Key Takeaways
- ·The AMA recommends that governance working groups ask each department head to inventory AI tools, including AI features embedded within existing enterprise technology. That last part is where most inventories have their largest blind spot.
- ·A shared, organization-wide definition of 'AI tool' is the most important step before launching any inventory effort. Without it, departments will report inconsistently and your inventory will be incomplete before you've started.
- ·The HHS FY25 AI Use Case Inventory provides a practical, field-tested template for the data fields a health system should track for each tool.
- ·Inventory is the first of four non-negotiable elements of AI governance. Data access control, PHI and PII handling, and output monitoring all depend on having a complete inventory first.
- ·Annual review cycles are not sufficient. Inventory maintenance should be tied to vendor contract reviews, procurement decisions, and a standing update process, not a once-per-year audit.
- ·A complete tool inventory answers what AI is running. The governance question it enables — but doesn't answer on its own — is which decisions AI influences, at what consequence level, and with what human-in-the-loop status. Inventory is the foundation for that analysis, not the analysis itself.
The short answer
Start by establishing a shared organization-wide definition of what counts as an AI tool, then ask each department head to inventory their tools, including AI features embedded in platforms already in use. Use the HHS FY25 AI Use Case Inventory data fields as your template. Categorize what you find by clinical risk level, identify tools with no named owner or validation evidence, and build a continuous update process from there. You can't govern what you haven't counted, and maintaining that count is an ongoing organizational commitment, not a one-time project.
Why Most Health Systems Undercount Their AI Footprint
When health system leaders are asked how many AI tools their organization is running, the first estimate is almost always low. Not because anyone is hiding anything, but because the question is harder to answer than it sounds.
Standalone AI products that went through a formal procurement process are relatively easy to see. The AI scribe a clinical department has been piloting, the sepsis prediction tool an ICU adopted, the revenue cycle optimization platform a CFO approved. Those tend to be visible because they had a buying decision attached to them.
What gets missed are AI features embedded within enterprise software the organization already runs. An EHR almost certainly has AI-assisted documentation, predictive risk scoring, or AI-enhanced imaging reading built into modules that were licensed years before anyone was asking governance questions about AI. A billing platform may have machine learning-driven claim prioritization running continuously in the background. These aren't new purchases. They arrived through software updates, often without triggering any governance review, and they're rarely top of mind when someone asks about AI use.
The AMA is explicit on this point: governance working groups should ask department heads to inventory AI tools including AI features embedded within existing enterprise technology. That's the gap where most inventories fall short.
Inventory as a Governance Foundation
Field guidance from HIMSS 2026 identifies inventory as the first of four non-negotiable elements of AI governance, particularly for agentic AI. The other three, data access control, PHI and PII handling, and output monitoring, all depend on having a complete inventory first. An organization that doesn't know what AI tools are running can't systematically assess data access, can't ensure PHI handling policies apply to all tools, and has no basis for a monitoring program. Inventory is where governance starts.
Define "AI Tool" Before You Ask Anyone to Report
The most common reason AI inventories fail before they start is definitional ambiguity. If you ask department heads to report their AI tools without giving them a shared definition, you'll get wildly inconsistent results. One department head will list only FDA-cleared clinical decision support tools. Another will include every software product with a chatbot feature. A third will omit the consumer generative AI tools their staff use informally because those weren't officially approved.
Before any survey goes out, your governance working group needs to agree on a definition that department leaders across the organization can apply consistently. A working definition should cover: predictive and statistical models, classical machine learning, generative AI including large language models, AI features embedded within existing enterprise platforms such as EHRs and imaging systems, and consumer AI tools staff may be using in workflows even without formal approval.
This definition doesn't need to be perfect. It needs to be specific enough that the people responding understand what to include and what to leave out. You can refine scope in subsequent inventory cycles once the baseline is established. The AMA guidance is explicit that this shared definition is foundational to getting complete coverage, and that organizations should incorporate the inventory into a standard management tool rather than maintaining it informally.
What to Track for Each Tool
The HHS FY25 AI Use Case Inventory provides a practical, field-tested data model. For each tool in your inventory, the following fields capture what you need for governance, monitoring, and regulatory preparedness.
Use case name and description
What the tool does, what problem it's solving, and what clinical or operational workflow it touches.
Responsible department and named owner
Which department or function is accountable for this tool's performance and governance. A tool with no named owner is a governance gap.
Stage in the lifecycle
Pre-deployment, pilot, deployed, or retired. The HHS inventory tracks retired tools as well, which is important for understanding what has been discontinued and why.
Clinical impact classification
Whether the tool directly influences patient care decisions, is one step removed in care coordination or operational workflows, or is primarily administrative. Clinical tools require the most rigorous governance attention.
AI type
Predictive analytics, generative AI, natural language processing, computer vision, or another category. This shapes the relevant governance questions about validation, failure modes, and output review.
