Only 22% of hospital leaders can produce a 30 day audit trail of their AI, even as two thirds of U.S. physicians now use these tools in patient care.
A sepsis alert at a U.S. hospital can shift its failure pattern between two nursing shifts. The hospital's committee that oversees that alert meets once a quarter. A STAT+ opinion published Tuesday puts that speed mismatch in front of the people it says should fix it: hospital CEOs, boards, and chief medical officers.
The column, written by Peter Pronovost, Justin Norden, and Kedar Mate, argues that U.S. hospitals are running clinical AI oversight on a template built for 2010-era MRI safety: subcommittees, checklists, six-month approval cycles, quarterly reviews. That template was designed for a machine whose performance barely changed after installation. Modern clinical AI does not behave that way.
Models that draft clinical notes, flag sepsis risk, screen imaging, automate prior authorizations, and message patients learn from new data and shift outputs as patient populations, workflows, and upstream vendors change. A scoping review in Nature's npj Digital Medicine describes the result: a fragmented governance landscape where few frameworks have been implemented or evaluated in real-world settings, and the authors call for sociotechnical, organization-level oversight rather than bolt-on technical reviews.
A 2026 industry outlook from Censinet puts numbers on it: only 22% of hospital leaders say they can produce a 30-day audit trail of what their AI did. Just 23% report having business associate agreements covering third-party AI tools. Yet 66% of U.S. physicians are already using AI in their practice, 21 states have written hospital-AI statutes on the books, and legislators in 47 states introduced more than 250 healthcare AI bills last year. The rulemaking is arriving faster than the internal oversight it is supposed to anchor.
The opinion's core demand is an ownership change. Responsibility for AI oversight, the authors argue, belongs in the C-suite and the board room, not in an IT subcommittee. The reasoning is patient safety, not procurement: when a sepsis alert quietly stops flagging the right patients, when a prior-authorization bot hallucinates a denial, when a clinical-note drafter degrades in ways only the end clinician notices, the failure needs a named executive owner and a continuous monitoring loop, not a retrospective slide deck.
A patient, clinician, or board member can apply a simple test. Ask the hospital who is the named executive owner of each clinical AI model, and whether the institution can show the last 30 days of model decisions, errors, and overrides. If the answer is a subcommittee chair or a vice president of information technology, the governance has not caught up to the deployment.
The next statute cycle will not wait. Twenty-one states already have hospital-AI laws, and the bill pipeline in 2025 was the heaviest on record. Hospitals that move AI governance out of IT and into executive ownership now will be the ones reading their own audit trails when regulators come asking, rather than reconstructing them.