To All Articles

The AI Rules You Already Signed

Michael Nikitin

CTO & Co-founder AIDA, CEO Itirra

Published on August 17, 2026
Comparison of contested state AI legislation against three healthcare AI compliance layers: EHR certification, voluntary accreditation, and vendor and payer terms

On July 29, 2026, Hackensack Meridian Health announced that it had become the first health system in the country to earn The Joint Commission’s Responsible Use of AI in Healthcare certification. The detail worth noticing isn’t the certification. It’s the date on their governance structure: 2022. They built it four years before an accreditation body existed to ask for it.

Most hospitals are in the opposite position — watching AI legislation move through state houses and federal courts, waiting to learn what they’ll be required to do. Three other layers already shape what a hospital has to be able to produce, and none of them are legislation. This is what each one asks for, why federal deregulation doesn’t make the question go away, and why only 22% of hospital leaders in one recent survey said they could answer it on request.

Why AI Legislation Is the Wrong Signal to Plan Against

State AI law is the loudest signal available and the least stable one. A December 11, 2025 executive order directed federal agencies toward a single national AI framework and told the Department of Justice to challenge state laws that conflict with it. The DOJ stood up an AI Litigation Task Force on January 9, 2026.

Colorado shows what that looks like. xAI sued to block the Colorado AI Act on April 9, 2026. The DOJ moved to intervene on April 24 — its first intervention against a state AI law. A federal court stayed enforcement on April 27. Three weeks later Colorado enacted SB 26-189, repealing and reenacting the framework as a narrower automated-decision-making law scheduled for January 1, 2027, with its enforcement path still subject to litigation and rulemaking. Challenged and stayed before its effective date, then replaced by its own legislature before it ever took effect. Where state requirements apply, they apply — but that’s not a sequence to build a roadmap against.

The Rule Already Inside Your Base EHR Definition

If your hospital attests to the Medicare Promoting Interoperability Program, the software you’re attesting with is already certified to an AI transparency standard. As of January 1, 2025, the Decision Support Interventions (DSI) criterion at §170.315(b)(11) is part of the Base EHR definition — certified health IT has to meet it for your technology to count as Certified EHR Technology for certain CMS programs (Source: ASTP/ONC, HTI-1 final rule).

Under it, certified health IT must enable clinical users to access, record, and change 13 source attribute fields for evidence-based decision support and 31 for Predictive DSIs — a category ASTP/ONC defines broadly enough to cover large language models and both clinical and administrative uses, though not everything a vendor markets as AI falls inside it. The 31 describe the model: training data inclusion and exclusion criteria, demographic representativeness, bias management, external validation, how validity and fairness are monitored in local data, update frequency.

Read the division carefully, because it’s the part hospitals collapse. The certification obligation sits with the developer. The attestation sits with the hospital. And the access isn’t hypothetical — ASTP/ONC’s own clinician guidance says decisions about who sees source attribute information, where, and when are a customer-level decision, and tells clinicians to ask their leadership and their developer to “show me the source attributes.”

Then it adds the part that explains everything: there is no Certification Program requirement for clinical users to review them. Reviewing is described as best practice.

So the information is already in the building. Nothing makes anyone look at it. That gap — between access that exists and review that nobody owns — is where the governance problem actually lives. ASTP/ONC even tells clinicians how to read a blank field: some source attributes may be listed as “unknown,” and that absence is itself a signal about the quality of the tool.

Three roles, three different obligations, and most confusion about healthcare AI compliance requirements comes from blending them. The developer supplies the documentation the certification criterion calls for. The hospital, as deployer, evaluates local clinical fit, workflow, oversight, privacy and security, and holds the vendor accountable. The payer sets payment, utilization management and audit expectations through its own programs and contracts. A certified product doesn’t discharge a deployer’s responsibility, and a governance committee doesn’t discharge a developer’s.

