EHR AI agent governance when the health system is the developer
As Epic and Oracle open agent tooling to customers, validation, monitoring and liability quietly move onto provider organizations whose AI committees were chartered to review vendor purchases, not in-house builds.

For most of the past decade, health system AI oversight meant reviewing what a vendor shipped. That assumption is breaking. With Epic opening agent-building tooling to customer organizations and Oracle Health shipping AI features switched on by default, EHR AI agent governance now has to cover software the health system itself specifies, configures and, increasingly, builds. Most AI governance committees were never chartered for that job.
The shift from buyer to builder happened faster than the charters
At HIMSS 2026 in March, Epic unveiled tooling that lets customer health systems build their own agents, including work on custom foundation models, as reported by HIT Consultant and Healthcare IT News. MedCity News covered the same announcement and framed the open question precisely: the issue is not whether health systems can build agents, but whether they are ready to own what happens next.
The market did not wait for an answer. STAT News reported in March 2026 that AI agents were spreading rapidly across health care while validation practices lagged behind deployment across the Google, Microsoft, Epic and Oracle ecosystems. By August, Healthcare Dive reported Epic targeting outpatient visits with a new AI tool, which puts agents inside core clinical workflow rather than in a sandboxed pilot. On Sept. 12, 2026, Healthcare IT Today and RamaOnHealthcare flagged that Oracle Health's AI-powered patient portal had reached general availability in the US, meaning agentic features now arrive enabled rather than opt-in.
Demand is not the constraint. Fierce Healthcare reported in March 2026 that roughly three-quarters of US health systems were using or planning to use an AI platform, with executives describing improved return on investment. The constraint is assurance capacity, and that has not scaled at the same rate.
A health system that writes the prompt logic and sets the escalation threshold is no longer a passive purchaser. It is a developer, with everything that implies.
What changes legally when you configure the agent
A health system that buys a certified feature sits, roughly, in the position of a purchaser. A health system that writes the prompt logic, selects the data scope, sets the escalation threshold and tunes a model is closer to a developer. That distinction matters when an agent drafts an order, triages an inbox message or summarizes a chart into the legal medical record.
Boards should expect a specific set of questions, and general counsel should have answers before the first agent touches patient-facing workflow. Who signs off on a model change, and does a prompt revision count as a change? Are agent actions logged at a level that lets a reviewer reconstruct why a recommendation appeared on a given day? What is the human-in-the-loop threshold, and is it enforced technically or by policy alone? Can the organization roll an agent back within hours, not weeks, after an incident?
Insurance language deserves its own review cycle. Malpractice policies were written around clinician judgment, and cyber policies around breach and extortion. Neither was drafted with in-house clinical software failure in mind. If agent output enters the record, attribution needs to be unambiguous: which decisions were the agent's, which were the clinician's, and what the reviewing clinician actually saw at the moment of signature.
Less certification scaffolding, more in-house burden
The regulatory backdrop pushes in the same direction. ASTP/ONC's proposed HTI-5 rule, published in the Federal Register on Dec. 29, 2025, would cut a substantial share of certification criteria while tightening information blocking exceptions. Analyses from McDermott and Hooper Lundy, and the American Hospital Association's comment letter filed Feb. 27, 2026, have parsed the tradeoffs in detail.
For CIOs the practical read is simple. Certification has functioned as a floor that health systems quietly relied on, even when they complained about it. Removing criteria does not remove the underlying assurance need. It relocates it. Fewer standardized vendor attestations means more internal testing, more local documentation and more evidence the organization has to produce itself if a regulator, payer or plaintiff's attorney asks how an agent was validated for the population it serves.
Platform commitment is now an exit-planning problem
MedCity News reported in August 2026 that Epic's agent push was tied to a new FTC probe, which moves platform dependence from a procurement footnote to a board agenda item. Whatever the outcome, the strategic point stands: agents built on a single vendor's orchestration layer are far harder to move than data.
Health systems have spent years building interoperability muscle around records. Agent logic is different. Prompt libraries, tool definitions, permission scopes and workflow triggers are typically expressed in vendor-specific form. A CIO who can export twenty years of structured clinical data in a standard format may still find that a year of agent engineering does not travel at all. Exit planning should be documented at the point of build, not discovered during a renegotiation.
The practical hedge is not refusing to build. It is keeping the clinical intent, the validation evidence and the performance baselines in portable, vendor-neutral documentation, so that what has to be rebuilt is implementation rather than institutional knowledge.
A governance charter that fits the build era
Most existing AI committees were designed to evaluate procurement: review the vendor's evidence, check bias documentation, approve or decline. A build-capable charter needs three additions. First, a software development lifecycle for clinical agents, with named owners, versioning and a defined test environment that uses local data. Second, continuous monitoring with predefined drift and error thresholds that trigger automatic review, rather than annual attestation. Third, an incident pathway that treats agent failure like a clinical safety event, including reporting, root cause analysis and a rollback decision-maker on call.
Staffing is the honest constraint. Validation work requires informaticists, biostatisticians and clinical operations leaders with time protected for it. Health systems that fund agent development without funding the assurance function are choosing to absorb risk quietly. National Health IT Week, running Sept. 14-18, 2026, is a reasonable moment to put that tradeoff in front of the board in plain terms.


