Is AI in Healthcare Moving Faster Than We Can Regulate It?

Estenda Solutions

Jul 24, 2026

AI in healthcare regulation

AI already works inside the exam room. It takes notes during visits, spots tumors on scans, and sorts billing data in seconds. The rules meant to govern it are still being written.

That gap runs through everything. AI in healthcare keeps racing ahead while regulation walks behind, trying to catch up.

We have spent more than 20 years at Estenda Solutions building software and data systems for healthcare, MedTech, and life sciences organizations. We hold ISO 13485 certification, so safety and quality sit at the center of how we work. Our very own COO and co-founder, RJ Kedziora, has been a guest on the Gravity Healthcare Hacks podcast for a 30-minute episode, AI, Advantage or Danger in Healthcare?, and talked through where this technology helps, where it turns risky, and why the speed matters so much.

Is AI in Healthcare Moving Faster Than We Can Regulate It?

The FDA has authorized more than 1,200 AI-enabled medical devices, and about 331 of them cleared in 2025 alone, the most in a single year in the agency's history. Congress still has not passed a broad federal AI law. Dozens of AI bills have come up since 2023, and none have become law.

States try to fill the void. By early 2026, more than 20 states had passed their own healthcare-specific AI laws, each with slightly different rules on disclosure, transparency, and clinical use.

  1. Products hit the market faster than anyone can review them

AI tools reach clinics faster than any regulator can check them. Most medical AI never gets a formal review from a federal agency at all.

The FDA only reviews products that meet the legal definition of a medical device. A big share of the AI now used in healthcare never crosses that line, things like scheduling tools, ambient scribes, administrative software, and general chatbots. Analysts who track this point out that most medical AI never passes a federal regulator, and often no state regulator either. The risk lands on you, the buyer.

RJ described this pattern on the podcast.

“More and more vendors bring these products to market, and they're being implemented. And the FDA does, in some of these cases, review these systems to make sure that they're okay. You do really need to do that testing and double-checking of how it works in your environment to make sure that it works for you."

You can act on this. Ask what data trained it. Ask how output is monitored in your own setting. Then test it on your workflows before you trust it. A vendor who cannot answer those questions clearly has already told you something. See how we handle this in our work on clinical data accuracy and error reduction.

  1. The speed outruns our ability to predict where it goes

Even experts cannot say where healthcare AI will be in a few years. Rules cannot get ahead of a target that keeps moving.

The FDA released its first full draft guidance for AI-enabled devices in January 2025. That guidance stayed a draft well into 2026. Over that same stretch, generative AI in healthcare went from a curiosity to a daily clinical tool. A technology that reinvents itself every few months will always sit ahead of a rulemaking process that takes years.

RJ made this point with a line from Bill Gates.

"Bill Gates said a while ago that we as humans tend to overestimate what's possible in two years but underestimate what's possible in 10 years. I don't think we understand where this technology is going in 10 years. I don't think we can conceive that, let alone two years."

He also pushed back on the idea that trustworthy AI sits a lifetime away.

"The pace that this is advancing, it's not that far away where it is going to be better than the average human."

You can plan for this. Pick vendors who publish update logs and support monitoring for performance drift over time. Review your AI policies every quarter instead of every few years. A tool that ran safely at launch can behave differently after an update or after your patient mix shifts. Our piece on how AI optimizes data and the patient-physician partnership shows what that ongoing relationship looks like.

  1. The industry protects patients with proven human-era processes while AI-specific rules catch up

The first broad guidance for responsible healthcare AI landed in September 2025, when the Joint Commission and the Coalition for Health AI put out a set of recommendations. That was a real step forward. Healthcare also has something even stronger already in place: decades of proven review habits, things like second opinions, chart audits, sign-off steps, and compliance review. Those systems were built to catch human error, and they catch AI error just as well.

RJ framed it well.

