AI and the DOJ’s Signal to Compliance Programs

August 8, 2026, by: ComplyAIQ

Artificial intelligence is increasingly becoming part of the compliance professional’s responsibility.

One of the clearest indications came in September 2024, when the U.S. Department of Justice Criminal Division updated its Evaluation of Corporate Compliance Programs (ECCP) to expressly address artificial intelligence and other emerging technologies.

The ECCP is designed to assist federal prosecutors in evaluating the effectiveness of corporate compliance programs when making charging and resolution decisions. Importantly, the DOJ emphasizes that its questions are neither a checklist nor a rigid formula. Compliance programs are evaluated in the context of an organization’s particular size, industry, regulatory environment, risk profile, and other circumstances.

Within that framework, however, the DOJ now expressly directs attention to how organizations identify and manage risks associated with AI and other emerging technologies.

For healthcare compliance professionals, the questions provide a useful framework for considering how AI oversight fits within an effective compliance program.

What the DOJ Is Asking About AI

The DOJ addresses AI within the risk assessment portion of the ECCP, beginning with a broader question about emerging risks:

“Does the company have a process for identifying and managing emerging internal and external risks” that could affect compliance with applicable law?

From there, the DOJ expressly turns to artificial intelligence:

“How does the company assess the potential impact of new technologies, such as artificial intelligence (AI), on its ability to comply with criminal laws?”

The ECCP then asks a series of questions addressing how AI is governed and managed within an organization. Among them:

  • Is management of AI and other emerging-technology risks integrated into the organization’s broader enterprise risk management strategy?

  • What governance approach has the organization established for AI used within the business and within the compliance program?

  • How does the organization address unintended consequences and the potential for deliberate or reckless misuse of technology?

  • Are controls in place to monitor AI for “trustworthiness, reliability, and use in compliance with applicable law and the company’s code of conduct”?

  • Are controls in place to ensure that technology is used only for its intended purposes?

  • “What baseline of human decision-making is used to assess AI?”

  • “How is accountability over use of AI monitored and enforced?”

  • “How does the company train its employees on the use of emerging technologies such as AI?”

Taken together, these questions provide a meaningful picture of how the DOJ is approaching AI within the broader evaluation of compliance program effectiveness.

They also map closely to functions that are already familiar to healthcare compliance professionals: risk assessment, governance, policies and controls, education, monitoring, accountability, and corrective action.

AI Within the Compliance Risk Assessment

Risk assessment has long been foundational to the DOJ’s evaluation of compliance program effectiveness. The ECCP describes the starting point as understanding how an organization has identified and assessed its risk profile and whether the compliance program devotes appropriate scrutiny and resources to those risks.

The 2024 update makes clear that AI and emerging technology should be part of that analysis where relevant.

For healthcare organizations, this means understanding where AI is being used and the risks associated with those uses. AI may now appear across clinical decision support, documentation, billing and claims processes, privacy and security functions, research, workforce management, compliance operations, and numerous administrative functions.

The analysis should also be risk-based. An AI application performing a limited administrative function does not necessarily warrant the same level of oversight as an AI system influencing clinical, financial, or other consequential decisions.

The objective is not uniform oversight of every AI application. It is oversight proportionate to the particular technology, use case, and organizational risk.

Governance and Accountability

The DOJ specifically asks about an organization’s governance approach to AI and how accountability over AI use is monitored and enforced.

These questions are particularly significant because effective AI governance extends beyond identifying individual risks. Organizations need to determine who has authority and responsibility for making decisions about those risks.

Depending on the organization and use case, governance may involve compliance, legal, privacy, information security, information technology, clinical leadership, internal audit, risk management, and/or operational stakeholders.

Compliance does not necessarily need to own every aspect of AI governance. It should, however, have a defined role where AI intersects with regulatory and compliance risk.

Organizations should be able to answer practical questions such as:

Who evaluates AI-related compliance risks? Who approves higher-risk uses? What issues require escalation? Who can suspend or restrict an AI system when significant concerns arise? How are important decisions documented? Who is accountable when established requirements are not followed? Are staff sufficiently trained and educated on AI use and risk? Who is responsible for monitoring AI systems? Does the organization have a current inventory of all AI tools in use? Are policies regarding AI use clear and communicated to staff?

These are governance questions that fit naturally within the broader compliance framework.

Controls, Intended Use, and Human Oversight

The DOJ questions move beyond governance structures to the controls surrounding AI itself.