Three roles in healthcare AI compliance — developer supplies certification documentation, hospital deployer evaluates local fit and oversight, payer sets audit expectations by contract

The Rule That May Narrow That Rule

On December 29, 2025, ASTP/ONC proposed HTI-5, a deregulatory rule that would remove 34 of the certification program’s 60 criteria and revise seven more. One revision would reduce the scope of the DSI criterion to remove the AI “model card” requirements (Source: ASTP/ONC, HTI-5 proposed rule fact sheet). It’s still proposed, not final. The American Hospital Association filed comments on February 27, 2026 urging ASTP/ONC to keep the decision support intervention criteria in place.

Read the sequence. Hospitals gained a transparency capability in January 2025 that nobody was ever required to use, and it may be narrowed before that changes. The American Hospital Association — representing hospitals and health systems, not vendors — is the party asking ASTP/ONC to keep it.

What doesn’t narrow is the need to explain a decision after the fact. That expectation just gets more scattered: internal governance, accreditation if you pursue it, clinical risk management, applicable state law, and whatever your payer contracts say. Deregulation narrows one route to vendor transparency. It doesn’t remove the need to show how an AI-influenced decision was made.

Accreditation Is Filling a Different Gap

The Joint Commission launched the Responsible Use of AI in Healthcare (RUAIH) certification in June 2026 — the first AI program built for healthcare organizations rather than for AI products, following initial guidance issued with the Coalition for Health AI (CHAI) in September 2025. It is voluntary. It’s open to organizations The Joint Commission doesn’t accredit, and it’s organized around five areas: governance; effective data management; risk and bias reduction; monitoring, evaluating and validating safety performance, effectiveness and responsible use; and transparency, education and training.

This isn’t accreditation racing legislation — it’s a separate, voluntary assurance layer forming while legislation stays contested. Voluntary matters: nobody is required to pursue it. But note what the five areas have in common. Each requires evidence beyond a position statement — documented governance, operational controls, monitoring activity, training, and records showing how the organization applies them. A monitoring requirement means showing what a model actually did last quarter, not merely describing how it would be reviewed. Organizations that pursue certification, and organizations whose payer contracts or clinical risk processes call for supporting documentation, end up needing many of the same underlying records.

Which is why the Hackensack timeline matters more than the certificate. A governance structure stood up in 2022, evaluated in 2026 across governance, patient safety and data safeguards, bias and risk reduction, monitoring, and education. The certification didn’t create that architecture. It found it.

What Each Layer Actually Asks For

Payer provisions are the layer most often misdescribed, so it’s worth being exact: there is no universal payer rule for AI. What exists is a set of contracts, and what they require depends on the payer, the program, the service, and the basis for review. What’s consistent is that a documentation request supporting a medical-necessity determination doesn’t arrive with a carve-out for decisions an algorithm influenced.

Layer Enforced by In force since What it may require Current state
EHR certification — DSI §170.315(b)(11) ASTP/ONC certification program; reached via CMS program participation January 1, 2025 Source attributes made available by developers of certified health IT Narrowing — HTI-5 proposes removing the AI model card requirements
Accreditation — RUAIH certification The Joint Commission June 2026 Governance, monitoring, and training records at the organization level Voluntary and expanding — first certification announced July 2026
Payer, utilization-management, and audit provisions Specific commercial or government payer arrangements Contract- and program-specific Documentation supporting medical necessity, clinical rationale, and claim or authorization decisions; AI-specific documentation only where contract, policy, or risk management calls for it Variable — review payer-specific terms
State AI legislation State legislatures / courts Varies May include disclosure, impact assessment, notice, human review, documentation, or appeal obligations, depending on the statute Contested — under active federal challenge

This table is an operational framework, not legal advice. Applicability varies by hospital, payer contract, care setting, state, and the clinical role of the AI-enabled tool. Two tracks sit outside it entirely: any deployment touching protected health information (PHI) raises separate HIPAA privacy, security, and vendor-access questions, and a complete model record is neither a security assessment nor a business associate agreement. For AI-enabled software that may meet the definition of a medical device — diagnostic, triage, imaging, risk-scoring, treatment-recommendation — FDA oversight is a separate track from EHR certification and organizational governance.

