Last month, President Trump issued an Executive Order entitled Promoting Advanced Artificial Intelligence Innovation and Security. The Order seeks to advance American leadership in AI and address cybersecurity, infrastructure, and national security risks from increasingly capable AI systems. For healthcare organizations, the Order's significance lies in what it signals about the trajectory of AI governance and cybersecurity expectations at a time when AI is becoming deeply embedded in clinical, operational, and administrative functions.
Federal agencies are directed to take several actions, including:
- Accelerating adoption of advanced AI and reducing barriers to innovation
- Establishing a voluntary program for government-led cybersecurity testing of the most advanced AI models before public deployment
- Strengthening cybersecurity through AI-enabled tools
- Protecting critical infrastructure from AI-driven cyber threats
- Developing security standards, testing methods, and best practices for advanced AI systems
- Promoting information sharing about AI-related vulnerabilities and threats
- Evaluating risks from increasingly capable AI models and their potential misuse
AI and cybersecurity are converging
Healthcare AI discussions have long centered on privacy, bias, transparency, and patient safety. The Executive Order shifts attention to a different, urgent issue: the intersection of AI and cybersecurity. AI systems can serve both defensive and offensive purposes. They can automate threat detection, spot vulnerabilities, and speed incident response. But malicious actors can also use AI to accelerate attacks, enhance phishing, discover vulnerabilities, and generate malicious code.
For healthcare organizations, AI must be evaluated not only as a technology initiative but as part of the overall cybersecurity and enterprise risk management program. Organizations deploying AI across clinical, operational, or administrative functions should assess whether their governance frameworks adequately address AI-specific security risks such as model manipulation, unauthorized access, data poisoning, prompt injection attacks, and misuse of AI-enabled workflows.
AI adoption is expanding the healthcare attack surface
The Order arrives as healthcare organizations integrate AI into core functions like clinical documentation, coding, claims processing, cybersecurity operations, and patient communications. These technologies interact with sensitive data repositories, electronic health records, and enterprise applications, often with broad access to organizational data. Traditional cybersecurity assessments may not fully address risks tied to model behavior, third-party foundation models, autonomous decision-making, or AI-enabled access to enterprise systems.
As healthcare organizations expand their use of AI, security reviews should be folded into the AI deployment lifecycle from the start, not treated as a downstream consideration. The Order reinforces the need to account for new technologies in existing security controls, rather than relying on standard software risk assessments that miss AI-specific threats.
Enhanced focus on AI vendor risk management
The Order also underscores the importance of understanding AI systems' security posture before deployment. Many healthcare organizations evaluate AI vendors through procurement processes designed for traditional software. AI systems raise additional questions about model training, data usage, third-party dependencies, and ongoing monitoring. Organizations evaluating vendor review processes should consider questions such as:
- How was the model developed and tested?
- What security controls protect the model and underlying infrastructure?
- How does the vendor use customer data, and is it incorporated into future model training?
- What subcontractors or third-party models are involved?
- How are vulnerabilities identified and remediated?
- What monitoring and incident response capabilities are in place?
As adoption accelerates, healthcare organizations should seek contractual protections that address AI-specific risks, including data usage restrictions, audit rights, security commitments, and incident notification requirements. The growing integration of AI for Healthcare makes thorough vendor review indispensable.
Agentic AI creates new governance considerations
The Order's focus on advanced AI systems is particularly relevant as healthcare organizations begin exploring agentic AI-systems that act with significant autonomy. Unlike traditional software, these systems may independently execute tasks, interact with multiple applications, access enterprise systems, and make decisions with limited human intervention. In healthcare, agentic AI could eventually assist with administrative processes like scheduling, revenue cycle functions, patient communications, clinical workflows, and supply chain operations.
These capabilities also create novel governance and security challenges. An AI agent that interacts with enterprise systems effectively functions as a new category of user within the organization. Existing governance structures may not adequately address access management, activity monitoring, escalation procedures, auditability, human oversight, and operational controls for such systems. Building these considerations into AI governance programs now will become critical as more autonomous systems are deployed.
Why this matters for healthcare organizations
The Executive Order serves as a signal about the future direction of AI governance and cybersecurity policy. Healthcare organizations should consider several near-term priorities:
- Evaluating whether existing AI governance programs adequately address cybersecurity risks
- Assessing whether AI vendor due diligence processes are sufficiently thorough
- Developing governance frameworks for advanced AI technologies, including agentic AI deployments
- Ensuring that AI-related risks are addressed through enterprise-wide governance structures, not siloed in IT or innovation teams
As AI becomes more embedded in healthcare operations, organizations that proactively address governance, cybersecurity, and operational resilience will be best positioned to realize the benefits while managing the risks. For leadership teams, integrating AI for Executives & Strategy into their planning can help align technical decisions with business risk and regulatory expectations.
Your membership also unlocks: