Agentic AI Moves From Experimentation to Clinical Operations, Raising New Security and Governance Challenges
核心洞察
More than two-thirds (68%) of healthcare providers have adopted AI agents into their workforce, according to KPMG (搜索), marking a shift from pilot programs to operational deployment.
At Hospital for Special Surgery, AI agents now complete 1,100 insurance claims per month, reducing appeals time from 45 minutes to five and improving success rates from 65% to 100%.
The rise of "shadow AI" poses significant risks, with one health system discovering over 400 unsanctioned AI agents already in use across its network.
The conversation around artificial intelligence in healthcare has undergone a fundamental transformation over the past year. What was once a cautious exploration of ambient listening tools and isolated pilots has evolved into full-scale operational deployment of agentic AI—autonomous systems capable of acting, deciding, and interacting across clinical environments in ways that mirror human behavior. This shift, while promising significant efficiency gains, is introducing urgent new questions about security, governance, and patient safety.
More than two-thirds (68%) of healthcare providers have already adopted AI agents into their workforce, according to KPMG (搜索) research cited by MIT Technology Review. The technology is being deployed to automate complex back-office processes, collaborate with medical teams, and triage patients—all in an effort to reduce cognitive load on clinicians as the supply of human healthcare workers dwindles.
From Tool to Actor: A Paradigm Shift
Fran Rosch, CEO of Imprivata (搜索), describes the change as a move from AI as an enterprise tool to AI as an autonomous actor. "AI agents are now active participants in the workforce, operating across clinical applications, browsers and endpoints in ways that mirror human behavior," Rosch writes. "The question, however, is whether organizations are truly prepared for what that level of autonomy brings from a security perspective."
This observation is echoed by clinical leaders at major U.S. healthcare systems, who report that health systems are no longer piloting AI tools in isolated workflows. Instead, they are embedding AI into real clinical and operational environments—drafting clinical notes, triaging patient messages, managing prior authorizations, and coordinating care pathways.
Measurable Impact at Hospital for Special Surgery
At the Hospital for Special Surgery (HSS) in New York, an academic medical center focused on musculoskeletal health, the results of agentic AI deployment are already quantifiable. Ashis Barad, MD, chief digital and technology officer at HSS, reports that AI agents now complete 1,100 insurance claims per month. The technology has reduced the appeals stage from 45 minutes to five and improved the success rate of those appeals from 65% to 100% in the nine months since implementation. HSS now handles all claims in-house, eliminating the need for third-party contractors.
"Agentic AI takes your workflow and collapses it, augments it, supercharges it, and makes it more performant," says Dr. Barad.
Building on that success, HSS is deploying AI agents in non-clinical patient-facing settings through a collaboration with enterprise agentic AI developer Ema Unlimited (搜索). The AI scheduling and triage service is accessible 24/7 via web, text, or phone, using conversational AI to ask patients clarifying questions about their condition before booking appointments with the most appropriate clinician. The system factors in location, insurance coverage, and physician availability.
Built-In Safeguards and Human Oversight
Given the high-stakes nature of healthcare decisions, the triage service incorporates multiple safeguards. Sensitive, complex, or uncertain scenarios are escalated to human specialists. Every decision made by the AI agent is auditable, and human staff can intervene at any point. Patient data is kept secure, and the system is trained on all HSS protocols, policies, and care pathways.
At HSS, all decisions around the technology are filtered through an AI subcommittee that Dr. Barad co-chairs alongside a senior nursing executive. AI agents that may touch on patient care face far more rigorous scrutiny than those handling backend processes.
The Rise of Shadow AI
A concerning pattern emerging alongside formal AI adoption is the rise of "shadow AI"—unsanctioned tools adopted by frontline staff seeking to work more efficiently. Rosch notes that many healthcare delivery organizations believe they have little to no unauthorized AI activity, but the reality is often different.
One Imprivata (搜索) customer, after conducting a manual review of identity provider data and network traffic, discovered more than 400 different AI agents and services already in use, many tied to individual employee-driven workflows. "This finding underscores how quickly AI adoption is outpacing control," Rosch writes.
Unlike traditional software, these agents learn and adapt, sometimes behaving in ways that were not fully anticipated at deployment. "This introduces a fundamentally new dynamic: These systems are not purely deterministic and must be managed more like co-workers than code."
The Speed Problem: Machine vs. Human Oversight
The core security challenge, according to Rosch, is that healthcare organizations have built compliance around human timelines—reviews taking hours or days, audits taking weeks or months, and access decisions that are normally static. AI collapses those timelines to seconds.
"An AI agent can execute hundreds of actions before a human has reviewed a single event," Rosch explains. "This creates a fundamental imbalance, where human-speed oversight cannot keep pace with machine-speed action."
Securing AI Agents as Identities
If AI agents are becoming actors in clinical environments, Rosch argues they must be treated as identities—the same as any clinician. This requires moving beyond traditional access controls to identity-driven security frameworks that answer critical questions: What is this agent allowed to do? Under what conditions? How is compliance verified? What happens when it deviates? Who is accountable?
Dynamic, context-aware controls are necessary, including just-in-time access, clear ownership models, and the ability to rapidly provision and revoke permissions at machine speed.
A General-Purpose Technology
Dr. Barad envisions a future in which 90% of non-clinical healthcare tasks could be administered by AI agents, freeing clinicians for what he calls "white-glove work"—the most complex, specialized, and sensitive cases. According to KPMG (搜索), 84% of providers are already comfortable handing decision-making about specific processes over to AI agents.
"It's wrong to think of agentic AI in use cases," Dr. Barad says. "It's a general-purpose technology, analogous to electricity."
To achieve this vision, healthcare providers must establish unified data strategies that integrate fragmented data sources across organizations. Dr. Barad notes that each hospital he has worked in had a slightly different definition for "time to start surgery," a metric commonly used to gauge operating room efficiency. Such fragmentation impedes AI agents from retrieving and assimilating information across systems.
"We're spending so much time on keyboards and computers right now that we're actually not doing what we should be doing," says Dr. Barad. "This is going to rehumanize health care."