The ECCP asks whether controls exist to monitor the trustworthiness and reliability of AI, whether the technology is being used consistently with applicable law and the organization’s code of conduct, and whether controls ensure that technology is used only for its intended purposes.

The DOJ also specifically asks about the baseline of human decision-making used to assess AI.

For healthcare organizations, these considerations can be incorporated throughout the lifecycle of an AI system.

Before implementation, organizations can define approved uses, identify prohibited or restricted uses, assess relevant compliance and regulatory risks, and establish appropriate human oversight.

After implementation, those expectations can be reinforced through policies, access controls, monitoring, training, escalation mechanisms, and periodic reassessment.

Human oversight becomes particularly important where AI outputs influence consequential decisions, especially patient care. The appropriate form of oversight will vary by use case, but AI should support rather than silently displace professional accountability where meaningful human judgment remains necessary.

Monitoring AI in Practice

The ECCP also asks how organizations address potential negative or unintended consequences associated with technology and mitigate deliberate or reckless misuse.

Those questions point toward an important principle: AI governance does not end when a system is approved.

AI systems and their uses can change over time. Performance may shift. Organizational workflows may evolve. Vendors may modify products or introduce new capabilities. Employees may also begin using approved technologies in ways that were not originally contemplated.

Healthcare compliance programs can address these risks by extending established auditing and monitoring practices to AI.

Depending on the system and its risk profile, this might include monitoring adherence to approved-use requirements, evaluating vendor performance, reviewing incidents and unexpected behavior, assessing bias or performance drift where relevant, and periodically reassessing whether existing controls remain appropriate.

The technology is different, but the compliance discipline is familiar: identify the relevant risk, establish controls, monitor their effectiveness, and respond when weaknesses are identified.

Training, Communication, and Accountability

One of the DOJ’s most direct AI-related questions is:

“How does the company train its employees on the use of emerging technologies such as AI?”

That question has immediate relevance for healthcare organizations.

Employees using AI tools may need guidance regarding acceptable use, privacy and confidentiality, human review, organizational policies, and escalation of concerns.

Managers and operational leaders may require additional education regarding their oversight responsibilities. Compliance, privacy, legal, audit, and other governance professionals may require deeper knowledge to effectively evaluate AI-related risks and controls.

Training should therefore be tailored to role and risk rather than treated as a single, uniform educational requirement.

Education should also connect employees to established mechanisms for seeking guidance and reporting concerns. When inappropriate AI use or other problems are identified, organizations should be prepared to investigate, address the issue, apply accountability where appropriate, and use lessons learned to strengthen the governance process.

Integration, Not Addition

Perhaps the most useful takeaway from the DOJ’s treatment of AI is where these questions appear.

The DOJ did not create a separate evaluation framework for an “AI compliance program.” It incorporated AI and emerging technology into its broader framework for evaluating corporate compliance programs.

Healthcare organizations already have much of the architecture needed to begin addressing AI-related compliance risks.

Existing risk assessments can incorporate AI.

Codes of conduct and policies can establish expectations for appropriate AI use.

Governance structures can define responsibility and accountability for AI-related decisions.

Training programs can incorporate AI-related responsibilities.

Reporting and escalation mechanisms can receive AI-related concerns.

Auditing and monitoring functions can assess AI systems, uses, and controls.

Established investigation and corrective-action processes can respond when AI-related issues occur.

The emergence of AI does not make these established compliance functions obsolete. It expands the environment in which they must operate.

For healthcare compliance professionals, the DOJ’s 2024 ECCP update therefore provides more than a list of questions about a new technology. It illustrates how emerging AI risks can be addressed through the core disciplines of an effective compliance program.

As artificial intelligence becomes increasingly integrated into healthcare operations, the opportunity is to evolve those established compliance practices alongside it—supporting innovation while maintaining appropriate governance, accountability, and oversight.

The Takeaway

The DOJ’s inclusion of AI questions in the 2024 ECCP sends a clear signal to compliance professionals: as AI becomes more integrated into organizational operations, the organization’s compliance program should be utilized to address associated risks.

For healthcare compliance leaders, this does not require building an entirely new compliance framework. It means applying established compliance disciplines—risk assessments, governance, policies, training, monitoring, accountability, and corrective action—to the evolving use of AI.

The opportunity for compliance professionals is to help their organizations adopt AI responsibly and to evolve the compliance program alongside the evolution of technology.

Previous
Previous

You Can't Manage AI Risk You Can't See