Insights

AI Governance

Fifty-seven percent is a product requirement, not a compliance finding

A Wolters Kluwer Health survey found 57% of healthcare professionals have encountered or used unauthorized AI at work, and about half said the reason was speed. If you sell into health systems, that number is telling you what your product does not do yet.

September 19, 2026 · 6 min read

Fifty-seven percent is a product requirement, not a compliance finding

A Wolters Kluwer Health survey of 518 clinicians and administrators, fielded in December 2025 and reported out in early 2026, found that 57% had encountered or used unauthorized AI tools at work. Roughly 40% had seen a colleague do it and about 17% admitted to doing it themselves. Around half of respondents gave the same reason: faster workflows. ECRI, separately, named misuse of AI chatbots the number one health technology hazard for 2026, ahead of cybersecurity threats and device failures.

Most people read those two findings as a compliance story. A governance gap. Something for the privacy officer to write a memo about.

I read them as a product requirement, and if you build software that health systems buy, so should you.

The number describes a vacuum, not a violation

Every row in that 57% is a person who had a task, looked at the sanctioned toolkit, found nothing that would finish the task before the shift ended, and went around it. The survey says so directly. Over 50% of administrators and 45% of providers cited speed. Nearly 40% of administrators and 27% of providers said the approved alternative either did not exist or did not work well enough. About a quarter of providers said curiosity.

That is not a workforce with a discipline problem. That is a workforce telling you, in aggregate and for free, exactly which parts of their day your software does not touch. Documentation. Literature lookup. Coding assistance. Message triage. The tasks where someone will paste a chart note into a consumer chatbot are the tasks where the clinical workflow is still manual, and the clinician has decided that a 30-second unauthorized answer beats a 10-minute authorized one.

Ban the tool and the task does not go away. It just moves further out of view, onto a phone, off the network, past whatever logging you had.

Same model, opposite risk, and the only difference is paperwork

Here is the part that matters for anyone building or buying in healthcare. The underlying model in a sanctioned ambient scribe and the underlying model in a clinician's personal chatbot account are frequently the same family of model, sometimes literally the same vendor. The clinical quality argument is not where the line falls.

The line falls on four contract facts.

Is there a Business Associate Agreement. OpenAI does not sign BAAs for consumer accounts, and neither do the other consumer tiers. Without one, a clinician pasting a patient identifier into that window has made an unauthorized disclosure of PHI to a third party with no safeguards agreement behind it, regardless of how careful the clinician was being.

Is the input retained, and for how long. Is it used for training. And is the session logged anywhere the organization can actually review after the fact.

Those four facts are the whole difference between a managed risk and an unmanaged one. They are also entirely invisible at the moment of use. There is no error message when someone pastes PHI into the wrong window. No alert fires. The violation is silent, and it surfaces weeks later in a breach investigation or an OCR inquiry, if it surfaces at all.

What this means if you sell into health systems

If you are a HealthTech product company, the shadow AI numbers are a competitive read on your own roadmap. Three things follow.

First, find the task, not the tool. The security review will ask you about your AI features. Your buyer's real problem is the clinician who is going around all of it. The feature worth building is the one that makes the unauthorized shortcut pointless, delivered inside the workflow where the shortcut is happening. That is a product decision, not a policy decision, and it is made by whoever owns the roadmap.

Second, ship the contract facts as a feature. When your product uses a model, your buyer's security reviewer needs four answers in writing: BAA coverage, retention window, training behavior, and what gets logged. Having those answers ready, in a document you can forward, is worth more in a procurement cycle than another accuracy benchmark. The buyers who are moving fastest right now are the ones who can hand the answer to their own compliance team without a meeting.

Third, price the alternative honestly. Every sanctioned tool that is slower than the unsanctioned one is a tool your buyer's staff will route around. Speed is not a nice-to-have in this category. It is the control. A governed tool that nobody uses provides zero governance.

What this means if you run the health system side

Start with the honest list of tasks, not the honest list of tools. Ask each team lead one question: what is the work your people are doing where the approved software does not help. You will get a short list, and it will map almost exactly onto whatever shadow AI you find.

Then decide, per task, whether you are going to sanction something, build something, or accept that the task keeps happening off-platform. Those are the only three outcomes. Pretending there is a fourth one where the memo works is how organizations end up with a policy binder and a 57% problem at the same time.

For the tasks you sanction, the four contract facts above are your intake. For the ones you cannot cover yet, say so out loud and say what the interim rule is, because silence is what produced the shadow in the first place.

The uncomfortable version

The most common response to this data is a ban with no replacement. I understand the instinct. It is fast, it is cheap, and it creates a paper record that someone did something.

It also guarantees that the next tool stays hidden, which converts a manageable inventory problem into an undetectable one. You lose the ability to see your own exposure in exchange for the feeling of having acted. That trade is bad on its own terms, and it gets worse every quarter, because the tools keep arriving and the tasks keep being due.

The 57% is not telling you your people are reckless. It is telling you where the work is. Treat it as requirements intake and you get a roadmap out of it. Treat it as a compliance finding and you get a memo.

One of those two documents changes what happens on Monday.