"People are not perfect…We've developed the processes to account for that imperfection. So while the industry is working out how to improve AI to be better than humans, let's apply the processes we have right now to overcome some of those hurdles."

That is the key point. The safeguards healthcare already uses to reduce human error are just as valuable when AI becomes part of the workflow. Until AI-specific regulation matures, consistent review, clear accountability, and documented decision-making remain effective guardrails for safe adoption.

You can put this to work. Treat AI output like a first draft from a new hire. Someone qualified reads it and signs it. Write down who reviewed what, and when. Keep a clear audit trail so you can trace any error back to its source. The same habits make AI-driven diagnosis safer and more accurate.

  1. Vigilance, not standards, keeps hallucination and bias in check

The two biggest risks in healthcare AI, hallucination and bias, mostly stay in check because people stay alert. Not because enforceable standards force it.

Generative AI can invent details that no one said or wrote. RJ noted that human transcripts carry error rates too, and careful review fixes both. Bias works the same way. A tool trained on data from one group can quietly underperform on another. RJ used a plain example. An AI built around an urban Philadelphia setting may not work as well in rural Kansas, because each place records data differently. Both teams mean well. The tool still behaves differently.

His rule for using these systems stays simple.

“Today you do have to worry about a couple key things. One, the idea of hallucinations. So you have to remain vigilant when you're using it. So you can't just take it and say, okay, here's the note and move on with life."

The federal stance in late 2025 leaned more hands-off on AI. That trend drops even more of this responsibility onto individual organizations. The vigilance has to come from you.

You can act here. Ask vendors for performance data across different patient groups. Test tools on your own population before you roll them out. Never let AI make the final call on a clinical decision. Keep a human in the loop every single time.

Ready to Adopt AI the Right Way?

Explore our AI and machine learning services for healthcare, then book your free 30-minute consultation today, or contact Estenda at info@estenda.com.

Frequently Asked Questions

Is AI in healthcare regulated by the FDA?

Not all AI systems. The FDA reviews AI that counts as a medical device, such as diagnostic imaging tools, and it has authorized more than 1,200 of them. Many AI tools used in healthcare, like ambient scribes, scheduling software, and general chatbots, fall outside FDA review. That means a large share of medical AI reaches the market with no federal check.

Is there a federal law for AI in healthcare in 2026?

In March 2026, the Trump Administration unveiled a National AI Legislative Framework to guide future legislation, followed by the June 2026 Executive Order Promoting Advanced Artificial Intelligence Innovation and Security, which established new federal priorities around AI innovation, cybersecurity, and security. Alongside these initiatives, the FDA continues to regulate certain AI-enabled medical devices, while healthcare organizations must also comply with existing healthcare regulations and applicable state AI laws. Together, these measures form an evolving federal policy framework rather than a single healthcare AI law.

Can doctors use ChatGPT with patient information?

Not with identifiable patient information in a public tool. The safer path is to remove all identifying details, describe the clinical situation in general terms, and sign a business associate agreement, or BAA, with the vendor. Major providers like OpenAI will sign BAAs for eligible accounts. Always follow your organization's approved AI policy.

What is the biggest risk of AI in healthcare?

Over-reliance on tools that still make mistakes. AI can hallucinate, which means it can produce information that is wrong or was never stated, and it can carry bias from its training data. Both risks stay manageable the same way, with a qualified human in the loop to review and approve every output before it affects care.

How many AI medical devices has the FDA approved?

The FDA has authorized more than 1,200 AI-enabled and machine learning-enabled medical devices, with about 331 cleared in 2025 alone. That was the highest number in a single year in the agency's history, which shows how fast adoption is speeding up.

How can my healthcare organization start using AI safely?

Start with clear goals, vetted vendors, and strong review steps. Confirm what a tool is cleared for, test it on your own data and workflows, keep a human in the loop for every clinical decision, monitor performance over time, and write an AI use policy for your staff. If you want expert help, reach out to Estenda for a free consultation.

Tags

AI in Healthcare