# Five Bills, One Governance Framework: Enterprise Action Items for Health Care Use of AI - Quarles

*Источник: Quarles*
*Дата: 2026-09-22*
*Язык: en*

**Кратко:** Five Bills, One Governance Framework: Enterprise Action Items for Health Care Use of AI
Five bills, one legislative session, and a single premise: that artificial intelligence may inform health care decisions but may not make them. If the bills are enacted, that premise would hold true at every layer of the patient relationship: the clinical encounter, the tools that support it, the records that document it, and the service channels that surround it.

Five Bills, One Governance Framework: Enterprise Action Items for Health Care Use of AI
Five bills, one legislative session, and a single premise: that artificial intelligence may inform health care decisions but may not make them. If the bills are enacted, that premise would hold true at every layer of the patient relationship: the clinical encounter, the tools that support it, the records that document it, and the service channels that surround it.
This is the concluding installment in our series on California’s 2026 health care AI legislation. The preceding parts traced that premise bill by bill: AB 1979 reserves licensed clinical judgment to licensed professionals; SB 503 allocates bias identification and mitigation duties between the developers and deployers of clinical decision support systems; AB 2575 protects the clinician who overrides them; SB 903 applies human-authority and specific-consent requirements to psychotherapy; and AB 1609 extends the insistence on human availability to consumer-facing customer service channels.
Read together, these measures are not five discrete compliance projects; instead they are best understood as a single governance problem. The obligations they impose (inventory, documentation, human oversight, disclosure, and consent) draw on the same underlying record of what AI tools an organization uses, how the tools were built and tested, who is accountable for their outputs, and what should be done with those outputs. This installment therefore turns from bill-specific analysis to the enterprise question: what a health care organization should build once, and maintain, in order to satisfy obligations under these bills. Entities operating outside California should apply the same steps as a readiness exercise for comparable legislation in their own states.
In This Series
- Part One: Background and Prohibition on AI Independently Performing Licensed Clinical Functions (AB 1979)
- Part Two: Bias Identification and Mitigation for Clinical Decision Support Systems (SB 503)
- Part Three: New Liability and Worker Protection Framework for AI-Driven Clinical Decision Support Systems (AB 2575)
- Part Four: Regulation of AI in Psychotherapy Services (SB 903)
- Part Five: The Right to Human Customer Service Act (AB 1609)
- Series-Wide Action Items for Health Care Organizations
Action Items for Health Care Organizations
- Conduct an AI inventory. Identify and catalog all AI tools, clinical decision support systems, and automated decision systems used in clinical, administrative, patient-facing, and customer service settings, classifying each by function (clinical, administrative, supplementary) and determining whether the organization acts as a developer, deployer, or both (SB 503). Document training data sources, evaluation methodologies, and known limitations for in-house tools.
- Assess clinical AI deployment practices and human oversight protocols. Evaluate whether any AI systems are being used in ways that could be characterized as independently performing licensed clinical functions (AB 1979) or making independent therapeutic decisions (SB 903). Map AI-supported workflows against the licensure requirements of each professional category involved and confirm that licensed professionals retain decision-making authority. Review workflows involving unlicensed personnel to ensure AI is not directing, guiding, supervising, or instructing them in performing licensed clinical functions.
- Implement bias monitoring programs and establish compliance benchmarks. Establish protocols for identifying and mitigating biased impacts in clinical decision support systems, and ensure that developer documentation (training data demographics, bias testing, intended use statements, and monitoring recommendations) is obtained and maintained as required by SB 503. Consider aligning bias testing with recognized industry standards (e.g., NIST AI Risk Management Framework, ISO/IEC 42001 (AI Management Systems), or emerging ONC and CMS guidance on algorithmic transparency) or recurring algorithmic impact assessments to establish a defensible compliance path.
- Update consent workflows. Review and update patient consent forms and processes, particularly for AI-assisted psychotherapy recording or transcription (SB 903), to ensure that consent is purpose-specific, written, informed, voluntary, unambiguous, documented in the patient record, and revocable at any time without affecting the patient’s right to care. Ensure consent is not buried in general terms of service or obtained through deceptive design patterns.