What Happens When Someone Asks

In a Black Book Research survey of 182 US hospital leaders, only 22% reported high confidence that they could deliver a complete, auditable AI explanation within 30 days to regulators or payers (November 2025). Just 29% said they had implemented and enforced policies covering AI model inventory, lineage, and sign-offs; 48% were still drafting them. By size: 15% at small hospitals, 21% at community systems, 34% at large systems. It’s vendor research rather than an industry census — but the barrier ranking is the useful part.

22 percent of hospital leaders surveyed reported high confidence they could produce a complete auditable AI explanation within 30 days, with top audit barriers named

Those barriers aren’t policy problems. Limited explainability artifacts from vendors — model cards, drift reports — was the top audit barrier at 41%. Incomplete tracking of data inputs and model versions, 37%. Unclear ownership between IT, quality and safety, and compliance, 33%. Those are integration and data-lineage gaps. You don’t close them with a committee; you close them by building vendor-documentation intake and decision logging into the deployment path.

Note what sits at the top of that list. The barrier these leaders named most often overlaps directly with what HTI-5 would narrow: hospitals report limited access to vendor explainability artifacts, and HTI-5 proposes reducing the DSI source-attribute requirements often described as AI “model card” information. It isn’t one-to-one — HTI-5 doesn’t govern every artifact on that list, and drift reporting isn’t part of it — but the overlap is the part worth watching.

And regulators and payers aren’t the only ones who ask. The same record is what a patient safety review needs after an adverse event, what tells you whether clinicians are overriding a model and why, and what your own counsel will want if a case ever turns on how a decision was made. Those requests don’t depend on a rule surviving notice-and-comment.

The gap also isn’t funded evenly. The median share of 2026 IT and quality budget going to AI governance was 2.3% at small hospitals, 4.5% at community systems and 6.8% at large systems — tracking alongside those same audit-confidence figures of 15%, 21% and 34%. An association, not a demonstrated cause. What it does show is how unevenly organizations are resourced for the same work: smaller hospitals face the same vendor-transparency and documentation pressure with a fraction of the budget, even though which obligations actually apply depends on their CMS programs, their technology, and their payer mix. That’s not an attention problem. It’s an architecture problem, and architecture is the only thing that scales down.

Bar chart showing median 2026 AI governance budget share of 2.3 percent at small hospitals, 4.5 percent at community systems and 6.8 percent at large systems, paired with audit confidence

Where This Actually Starts

Not with a framework. With an inventory: every AI or predictive feature live in your environment right now, including the ones that arrived inside an EHR upgrade and were never procured as AI. For each one, three questions. Do we have the vendor’s documentation on file? Does the system log who reviewed its output, and when? Could we hand both to someone who asks without reconstructing anything?

One change worth making this quarter regardless of how HTI-5 lands: move the explainability requirement out of your certification assumptions and into your vendor agreements. Documentation rights can also come from state law, procurement policy, clinical governance, or accreditation you choose to pursue — but if the certification requirement is narrowed, the contract you sign is the most reliable place to preserve them.

We keep ending up early on problems like this — reading certification criteria a year or two before anyone treats them as a deadline, building the audit trail before someone asks for it. It rarely feels like foresight at the time. Mostly it’s what happens when you spend enough years in the seam between clinical workflow and the systems that get audited for it.

Which AI tools in your environment arrived through an EHR upgrade rather than a procurement decision — and does anyone own them?

Frequently Asked Questions

What healthcare AI compliance requirements are actually in force in 2026?

Several layers with different authority and reach. The Decision Support Interventions criterion at §170.315(b)(11) has been part of the Base EHR definition since January 1, 2025 and reaches hospitals through participation in certain CMS programs. The Joint Commission’s Responsible Use of AI in Healthcare certification launched in June 2026 and is voluntary. Payer utilization-management and audit provisions are contract-specific and predate AI rulemaking; state AI legislation is a fourth layer and the least settled, with obligations varying by statute. HIPAA and, for software that may meet the medical device definition, FDA oversight run on separate tracks.

