The FDA Stopped Defining Safe AI in the Exam Room. Health System Boards Just Inherited the Standard.

On January 6, 2026 the FDA stepped back from defining safe clinical AI. New state liability laws hold hospitals accountable anyway. The standard-setting duty just moved to the health system board.

Health systems that deployed clinical AI on the expectation that the FDA would tell them when a tool was safe are now governing a category the agency has stepped back from. On January 6, 2026, the FDA revised its guidance on Clinical Decision Support software, the class of AI that recommends diagnoses and treatments, substantially loosening oversight and declining to define what counts as "clinically appropriate." The agency did not lower the clinical risk. It moved the question of who answers for that risk from Washington to the boardroom.

GOVERNING EVIDENCE

  • FDA Clinical Decision Support guidance (January 6, 2026) loosened oversight of AI diagnostic and treatment tools and explicitly declined to define "clinically appropriate," leaving the deployment threshold to health systems.
  • New 2026 state AI liability statutes hold hospitals and physicians accountable for diagnostic errors that follow uncritical reliance on AI, extending institutional exposure to negligent implementation, retention, and monitoring.
  • ISS STOXX found that five sectors, Industrials, Information Technology, Consumer Discretionary, Financials, and Health Care, account for nearly 75% of all disclosed instances of board-level AI oversight, meaning the practice is concentrated, not embedded.
  • Among S&P 100 companies, just over half disclose board-level AI oversight and fewer than one-third disclose both oversight and a formal AI policy (Glass Lewis, 2026 proxy season).
  • Disclosed AI expertise among S&P 500 directors rose only from 1.5% to 2.7% between 2021 and 2025, against 51% for general technology expertise.

The signal is not the loosening itself. It is the timing. The FDA reduced its gatekeeping in the same year that state legislatures began holding hospitals and physicians directly accountable for diagnostic errors that follow from unmonitored AI. A health system now sits between a regulator that has declined to set the safety threshold and a liability regime that will judge whether the system set one itself. That is not deregulation. It is a transfer of the standard-setting duty onto the board.

What comparable systems are already building

The health systems moving first are not waiting for a federal definition of safe. They are writing their own. Norton Rose Fulbright's March 2026 guidance to health system boards frames clinical AI oversight as a direct board responsibility, not a delegated IT function, and points boards toward a structural answer: a standing AI Clinical Advisory Board with representation from clinical departments, IT, legal, ethics, and patient advocacy, feeding a validation gate that every clinical AI system must clear before deployment.

That gate is specific. It requires clinical performance testing against defined accuracy thresholds, bias assessment across patient demographics, integration testing with existing EHR workflows, and documented regulatory verification. The systems that build it convert a vague duty into an auditable record. The systems that do not are relying on vendor assurances the FDA has now declined to underwrite.

The peer data shows how thin the field still is. ISS STOXX places Health Care among the five sectors that together account for roughly three-quarters of all disclosed board AI oversight, yet that concentration hides how few individual systems have formalized it. Presence on a list of active sectors is not the same as a functioning oversight structure, and a board that has named AI as an enterprise risk in a filing has not thereby built the mechanism to govern it.

The pressure is coming from two directions at once

The regulatory retreat and the liability expansion are not separate stories. They compound. The FDA's decision not to define "clinically appropriate" removes the reference point a defense counsel would otherwise reach for after an adverse event. When a diagnostic AI contributes to patient harm, the question in front of a court will not be whether the tool cleared a federal bar. There is no longer a clear federal bar. The question will be whether the health system exercised its own reasonable oversight, and the answer will be found in board minutes, validation records, and monitoring logs, or in their absence.

This is the market pressure that reaches the governance committee before it reaches the balance sheet. Malpractice underwriters, credentialing bodies, and health system counsel are already asking for evidence of AI oversight architecture. A system that cannot produce it is not merely exposed to a single case. It is exposed on every deployment simultaneously.

The governance implication most boards least want to hear

A board that held AI oversight only while the FDA required it never owned the standard. It borrowed one. When the regulator relaxed its grip, the borrowed standard evaporated, and any board that treated compliance as the ceiling now has no floor. This is the Governance Boundary Principle applied to clinical AI: oversight that exists because an outside authority imposes it is not governance, it is compliance, and it disappears the moment the authority steps back.

The Caremark line of Delaware doctrine has said for years that directors owe a duty to establish and monitor systems for mission-critical risks. In a health system, patient-facing diagnostic AI is mission critical by definition. The FDA's January retreat did not narrow that duty. It removed the argument that someone else was discharging it.

Strategic options

A health system board has three concrete moves available before the next quarterly cycle, none of which requires new regulation to justify.

First, stand up the AI Clinical Advisory Board and the validation gate as a formal, minuted structure, and require that no clinical AI reaches patients without clearing it. The record this produces is both the safety mechanism and the liability defense.

Second, add a standing AI oversight item to the board or quality committee agenda that reports accuracy performance, demographic bias findings, and post-deployment incident data on every clinical AI in use. Oversight that appears only when something fails is not oversight.

Third, rewrite vendor agreements so that accuracy claims, monitoring obligations, and error-rate disclosure sit inside the contract rather than inside a sales deck. The FDA will no longer verify the vendor's claim. The board must.

The health system that builds this now is not protecting itself from the last adverse event. It is setting the clinical AI safety standard for its region before a court, a competitor, or a plaintiff sets it first. The regulator handed the standard back. The only question is which boards pick it up while they still have the choice.

This analysis draws on the board fiduciary framework developed in the AI Agent Orchestration authority research.

Glenn E. Daniels II, Touch Stone Publishers