What is the problem?

Institutions are deploying AI they do not control, generating data they do not own, and creating liability they cannot defend. Vendor AI runs in a third party's cloud, so the audit trail sits outside the institution and the decision cannot be reconstructed when it is questioned. When connectivity fails, oversight fails with it. Right now most institutions do not own the evidence they would need to defend themselves.

Read the full case in Chapter 01, The Problem

Why now?

Three market forces are converging on a single timeline. Federal deregulation is removing the compliance frameworks that anchored traditional governance, while tort liability and insurance scrutiny stay exactly where they were. Based on Medigram's market intelligence analysis, D&O insurance carriers are moving from AI-risk questionnaires toward explicit governance requirements. Medigram expects explicit AI-governance requirements to become materially more common in D&O and related underwriting by early 2028. Hospitals unable to demonstrate control over consequential AI decisions should expect increasing exposure to coverage limitations, exclusions, higher costs, or unfavorable underwriting outcomes. Meanwhile procurement frameworks adopted across thousands of hospitals now reference the standards Medigram helped author.

See the three converging forces in Chapter 03, Why Now

How does it affect me?

Say you have just taken over basketball or baseball operations. You did not choose the tools already in the building, but every return-to-play call now carries your name and the franchise's. The inputs behind those calls already have an algorithm in them somewhere: recovery scores, workload models, wearable trends. The judgment stays with the physician, and it is still made on a sideline or in a training room with a phone as the only computer present.

Read the team physician's account in Chapter 06

How does this affect our reputation?

The question that arrives the morning after is never whether the call was right. It is how the decision was made: who was accountable, what the AI actually did, and where the evidence is. Assembling that answer later from screenshots, emails and memory produces nothing contemporaneous, which is exactly what a grievance, a committee or a court is asking for. Reputation turns on whether anyone can prove how the decision was made.

Read the hospital physician's account in Chapter 06How should boards evaluate consequential AI?

What is the solution for me?

The governed record is created at the moment and the place the decision is made: what informed the call, what the system was permitted to contribute, and the accountable authority who owned it, sealed then rather than reconstructed later at a desk. When the inputs are not sufficient, it holds rather than guesses, and the hold is on the record. The evidence sits on your premises and under your keys, because if the institution did not generate it, store it and control it, it is not governance. It is a report from someone else's server.

See the fields of a Governed Decision RecordRead the architecture in Chapter 07

You will have answers, and ongoing answers, when the question comes.