System outputs
What the tool actually produces: a recommendation, an alert, a generated document, an autonomous action, or a score. The output type determines what clinician oversight looks like.
Vendor and build or buy status
Vendor name, version or release information if available, and whether the tool was built internally, procured from a vendor, or is a feature embedded in a larger enterprise platform.
Authorization to operate status
Has this tool been formally reviewed and approved for use? By whom? When? This field captures the governance history of the deployment decision.
PII and PHI involvement
Does the tool use protected health information? Does it use demographic variables such as race, age, or socioeconomic status in its predictions? Both have governance implications.
Training data description
What data was the model trained on? Does it reflect your patient population or a different clinical context? This is directly relevant to the local validation question surveyors and legal counsel will ask.
The goal isn't to fill in every field for every tool on day one. A partially complete inventory is significantly more useful than no inventory. Start with the fields you can answer quickly, flag the gaps, and build a process to fill them over time.
Categorizing What You Find by Risk Level
Once you have an initial catalog, sort it by risk level. Clinical tools that influence patient care decisions carry different governance obligations than tools managing scheduling, supply chain, or administrative workflows. A practical three-tier framework.
Clinical (Tier 1)
Tools that directly influence clinical decisions, patient care workflows, or diagnostic outputs. Examples include sepsis prediction models, AI-assisted radiology reads, ambient documentation scribes, and clinical decision support alerts. These require the most rigorous validation, named clinical ownership, active monitoring, and documented oversight. Joint Commission surveyors will focus here.
Operational (Tier 2)
Tools managing care coordination, utilization management, prior authorization support, or patient communication workflows. These carry real governance obligations, particularly around health equity and access to care, but are one step removed from point-of-care decisions. Validation and monitoring are still required, though the urgency is lower than Tier 1.
Administrative (Tier 3)
Tools handling revenue cycle, supply chain, HR, facilities management, or other non-clinical functions. Lower direct patient safety risk, but still subject to data governance, privacy, and bias considerations. These shouldn't be invisible in your inventory, but they don't require the same governance intensity as clinical tools.
What to Do with Tools Discovered Without Formal Approval
You will find them. Departments that moved quickly, vendors who rolled out AI features quietly through platform updates, staff using consumer generative AI tools in daily workflows. The inventory process should not be framed as an audit designed to penalize anyone for using technology that was helping them do their jobs.
The AMA's guidance is explicit on framing: the inventory effort is meant to catalog successful use cases, identify future opportunities, and ensure compliance with applicable law, not to challenge existing activity. That framing matters because it determines whether department heads are honest with you or protective of their teams. An inventory effort perceived as punitive will produce an incomplete inventory.
Tools discovered without prior approval should be assigned to an "under review" category. High-risk clinical tools in that category need expedited governance review. Lower-risk administrative tools can move through a standard review queue. What they can't do is remain in limbo indefinitely with no named owner and no review timeline.
EHR-Embedded AI: The Most Common Blind Spot
- ·EHR vendors have been adding AI capabilities through platform updates for years. Predictive risk scores, ambient documentation features, AI-enhanced coding support, and clinical decision support modules may all be running in your environment without having gone through a governance review.
- ·The starting point is to formally request from your EHR vendor a complete list of all AI-enabled features currently active in your deployment. Most vendors can provide this. Organizations that haven't made that request are operating without a complete picture of their clinical AI footprint.
Keeping the Inventory Current
An AI tool inventory that's twelve months out of date is a liability more than an asset. The AI deployment environment in most health systems is changing faster than annual review cycles can track.
Practical approaches to continuous maintenance include tying inventory updates to vendor contract review cycles, requiring that any new AI tool deployment or vendor-pushed AI capability update triggers a notification to the inventory owner, including AI inventory status as a standing item in department leadership meetings, and assigning a named inventory owner with clear authority to query vendors and department heads when changes are suspected.
At enterprise scale, human-only review processes break down. HIMSS 2026 guidance framed this as "using technology to govern technology": deploying tools for governance inventory and model monitoring rather than relying solely on manual review. Organizations building governance infrastructure for larger AI portfolios should be evaluating purpose-built governance tools rather than maintaining a growing inventory in a spreadsheet.
The inventory is also directly relevant to HTI-5 preparedness. Regulatory analysis of HTI-5 calls for health systems to inventory existing AI-enabled tools and workflows with specific attention to tools subject to transparency requirements and to review vendor contracts for transparency, monitoring, notification, and validation provisions. Starting the inventory now creates the foundation for that compliance work before regulatory deadlines arrive.
What the Inventory Enables — and Doesn't Resolve
A complete, maintained tool inventory tells you what AI is running in your organization. That's a necessary starting point. It's not a sufficient governance posture on its own.
