Shadow AI in Healthcare: Risks, Possibilities, and a Path Forward
If you manage, lead, or work in a healthcare organization—whether a hospital system, physician practice, nursing facility, ambulatory surgery center, or behavioral health provider—there is a near certainty that someone on your team is already using artificial intelligence tools that your IT department has never approved. They are not doing it to be reckless. They are doing it because they want to work faster, serve patients better, and reduce administrative burdens that are challenges of modern healthcare.
This phenomenon has a name: shadow AI—the use of unapproved artificial intelligence applications by employees outside the oversight of organizational leadership and information technology governance. And the data tells us it is far more widespread than most organizations realize.
The Scope of the Shadow AI Problem: Bigger Than You Think
A January 2026 survey by Wolters Kluwer Health of more than 500 healthcare professionals and administrators found that 57% of respondents have encountered or personally used unauthorized AI tools at work.[i] More than 40% were aware of colleagues using shadow AI, and nearly 20% admitted to personally using an unsanctioned tool. These numbers align with broader workforce trends: Microsoft’s 2025 Work Trend Index reported that 78% of AI users at work bring their own tools outside IT approval,[ii] and UpGuard’s State of Shadow AI Report found that more than 80% of workers use unapproved AI tools, with one-quarter considering AI their most trusted source of information.[iii]
Why are healthcare workers turning to these tools? The Wolters Kluwer survey provides clear answers: over 50% of administrators and 45% of providers cited faster workflows. Nearly 40% of administrators and 27% of providers pointed to better functionality or the absence of approved alternatives. And 26% of providers said simple curiosity and experimentation drove their use. In short, shadow AI is filling a vacuum—one created by organizations that have not yet provided governed, fit-for-purpose AI solutions to their workforce.
The Risks of Shadow AI Are Real
ECRI named the misuse of AI chatbots as the number one health technology hazard for 2026—ahead of cybersecurity threats and surgical device failures.[iv] The ECRI analysis documented chatbots suggesting incorrect diagnoses, recommending unnecessary testing, promoting subpar medical supplies, and even inventing body parts--all while remaining seemingly authoritative. These are not regulated medical devices, nor have they been validated for clinical purposes.
Some specific risks of uncontrolled AI use in healthcare include:
- HIPAA violations when staff enter protected health information (PHI) into AI tools without a signed Business Associate Agreement (BAA)—a clear regulatory breach regardless of intent.
- Patient safety harm from AI hallucinations—confidently stated but factually wrong outputs that could influence clinical decisions.
- Data breach exposure when sensitive data leaves organizational control and enters third-party systems with unknown retention and security practices.
- Bias in AI outputs that may disproportionately affect vulnerable patient populations, creating equity concerns and potential liability.
- Re-identification risks where AI tools may reassemble de-identified data into identifiable patient information, and the “black box” problem of opaque AI decision-making that undermines clinical accountability.
A Path Forward with AI in Healthcare: Governance, Not Prohibition
The solution is not to ban AI. Prohibition will simply drive usage further underground, increasing risk while forfeiting the genuine productivity and quality gains that well-governed AI can deliver. Instead, organizations should pursue a strategy of governed adoption—channeling workforce demand for AI into safe, compliant, and clinically appropriate pathways. Here is a practical roadmap:
- Start with a non-punitive inventory. Conduct an honest assessment of what AI tools your workforce is currently using. Frame this as a learning exercise, not a disciplinary one. Amnesty-style surveys and confidential interviews can surface the true landscape of shadow AI in your organization and identify the unmet needs driving its use.
- Establish a multidisciplinary AI governance committee. Effective governance requires perspectives from clinical leadership, information technology, compliance, legal, privacy, and frontline staff. This committee should own the ongoing process of evaluating, approving, and monitoring AI tools.
- Develop clear, accessible policies. Your workforce needs straightforward guidance on which AI tools are approved, which uses are prohibited (such as entering PHI into consumer-grade chatbots), and how to request evaluation of new tools. Complexity and ambiguity are the enemies of compliance.
