Healthcare AI Governance

    What Does the Joint Commission's AI Guidance Mean for My Health System?

    On September 17, 2025, The Joint Commission and the Coalition for Health AI (CHAI) jointly released the Guidance on Responsible Use of AI in Healthcare (RUAIH). It's the first formal AI governance guidance from a major healthcare accreditor. Here's what it actually requires, what it doesn't, and where most organizations get stuck.

    Last updated: · By Teresa Younkin & Jim Younkin, Mosaic Life Tech

    Key Takeaways

    • ·RUAIH isn't binding today, but The Joint Commission's deeming authority under 42 CFR makes it functionally authoritative for the 22,000+ organizations it accredits.
    • ·TJC and CHAI have outlined a three-stage path: the current RUAIH advisory guidance, forthcoming governance playbooks, and a voluntary AI certification program. No firm dates have been publicly confirmed for the later stages.
    • ·TJC has signaled a transition toward formal binding standards, though no specific date has been publicly confirmed. Organizations building governance posture now will be ahead of that transition, not caught by it.

    The short answer

    RUAIH isn't a binding accreditation standard today. But The Joint Commission accredits over 22,000 healthcare organizations and holds deeming authority for Medicare participation under 42 CFR. That leverage makes this guidance functionally authoritative whether or not it carries a formal mandate. Organizations that can't demonstrate a governance posture aligned with the seven RUAIH domains are exposed to risk that already exists — from boards, litigators, and a regulatory trajectory that moves in one direction.

    What the Guidance Actually Covers

    RUAIH organizes its expectations around seven domains. These aren't aspirational principles; they're the categories surveyors, litigators, and boards are beginning to use as a reference for what reasonable governance looks like.

    1

    AI Policy and Governance Structures

    A formalized governance framework with a multidisciplinary oversight committee that includes executive leadership, technical experts, and frontline staff. The committee structure is recommended, but the accountability question — who owns the outcome when something goes wrong — is yours to answer.

    2

    Education and Training

    Role-specific training on how AI tools work, their intended use, and their limitations, extended to all staff who interact with AI-influenced decisions. General AI literacy isn't sufficient; the guidance expects staff to understand the specific tools in use.

    3

    Transparency

    Mechanisms to disclose AI use to patients and staff, including how AI functions in decision-making processes. This applies to both clinical tools and administrative ones.

    4

    Equity and Bias Mitigation

    Pre- and post-deployment evaluation for bias, with vendor disclosure of known risks and limitations. The guidance expects organizations to require this from vendors, not assume it was addressed during product development.

    5

    Data Security and Data Use Protections

    Encryption, access controls, incident response planning, and vendor contract guardrails that limit re-identification and define permitted data uses. These obligations extend to how you contract with vendors, not just how you configure systems internally.

    6

    Ongoing Quality Monitoring

    Pre-deployment validation on your patient population — distinct from vendor FDA clearance — and post-deployment monitoring for drift and degraded performance. Model drift is real; a tool that performed well at deployment may not perform well six months later as patient populations, workflows, or data inputs change.

    7

    Patient Safety and Risk Management

    Integrating AI oversight into existing quality and safety structures. The guidance doesn't prescribe a separate governance system — it expects AI decision accountability to connect to the structures you already have.

    The guidance also points to what's coming. TJC and CHAI have outlined a three-stage roadmap: the current RUAIH advisory guidance establishes the framework; forthcoming governance playbooks will provide implementation detail; and a voluntary AI certification program represents the next formal milestone. No confirmed public dates have been announced for the later stages. Organizations building governance posture now will be positioned ahead of that progression rather than scrambling to respond when expectations harden into requirements.

    What the Guidance Does Not Require

    A few common misconceptions are worth clearing up before your organization builds a response plan around them.

    RUAIH does not require compliance with "Joint Commission AI standards." No such standards exist yet. What exists is a framework describing what reasonable governance looks like. Surveyors are using it as a reference point, and that's meaningfully different from a scored accreditation requirement.

    Having your AI tools certified by a third party isn't what the guidance asks for, either. Vendor FDA clearance and third-party certifications address product performance. The guidance addresses organizational accountability for the decisions those tools influence. Those are separate questions.

    The guidance also doesn't transfer governance responsibility to a vendor, a committee, or a policy document. It assumes organizational leadership owns the oversight function. A policy that sits without anyone accountable for applying it to new AI deployments doesn't satisfy what the guidance is describing.

    On the federal context: HTI-5 removed federal model card requirements for AI transparency. That regulatory pullback increases organizational accountability rather than reducing it. With less federal oversight structure, the Joint Commission and CHAI guidance has become the most relevant external reference framework for demonstrating reasonable oversight to surveyors, boards, and litigators.

    What This Means by Role

    CEO / COO

    The question your board will face is whether your organization has a reasonable oversight story for AI-influenced decisions. That story should exist before it's asked for. The guidance expects intentional oversight, not perfection, and the organizations best positioned to demonstrate that are the ones who built the structure before a survey or adverse event made it urgent.

    CIO / CMIO

    Local validation is the expectation that catches most organizations off guard. Your AI vendor's FDA clearance documents performance on the vendor's dataset, not on your patient population. The guidance expects local validation before deployment and post-deployment monitoring for drift. Those are different activities, and the gap between them is where most post-deployment surprises originate.

