Artificial intelligence has quickly moved from an emerging technology to a boardroom priority. Yet as organizations race to implement new tools, a critical question remains: How can businesses harness AI's benefits while managing the legal, operational, and insurance risks that come with it?
That question drove a recent Candello Patient Safety Study Group discussion featuring Katarina Vickovic of Honigman LLP, Janell Forget of UMass Memorial Health, and Britni Strong of Strategic Risk Solutions.
AI Is Evolving Faster Than Many Organizations Can Adapt
One theme drove the conversation: AI is changing at an extraordinary pace.
While most organizations are becoming familiar with generative AI tools such as Microsoft Copilot and ChatGPT, the industry is already exploring agentic AI systems that can perform tasks autonomously with limited human intervention. Presenters noted that as AI evolves beyond content generation into areas such as automated decision-making, risk assessment, and workflow management, organizations must prepare not only for today’s capabilities but also for what comes next.
The Legal Landscape Remains Unsettled
Despite widespread adoption, there is currently no comprehensive federal law governing AI in the United States. Instead, organizations face a patchwork of evolving federal initiatives, state regulations, and emerging litigation.
The panel highlighted a significant shift taking place in the legal environment. Early concerns focused largely on AI developers, but increasing scrutiny is being directed toward organizations that deploy AI. As businesses rely more heavily on AI-generated recommendations and automated processes, they may be held accountable for how those systems are monitored, validated, and governed. Questions surrounding transparency, informed consent, bias, and human oversight are becoming central considerations for regulators and courts alike.
Healthcare Is Offering a Governance Blueprint
Healthcare organizations are among the earliest adopters of AI, making them a valuable source of lessons learned. At UMass Memorial Health, AI applications support research, clinical practice, and operational functions, including tools that help analyze large datasets, improve workflow efficiency, and enhance decision-making. Yet adoption has not occurred without safeguards.
Forget outlined how her organization established a multidisciplinary “Responsible AI Committee” to evaluate new AI initiatives before implementation. The committee brings together experts from legal, compliance, privacy, information technology, security, and risk management to evaluate AI initiatives before implementation, helping ensure that projects are introduced thoughtfully and responsibly while still supporting innovation and process improvement.
The committee reviews factors such as:
- The problem the tool is intended to solve
- Data collection, storage, and security practices
- Regulatory approvals
- Audit capabilities
- Potential bias and unintended consequences
- Patient consent requirements
Notably, healthcare organizations continue to maintain a "human in the loop" approach using AI to support analysis and recommendations while keeping people accountable for decisions and outcomes.
Insurance Opportunities Extend Far Beyond Automation
According to Strong, insurers and captive programs are already finding value in applications that improve operational efficiency, support underwriting, strengthen financial reporting, enhance analytics, and uncover insights within large volumes of data.
More advanced applications can help organizations aggregate data from multiple sources, identify emerging risks, improve pricing models, and detect anomalies that may otherwise go unnoticed. In one example, AI-driven analysis helped identify employee benefit utilization patterns that ultimately reduced overall risk and costs. The potential benefits are substantial, but speakers emphasized that success depends on having quality data, clear objectives, and appropriate oversight.
Governance May Be the Competitive Advantage
The discussion closed on a theme that resonates across industries: organizations do not need to be AI experts to manage AI effectively. They need strong governance structures, cross-functional collaboration, and trusted advisors who understand both technology and risk. Those foundations will help organizations and industries adapt as AI, regulation, and insurance coverage continue to evolve.