- Provide sanctioned alternatives. If staff are turning to shadow AI for documentation, literature review, coding assistance, or administrative tasks, the most effective risk mitigation is providing BAA-covered, vetted alternatives that meet those needs. Remove the incentive for workarounds by giving people approved tools that actually work.
- Involve legal counsel early. When selecting and procuring AI tools, robust vendor contracting is critical. Contracts should address data ownership, data use and retention, security obligations, BAA requirements, liability allocation, indemnification, and the vendor’s obligations regarding model updates and other changes. Legal counsel should be involved early in the evaluation and procurement process to help ensure contracts protect the organization’s interests, comply with HIPAA, and clearly delineate responsibilities if something goes wrong. Pay particular attention to how the vendor handles PHI, whether data may be used to train the vendor’s models, and what happens to organizational data when the contract ends.
- Train comprehensively—and explicitly address shadow AI. HIPAA’s Security Rule already requires security awareness training for all workforce members.[v] Update your training programs to address AI-specific risks, including the consequences of entering PHI into unapproved systems, the limitations of AI-generated clinical information, and the organization’s process for reporting and requesting AI tools.
- Implement technical guardrails and monitoring. Network-level controls, data loss prevention tools, and endpoint monitoring can detect and prevent unauthorized AI tool access. HHS’s proposed strengthened HIPAA Security Rule includes mandatory asset inventories and network mapping requirements that are directly relevant to shadow AI identification.[vi]
- Align with emerging frameworks. The Joint Commission’s Responsible Use of AI in Healthcare (RUAIH) framework[vii] and the Coalition for Health AI (CHAI) governance playbooks released in May 2026[viii] provide structured approaches to AI governance that can accelerate your organization’s efforts. The NIST AI Risk Management Framework also offers a technology-agnostic structure for identifying and mitigating AI-related risks.
- Treat governance as ongoing. AI capabilities are evolving rapidly. A policy written today may be outdated in six months. Build review cycles, incident response processes, and feedback loops into your governance framework from the start.
The Bottom Line
Shadow AI is a present reality in healthcare organizations of every size and type. Employees are using these tools because they see genuine value in them, and in many cases, they are right. The challenge for organizational leadership is not to eliminate AI use, but to bring it into the light: to understand it, govern it, and channel it toward better patient care and more efficient operations without sacrificing privacy, safety, or compliance.
The organizations that thrive will be those that treat shadow AI as a signal—a message from their workforce about unmet needs—and respond with thoughtful governance rather than reflexive prohibition.
[i] Wolters Kluwer Health, “Shadow AI: A Hidden Risk to Healthcare” (January 2026), available at https://www.wolterskluwer.com/en/solutions/uptodate/ai-clinical-decision-support/shadow-ai-report
[ii] Microsoft, 2025 Work Trend Index.
[iii] UpGuard, “The State of Shadow AI Report 2025,” available at https://www.upguard.com
[iv] ECRI, “Top 10 Health Technology Hazards for 2026” (January 2026), available at https://home.ecri.org/blogs/ecri-news/misuse-of-ai-chatbots-tops-annual-list-of-health-technology-hazards
[v] 45 C.F.R. § 164.308(a)(5) (requiring security awareness and training for all workforce members).
[vi] HHS proposed strengthened HIPAA Security Rule (NPRM, January 2025), including mandatory asset inventories and network mapping requirements.
[vii] The Joint Commission launched its Responsible Use of AI in Healthcare (RUAIH) framework and voluntary certification program. Available at https://www.jointcommission.org/en-us/certification/responsible-use-of-ai-in-healthcare
[viii] Coalition for Health AI (CHAI), Governance Playbooks (May 2026), translating RUAIH principles into actionable implementation steps. Available at Coalition for Health AI (CHAI) Releases Comprehensive Governance Playbooks to Streamline AI Implementation for Health Systems | CHAI
This article is for informational purposes only and does not constitute legal advice. For guidance on AI governance specific to your organization, contact the Sands Anderson Health Law Team.