
Who will define healthcare's AI standards? An executive order fuels the conversation | Viewpoint
Key Takeaways
- Federal agencies are directed to improve access to cybersecurity tools for critical infrastructure operators, potentially narrowing rural hospitals’ defensive capability gap amid AI-enabled threats.
- Classified benchmarking and voluntary early-access programs emphasize upstream model evaluation, yet most provider exposure arises later through embedded AI across clinical, operational, and revenue-cycle environments.
The risk comes in how AI is deployed inside and across the healthcare system.
Healthcare has officially entered the “chat” when it comes to the future of AI security.
The federal government’s new AI Executive Order (EO) addresses it in earnest for the first time, but it does leave a critical gap. By focusing on regulating the most advanced models at the point of creation, the order largely sidesteps where risk actually lives: how AI is deployed inside and across the healthcare system.
We believe that approach raises a fundamental question about who is setting the standards for AI use in real-world care settings, and where patient risk, operational complexity, and financial pressures converge?
In healthcare, the greatest exposure isn’t at the frontier - it’s downstream. This is where healthcare leaders can help close the gap by paying attention to what comes next.
What the executive order does for healthcare
The order is notable because it directs federal agencies to facilitate access to cybersecurity tools and services for critical infrastructure operators, including rural hospitals, community banks, and local utilities. This is a welcome development because it places healthcare delivery squarely in a conversation about national security and resilience.
Smaller providers face many of the same AI-enabled cyber threats as large health systems, but they often must combat challenges with tighter budgets, leaner technology teams, and more fragile operating margins. Directing more advanced defensive capabilities toward rural hospitals could help them close this gap.
The most vulnerable organizations in the healthcare system shouldn’t be left alone to defend themselves against increasingly sophisticated threats.
As the Healthcare Leadership Council emphasized in a report earlier this year, achieving the full potential of AI and protecting patients requires public-private sector collaboration and targeted attention to the unique risks and demands of its use in healthcare.
This EO builds on that effort and has the potential to make meaningful progress by channeling better tools, guidance, and coordination to these organizations.
Healthcare’s real AI risk lives downstream
The order primarily targets how AI models are developed and evaluated upstream. It calls for a classified benchmarking process to assess the advanced cyber capabilities of AI models, along with a voluntary framework through which developers can give the federal government early access to certain frontier models before broader release to trusted partners.
This is a logical place for national security officials to focus. The earliest version of a powerful model may have capabilities that need to be understood before they’re released into the market. However, most healthcare organizations experience AI downstream, much later in the lifecycle.
They encounter AI months or years after a frontier model is released - inside vendor products, administrative workflows, clinical support tools, revenue cycle processes, cybersecurity platforms and more. Even if frontier models are evaluated before they’re released, that doesn’t remove the risk providers face later.
In other words, the EO’s focus is model-centric, while healthcare risk is focused on deployment.
This distinction matters. The order may help shape expectations for frontier models, but it doesn’t solve the deployment challenge inside healthcare organizations. Nor was it designed to. The responsibility for that layer still sits with healthcare leaders, their technology teams, their vendors and their governance processes.
Voluntary doesn’t mean inconsequential
Which brings us to the question many leaders and their general counsels will ask: Is any of this mandatory? On its face, no. The executive order explicitly says the framework should not be construed to create mandatory licensing, preclearance or permitting requirements for developing, publishing, releasing or distributing new AI models, including frontier models.
But voluntary doesn’t necessarily mean inconsequential. Standards often affect healthcare before formal mandates arrive, whether through procurement, contracts or legal liability.
As federal contracts and large health systems begin to expect specific AI governance practices from their vendors, those expectations propagate through the supply chain long before any rule requires them. Healthcare leaders shouldn’t wait for a formal mandate before preparing for more stringent expectations.
What is next?
So, what should healthcare organizations do now? In our opinion, they should focus on three areas.
First, organizations need a clearer view of where AI is actually being deployed, because an inventory of vendors is no longer the same thing as an inventory of AI-enabled workflows.
Second, leaders need to strengthen vendor governance. It’s no longer enough to ask whether a vendor uses AI. Organizations need to understand how models are monitored, how data is protected, how access is controlled, how performance is tested and how failures are escalated.
Third, healthcare organizations need to define their own deployment standards. For high-stakes workflows, leaders should be clear about human oversight, auditability, security, privacy and accountability. This is especially important when AI is embedded into systems that influence patient access, clinical operations, reimbursement, compliance or care delivery.
This is not a call to slow innovation - it’s a call to lead it. Organizations that get governance right will be the ones best positioned to scale AI with confidence and trust.
Maria Ghazal is president and CEO of the Healthcare Leadership Council, and Arun Shastri, principal of AI & analytics at ZS.




