- Prepare for a new CDSS liability framework. Developers and deployers of clinical decision support systems (CDSS) should consider how to prepare for a liability framework in which a clinician’s failure to override an AI output would no longer serve as a superseding-cause defense (AB 2575). Audit existing disclosures, disclaimers, and documentation to ensure they clearly articulate intended use, scope, known risks, and limitations. Update vendor contracts to address the proposed liability framework, including indemnification provisions and representations about system capabilities. Implement post-deployment monitoring and incident tracking to support a reasonable-precautions defense.
- Weigh litigation risk and insurance considerations. Reassess litigation risk allocation with counsel and insurers in light of AB 2575’s elimination of the superseding-cause defense. Revisit indemnity, defense, and limitation of liability terms in vendor agreements and consider whether existing professional liability coverage adequately addresses AI-related exposure.
- Update employment policies for clinical AI anti-retaliation compliance. Review employment policies, procedures, and protocols to ensure that none require workers to accept, defer to, or refrain from overriding CDSS output; any such policy is explicitly prohibited by AB 2575. Train managers and supervisors on the anti-retaliation requirements, document the reasons for any adverse employment action taken against a workforce member who has overridden CDSS output, and establish internal processes to respond to regulatory investigations.
- Engage cross-functional teams. These laws cut across legal, compliance, IT, clinical operations, health information management, human resources, and vendor management. Establish a working group to coordinate readiness efforts and ensure that the same underlying record of AI tools, testing documentation, human oversight, and accountability serves each bill’s requirements.
- Audit customer service chatbot deployments for AB 1609 compliance. Non-hospital health care entities (g., including health plans, PBMs, pharmacies, digital health, telehealth, and health care-adjacent technology companies) should determine whether they meet the $500 million annual revenue threshold and, if so, implement clear AI disclosures, build frictionless mechanisms for customers to request a human agent, and staff to meet the 15-minute connection window and one-hour cumulative hold cap. Entities operating through hospital-licensed facilities should confirm and document which chatbot communications fall within the hospital exemption and which do not, recognizing that non-hospital affiliates, retail pharmacy operations, and health plan functions may not qualify even if the parent organization includes licensed hospitals.
- Conduct vendor diligence and update contracts. Build vendor diligence and contracting processes that require developer documentation on training data demographics, evaluation methodology, bias mitigation, and monitoring recommendations (SB 503). For CDSS vendors, secure clear and conspicuous disclosures regarding intended use, scope, known risks, and limitations, along with affirmative obligations for the vendor to provide material updates (AB 2575). Confirm, and document in contract, which entity bears the documentation obligations at each integration point, including electronic health record vendors that embed third-party CDSS modules.
- Do not forget about other California AI and privacy legislation. The legislature also passed additional bills, including amendments to California Consumer Privacy Act obligations and data broker laws, as well as new bills addressing children’s privacy, automated decision-making, AI transparency, and chatbots.
The five bills examined in this series share a common thread: human judgment must remain at the center of health care, whether in the clinical encounter, the tools that support it, or the service channels that surround it. These are not new concepts, but California is the first state to pass a coordinated suite of health care AI bills with operational compliance mandates and enforceable penalties. Organizations that build a unified AI governance infrastructure now—one that addresses inventory, documentation, bias monitoring, human oversight, consent, and disclosure—will be positioned to satisfy these requirements efficiently and to scale that compliance architecture as other states follow California’s lead.
Quarles & Brady is actively tracking AI legislation affecting health care and will continue to provide updates as these bills move through the Governor’s review and as other jurisdictions introduce similar measures. The time to assess compliance architecture and build scalable compliance programs is now, before a January 1, 2027 effective date arrives.
For any questions on development or deployment of AI in the health care setting contact your Quarles attorney or:
- Meghan O’Connor: (414) 277-5423 / meghan.oconnor@quarles.com
- Candice Andalia: (202) 780-2627 / candice.andalia@quarles.com
Related Capabilities
- 340B Program
- Artificial Intelligence
- Health & Life Sciences
- Health Information Technology, Privacy and Security
- Health Insurance Industry Partners (PBMs, TPAs, DMPOs and URAs)
- Hospitals and Health Systems
- Long-Term Care and Senior Housing
- Pharmacy, Drug and Device
- Provider and Physician Groups
- Telehealth

[Оригинал](https://www.quarles.com/newsroom/publications/five-bills-one-governance-framework-enterprise-action-items-for-health-care-use-of-ai)