Key Takeaways
- ·RUAIH isn't binding today, but The Joint Commission's deeming authority under 42 CFR makes it functionally authoritative for the 22,000+ organizations it accredits.
- ·TJC and CHAI have outlined a three-stage path: the current RUAIH advisory guidance, forthcoming governance playbooks, and a voluntary AI certification program. No firm dates have been publicly confirmed for the later stages.
- ·TJC has signaled a transition toward formal binding standards, though no specific date has been publicly confirmed. Organizations building governance posture now will be ahead of that transition, not caught by it.
The short answer
RUAIH isn't a binding accreditation standard today. But The Joint Commission accredits over 22,000 healthcare organizations and holds deeming authority for Medicare participation under 42 CFR. That leverage makes this guidance functionally authoritative whether or not it carries a formal mandate. Organizations that can't demonstrate a governance posture aligned with the seven RUAIH domains are exposed to risk that already exists — from boards, litigators, and a regulatory trajectory that moves in one direction.
What the Guidance Actually Covers
RUAIH organizes its expectations around seven domains. These aren't aspirational principles; they're the categories surveyors, litigators, and boards are beginning to use as a reference for what reasonable governance looks like.
AI Policy and Governance Structures
A formalized governance framework with a multidisciplinary oversight committee that includes executive leadership, technical experts, and frontline staff. The committee structure is recommended, but the accountability question — who owns the outcome when something goes wrong — is yours to answer.
Education and Training
Role-specific training on how AI tools work, their intended use, and their limitations, extended to all staff who interact with AI-influenced decisions. General AI literacy isn't sufficient; the guidance expects staff to understand the specific tools in use.
Transparency
Mechanisms to disclose AI use to patients and staff, including how AI functions in decision-making processes. This applies to both clinical tools and administrative ones.
Equity and Bias Mitigation
Pre- and post-deployment evaluation for bias, with vendor disclosure of known risks and limitations. The guidance expects organizations to require this from vendors, not assume it was addressed during product development.
Data Security and Data Use Protections
Encryption, access controls, incident response planning, and vendor contract guardrails that limit re-identification and define permitted data uses. These obligations extend to how you contract with vendors, not just how you configure systems internally.
Ongoing Quality Monitoring
Pre-deployment validation on your patient population — distinct from vendor FDA clearance — and post-deployment monitoring for drift and degraded performance. Model drift is real; a tool that performed well at deployment may not perform well six months later as patient populations, workflows, or data inputs change.
Patient Safety and Risk Management
Integrating AI oversight into existing quality and safety structures. The guidance doesn't prescribe a separate governance system — it expects AI decision accountability to connect to the structures you already have.
The guidance also points to what's coming. TJC and CHAI have outlined a three-stage roadmap: the current RUAIH advisory guidance establishes the framework; forthcoming governance playbooks will provide implementation detail; and a voluntary AI certification program represents the next formal milestone. No confirmed public dates have been announced for the later stages. Organizations building governance posture now will be positioned ahead of that progression rather than scrambling to respond when expectations harden into requirements.
What the Guidance Does Not Require
A few common misconceptions are worth clearing up before your organization builds a response plan around them.
RUAIH does not require compliance with "Joint Commission AI standards." No such standards exist yet. What exists is a framework describing what reasonable governance looks like. Surveyors are using it as a reference point, and that's meaningfully different from a scored accreditation requirement.
Having your AI tools certified by a third party isn't what the guidance asks for, either. Vendor FDA clearance and third-party certifications address product performance. The guidance addresses organizational accountability for the decisions those tools influence. Those are separate questions.
The guidance also doesn't transfer governance responsibility to a vendor, a committee, or a policy document. It assumes organizational leadership owns the oversight function. A policy that sits without anyone accountable for applying it to new AI deployments doesn't satisfy what the guidance is describing.
On the federal context: HTI-5 removed federal model card requirements for AI transparency. That regulatory pullback increases organizational accountability rather than reducing it. With less federal oversight structure, the Joint Commission and CHAI guidance has become the most relevant external reference framework for demonstrating reasonable oversight to surveyors, boards, and litigators.
What This Means by Role
CEO / COO
The question your board will face is whether your organization has a reasonable oversight story for AI-influenced decisions. That story should exist before it's asked for. The guidance expects intentional oversight, not perfection, and the organizations best positioned to demonstrate that are the ones who built the structure before a survey or adverse event made it urgent.