Does HTI-5 mean hospitals no longer need AI model documentation?

No, and HTI-5 hasn’t been finalized. Proposed December 29, 2025, it would remove the AI “model card” requirements from the DSI certification criterion — meaning developers of certified health IT would no longer be compelled through certification to supply that documentation. Accreditation you pursue, payer contracts, clinical risk management, and applicable state law can each still call for the same underlying records, so the requirement has to be preserved somewhere else — most reliably in vendor agreements. The American Hospital Association asked ASTP/ONC to keep the criterion.

What are DSI source attributes, and who is responsible for them?

Source attributes are the disclosure record behind a decision support tool — training data inclusion and exclusion criteria, demographic representativeness, bias management, external validation, ongoing monitoring of validity and fairness, and update frequency. Under the current criterion, certified health IT must enable clinical users to access, record, and change 13 source attribute fields for evidence-based decision support and 31 for Predictive Decision Support Interventions. The certification obligation is the developer’s. Hospitals remain responsible for deciding how that information is reviewed, retained, and used in local governance and deployment decisions — ASTP/ONC describes access as a customer-level decision and does not require anyone to review it.

Is The Joint Commission’s AI certification mandatory?

No. It’s voluntary, open to any healthcare organization including those The Joint Commission doesn’t accredit, and it certifies an organization’s governance, monitoring, and training practices rather than individual AI products. Hackensack Meridian Health announced the first publicly reported certification on July 29, 2026.

Can a small or rural hospital realistically meet these requirements?

The pressure doesn’t scale with size even though the resources do. In Black Book’s survey, small hospitals reported a median 2.3% of IT and quality budget going to AI governance versus 6.8% at large systems, and 15% reported high audit confidence versus 34%. Which obligations actually apply depends on the CMS programs a hospital participates in, the technology it runs, and its payer mix — and the practical answer is to produce the record as a byproduct of the workflow rather than staffing manual review a smaller organization can’t sustain.

Building the layer that produces these records — model inventory, vendor documentation intake, decision logging inside the workflow?

Let’s talk about your project.

Contact Itirra →

Sources

  1. ASTP/ONC — HTI-1 Final Rule, Decision Support Interventions Fact Sheet, §170.315(b)(11), December 2023
  2. ASTP/ONC — “What New CDS Regulation Means for You: Benefits for Clinicians”, December 2024 — certified health IT must enable clinical users to access, record, and change source attributes; access is a customer-level decision; no requirement to review them
  3. ASTP/ONC — Health Data, Technology, and Interoperability: ONC Deregulatory Actions to Unleash Prosperity (HTI-5) Proposed Rule, December 2025
  4. American Hospital Association — Comments on ASTP/ONC Health Care Technology Interoperability Proposed Rule, February 27, 2026
  5. The Joint Commission — Responsible Use of AI in Healthcare certification
  6. Colorado General Assembly — SB 26-189, signed May 14, 2026, effective January 1, 2027
  7. The White House — Executive Order, “Ensuring a National Policy Framework for Artificial Intelligence”, December 11, 2025
  8. CMS — Medicare and Medicaid Promoting Interoperability Programs
  9. Black Book Research — “U.S. Hospitals Underfund AI Governance as Adoption Accelerates,” November 12, 2025. Survey of 182 US hospital leaders, fielded October 15–November 8, 2025
  10. Hackensack Meridian Health — “HMH Becomes First Health System in the Country to Earn Responsible Use of AI in Healthcare Certification from Joint Commission”, July 29, 2026 (primary announcement)
  11. Independent coverage — Healthcare Dive; ROI-NJ, July 30, 2026; Healthcare Finance News, August 5, 2026
  12. Healthcare IT News — “Joint Commission intros new voluntary AI responsibility certification”, June 2, 2026
  13. Itirra — AI Governance in Healthcare Isn’t a Policy Document. It’s an Audit Trail.
  14. Itirra — The Prior Authorization API Is Still “Coming Soon.” The Compliance Deadline Isn’t.