YUUKI EDGE — The Read · Issue #27 · September 16, 2026
1 · The claim
Last week I wrote that in clinical workflow, what decides survival is what you can write to. An EHR vendor's agents inherit its authentication and its audit trail, so anything that begins and ends inside that tenant turns into a feature of the tenant sooner or later. The way out was the loop that crosses into an organization the incumbent doesn't run.
I ended on a question I didn't answer: who's paying for the evidence?
This week gave me the answer, and it isn't the vendor.
Accreditation for AI in healthcare applies to the organization. The Joint Commission's Responsible Use of AI in Healthcare certification looks at whether a health system has governance, monitoring and education in place. It doesn't validate individual tools.
So the burden lands on the buyer's side of the line, and it stays there, because that's where accountability lives. You can hand a customer a model card, a log, a monitoring dashboard. You can't hand them an attestation, since an attestation only counts if it comes from someone who isn't you.
One correction before I go further. I wrote last week that the dominant EHR's agent platform arrives in 2027. I was wrong. Agent Factory was announced in August with more than 120 pre-built agents, and Ergo ships in November. The clock I described in that issue is about a year shorter than I said it was. The direction of the argument doesn't change. The time you have to act on it does.
2 · The Survival Three
Same three questions every week. They take ten minutes and they're usually unpleasant.
1. When the artifact is free, what's left?
Assume that next year the thing your product generates costs nothing, because in most of these categories two large platform companies are already shipping toward exactly that. Describe your product without it. Whatever you can still describe is the real business.
2. Does it write into a system your customer's organization doesn't control?
Anything that starts and ends inside one tenant belongs to the platform eventually. The platform owns the permissions, the logging and the contract, and it can bundle. What it can't do is write into an organization it doesn't run.
3. Where does it sit on the activity axis, and who's paying for the evidence?
Informing, directing, acting under supervision, acting alone. Moving up that ladder is how you get out of commodity pricing. It's also how you inherit a much heavier evidence burden, and almost nobody budgets for it.
This week it's the third one doing the work.
3 · The tailwind and the threat
The tailwind. There's finally a named standard for organizational AI governance that a health system can go out and get, whether or not it's already accredited. That matters more than it sounds like it should. A certification with five defined areas is something a CIO can take to a board and ask for money against. "We should probably have a policy" is not. The content underneath it is free and already published, in CHAI's governance playbooks, built with more than 150 health AI leaders.
The threat. The buyer is nowhere near ready, and now there's data on it rather than anecdote. Cotiviti and MedCity News surveyed 70 payer and provider executives and published on September 8. More than 70% have started using AI. Fewer than 40% have detailed policies covering how their own staff use generative tools. Among payers, 60% said employees are using tools that never went through IT. Fewer than half of either group called themselves very prepared for an AI-assisted cyberattack.
Seventy self-selected executives tells you about kinds of exposure, not rates across the industry. I'd still take the shape seriously. Adoption is running ahead of the control environment, and the control environment is exactly what certification measures.
It's also worth knowing what didn't get built. A national network of assurance labs, meant to independently validate the products themselves, was announced and then quietly fell apart. There's no national infrastructure grading these tools. What exists grades the hospital.
The survival question this week: does your product make the buyer's governance job lighter or heavier?
Every AI a health system turns on becomes one more thing they have to govern, monitor, document and defend when a surveyor shows up. The field splits three ways from there. Some products arrive with capability only and leave the evidence work to the customer. Some arrive with the chain already attached, which takes cost off a bill the buyer can't avoid. And then there's the platform, which can bundle governance for the agents it runs and can't discharge accountability for anything it doesn't.
Which names sit in which group, the position scores behind that, and the calls I'm willing to be held to are in this week's Institutional issue.
4 · Dimension in focus: Governance
One of the ten Deployment Readiness dimensions, rotating.
People hear governance and picture a policy document. Under survey it's a chain of evidence. Somebody made a decision, under some authority, with monitoring that should have caught it going wrong, and an escalation that fired when it did. Four links, and you need all of them.
Where this usually breaks is that the log proves the output and not the chain. A system can show you that an AI-assisted action happened, with a timestamp and a username attached. What it generally can't show you is that the model running in production was the one that got validated, that the person who accepted the output had the authority to accept it, and that drift monitoring was switched on at the time. Those are separate artifacts. The AI doesn't produce any of them.
What it costs.
Nobody has a line item for this, so here's what's actually in it. Treat it as the shape of the bill, not a quote. What it comes to depends on how many use cases are in scope and how much of your data work is already done.
Inventory. Somebody has to walk the building and find every AI in it, including the tools that came bundled inside something else and the ones staff started using on their own. It's weeks of work, it's dull, and it's the step that gets skipped. The shadow-tool numbers above tell you your list is already wrong before you start.
Standing capacity. A review body that meets on a calendar and has the authority to say no. Not a group that gets convened when someone remembers. That's recurring headcount, spread across clinical, IT, compliance and legal.
Monitoring. Drift and performance monitoring for each deployed model, running continuously, and a person whose job is to look at it. This is the line that turns a project into an operating cost, and it's the one that gets cut first.
Evidence production. The artifacts a surveyor asks for, kept somewhere you can hand them over on request rather than rebuilding them in a panic.
Vendor risk. An assessment you can run repeatedly, re-run when a vendor ships. Your vendors update faster than your procurement cycle looks at them again.
The economics are the part worth arguing about internally. Your first use case pays for nearly all of this. Your tenth pays almost nothing. Governance behaves like a fixed cost while everyone treats it as a variable one, which is why deferring it feels cheap right up until it isn't. Build it early and every deployment after that gets less expensive. Put it off and you build the whole thing during a survey or after an incident, when you have the least room to do it properly.
If you sell into these organizations, that fixed cost is sitting between you and your next contract whether or not it shows up anywhere in your pricing.
5 · The scan
Cotiviti and MedCity News published the 2026 Healthcare AI Readiness Index on September 8, from 70 payer and provider executives. 90% expect AI and cybersecurity spending to go up over the next year.
Epic's Agent Factory ships with more than 120 pre-built agents and no-code customization. Ergo arrives in November, with a live pilot at Ochsner.
Thirty years of FDA AI/ML device authorizations: 1,430 in total, 331 of them in 2025 alone, and 76.5% reviewed by the radiology panel. Product-level regulation covers far less ground than the deployment surface does.
No meaningful healthcare-AI governance financing closed this week. The category's reference round is still Qualified Health's $125M Series B led by NEA back in March.
The free issue gives you the lens. Institutional gives you the calls.
This week's paid issue takes the assurance and governance layer apart: named companies with BACK / WATCH / PASS calls, position scores across six fixed dimensions, the financing read, and the falsifier for every call written down so you can hold me to it.
It's written for people who diligence these companies for a living. Founding rate, locked for as long as you stay.
Yuuki Edge — the survival read on healthcare AI. Written by Victor Phillips, MD.
