
James Gain
Chief Technology Officer
James Gain is Chief Technology Officer at Vizient, bringing more than 25 years of leadership experience in healthcare, insurance, and technology.
Article
The headlines may be new, but the playbook isn’t. Health systems should double down on the same principles that have always protected their data and people — because the cost of getting them wrong just went up.
![]()
When you bring a baby home, no one assumes the hard part is over.
You feed it, watch it, teach it. Even as it grows more capable and independent, the questions never disappear. They just become a whole lot more complicated.
Artificial intelligence is a little like that. For decades, we’ve treated technology deployment as the finish line: You build something, test it, release it, and fix the bugs that users find. But with AI, deployment is only the beginning. You have to keep watching how it behaves to ensure it doesn’t hallucinate, introduce bias, or drift away from its intended purpose.
If the baby analogy feels too gentle, think of AI as a teenager.
I have teenagers. They’re smart, creative, and capable of doing remarkable things. But judgment doesn’t always develop as quickly as capability. A teenager may not intend to make a bad decision, but if there aren’t enough boundaries in place, mistakes can happen. The goal isn’t to keep the car keys forever; it’s to make sure there’s a conversation about responsibility before they’re handed over.
Similarly, AI doesn’t have to mean harm to cause it. If an AI system is poorly trained or allowed to operate without sufficient oversight, it can still make a consequential mistake.
That’s why the adults in the room matter. We’re the guardrails.
Because AI is evolving so quickly, leaders may feel as if they need to invent an entirely new safety system to keep up. Some new governance mechanisms will certainly be necessary, but much of the work is more familiar than it might seem. Strong cybersecurity policies mattered before generative AI. So did access controls, employee education, independent assessments, monitoring, and incident-response plans. AI hasn’t made those fundamentals obsolete, but it’s undoubtedly made failures in those areas more consequential.
The same principles we recommend to clients (and really to any organization in any industry) are the ones we’re applying within Vizient. Maintaining our role as a trusted partner across the continuum of care depends on protecting the data we manage and turning it into useful insights.
The goal isn’t to eliminate every possible risk, which is frankly unrealistic. Nor should governance make responsible innovation so difficult that people look for ways around it. The goal is to create enough structure to move confidently. Here’s where to start.
Not every employee needs access to every AI tool, data set, or capability. Organizations should define which tools are approved, what information may be entered into them, and what actions different users are permitted to take. Access should reflect a person’s role, business need, and the potential consequences if something goes wrong.
This becomes even more important as organizations move from AI that generates content to AI that can act. An agent that summarizes information presents one kind of risk, while an agent that initiates a workflow or communicates with another system presents another. It’s the difference between a teenager reading your mail and a teenager sending mail in your name.
Leaders also need a plan for the rise of citizen builders. Employees and clinicians will increasingly be able to create their own agents and automated workflows. That creativity can be valuable, but without visibility, it can quickly become agent sprawl. If you think shadow IT is a problem, wait until you meet shadow AI. And sprawl is only half the danger; the other half is never noticing when something goes wrong.
Leaders should be able to answer two simple questions at any given moment: What are our agents doing, and what data are they touching? Independent assessments and industry certifications can help determine whether the right controls are in place, but a certification isn’t a substitute for an operating discipline. The distance between a policy someone wrote and a policy someone actually follows is where governance lives or dies. A metric that no one reviews is just a number, and an alert that no one acts on is just noise.

An AI system needs an owner, a defined purpose, and an ongoing evaluation process. Who’s responsible for its performance? How will its outputs be reviewed? What metrics will indicate that it’s working properly? What would cause the organization to modify, suspend, or retire it?
Most organizations can answer the launch questions but go quiet on the rest. AI is a living, changing capability; the data changes, as does the environment and the way people use the system. A system that was safe at month one can drift into unsafe by month nine. No one will tell you, because no one was watching. The lifecycle — the stages from deployment to monitoring to modification to retirement — is the structure. But a calendar with real dates attached only matters if someone actually shows up on those dates and asks the uncomfortable questions. That’s the discipline. Governance has to evolve with the system, and it has to be practiced, not just documented.
And at every checkpoint in that lifecycle, “human in the loop” sounds reassuring, but only if that human has the expertise to question the AI. A person should not be included simply to check a governance box. They need to actually understand what the system is doing so they can flag when an output doesn’t make sense and intervene before it causes harm. A rubber-stamp human is worse than no human at all, because it transfers blame without adding judgment, and it lets everyone pretend the risk is handled.
Organizations should be explicit about where the line sits: what AI can support, what it can automate on its own, and what must always remain a human decision. The greater the potential consequence, the stronger that oversight needs to be. In healthcare, the stakes are rarely small. An AI output can touch everything from a patient’s care to a clinician’s decision to the organization’s financial and operational integrity. Human accountability cannot become ceremonial.
The annual cybersecurity training that everyone loves to complain about matters now more than ever.
Employees still need to recognize phishing attempts and follow sound data-handling practices. But AI education should go further. People need to understand which tools are approved, how to write and evaluate prompts, what information should never be entered, how to validate an answer, and when to escalate a concern.
They also need to understand that “polished” is not the same as accurate. A confident AI-generated response can still be wrong, and a convincing email can still be fraudulent. Training cannot be treated as a one-time event because the technology will not stand still. As the tools change, the education must evolve with them.
Trust depends on clarity. Organizations should be able to explain, in plain terms, how data will be used and where it will go, including which third parties may interact with it and who’s accountable if something goes wrong. Those expectations shouldn’t be left as assumptions; they should be baked into contracts, vendor reviews, and internal policies.
Particularly in healthcare, leaders need confidence that sensitive information won’t inadvertently enter a public model or end up somewhere it was never meant to be. The moment that trust breaks, everything downstream from it breaks too. Responsible AI begins with clear commitments about data and continues with the infrastructure and controls needed to keep those commitments.

For Vizient, this responsibility extends across our relationships with financial, clinical, quality, operational, and technology leaders. Our opportunity is to help those leaders get trusted data and actionable insights at the right moment, in the right format, and within the right workflow, while protecting what makes those insights valuable in the first place.
That’s why the fulcrum of any effective tech strategy is people, especially as AI continues to grow more capable. Like a child, it will surprise us, and like a teenager, it may act before it fully understands the consequences. Like both, it will need us to show up — not once at launch, but every day.
Treat AI safety as a technology problem, and you’ll lose trust faster than you gain capability. Treat it as a people and discipline problem, and you’ll keep both.

Chief Technology Officer
James Gain is Chief Technology Officer at Vizient, bringing more than 25 years of leadership experience in healthcare, insurance, and technology.