Healthcare Is Showing Why AI Governance Is Becoming Part of Product Value

21 September 2026

Healthcare may offer one of the clearest demonstrations of why artificial intelligence governance can no longer be treated as a legal or compliance exercise sitting outside product development. When AI contributes to medical imaging, diagnosis or clinical decision support, governance becomes part of how the product itself is designed, tested, sold and ultimately trusted. That was the central message from a discussion at Ai4 2026 in Las Vegas involving the International Association of Privacy Professionals and Lara Liss, Chief Privacy and Data Trust Officer at GE HealthCare. The discussion examined how AI governance is evolving in a highly regulated sector where safety, clinical reliability, privacy and accountability need to be considered alongside innovation.

Healthcare is particularly important because AI is already embedded in medical technology rather than remaining a future concept. GE HealthCare has one of the largest portfolios of FDA-authorised AI-enabled medical devices, and the US Food and Drug Administration maintains a dedicated list of such products that have met the applicable requirements for marketing in the United States. The rapid growth of healthcare AI is also creating a more complicated boundary between traditional medical companies and technology businesses. Medical-device manufacturers operate within established regulatory systems covering safety and effectiveness, while consumer technology companies are increasingly developing products capable of offering health-related information and advice. That raises questions about whether users fully understand the difference between regulated medical technology and general-purpose AI applications that may appear to perform similar functions.

Liss emphasised that, under the current US framework, AI should be viewed primarily as a tool supporting healthcare professionals rather than as an independent medical practitioner. That distinction becomes increasingly important as chatbots and other consumer-facing AI systems begin providing information that users may interpret as medical advice. The legal and regulatory questions around those systems are still evolving, but the broader governance issue is already clear: the greater the potential consequence of an error, the stronger the controls surrounding the system need to be.

Healthcare organisations therefore increasingly combine several governance frameworks rather than relying on a single standard. These can include the EU AI Act, the NIST AI Risk Management Framework, ISO standards and existing medical-device requirements. The value of those frameworks is not simply that they create another layer of documentation. They force organisations to define how risks such as safety, reliability, fairness, privacy, cybersecurity, transparency and explainability will be addressed throughout development and use. For GE HealthCare, safety remains the central consideration, but the same principle can apply elsewhere. Every organisation needs to identify what matters most in its own industry, understand what failure could mean and establish evidence that those risks are being managed appropriately.

GE HealthCare’s Vscan Air handheld ultrasound system provides an example of how AI can be integrated into clinical technology. The pocket-sized wireless device is designed for trained healthcare professionals and can be used in settings ranging from routine examinations to triage and point-of-care assessments. AI-supported functions available with the platform can assist with image acquisition and interpretation, but the important governance point is that the technology remains embedded within a broader clinical process. It supports clinicians rather than eliminating their role, while intended-use restrictions, training, product controls and medical-device regulation form part of the surrounding infrastructure.

That demonstrates why human oversight cannot be considered separately from product design. Simply saying that a human remains in the loop does not automatically make an AI system safe. Companies need to define what that person is expected to do, what information they receive, when they can override the technology and which decisions remain entirely their responsibility. Healthcare has dealt with comparable questions around clinical accountability for decades, giving the sector experience that many other industries are now having to develop for the first time.

Another major theme from the discussion was organisational structure. There is still no universally accepted answer to where AI governance should sit inside a company. Liss argued that the location of the function matters less than whether the right people are involved and whether the programme has sufficient resources and influence. A governance function confined entirely to legal or compliance can struggle because policies written on paper may not reflect how models and products actually operate. Product teams, data scientists, engineers and business leaders therefore need to participate directly in governance decisions.

This effectively brings governance into the product-development lifecycle. Legal and compliance teams identify obligations and risk, technical specialists understand models and data flows, while product and business teams determine how the technology will actually be used. Healthcare can add another important voice through ethicists and bioethicists, particularly where technology intersects with patient welfare, difficult clinical choices or questions about appropriate treatment. Ethics expertise is not new to medicine, but AI introduces new circumstances in which that judgement must be connected directly to operational and product decisions.

Data governance becomes increasingly important as AI systems become more autonomous. A model or agent cannot make reliable decisions if the information available to it is incomplete, poorly controlled or inappropriate for the task. Governance teams therefore need to understand not only what the AI application does, but how information flows through it, what data it can access and how outputs feed into subsequent decisions. As agentic AI develops, companies may also need to rethink traditional responsibility structures by identifying what tasks automated agents perform, what authority they have, who remains accountable for their actions and when human intervention is required.

That could change familiar organisational frameworks. Companies commonly identify who is responsible, accountable, consulted and informed for particular business activities. If an AI agent begins performing part of the work previously carried out by an employee, management may need to map that system alongside the human participants. Automation should not create gaps where responsibility becomes unclear simply because part of the workflow has moved from a person to software.

The discussion also highlighted a commercial consequence that is likely to become increasingly important beyond healthcare. Liss argued that organisations developing AI products should treat governance as part of the product’s value because potential buyers, investors and strategic partners are likely to examine how the technology was trained, tested and controlled during due diligence. That changes the economics of governance. A company preparing for an acquisition, investment round or public offering may find that incomplete documentation, unclear data rights or poorly defined AI controls are not merely compliance weaknesses, but transaction risks.

A buyer acquiring an AI-enabled company or product inherits the technology together with potential privacy, intellectual-property, regulatory and operational exposures. Strong governance can therefore improve the quality of the asset being sold. A business that can explain how its models were developed, where its data originated, how performance was evaluated, what risks were identified and how systems are monitored gives potential investors or acquirers a much clearer picture of what they are buying.

That lesson applies directly to technology investment and increasingly to commercial real estate. Property businesses are introducing AI into asset management, tenant services, building energy systems, valuation, leasing, security and investment analysis, while proptech companies developing these products may eventually become acquisition targets for landlords, investors or larger technology platforms. Their governance arrangements could consequently become part of corporate and technology due diligence. A buyer considering an AI-enabled building-management platform, for example, may need to understand what building and tenant data the system collects, whether that information can legally be transferred, how automated decisions are made, what happens if the system fails and whether the underlying models depend on third-party technology providers.

Healthcare provides a useful model because its regulatory environment forced many of these questions to be considered earlier than in less regulated industries. Product safety, validation, documented processes, privacy and human accountability were already part of the operating environment before generative AI arrived. The broader corporate lesson is that AI governance works most effectively when it is embedded in the infrastructure of the organisation rather than added after a product has been built.

Policies alone cannot create trustworthy AI if developers, business leaders and risk teams operate separately. Governance becomes valuable when those disciplines influence product decisions from the beginning. That may also explain why the boundary between governance and infrastructure is starting to blur. Technology organisations traditionally receive substantial budgets for platforms, data and security, while governance functions have often been comparatively lightly resourced. As AI becomes core infrastructure, companies may begin treating the systems required to monitor, test and control it as infrastructure as well.

Healthcare ultimately demonstrates why this matters. AI can create substantial value by helping clinicians work more efficiently and extending access to sophisticated diagnostic tools, but the greater the role technology plays in consequential decisions, the more important it becomes to know where responsibility sits, what standards apply and how performance is monitored. For companies in any industry, that makes governance much more than a regulatory obligation.

It increasingly forms part of product quality, corporate resilience and enterprise value. Businesses that can demonstrate how their AI systems were built, tested, controlled and integrated into human decision-making may therefore have an advantage not only with regulators and customers, but with investors, strategic partners and potential acquirers as well.

Source: CIJ.World Research & Analysis Team

front page info
LATEST NEWS