Key Takeaways
- ·The guidance is voluntary. It describes itself as "an initial, high-level document," and nearly every statement in it is a "should."
- ·Its seven elements are AI Policies and Governance Structures; Patient Privacy and Transparency; Data Security and Data Use Protections; Ongoing Quality Monitoring; Voluntary, Blinded Reporting of AI Safety-Related Events; Risk and Bias Assessment; and Education and Training.
- ·It doesn't call for a new committee. The governance structure "does not need to be its own standalone team," and the guidance encourages using the quality, patient safety and compliance structures you already have.
- ·It asks for a mechanism to keep the governing body updated on AI uses, outcomes and potential adverse events.
- ·CHAI released governance playbooks that build on the guidance on May 27, 2026. On June 1, 2026 the Joint Commission launched a voluntary RUAIH certification for organizations. It doesn't certify AI products, and an organization doesn't need to be Joint Commission accredited to apply.
- ·Neither the guidance nor the certification is part of Joint Commission accreditation.
The short answer
It gives you a shared, credible description of what responsible AI use looks like in a healthcare organization, written by the country's largest accreditor together with an industry coalition. It doesn't add an obligation. Leaders can use it as a yardstick for their own governance, as a common language with vendors and the board, and, since June 2026, as the basis of a voluntary certification if they want outside recognition.
What the Guidance Is
The document calls itself "an initial, high-level document to help promote a shared understanding of responsible deployment and use of AI tools across healthcare organizations." It is addressed to the organizations that use AI. In its words, it "is not intended to direct the development of AI tools or validate the effectiveness of AI tools themselves."
Its scope is wider than clinical decision support. It defines health AI tools as "clinical, administrative, and operational solutions," and its examples run from diagnosis and imaging to clinical documentation, scheduling, revenue cycle management, coding and prior authorization. An AI feature in your billing system falls inside the definition.
The Seven Elements, in the Guidance's Words
Each card gives the element's name as the guidance lists it, its core statement quoted in full, and one or two details worth knowing.
AI Policies and Governance Structures
"Healthcare organizations should establish policies and procedures for implementing and using AI and a governance structure to manage the responsible use of health AI in their organization, including a mechanism to keep the hospital's governing body updated on uses, outcomes, and potential adverse events."
The guidance says the governance structure "does not need to be its own standalone team." It should include "a designated individual(s) with appropriate technology expertise," and "the fiduciary board of the healthcare organization should be regularly updated on AI use and its outcomes in healthcare."
Patient Privacy and Transparency
"Healthcare organizations should have policies in place regarding data access, use, and protection as well as consumer transparency disclosures or education regarding AI-enabled tools."
On telling patients: "When appropriate, patients should be notified when AI directly impacts their care and how their data may be used in the context of AI. Where and when relevant, consent should be obtained." State law may say more, which is a question for counsel.
Data Security and Data Use Protections
"Healthcare organizations should take steps to promote data security and establish requirements within their data use agreements to limit the permissible uses of exported data."
It lists elements to consider in data use agreements: permitted uses, data minimization, a prohibition on re-identification, third-party obligations, and audit rights. It notes that de-identified data "may be used to train, tune, or test AI tools."
Ongoing Quality Monitoring
"Healthcare organizations should have a process to monitor and regularly evaluate the safe performance of AI-enabled clinical tools."
"Ongoing post-deployment monitoring should be risk-based and scaled to your setting." The guidance suggests asking vendors during procurement how a tool was tested and validated, and adds: "When possible, use structures you already have (quality, patient safety, compliance) rather than creating something new."
Voluntary, Blinded Reporting of AI Safety-Related Events
"Healthcare organizations should have a process for the voluntary, blinded reporting of AI-safety related events to monitor and regularly evaluate the safe performance of AI tools."
It points to existing channels as examples, including "Joint Commission's sentinel-event process and confidential reporting to federally listed Patient Safety Organizations (PSOs), among several others," and says to "use FDA pathways if the AI is a regulated device."
Risk and Bias Assessment
"Healthcare organizations should implement a process to identify and address risks and biases in healthcare AI tools, when possible, especially those that may pose a threat to patient safety or limit access to care."
Organizations should determine whether tools "are tested for the specific populations they serve and ensure they are appropriately tuned and/or tested on local data," in addition to reviewing what the vendor reports. The guidance doesn't list demographic categories. Its one example is a tool built on younger, healthy patients being used with older patients.
Education and Training
"Healthcare organizations should provide basic education and training tools to healthcare providers, ensuring they understand the benefits of AI and can be partners in protecting against potential risks."
At a minimum, organizations should "define and document how users of the AI system will be given relevant AI tool and system documentation and role-specific training." It also suggests broader AI literacy efforts for all staff.
What the Guidance Doesn't Do
It isn't an accreditation standard
The guidance is voluntary, and we haven't found a Joint Commission accreditation standard specific to AI. It doesn't mention accreditation surveys or surveyors.
It doesn't evaluate AI products
It is about how an organization governs and uses AI. It says nothing about whether a particular tool is good.
It doesn't call for a dedicated AI committee
It describes a governance structure with the right expertise and says that structure doesn't need to be a standalone team. A small organization can meet the intent through an existing quality or compliance body.
It doesn't prescribe a method
There are no required metrics, review intervals or demographic categories. Monitoring is meant to be risk-based and scaled to the setting. CHAI's playbooks are where the operational detail lives.
