Previously, in Part 1, our Change Management discussion focused on identifying AI that is being automatically included through the system update process and how that process needs to evolve to better understand the changes being introduced and how they can affect the workflow for clinicians and patients. In this segment, we will discuss these changes from a risk management perspective and how to effectively adapt the change management process to identify and address the inclusion of AI functions.
Focus Attention Where the Risk Is Highest
Put attention where the risk lives. This can make people nervous about taking updates automatically. The reality is you don’t need the same intensity for every change. A security patch should move differently than a minor release that adds new generative AI behaviors to patient messaging. Treating everything like a high-risk event just creates paperwork and delays potentially important updates. A risk-based approach keeps things practical. Infrastructure, performance, and security updates can often follow standard testing. Updates that influence clinical workflow, patient interactions, financial decisions, or operational priorities should trigger additional review.
Bring the Right People Into the Conversation
It is important that we do not arbitrarily slow upgrades. It’s to identify and understand impact, especially when AI is involved, and spend time where it’s justified. Bring more than IT to the table. A frequent misstep is treating AI review as purely technical. IT teams are responsible to document features, inputs, outputs, and dependencies, but they rarely have full visibility into what a change means in practice. The best reviews pull in multiple perspectives from these key disciplines:
- IT leadership
- Clinical informatics
- Operations leaders
- Revenue cycle
- Compliance and privacy
- Even End users
These groups often bring attention to workflow problems that never show up in a traditional test script.
Test the Workflow, Not Just the Software
Standard testing asks, “Does it function?” It checks integrations, dependent systems, and expected outputs. With AI-enabled behavior, you also need to test usage. How do people respond to it? Does the recommendation make sense in context? Will staff trust it or ignore it? Could it be misread? What happens when it’s wrong, and what’s the fallback? Legal and Compliance teams often care deeply about that last one. A patient messaging tool can produce correct responses most of the time and still be risky if staff don’t have a clear review process, or if safeguards don’t catch the occasional bad output.
Avoid Creating a Governance Bottleneck
In today’s fast-paced environments, be aware of building a governance bottleneck. Leaders worry, reasonably, that extra AI oversight will turn every release into a multi-week ordeal. Nobody wants a six-week review cycle for routine vendor application updates. The practical path is to weave AI evaluation into governance programs that already exist. Often, a lightweight checklist, a brief risk assessment, and clear escalation rules are enough. If it becomes clear a vendor is introducing AI without proper disclosure or documentation, this should be a cause for concern and action should start with a direct conversation. One recommendation is to select tools that can detect where AI is in use and can help identify undisclosed behavior. A sensible early step is to focus on identifying the small portion of updates that carry real workflow, clinical, financial, or compliance implications. Most releases should still move through the current process with little disruption.
The Bottom Line
AI is quickly becoming a default ingredient in healthcare software, and in many cases, it arrives through ordinary vendor updates that don’t look dramatic on paper. That makes change management more critical, not less. The challenge is to understand the impact of innovation while properly adopting new features. It’s knowing what changed, understanding how it reshapes user behavior, and confirming safeguards are in place before new capabilities hit production. Healthcare organizations have spent decades building disciplined technology governance. AI doesn’t require abandoning that discipline. It asks for an extension of it. Organizations that manage this well will adopt new capabilities faster, get more from their technology spend, and avoid the headaches that come with poorly understood change. They’ll also keep the trust of clinicians, staff, and patients, the people affected by every technology decision.