Compliance Professionals Don’t Need to Own AI Governance. They Need to Own Their Lane.
August 30, 2026, by: ComplyAIQ
As healthcare organizations work to build AI governance structures, a basic question is emerging:
Who should own AI governance?
Should it be IT? Information Security? Compliance? Clinical leadership? A dedicated AI governance function?
There may not be one right answer. More importantly, it may not even be the most important question.
A better question might be: Does everyone involved understand their role, and are they prepared to own it?
One of the biggest risks in building effective AI governance is any single group within an organization thinking it can do it alone.
AI simply touches too many areas.
Its use can affect patient care, privacy, cybersecurity, regulatory compliance, billing, employment, contracting, operations, quality, data governance, and much more. No single function has the expertise or perspective to fully understand all of those risks.
That is why a strong foundation for AI governance should be multidisciplinary.
Clinicians understand patient care and clinical workflows. IT and information security bring critical knowledge of technology, infrastructure, access, and security. Operational leaders understand how technology is actually being used in day to day work. Legal brings an important perspective on legal obligations and liability. Privacy professionals understand how information is collected, used, shared, and protected.
And compliance professionals bring an important perspective too.
Compliance has a lane to own
Compliance does not need to own the entire AI governance program.
That should not be an unfamiliar concept for compliance professionals.
Consider billing. Compliance does not own billing. Revenue cycle, coding, clinical operations, finance, and other functions may own the processes that ultimately produce a claim. But compliance still plays an important role in helping the organization identify and mitigate billing compliance risk.
Compliance assesses risk. It helps establish policies and controls. It provides or supports education. It conducts or oversees auditing and monitoring. It investigates concerns. It helps identify corrective action when problems are found.
The fact that Compliance does not own billing does not mean that billing compliance risk belongs to someone else.
AI should be viewed in much the same way.
Compliance does not need to own the technology, develop the models, manage every AI enabled workflow, or make every decision about how AI is used. But when AI creates or changes compliance risk, Compliance has a responsibility to understand that risk and help the organization address it.
That distinction matters.
Compliance professionals do not need to become data scientists or understand every technical detail of how an AI model works.
But they do need to own their lane.
Healthcare compliance programs already have established responsibilities for identifying risk, setting expectations, providing education, monitoring activity, investigating concerns, escalating issues, and promoting accountability.
AI does not make any of those responsibilities go away.
Instead, it changes the environment in which they are carried out.
Compliance professionals should be considering how AI changes the organization’s compliance risk profile. They should consider whether existing policies and controls still work when AI enters a workflow. They should recognize where AI may affect areas already within the scope of the compliance program, whether that involves billing and coding, auditing and monitoring, investigations, regulatory requirements, or other established compliance areas.
Compliance professionals also need to recognize when something falls outside their expertise and make sure the right people are involved.
Owning the lane requires understanding AI
There is an important prerequisite to all of this.
Compliance professionals cannot meaningfully evaluate AI related compliance risk without understanding AI well enough to recognize the risks it creates.
That does not mean learning how to build a large language model.
It means developing enough AI literacy to understand how these technologies are being used, what can go wrong, and where those risks intersect with existing compliance responsibilities.
The same is true for everyone involved in AI governance.
Clinicians do not need to become attorneys or AI engineers. But clinicians involved in governance should understand the unique risks AI can introduce into clinical care.
Operational leaders do not need to become cybersecurity professionals. But they should understand how AI can change the risks within the workflows they oversee.
This is where multidisciplinary AI governance becomes meaningful.
Each discipline brings its existing expertise to the table, along with enough understanding of AI to recognize how AI changes the risks within that area of expertise.
Collaboration still requires accountability
There is another challenge with multidisciplinary governance.
If AI governance belongs to everyone, there is a risk that specific responsibilities end up belonging to no one.
An AI committee alone does not solve that problem.
Organizations still need clarity about who identifies new AI uses. Who evaluates the risks. Who has authority to make decisions. Who monitors what happens after implementation. Who responds when something goes wrong. And who makes sure significant issues reach the right level of leadership.
Those responsibilities are likely to cross traditional organizational boundaries. That is exactly why clearly defined roles matter.
The goal does not have to be finding one department capable of owning everything. The goal should be building a structure where the right people are involved and everyone understands what they are responsible for.
For compliance professionals, that means avoiding two extremes.
Compliance does not need to argue that AI governance belongs to Compliance.
But compliance professionals cannot reasonably conclude that someone else “owns AI,” so compliance risks associated with AI are sufficiently being addressed without Compliance at the table.
Own your lane
AI governance will not look exactly the same in every healthcare organization. Size, structure, technology, resources, existing governance functions, and risk profile all matter.
But the foundation should be consistent.
AI governance requires collaboration among people with different areas of expertise. Those professionals need to understand the unique risks AI introduces generally, but they also need to understand how those risks intersect with their own responsibilities.
For healthcare compliance professionals, that makes AI competence increasingly important.
Compliance does not have to own AI governance.
But compliance professionals should be prepared to own their lane within it.
That means understanding AI well enough to bring their existing compliance expertise to the table, and getting to that table early enough for that expertise to matter.
Compliance functions that wait to get involved in AI governance discussions until the risks are already baked in will be much less effective at helping their organizations address them.
It’s time for the compliance profession to get involved early, bring its expertise to the table, and own its lane.
About ComplyAIQ
ComplyAIQ is a professional organization dedicated to modernizing the healthcare compliance profession for the AI era. Through professional credentials, thought leadership, and practical resources, ComplyAIQ equips healthcare compliance professionals to become trusted leaders in responsible AI governance.
The AIP-HC™ – Artificial Intelligence Professional in Healthcare Compliance is ComplyAIQ’s flagship professional credential, designed to define and validate competence in navigating AI-related risks and governance within healthcare compliance.
Ready to build your AI governance expertise?