    Board Risk / Quality / Audit Committee

    Your oversight role for AI governance follows the same logic as your oversight of financial controls or quality programs. You don't need to understand the technical details of every AI tool your organization runs. You do need to be able to explain what oversight exists, who's accountable, and how the organization knows when something's wrong. The guidance assumes that visibility exists at the board level.

    Compliance and Quality Leaders

    The most practical starting point is integrating AI oversight into existing quality and safety infrastructure. Survey findings are currently landing under Leadership and Quality Improvement categories, which means this is already in scope for existing compliance functions. Connecting AI governance to structures you already have is more durable than building parallel systems.

    Where Most Organizations Get Stuck

    The most common pattern looks like this: an organization assigns a working group to develop an AI governance policy. The policy gets written. Then it sits. No one is accountable for applying it to new AI deployments, monitoring existing ones, or reporting AI risk to the board. The governance document exists, but the governance posture doesn't.

    That gap between policy and practice is what the guidance is actually targeting. When an AI tool influences a clinical or operational decision, who saw that? Who validated it on your patient population? Who would explain that decision process if a surveyor, a plaintiff's expert, or a board member asked?

    Those questions are already being asked. Most organizations discover their governance posture isn't what they thought it was when a question they couldn't answer arrives, not when they went looking.

    Frequently Asked Questions

    Common questions from healthcare executives reviewing the RUAIH guidance.

    Is the Joint Commission AI guidance mandatory?

    Not today, but the practical answer is more complicated. RUAIH is advisory guidance, not a binding accreditation standard. However, The Joint Commission's accreditation carries deeming authority for Medicare participation under 42 CFR — meaning it functions as a meaningful signal before it becomes a formal requirement. TJC has indicated a transition toward formal binding standards, though no specific date has been publicly confirmed.

    Does my health system need a formal AI governance committee?

    Yes. The RUAIH guidance's first domain calls for a formalized governance framework with a multidisciplinary oversight committee. Whether that rises to a scored accreditation requirement depends on when formal standards take effect, but the expectation is present in the guidance today — and boards, litigators, and future surveyors will use RUAIH as the reference for what reasonable governance looks like.

    What's the difference between AI governance and AI compliance?

    Governance is the broader category — it covers accountability, oversight structure, and the organization's ability to explain how AI-influenced decisions are made and monitored. Compliance addresses specific regulatory requirements. RUAIH describes a governance posture, not a compliance checklist. Organizations that treat this as a compliance exercise tend to produce policies that check a box without building the oversight infrastructure the guidance is actually asking for.

    What does the HTI-5 rule change mean for AI governance?

    HTI-5 removed federal model card requirements for AI transparency. The effect is the opposite of what many organizations assumed: reduced federal requirements increase organizational accountability, not decrease it. With less federal oversight structure in place, the Joint Commission and CHAI guidance has become the most relevant external reference for demonstrating reasonable oversight to surveyors, boards, and litigators.

    What's the difference between vendor validation and local validation?

    Vendor validation tests AI tool performance on the vendor's dataset or in a controlled research environment. Local validation tests how the tool performs on your patient population, in your workflows, with your data. The guidance expects local validation before deployment and ongoing monitoring after. These are different activities, and the gap between them is where most post-deployment performance problems originate.

    When will the Joint Commission AI guidance become a formal requirement?

    TJC and CHAI have outlined a progression from current RUAIH advisory guidance to forthcoming governance playbooks to a voluntary certification program — but no confirmed public dates exist for any of these stages. Organizations that build governance infrastructure now will be positioned ahead of that progression rather than scrambling to respond when formal standards arrive.

    Source

    Joint Commission / Coalition for Health AI (CHAI). Guidance on Responsible Use of AI in Healthcare (RUAIH). September 17, 2025. Analysis and interpretation by Mosaic Life Tech based on direct review of the guidance document and survey intelligence as of April 4, 2026.

    Related Questions

    • Who is responsible when an AI algorithm makes a wrong clinical decision?
    • Does the Joint Commission require an AI governance policy?
    • How do I present AI governance to my hospital board?
    • What should be in an AI vendor contract for a health system?

    Pages for these questions are in development.

    About the Authors

    Teresa Younkin, CEO and Co-Founder of Mosaic Life Tech

    Teresa Younkin, MSHI

    CEO & Co-Founder, Mosaic Life Tech

    20+ years leading AI, data governance, and interoperability initiatives across provider, payer, and federal health IT environments, including HL7 Da Vinci standards work and ONC programs.

    Jim Younkin, CTO and Co-Founder of Mosaic Life Tech

    Jim Younkin, MBA, FACHDM

    CTO & Co-Founder, Mosaic Life Tech

    30+ years across federal health IT programs, enterprise interoperability, and AI governance, including directing federal AI initiatives for ONC/ASTP and co-founding Pennsylvania's first regional HIE serving 4M+ patients.

    Mosaic Life Tech helps healthcare executives build board-visible AI governance posture aligned with Joint Commission and CHAI guidance. We don't sell AI tools or implementation services. Our work is advisory, and our interest is in helping organizations govern well before expectations harden into standards.

    Not sure where your organization stands?

    We help healthcare executives assess their AI governance posture and build the structure boards can see and defend.

    Start a Conversation