What is an AI governance committee in a hospital?
A hospital AI governance committee is the group accountable for overseeing how the organization selects, deploys, monitors, and retires AI tools. It sets AI policy, reviews new tools against risk, assigns owners, tracks performance and safety events, and reports to leadership and the board on how AI is used and what it is doing.
What guidance expects
The Joint Commission and Coalition for Health AI (CHAI) guidance on the Responsible Use of AI in Healthcare (RUAIH), released in September 2025, lists "AI Policies and Governance Structures" as its first element. It says there "should be a formal governance structure responsible for risk-based and organizationally appropriate oversight of health AI tools," covering tools used in direct or indirect patient care, care support services, and administrative operations. It adds that the structure "does not need to be its own standalone team," and that "the fiduciary board of the healthcare organization should be regularly updated on AI use and its outcomes."
The NIST AI Risk Management Framework makes a parallel point in GOVERN 2.1: roles, responsibilities, and lines of communication for managing AI risk should be "documented and are clear to individuals and teams throughout the organization."
Federal survey data suggest that hospitals using predictive AI often spread accountability across several groups. ASTP/ONC Data Brief No. 80 (September 2025) reports that in 2024, 71% of non-federal acute care hospitals used predictive AI integrated with their EHR, and that 74% of hospitals reported multiple entities were accountable for evaluating predictive AI.
Who sits on it
The RUAIH guidance suggests the team could include executive leadership, regulatory and ethical compliance, information technology, safety and incident reporting, relevant clinical and operational experts, cybersecurity and data privacy, and people who represent impacted populations such as staff, providers, patients, and caregivers. It also calls for "a designated individual(s) with appropriate technology expertise, ideally in AI if available," to lead implementation.
In practice, a committee might be chaired by a chief medical information officer, chief data or AI officer, or chief quality officer, with a smaller working group that handles day-to-day intake and monitoring.
What it decides
A working committee usually owns a few recurring decisions:
- Intake. Whether a proposed tool may be piloted or deployed, and at what risk tier.
- Conditions. Which data the tool may use, what actions it may take, and when a human must approve.
- Ownership. Who is accountable for each tool once it is live.
- Monitoring. How often each tool is revalidated, and what triggers a review, such as a vendor update or a safety event.
- Retirement. When to restrict, pause, or retire a tool.
The committee's decisions only matter if they reach the systems where AI runs. A decision recorded in minutes but not reflected in access rights or configuration leaves a gap between policy and practice.
How Skovos handles this
Skovos turns committee decisions into enforced settings. The owner and scopes recorded for each agent drive its runtime permission checks, a recall stops it, and the audit trail gives the committee evidence of what each agent actually did.
Frequently asked questions
Does a hospital need a separate AI committee?
Not necessarily. The Joint Commission and CHAI guidance says the governance structure does not need to be a standalone team. Some hospitals extend an existing IT, quality, or clinical decision support committee.
How often should an AI governance committee meet?
There is no required cadence. One workable pattern is a monthly meeting for policy and escalations, with a smaller group reviewing intake requests weekly or as they arrive.
What should the committee report to the board?
The RUAIH guidance says the board should be regularly updated on AI use and outcomes. Useful board reporting covers the tool inventory, risk tiers, monitoring results, and any AI safety events.
Is an AI governance committee required for Joint Commission certification?
The voluntary Responsible Use of AI in Healthcare certification lists governance among its areas. Check Joint Commission's published requirements for specifics.
Related reading
- Building an enterprise AI governance program in health systems
- AI governance frameworks for hospitals
- AI agent registry for hospitals
Sources
- Joint Commission and CHAI, Guidance on the Responsible Use of AI in Healthcare (RUAIH): https://digitalassets.jointcommission.org/api/public/content/dcfcf4f1a0cc45cdb526b3cb034c68c2
- NIST, AI Risk Management Framework (AI RMF 1.0), GOVERN 2.1: https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf
- ASTP/ONC Data Brief No. 80, Hospital Trends in the Use, Evaluation, and Governance of Predictive AI, 2023 to 2024: https://healthit.gov/data/data-briefs/hospital-trends-use-evaluation-and-governance-predictive-ai-2023-2024/
- Joint Commission press release on RUAIH certification, June 1, 2026: https://www.globenewswire.com/news-release/2026/06/01/3304442/0/en/joint-commission-releases-first-of-its-kind-exclusively-designed-for-healthcare-organizations-voluntary-responsible-use-of-ai-in-healthcare-certification.html