AI is not IT. Things to consider when implementing AI

September 9, 2026
AI is not IT. Things to consider when implementing AI
AI
News

Healthcare organizations adopting AI systems are often overwhelmed by complex risk assessments and conflicting recommendations from regulators, local authorities, think tanks, and global institutions such as the OECD and WHO. No single approach fits all, but four critical steps provide a basic framework.

Define the problem, build the business case, and test the solution

One strong piece of advice underpins all the guidelines: before implementing AI, check whether you can solve the problem without it. Unlike traditional health IT systems, AI-based solutions usually require more attention, larger budgets, and competencies that may not be in place.

An AI implementation always starts with a defined clinical or operational problem. The hospital should establish why AI is appropriate, what evidence supports the proposed solution, whether the required data are available, and how the system will fit into existing clinical workflows.

The assessment covers regulation, cybersecurity, data governance, staff readiness, patient involvement, monitoring, and the full cost of ownership. Current international guidance also emphasizes governance structures, workforce capacity, interoperability, and continuous evaluation as conditions for responsible AI adoption.

AI is the first choice when a task involves large quantities of data, analysis at a scale or speed that is difficult for humans, and outputs that can be tested against empirical evidence. Before choosing AI, consider whether automation, process redesign, or conventional statistical tools could address the problem just as effectively.

The next question is what success should look like. That might mean shorter diagnostic times, fewer errors, higher detection rates, a lower administrative workload, or better use of resources. Establishing a baseline before implementation makes it possible to assess the actual impact once the system is in use.

The business case should bring together the expected clinical and operational benefits, implementation requirements, risks and costs. NHS guidance, for example, recommends testing the underlying assumptions against historical data and then piloting before wider deployment.

The evidence behind a vendor’s claims deserves scrutiny. Validation results should show how the system performs across measures such as sensitivity, specificity, area under the curve (AUC), positive predictive value (PPV), negative predictive value (NPV), and calibration. But these numbers are meaningful only in the right clinical context. A model validated on a patient population that differs substantially from the hospital’s own may perform differently in practice. Evidence from external validation, prospective testing or clinical studies therefore carries more weight than results generated solely from the manufacturer’s data.

For procurement, the hospital can also request a model card or equivalent documentation describing the AI system's intended use, performance, limitations, risks, training and validation data. The OECD recommends treating model cards as living documents that are updated when models change, and real-world performance becomes available.

Check data, infrastructure and workflow readiness

Before implementation, every healthcare facility should assess its data foundation. Required data should be available, sufficiently complete, structured, representative, and legally usable. Assess data quality and representativeness across relevant patient groups, because differences between the development population and the hospital's population can affect performance. The OECD identifies findable, accessible, interoperable, and reusable data, together with population representativeness, as key conditions for scaling AI in health.

Interoperability is always a priority: The AI system may need to connect with the hospital information system, PACS, laboratory systems, and other clinical applications. Standards such as HL7 FHIR and DICOM can support data exchange, but the hospital should determine which interfaces, middleware, system modifications, and external IT resources are required.

Next, test the workflow with the people who will use the system. Doctors, nurses, technicians, and administrative staff should assess whether AI reduces workload, adds steps, changes responsibilities, or introduces new sources of error. The supplier should demonstrate the product in a representative working environment rather than relying solely on a prepared presentation.

A good pilot should have predefined entry and exit criteria. Specify the population, clinical setting, duration, performance indicators, safety thresholds, and conditions for scaling or stopping the project. This creates a controlled path from testing to routine use.

Establish governance, safety, and human oversight

Establish AI governance before deployment. A hospital should identify who is responsible for clinical performance, technical operation, data governance, cybersecurity, regulatory compliance, and incident management. NIST's AI Risk Management Framework provides a general structure for identifying, assessing, and managing AI risks across the system lifecycle.

Consider patient involvement where AI affects clinical care. WHO recommends involving healthcare professionals, patients, and other stakeholders early in development and implementation, with mechanisms to raise concerns and address ethical issues. The hospital should establish whether patients need to be informed about AI use, whether consent is required in the relevant context, and how this information is documented. The OECD specifically identifies patient consent, liability, and human oversight as issues that health systems should address when introducing AI into clinical care.

Human oversight should be defined operationally. Staff need clear instructions on when they can accept an AI recommendation, when they must review it, and what to do when their clinical assessment conflicts with the algorithm. For generative AI, hospitals should define verification requirements for outputs because the technology can generate plausible but incorrect information.

Cybersecurity and data protection assessments should precede deployment. The hospital should examine penetration-testing results, security audits, access controls, data flows, storage locations, and the supplier's incident-response procedures.

Prepare staff, procurement, and the post-deployment lifecycle

Hospitals should identify clinical and operational staff who can participate in evaluation and act as implementation leads. Training should cover system operation, output interpretation, limitations, bias, error reporting, and when to challenge an AI recommendation. Repeated training and feedback mechanisms are preferable to a single pre-launch training session. OECD analysis similarly identifies workforce capacity and systematic upskilling as key requirements for sustained AI adoption.

Procurement requirements must cover interoperability, data management, cybersecurity, evidence, monitoring, model updates, and contractual responsibilities. Early market engagement can help hospitals understand available solutions and communicate requirements to suppliers, while procurement decisions should remain documented and competitive.

The contract should define service levels, availability, response times, update procedures, incident management, and exit arrangements. The total cost should include licensing, integration, implementation, training, support, data storage, infrastructure, internal IT resources, and potential revalidation after model updates.

Plan post-deployment monitoring before launch. AI performance can change when patient populations, clinical protocols, data-entry practices, or input systems change. FDA guidance recommends monitoring model performance and managing risks associated with retraining and modifications throughout the product lifecycle.

For systems that can evolve over time, the hospital should agree with the supplier on how to evaluate, document, and approve model updates. Planned changes should have defined testing and performance criteria before deployment.

Add ICT&health on Google

Show more content from ICT&health in Google Search.

Add on Google

This topic will also have a prominent place at the ICT&health World Conference 2027. Want to be there and stay ahead of what’s next in healthcare? Reserve your ticket today.