CIO / CMIO
Local validation is the expectation that catches most organizations off guard. Your AI vendor's FDA clearance documents performance on the vendor's dataset, not on your patient population. The guidance expects local validation before deployment and post-deployment monitoring for drift. Those are different activities, and the gap between them is where most post-deployment surprises originate.
Board Risk / Quality / Audit Committee
Your oversight role for AI governance follows the same logic as your oversight of financial controls or quality programs. You don't need to understand the technical details of every AI tool your organization runs. You do need to be able to explain what oversight exists, who's accountable, and how the organization knows when something's wrong. The guidance assumes that visibility exists at the board level.
Compliance and Quality Leaders
The most practical starting point is integrating AI oversight into existing quality and safety infrastructure. Survey findings are currently landing under Leadership and Quality Improvement categories, which means this is already in scope for existing compliance functions. Connecting AI governance to structures you already have is more durable than building parallel systems.
Where Most Organizations Get Stuck
The most common pattern looks like this: an organization assigns a working group to develop an AI governance policy. The policy gets written. Then it sits. No one is accountable for applying it to new AI deployments, monitoring existing ones, or reporting AI risk to the board. The governance document exists, but the governance posture doesn't.
That gap between policy and practice is what the guidance is actually targeting. When an AI tool influences a clinical or operational decision, who saw that? Who validated it on your patient population? Who would explain that decision process if a surveyor, a plaintiff's expert, or a board member asked?
Those questions are already being asked. Most organizations discover their governance posture isn't what they thought it was when a question they couldn't answer arrives, not when they went looking.
Frequently Asked Questions
Common questions from healthcare executives reviewing the RUAIH guidance.
Is the Joint Commission AI guidance mandatory?
Not today, but the practical answer is more complicated. RUAIH is advisory guidance, not a binding accreditation standard. However, The Joint Commission's accreditation carries deeming authority for Medicare participation under 42 CFR — meaning it functions as a meaningful signal before it becomes a formal requirement. TJC has indicated a transition toward formal binding standards, though no specific date has been publicly confirmed.
Does my health system need a formal AI governance committee?
Yes. The RUAIH guidance's first domain calls for a formalized governance framework with a multidisciplinary oversight committee. Whether that rises to a scored accreditation requirement depends on when formal standards take effect, but the expectation is present in the guidance today — and boards, litigators, and future surveyors will use RUAIH as the reference for what reasonable governance looks like.
What's the difference between AI governance and AI compliance?
Governance is the broader category — it covers accountability, oversight structure, and the organization's ability to explain how AI-influenced decisions are made and monitored. Compliance addresses specific regulatory requirements. RUAIH describes a governance posture, not a compliance checklist. Organizations that treat this as a compliance exercise tend to produce policies that check a box without building the oversight infrastructure the guidance is actually asking for.
What does the HTI-5 rule change mean for AI governance?
HTI-5 removed federal model card requirements for AI transparency. The effect is the opposite of what many organizations assumed: reduced federal requirements increase organizational accountability, not decrease it. With less federal oversight structure in place, the Joint Commission and CHAI guidance has become the most relevant external reference for demonstrating reasonable oversight to surveyors, boards, and litigators.
What's the difference between vendor validation and local validation?
Vendor validation tests AI tool performance on the vendor's dataset or in a controlled research environment. Local validation tests how the tool performs on your patient population, in your workflows, with your data. The guidance expects local validation before deployment and ongoing monitoring after. These are different activities, and the gap between them is where most post-deployment performance problems originate.
When will the Joint Commission AI guidance become a formal requirement?
TJC and CHAI have outlined a progression from current RUAIH advisory guidance to forthcoming governance playbooks to a voluntary certification program — but no confirmed public dates exist for any of these stages. Organizations that build governance infrastructure now will be positioned ahead of that progression rather than scrambling to respond when formal standards arrive.
Source
Joint Commission / Coalition for Health AI (CHAI). Guidance on Responsible Use of AI in Healthcare (RUAIH). September 17, 2025. Analysis and interpretation by Mosaic Life Tech based on direct review of the guidance document and survey intelligence as of April 4, 2026.
Related Questions
- ›Who is responsible when an AI algorithm makes a wrong clinical decision?
- ›Does the Joint Commission require an AI governance policy?
- ›How do I present AI governance to my hospital board?
- ›What should be in an AI vendor contract for a health system?
Pages for these questions are in development.

