What Should Compliance Professionals Know About Agentic AI?
September 7, 2026, by: ComplyAIQ
There’s a lot of conversation right now about agentic AI. Technology companies are introducing AI agents, healthcare organizations are beginning to explore agentic workflows, and there’s no shortage of predictions about how AI agents are going to transform healthcare.
Healthcare compliance professionals should absolutely be paying attention. But there’s a risk in jumping too quickly to the newest AI topic before having a strong foundation in the basics.
Agentic AI is important, and it will create new and more complex governance questions. But its use in healthcare is still relatively early, and many healthcare organizations are still working through much more basic questions about AI governance.
So, what should compliance professionals actually know about agentic AI right now?
First, What Is Agentic AI?
There isn’t one universally accepted definition of agentic AI, and like a lot of AI terminology, the term is sometimes used pretty loosely. But the basic idea isn’t that complicated.
Most of the generative AI tools we’ve become familiar with primarily produce something. You ask a question or give the AI an instruction, and it generates a response, summary, draft, analysis, recommendation, image, or other output.
Agentic AI goes a step further. Instead of only producing an output, an AI agent can be given an objective and then take steps toward accomplishing it. Depending on the system and the authority it has been given, it might retrieve information, use other software tools, interact with systems, make a series of decisions, initiate workflows, communicate with people, or take other actions with varying levels of human involvement.
Think about a simple example. One AI system drafts an email for an employee, and the employee reviews it and decides whether to send it. Another system identifies who needs to receive the communication, gathers the necessary information, determines what needs to be communicated, drafts the message, and sends it.
Both might use generative AI, but the second system has been given much more authority to act. That’s where the compliance and governance conversation starts to change. Generative AI expanded what AI could produce. Agentic AI expands what AI may be permitted to do.
Is Healthcare Actually Using Agentic AI Yet?
This is an important question because the amount of attention agentic AI is getting can make it seem like autonomous AI agents are already everywhere. They aren’t.
AI adoption broadly is moving quickly in healthcare, and generative AI is increasingly being incorporated into healthcare organizations and technology. Agentic AI is earlier.
Research published in 2026 by Microsoft and The Health Management Academy found that 43% of surveyed healthcare organizations were piloting or testing agentic AI, but only 3% reported having agents deployed in live workflows. McKinsey has similarly found a significant gap between generative AI implementation and agentic AI maturity, while KLAS Research has described agentic AI as still being in its early days based on the healthcare AI use cases it has evaluated.
Academic research tells a similar story. There is growing interest in healthcare AI agents, but much of the research remains focused on exploratory studies, benchmarks, and controlled environments rather than widespread real-world deployment.
The exact numbers are going to vary depending on what someone means by an “AI agent,” what counts as implementation, and who is being surveyed. But the bigger picture seems pretty clear: healthcare is actively exploring agentic AI, and that is different from agentic AI being widely deployed across healthcare today.
That distinction is important for compliance professionals to understand. If your organization is still trying to figure out where AI is being used, who is responsible for governing it, how AI risks should be evaluated, or what basic guardrails should be in place, you’re not necessarily behind. Those are still very real governance questions across healthcare.
At the same time, agentic AI shouldn’t be dismissed as something far off in the future. Organizations are piloting it, vendors are building it into healthcare technology, and these capabilities will continue moving into actual healthcare workflows. Therefore, this is a good time to start understanding it.
Why Does Agentic AI Change the Risk?
Let’s go back to the email example. An employee asks an AI tool to draft a patient communication. The AI generates the draft. The employee reviews it, makes corrections if necessary, and decides whether to send it.
There are obviously still risks. The AI could generate inaccurate information, sensitive information could be handled improperly, or the employee could rely too heavily on the output. But there is still a person between the AI-generated output and the final action of actually sending the email.
Now imagine an AI system that identifies which patients need a communication, accesses information from organizational systems, determines what message should be sent, creates it, and sends it. The governance analysis starts to change.
Now we need to know what the AI is actually authorized to do. What systems can it access? What information can it retrieve? What decisions can it make on its own? When does a human need to approve an action? Can we see what actions the AI took after the fact? What happens when it encounters something outside the normal workflow? Who is ultimately accountable? And how do we stop or limit the system if something starts going wrong?
Those questions aren’t completely foreign to compliance professionals. In fact, a lot of them should sound pretty intuitive.
A Lot of the Governance Principles Aren’t New
Take the principle of least privilege. We generally don’t give people unlimited access to systems and information simply because access might be useful to them. Access should be appropriate for the role and purpose. The same concept becomes important when an AI agent can interact with organizational systems. What does the agent actually need access to, and what should it be allowed to do once it gets there?
The same is true for approval controls and segregation of duties. There are plenty of activities in healthcare where we intentionally require another person, another approval, or another control before something happens. If an AI system is capable of completing multiple steps in a workflow on its own, organizations will need to think carefully about where those checkpoints still belong.
