What is agentic AI in healthcare?
Agentic AI in healthcare refers to AI systems that pursue a goal by planning steps and taking actions in other software, such as reading a chart, drafting a message, filing a prior authorization, or updating a schedule. Unlike a chatbot that only answers, an AI agent acts, often with limited human involvement between steps.
How agents differ from earlier health AI
Most health AI deployed over the last decade was predictive: a model scores sepsis risk or flags an image, and a clinician decides what to do. Generative AI added drafting, such as ambient documentation and message replies. Agentic AI adds a third capability, tool use. An agent is given access to systems through connectors or APIs and decides which calls to make to finish a task.
The National Institute of Standards and Technology describes the category plainly. In a January 2026 request for information, NIST's Center for AI Standards and Innovation wrote that "AI agent systems are capable of taking autonomous actions that impact real-world systems or environments, and may be susceptible to hijacking, backdoor attacks, and other exploits."
Common healthcare uses include revenue cycle work (eligibility checks, claim status, prior authorization packets), patient access (scheduling and reminders), care coordination (gathering records, closing referral loops), and clinical documentation support.
New risks agents introduce
Because agents act, the risks shift from "a wrong answer" to "a wrong action":
- Scope creep. An agent given broad credentials can reach data or functions far beyond its task. HIPAA's minimum necessary standard still applies to what it reads and discloses.
- Prompt injection. Text inside a document or email can instruct an agent to do something its operator never intended.
- Speed and repetition. An agent can repeat an error across hundreds of records before anyone notices.
- Accountability gaps. When an agent acts under a shared service account, it can be unclear who authorized an action.
Controls hospitals apply
Health systems are adapting familiar controls to agents. The NIST AI Risk Management Framework calls for an inventory of AI systems (GOVERN 1.6), monitoring in production (MEASURE 2.4), and the ability to "supersede, disengage, or deactivate" systems that behave outside intended use (MANAGE 2.4). The OVERT runtime evidence specification goes further for agents: its TOOL-1 requirement says every agent tool call should be "evaluated against policy and attested before execution."
In practice that means registering each agent, granting only the actions it needs, requiring human approval for sensitive steps, logging every action, and keeping a way to stop it. Hospitals can route agent proposals through the same AI governance committee that reviews predictive models, adding questions about tool access, identity, and approval gates to the existing intake checklist. Starting with low-risk administrative tasks, and expanding scope only after monitoring shows the agent behaves as intended, limits the cost of early mistakes.
How Skovos handles this
Skovos is a governance layer built for AI agents. Each agent gets a registered identity, actions are checked against its registered scopes, each decision lands in a tamper-evident audit trail the hospital owns, and the hospital can recall an agent at any time.
Frequently asked questions
Is agentic AI the same as generative AI?
No. Many agents use large language models, but the defining feature is taking actions through tools. A generative model that only drafts text for a person to send is not acting as an agent.
Are AI agents regulated by the FDA?
Only if the software meets the definition of a medical device. Section 520(o)(1)(A) of the FD&C Act excludes software intended for administrative support, such as billing, claims, and appointment schedules, from that definition. HIPAA and other laws still apply.
What is the first governance step for agentic AI?
Know what agents are running. An agent registry with owners, permissions, and status is the foundation for every other control.
Related reading
- AI agent registry for hospitals
- HIPAA compliance for agentic AI in health systems
- How to stop an AI agent in a hospital
Sources
- NIST CAISI, Request for Information Regarding Security Considerations for Artificial Intelligence Agents, January 8, 2026: https://www.federalregister.gov/documents/2026/01/08/2026-00206/request-for-information-regarding-security-considerations-for-artificial-intelligence-agents
- NIST, AI Risk Management Framework (AI RMF 1.0): https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf
- 45 CFR 164.502(b), HIPAA minimum necessary standard: https://www.law.cornell.edu/cfr/text/45/164.502
- 21 U.S.C. 360j(o), exclusions from the device definition for certain software: https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title21-section360j&num=0&edition=prelim
- OVERT v1.1 standard text, TOOL-1 Pre-Execution Policy Enforcement: https://overt.is/latest.md