The governance question the inventory enables — but doesn't answer — is which decisions AI influences, at what consequence level, and with what human-in-the-loop status. Those are different questions than what tools are we running.
Most governance gaps that become visible during surveys or adverse events aren't inventory failures. They're decision accountability failures. A tool that's properly catalogued but governs a high-stakes clinical decision without named executive oversight is still exposed. The inventory shows the tool exists. It doesn't show whether anyone is responsible for what that tool decides.
The next layer of governance — mapping AI by the decisions it influences rather than by the tools themselves — is what board reporting and survey preparation ultimately require. The inventory makes that analysis possible. It doesn't substitute for it.
Frequently Asked Questions
Common questions from health system leaders building or improving their AI tool inventories.
What counts as an 'AI tool' for inventory purposes?
For inventory purposes, treat any software component using machine learning, statistical prediction, large language models, or algorithmic decision support as an AI tool. This includes standalone AI products, AI features embedded within existing enterprise platforms such as EHRs and imaging systems, and consumer AI tools staff may be using in workflows even without formal approval. The goal is a complete picture of what's running, not just the tools that went through a formal procurement process.
Should we include AI features built into our EHR?
Yes, and this is where most inventories have their largest blind spot. EHR vendors have been adding AI capabilities through platform updates for years. Risk prediction models, ambient documentation features, AI-enhanced coding support, and clinical decision support modules may all be running in your environment. The starting point is to formally request from your EHR vendor a complete list of all AI-enabled features currently active in your deployment. Most vendors can provide this list. Organizations that haven't made that request are operating without a complete picture.
How often should we update the inventory?
Annual review cycles are not sufficient given how quickly the AI deployment environment is changing. Tie inventory updates to your vendor contract review process, require notification from departments when new AI tools are deployed or when vendors push updates with new AI capabilities, and designate a named inventory owner responsible for maintaining currency. Treat the inventory as a living document, not a periodic audit. A tool discovered active in your environment a year after deployment without any governance review is a gap that matters to surveyors, legal counsel, and insurers alike.
What do we do with AI tools we discover were never formally approved?
Don't treat this as a punitive audit. Assign unapproved tools to an 'under review' category, communicate clearly to department heads that the goal is to catalog and support rather than penalize, and prioritize review based on risk level. Clinical tools with no validation or named owner need expedited governance attention. Administrative tools with lower risk profiles can move through a standard queue. What they can't do is stay in the inventory indefinitely without a resolution path.
Who should own the AI tool inventory?
Ownership typically sits with the AI governance committee or its designated lead, with day-to-day administration delegated to a named role within clinical informatics, IT governance, or the CMO's office depending on organizational structure. What matters more than the specific title is that the owner has clear authority to query department heads and vendors, an established process for surfacing new additions, and organizational backing to escalate when high-risk tools are found without governance documentation.
What's the minimum viable inventory for a smaller hospital?
For a smaller organization just starting, focus first on clinical AI tools in active use: tools that influence patient care decisions in any way. For each, capture what the tool does, which vendor supplies it or whether it was built internally, whether it has been formally reviewed and approved, who in the organization is accountable for it, and whether it uses patient data. That five-field foundation gives you a starting point you can build from without requiring a large governance infrastructure to launch.
How does our AI tool inventory relate to what a Joint Commission surveyor will ask?
The inventory is the first thing a surveyor will probe. Reports from health systems that have undergone recent surveys indicate that the first category of AI governance questions is inventory-focused: what tools are you using, which ones affect clinical decisions, and who authorized their deployment. An organization that can produce a formal, current AI inventory with documented authorization decisions for each tool is in a fundamentally different position than one that answers 'we use a few AI tools but haven't formally catalogued them.' The inventory is the foundation that makes all other governance documentation possible.
Sources
- American Medical Association. AMA 2025 AI Policy: Governance Considerations for Health System AI Programs.
- U.S. Department of Health and Human Services. HHS FY25 AI Use Case Inventory. 2025.
- Sethi, Tripti (Avanade). "New AI Operating Model for Healthcare." HIMSS 2026.
- Rhew, David. "Four Non-Negotiable Elements of Agent Governance." HIMSS 2026.
- HTI-5 Executive Brief. Mosaic Life Tech. 2025.
- Coalition for Health AI (CHAI). "Blueprint for Trustworthy AI Implementation Guidance and Assurance for Healthcare." 2023.
- American Hospital Association. "Trustworthy AI in Health Care: A Framework for AI Governance." 2024.
Related Questions
- ›What will a Joint Commission surveyor ask about our AI governance?
- ›What should we require from AI vendors before deployment?
- ›How do we evaluate an AI vendor's claims and what questions should we ask before signing a contract?
- ›How do we build an AI governance committee?
- ›How should we govern generative AI and agentic AI in health systems?
- ›What AI governance do rural health organizations need when implementing AI through RHTP funding?

