistake I would rather you not make. If what you need is someone to train a model, tune one, or build a data science function, that is a different hire and I will say so in the first conversation.
I do not hold AIGP, ISO/IEC 42001 certification, or any other AI credential, and I am not going to imply otherwise. What this rests on is having built and secured systems in regulated environments, which is where the governance questions actually land: agreements, data flows, access, accountability and evidence.
HIPAA and AI tools
If you handle protected health information, any AI vendor processing it on your behalf is a business associate, and an agreement has to be in place before data moves. That is the whole rule, and most of the difficulty is procedural rather than legal.
The instinct is to start a new negotiation with a model provider, which means legal review, a new vendor, and a security assessment of a company nobody in the organization has dealt with. Frequently that is avoidable. Managed model services from the major cloud providers let you reach the same class of models under an agreement your organization already holds, has already had reviewed, and already has a relationship behind. Check what you already hold before you start something new.
Two things are worth verifying rather than assuming, whichever route you take: what the terms say about using your data for model training, and which product tiers and features the agreement actually covers. Coverage is specific, and the consumer tier of a product is generally not the tier under contract.
This sits alongside the rest of the HIPAA security program rather than beside it as a separate exercise. The risk analysis has to account for where protected health information now goes.
What usually brings people here
A customer, an auditor or a partner has asked what AI tools you use and what happens to their data, and assembling the answer took a week.
You handle protected health information and staff are using assistants that nobody has an agreement with.
Somebody wants to ship an AI feature and there is no route to approving it other than a meeting that keeps being rescheduled.
Adoption is already widespread, it is working, and the governance never happened.
A board or an investor has asked what your AI exposure is.
How the engagement runs
The first pass is fixed-price: discovery of what is in use, the policy and the approved tool list, the vendor and agreement position, and the approval route, delivered with whatever data protection configuration the findings call for.
What decides whether it holds is who owns it afterwards. A policy nobody owns decays quickly, and AI tooling changes faster than most things you have written a policy about. Where there is nobody to hold it, that is an ongoing fractional CISO arrangement and this becomes one of the named responsibilities inside it.
Questions I get asked first
Is this the same as a fractional Chief AI Officer?
It is the governance and risk half of that role. Some companies use fractional Chief AI Officer or fractional CAIO for a job that also includes AI strategy, model selection and building things. This covers who is accountable, what data may go where, which vendors are approved on what terms, and how a use case gets said yes to. If you need someone to build models, that is a different hire.
Do we have to ban the tools while this gets sorted out?
No, and banning them is the failure mode rather than the fix. A ban moves the same activity onto personal accounts where you can neither see it nor govern it. The work is making the sanctioned route good enough that nobody needs the unsanctioned one.
Can we use AI tools with protected health information?
Often yes, under the right paper and the right architecture. Any vendor processing protected health information on your behalf is a business associate and needs an agreement in place before data moves. The quickest route is frequently a model service under a cloud agreement your organization already holds, rather than a new vendor negotiation nobody has started.
How do we find out what is already being used?
A combination of expense and subscription records, identity and sign-in logs, network and browser telemetry where it exists, and asking people directly without making it a disciplinary conversation. The last one works better than expected when staff understand the goal is a sanctioned route rather than a ban.
Do you hold an AI governance certification?
No. I hold CISSP and Azure architecture certifications, and I am not going to claim an AI credential I do not have. What this rests on is having built and secured systems in regulated environments, which is what the governance questions actually turn on.
Written on this
Start with a conversation
Tell me what’s going on. If you do not know what is in use yet, that is the normal starting position and the first thing to fix.
Bring what you know about the AI tools your staff are using, a vendor's terms, or a policy you're not sure holds up.
Not ready for a call? Send a message instead.
For companies looking to engage BATO. Vendors, please email.