What Came After: Playbooks and a Voluntary Certification
The guidance said what would follow. Feedback on it would "feed into the development and release of a series of community- and resource-informed Responsible Use of AI Playbooks," and "a voluntary Joint Commission Responsible Use of AI certification program will be developed based on these playbooks." Both have now happened.
CHAI released its governance playbooks on May 27, 2026. They cover AI policy, organizational structure, organizational resources, lifecycle management, risk and impact assessments, data management, third party management, and education and training, with suggested controls and worked examples.
On June 1, 2026 the Joint Commission announced its RUAIH certification. In its words, it is "a voluntary certification program designed to recognize organizations in the U.S. that demonstrate they have the governance, safeguards, monitoring processes, and education in place to use AI responsibly in healthcare settings." It "does not validate or certify individual AI products or tools." The standards are organized around five areas: "governance; effective data management; risk and bias reduction; monitoring, evaluating, and validating safety performance, effectiveness, and responsible use; and transparency, education, and training."
The announcement says "interested healthcare organizations do not need to be accredited by Joint Commission to apply for the certification." The Joint Commission's certification page lists eligibility: the organization is in the United States, is Joint Commission accredited or compliant with applicable federal laws including the Medicare Conditions of Participation, and already has a governance structure and processes for AI oversight. Certification is awarded to an organization or to a health care system. The program manual sets out nine standards with elements of performance, and one of them calls for a centralized registry of the health AI tools the organization governs, which is one reason we suggest starting with an inventory. We describe what the certification standards address on our companion page.
What This Means by Role
Board members
The guidance expects the governing body to be kept informed. Ask what mechanism exists today to update the board on AI uses, outcomes and potential adverse events, and how often it runs.
CEO and COO
Decide where AI governance sits. The guidance leaves room to use an existing body, and it asks for designated individuals with appropriate technology expertise to lead implementation and use.
CIO and CMIO
Elements 3, 4 and 6 are yours in practice: data use terms with vendors, monitoring that is risk-based, and checking whether tools were tested for the populations you serve.
Quality, risk and compliance leaders
The guidance repeatedly points to existing structures. AI-related near misses and harms can be captured in your current incident system, and the education element fits existing training programs.
Where We See Organizations Get Stuck
This part is our view, from our own work, and the guidance doesn't say it. Three things tend to slow organizations down. They don't have a complete list of the AI already running, especially features that came inside existing software. Nobody is named as accountable for each tool. And monitoring is assumed to be the vendor's job.
A workable first step is an AI tool inventory with a named owner for each entry. The rest of the seven elements are hard to act on without it.
Frequently Asked Questions
Common questions from healthcare leaders reading the guidance for the first time.
Is the Joint Commission AI guidance mandatory?
No. It is voluntary guidance, written almost entirely in terms of what organizations should do. The certification that followed in June 2026 is voluntary too. Other obligations may apply to the same activities, such as HIPAA, state AI disclosure laws and the federal nondiscrimination rule for patient care decision support tools, and those are questions for counsel.
Does it affect our accreditation?
The guidance and the certification are both voluntary, and the certification is a separate program that doesn't depend on accreditation. We haven't found a Joint Commission accreditation standard specific to AI or a published statement that accreditation surveys evaluate AI governance. If accreditation is your concern, ask your Joint Commission account executive directly.
Do we need a dedicated AI governance committee?
The guidance doesn't ask for one. It says there should be a formal governance structure, and that the structure does not need to be its own standalone team. It lists kinds of expertise that could be included, such as executive leadership, compliance, IT, safety reporting, clinical and operational expertise, cybersecurity and privacy, and people who reflect the needs of patients and staff.
What is the RUAIH certification?
A voluntary Joint Commission program, announced June 1, 2026, that recognizes organizations with the governance, safeguards, monitoring and education in place to use AI responsibly. Its standards are organized around five areas. It certifies organizations and health systems, and it doesn't certify AI products. Organizations don't need to be Joint Commission accredited to apply.
How do the CHAI playbooks relate to the guidance?
The guidance said playbooks would follow to build on and operationalize it, and that the certification would be developed from them. CHAI released the playbooks on May 27, 2026. They are the more detailed of the two, with suggested controls, examples and templates across eight areas. CHAI describes its implementation suggestions as recommendations that organizations will adapt to their own size and maturity.
Does the guidance cover administrative AI, or only clinical tools?
Both. Its definition of health AI tools includes clinical, administrative and operational solutions, and its examples include clinical documentation, scheduling, revenue cycle management, coding and prior authorization alongside diagnosis and imaging.
Sources
- The Joint Commission and the Coalition for Health AI. Guidance on The Responsible Use of AI in Healthcare (RUAIH). September 17, 2025. 8 pages. (PDF) All element names and quotations above are from this document.
- The Joint Commission. Joint Commission Releases First of Its Kind Exclusively Designed for Healthcare Organizations, Voluntary Responsible Use of AI in Healthcare Certification, news release. June 1, 2026.
- The Joint Commission. Responsible Use of AI in Healthcare certification (program page). Accessed September 20, 2026.
- Coalition for Health AI. CHAI Releases Comprehensive Governance Playbooks, news release, and the AI Governance Playbooks. May 27, 2026.
Related Questions
- ›What will a Joint Commission surveyor ask about our AI governance?
- ›How do we create and maintain an AI tool inventory for our health system?
- ›How do we validate that an AI tool performs safely and equitably across our patient population?
- ›Does our vendor's BAA actually prevent them from using our patient data?