Monitoring is critical too. If an AI tool generates a draft that a person reviews, there is already a natural point of human oversight. If an AI system is independently taking hundreds or thousands of actions, organizations need another way to know whether those actions are appropriate and whether the system is behaving as intended.
Don’t Skip the Fundamentals
This may actually be the most important point of this article: compliance professionals should learn about agentic AI, but they shouldn’t jump straight to agentic AI without first developing a strong foundation in AI and AI governance.
There is always going to be another AI term. We’ve moved through predictive AI, generative AI, copilots, agents, and multi-agent systems, and there will inevitably be something else after that. If we constantly chase the newest term, it’s easy to know a little bit about everything without developing a strong foundation in anything.
For compliance professionals, knowing the fundamentals will be critical because they provide the foundation for the additional complexity that emerging AI technologies will bring. Do you understand, at a practical level, what AI is and how it is being used? Do you understand the major risks AI can introduce into healthcare operations? Do you know where AI is being used in your organization? Does your organization have a process for evaluating the risk of different AI use cases? Who is accountable for AI governance? What guardrails are in place? How are vendors being evaluated? How is AI monitored after implementation?
Those may sound like basic questions, but they are important questions. And adding agentic AI doesn’t make any of them less important. In many cases, it makes them even more important.
An organization that doesn’t know where AI is being used today is going to have an even harder time governing AI that can independently take actions tomorrow. An organization that hasn’t decided who is responsible for evaluating AI risk isn't going to solve that problem by adding more autonomous AI technology.
The same applies to individual compliance professionals. If you are still developing your understanding of AI governance, you do not need to stop everything and become an expert in AI agents. Build the foundation first. Understand AI, understand the risks, and understand the fundamentals of AI governance. Then add agentic AI as another layer of that knowledge.
What Could This Look Like in Healthcare?
There are a lot of potential applications. Agentic systems could participate in workflows involving patient scheduling and communications, revenue cycle operations, administrative processes, compliance monitoring, contracting, credentialing, research, and other healthcare functions.
But simply hearing that something is an “AI agent” doesn't tell us very much about its actual risk. An agent performing a narrow administrative task with limited system access, limited authority, and human oversight is very different from an agent that can access sensitive information, move across multiple systems, make consequential decisions, and take actions without human approval.
For compliance professionals, I think there are four simple questions worth remembering: What can it access? What can it decide? What can it do? And who is overseeing it?
You don’t have to understand every technical component behind an AI agent to start asking those questions. They get us away from the terminology and back to what actually matters from a governance perspective: what authority are we giving this technology, what risk comes with that authority, and what controls are appropriate for that risk?
Compliance Still Needs to Own Its Lane
None of this means Compliance needs to become the AI engineering department, and it certainly doesn’t mean Compliance needs to own every AI agent or the organization's entire AI governance program.
Effective AI governance should be multidisciplinary. IT, information security, privacy, legal, clinical leadership, operational leaders, data teams, and others may all have a role depending on the organization and the use case.
But Compliance has an important lane to own. As AI systems become capable of taking more actions with less direct human involvement, compliance professionals need to be able to recognize where those systems could create or increase compliance risk.
Technical teams may understand how the agent works, and operational teams may understand what they want it to accomplish. Compliance needs to be prepared to ask what could go wrong from a compliance perspective and whether the governance surrounding the system is doing enough to mitigate that risk.
Learn About Agentic AI. But Build the Foundation First.
Agentic AI is real. It is developing quickly, and we will likely see much more of it in healthcare over the next few years. For many healthcare organizations, however, it isn't the most immediate AI governance challenge today.
The immediate challenges may be much more basic: Do we know where AI is being used? Do we have the right people involved in governing it? Are we evaluating AI based on risk? Do we have appropriate guardrails? Are we appropriately evaluating our vendors? Are we monitoring AI after implementation?
Healthcare organizations need to get those fundamentals right while preparing for what comes next. Compliance professionals should do the same.
Learn about agentic AI. Understand why increasing autonomy changes the risk, and pay attention to how these technologies are developing. But don't skip the foundation trying to get to the newest thing.
Strong AI governance fundamentals are what will prepare compliance professionals for agentic AI and whatever comes after it.
About ComplyAIQ
ComplyAIQ is a professional organization dedicated to modernizing the healthcare compliance profession for the AI era. Through professional credentials, thought leadership, and practical resources, ComplyAIQ equips healthcare compliance professionals to become trusted leaders in responsible AI governance.
The AIP-HC™ – Artificial Intelligence Professional in Healthcare Compliance is ComplyAIQ’s flagship professional credential, designed to define and validate competence in navigating AI-related risks and governance within healthcare compliance.
Ready to build your AI governance expertise?