The following is a guest article by Lesley Berkeyheiser, Senior Director of Accreditation Strategy and Development at DirectTrust
Artificial Intelligence (AI) is rapidly moving from experimentation to implementation across healthcare and other industries. Organizations are exploring everything from productivity tools and workflow automation to advanced analytics, decision support, and customer-facing applications.
With the recent launch of DirectTrust’s Artificial Intelligence Accreditation Program, we’ve had the opportunity to work closely with several organizations participating in the program’s beta phase. These early participants helped evaluate the accreditation criteria while assessing how AI fits into their business, operations, and governance structures.
Built upon the National Institute of Standards and Technology (NIST) AI Risk Management Framework, the program helps organizations assess, govern, and manage the risks associated with AI adoption.
One thing has become increasingly clear: governing AI is sometimes more challenging than deploying it. AI is evolving so quickly that many organizations are effectively building the plane while flying it. Definitions, use cases, risks, and governance expectations continue to change, making accountability, oversight, and risk management just as important as the technology itself.
Through the development of the program and discussions with organizations evaluating how AI fits into their operations, several common themes have consistently emerged.
1. AI is Not an IT Project
One of the most common misconceptions about AI is that it can be treated like a traditional technology deployment.
In reality, AI affects far more than technical teams. Decisions surrounding AI often involve legal, compliance, privacy, security, operations, human resources, executive leadership, and business stakeholders. Questions around accountability, transparency, acceptable use, risk tolerance, and oversight extend well beyond the IT department.
Organizations achieving the greatest success are approaching AI as an enterprise-wide initiative rather than a standalone technology project.
One of the most surprising observations has been how quickly AI conversations move beyond technology. Organizations frequently begin by evaluating a tool and soon discover that successful governance requires participation from across the enterprise.
2. Many Organizations Already Have Shadow AI
One of the first responsibilities of leadership is understanding where AI is already being used and establishing clear guidance for responsible and secure adoption.
Employees are increasingly using AI capabilities to support everyday work, sometimes without even thinking of them as AI. That may include publicly available tools such as ChatGPT, Gemini, or Claude, but it can also include AI-powered features embedded within familiar applications like Microsoft Outlook, Microsoft Copilot, Google Workspace, Grammarly, meeting assistants, coding tools, and other productivity platforms. In many cases, these activities begin long before formal policies, governance structures, or approved use cases have been established.
Together, these activities create what many now refer to as “shadow AI.” In some organizations, employees are already using AI tools to support their work whether formal governance structures exist or not. Leaders may discover they are not deciding whether AI will be used, but rather how to govern its use responsibly.
3. Governance Should Begin Before Deployment
Many organizations assume governance becomes important after AI has been selected and deployed.
The opposite is often true.
In several cases, participating organizations from our AI Accreditation program’s beta phase initially questioned whether they were ready to pursue an AI governance program because they had not yet fully implemented AI. What they discovered was that the framework itself helped identify the policies, controls, governance structures, and risk considerations they would eventually need. The exercise became a roadmap rather than simply an assessment.
Questions surrounding data sources, acceptable use, oversight, privacy, transparency, risk management, and accountability are often easier to address early than after AI becomes embedded in business processes.
Strong governance provides a foundation that helps organizations make informed decisions about how AI should be used and where additional controls may be necessary.
4. AI Requires Continuous Monitoring
Unlike traditional software implementations, AI systems can evolve, learn, change behavior, and produce different results over time.
Organizations must account for the possibility of inaccurate outputs, unexpected behavior, model drift, hallucinations, or unintended consequences. Effective AI governance therefore requires ongoing monitoring, validation, quality assurance, and performance measurement.
To proactively address these requirements, organizations should establish mechanisms to evaluate outcomes, measure effectiveness, identify risks, and determine when corrective action may be necessary.
The goal is not simply to deploy AI. The goal is to ensure it continues to perform as intended.
Several beta phase participants also emphasized the importance of validating outputs through multiple sources and maintaining quality assurance processes to help identify inconsistencies before they create downstream issues.
5. Every AI Process Needs a Way Back
One of the most practical lessons emerging from AI governance discussions is the importance of reversibility.
Whether AI is assisting with internal operations, supporting customer interactions, or contributing to decision-making processes, there should always be mechanisms for human oversight and control.
Organizations should consider how AI fits within existing business processes and ensure they maintain the ability to intervene, reverse outcomes, or temporarily disable AI-driven functions if necessary. In many ways, AI governance requires proactive contingency planning before problems occur.
6. AI Risk Extends Beyond Your Organization
AI risk extends beyond an organization itself. Workforce members, AI developers, customers, third-party vendors, and business partners all play a role in how AI is implemented and governed.
As organizations increasingly rely on external platforms and service providers that incorporate AI, new questions emerge around transparency, oversight, validation, and accountability. One must now grapple with the liability associated with accepting an outcome from another organization’s use of AI. Trust in AI depends not only on internal controls but also on understanding how AI is being used throughout the broader ecosystem.
Building Trust Through Governance
Artificial intelligence presents tremendous opportunities for innovation, efficiency, and improved outcomes. It also introduces new forms of risk that organizations must actively manage.
The organizations best positioned to realize the benefits of AI are not necessarily those deploying the most advanced technologies. They are the organizations establishing clear governance, engaging stakeholders across the enterprise, continuously evaluating risk, and creating structures for accountability and oversight.
DirectTrust’s Artificial Intelligence Accreditation Program was developed to help organizations navigate these challenges using the NIST AI Risk Management Framework as a foundation. As AI continues to evolve, governance, transparency, and trust will remain essential components of responsible adoption.
AI will continue to evolve, and the organizations using it will continue learning alongside it. The challenge is not simply deciding whether to adopt AI. The challenge is establishing the governance, accountability, and oversight necessary to use it responsibly.
Get Fresh Healthcare & IT Stories Delivered Daily
Join thousands of your healthcare & HealthIT peers who subscribe to our daily newsletter.
