Year Ahead

What JPM 2026 signaled for healthcare AI compliance

A retrospective on our January 2026 conversations: changing AI-law timelines, consent litigation, and demand for operating evidence beyond attestation letters.

3 min read
Joe Braidwood
Joe Braidwood
Co-founder & CEO
3 min read

Around JPM 2026, our conversations surfaced a practical shift: some healthcare AI uses already face existing legal duties, while newer AI-specific obligations are enacted or approaching. This is a retrospective on those conversations, not a survey of conference attendees or a claim that every AI use is regulated the same way.

In our January conversations, the questions moved beyond “are you using AI?” toward “what evidence supports the way this system is supervised?” and “when a patient asks how an AI system shaped a decision, what can you explain and document?” Signed records can support that inquiry; they do not prove that an AI system is safe.

That pattern framed the meetings we had. Other organizations may be at different stages.

What’s ahead on AI regulation

Let’s be honest about the landscape:

  • Colorado: The state reset its AI law. SB 24-205 was repealed and replaced by SB 26-189 (“Automated Decision-Making Technology”), signed May 14, 2026, with substantive compliance commencing January 1, 2027. It now turns on covered automated decision-making technology (ADMT) used to materially influence a consequential decision, including some healthcare access, cost, and coverage decisions.
  • European Union: The AI Omnibus entered into force on July 27, 2026. Relevant high-risk obligations apply from December 2, 2027 for Annex III systems and August 2, 2028 for Annex I product-embedded systems.
  • All year: State-level AI requirements and enforcement theories keep expanding, which makes jurisdiction-by-jurisdiction tracking part of the job.

And that’s just regulation. Litigation pressure is mounting too. The Sharp HealthCare lawsuit over ambient AI scribes is a reminder that consent and recording theories are active, and California’s wiretapping statute carries statutory damages that can scale quickly when plaintiffs plead per-encounter violations.

The question governance committees are asking

A recurring diligence question — presented here as a synthesis, not a named-customer quote or survey result — is what a health system could reconstruct if an approved AI vendor’s product hallucinated in a clinical workflow. SOC 2 reports and attestation letters remain useful, but they may not answer that event-level question.

Governance committees can ask for operating evidence alongside vendor claims: a signed record of what a configured guardrail reported for a covered event, plus routing, testing, and coverage evidence. The signature makes covered fields and attribution checkable; it does not independently establish source truth, effectiveness, safety, or compliance.

That’s the gap. And it’s why we’ve been heads-down building resources to help.

What we’ve built

Over the past few months, we’ve put together a library of practical guides for navigating what’s ahead. Not theoretical frameworks—actionable resources for real compliance challenges.

Plus deep-dives on HIPAA-compliant AI, NIST AI RMF implementation, ISO 42001 certification, and role-specific guides for CISOs, CMIOs, and General Counsel.

See you at JPM

We were in San Francisco January 12–15. If you’re navigating the same AI compliance questions now—whether you’re a health system trying to vet vendors, or a vendor trying to satisfy enterprise security reviews—the conversation is still open.

The shift from “trust us” to “prove it” is happening. The organizations that figure it out early will have a real advantage. The ones that wait will be answering the same questions under far more pressure.

It’s shaping up to be a consequential year for healthcare AI — and we’re ready for the conversation.

Meeting at JPM?

Missed us at JPM? Use the general scheduling link and we can pick up the same AI compliance conversation now.

Talk to us