Healthcare AI Adoption Runs Into a Global Regulatory Patchwork

AI, heatlhcare, diagnostics

Healthcare organizations are accelerating their use of artificial intelligence while struggling to reconcile a widening assortment of privacy, security and AI governance requirements across jurisdictions.

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    Subscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    Participants in a Tuesday (Sept. 8) webinar hosted by the Atlantic Council’s Cyber Statecraft Initiative warned that conflicting rules governing data use, infrastructure and cross-border transfers could impede clinical trials, pharmaceutical research and the development of tools intended to improve patient care, according to an account by the International Association of Privacy Professionals.

    The tension is particularly acute in healthcare because AI systems often require large quantities of sensitive and diverse patient information. Restricting access to that information can undermine the quality of models, but processing it exposes organizations to overlapping regulatory obligations and potentially serious consequences if safeguards fail.

    “When we develop an AI model, the goal is to drive a benefit for a population,” said Ranjit Kumble, VP of enterprise data science and advanced analytics at Pfizer. “If a model is deployed without the right safeguards, the benefit to the population is much, much more uneven.”

    Artificial intelligence is helping pharmaceutical researchers identify biological targets during the early stages of drug development, Kumble said. But companies operating internationally must navigate different approaches in China, the European Union and the U.S., along with conflicts among sector-specific and state laws within the U.S.

    In Europe, healthcare developers may need to account for both the EU General Data Protection Regulation (GDPR) and the EU AI Act, including its requirements for certain high-risk systems. In the U.S., organizations face a more fragmented framework encompassing health privacy rules, state consumer privacy statutes and AI laws that may emphasize disclosures or chatbot transparency rather than the risk-management obligations found in Europe.

    We’d love to be your preferred source for news.

    Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!

    This fragmentation creates a practical scalability problem, according to the participants. Kumble said organizations often prepare datasets separately for individual AI projects to ensure that the information is “AI ready.” Repeating that work as use cases multiply can become both unsustainable and unscalable.

    The burden is not limited to compliance teams. Different restrictions on sensitive-data processing can determine whether researchers obtain data of sufficient breadth, depth and quality to train reliable systems. That can affect product performance, patient confidence and a company’s ability to compete in an increasingly precise and data-intensive healthcare market.

    The webinar also highlighted the need for governance systems capable of adapting as AI technology changes. Daria Bahrami, head of policy at AI cybersecurity company Dreadnode, said faster AI-driven results are forcing companies to make real-time decisions about their tolerance for risks that previously remained in the background.

    Flexibility, however, should not displace baseline controls, she said. Organizations should assess data processing, retention and other governance requirements before deploying a tool. That is becoming more important as healthcare companies experiment with agentic AI systems capable of taking actions with limited human involvement.

    The risks include agents exceeding their intended permissions or escaping controlled testing environments. Stephen Moon, Snowflake’s global public sector chief technology officer, said organizations must limit agents at both the governance and data-security levels. An agent’s potential reach depends heavily on the systems and information it is permitted to access.

    For healthcare providers and technology vendors, that makes access controls, data segmentation and continuous monitoring patient-safety issues as well as cybersecurity obligations. A compromised artificial intelligence agent with access to medical records, diagnoses or prescription systems could cause substantially greater harm than a conventional data leak.

    The business takeaway is that healthcare organizations cannot wait for regulators to harmonize their rules. They need inventories of AI uses and applicable laws, documented pre-deployment reviews, strict limits on agent permissions and governance structures that can accommodate jurisdiction-specific requirements without rebuilding compliance programs for every project.

    They also need incident-communications plans grounded in verified facts. Kumble warned that disproportionate or poorly informed coverage of an AI incident can generate panic, making an already difficult event even harder to contain.