New state laws now require human oversight of AI-driven coverage and clinical decisions. Most healthcare organizations lack the technical governance to comply.
CHICAGO, Illinois — A wave of new state laws is changing the rules for artificial intelligence in healthcare, and it is exposing a readiness gap that few provider and payer organizations are prepared to close. These are not federal proposals waiting on Congress. They are state laws with effective dates that have already passed, and they carry reporting duties and liability that reach directly into how healthcare software is built. As of 2026, 37 states have enacted or introduced legislation governing the use of AI in healthcare. The fastest-moving group of laws targets coverage and clinical decisions. The common rule, that a qualified human must own any medical necessity denial, now appears in roughly a dozen states. Organizations that treated AI governance as a future concern are finding that the future is already on the statute books.
The laws are already in effect
The most comprehensive example took effect this summer. Washington’s Senate Bill 5395, effective June 11, 2026, allows only a licensed physician or health professional to deny a prior authorization based on medical necessity, and bars insurers from relying on AI alone to make that call. A human reviewer must weigh the requesting provider’s recommendation, the patient’s medical history, and the patient’s individual clinical circumstances. The AI criteria must reflect the individual patient, not just group data.
Other states are adding transparency and reporting duties on top of human review:
- Maryland (HB 1563, effective June 1, 2026): Insurers must report to the Insurance Commissioner each quarter how many adverse decisions they issued, what services were involved, and whether AI was used. The commissioner can investigate insurers that show sharp increases in denials, especially for emergency department services.
Georgia (SB 444, effective January 1, 2027): Insurers may use AI in prior authorization, but AI cannot issue an adverse decision until a qualified human completes a review in which a clinical peer takes part.
The direction is clear. Human oversight of AI decisions is moving from best practice to legal baseline. For organizations that operate across state lines, the challenge is not one law but many. Effective dates, reporting formats, and definitions of acceptable AI use differ from state to state, and there is no single federal standard to fall back on. A health system or digital health company serving patients in several states cannot simply meet the strictest rule and move on. It has to build systems flexible enough to satisfy each jurisdiction it touches, and to prove that compliance on demand. That is a software problem long before it is a legal one.
Why governance has fallen behind adoption
Taction Software, a Chicago-based healthcare IT and custom software development firm, has released a practical guide to responsible AI governance for healthcare organizations. Rather than restating the ethical case for oversight, the guide translates the new legal requirements into the technical architecture they demand. It covers human-in-the-loop review, decision traceability, HIPAA-aligned audit logging, model documentation, bias monitoring, and vendor oversight, and it maps each one to the obligations the new laws impose.
The timing reflects a documented gap between how fast AI has been adopted and how slowly governance has kept pace. A January 2026 study in Health Affairs, led by Stanford researcher Michelle Mello, found that many insurers lack strong governance processes to monitor the accuracy and bias of the AI tools they have deployed. That gap exists despite heavy use. A 2024 survey of 93 large insurers found that 84 percent were already using AI for some operational purpose. Public trust has not kept up. Two-thirds of US adults say they have little confidence that AI will be used responsibly in healthcare. The stakes go beyond compliance. Courts are now testing whether automated decisions deliver the individualized review that insurance contracts promise. Humana is facing a lawsuit in Kentucky over its use of an AI prediction tool, with patients arguing that rigid criteria ignored their specific clinical circumstances. For any organization putting AI into clinical or coverage workflows, the ability to show how a decision was reached is becoming both a legal requirement and a legal defense.
What “human review” actually requires in software
“The law now says a human must review AI decisions. What almost no one is explaining is what that actually requires under the hood,” said Arinder Singh Suri, CEO of Taction Software. “A compliance checkbox is not the same as an audit trail a clinician can act on. If a reviewer cannot see what the model saw, what data it weighed, and why it reached its recommendation, then the human in the loop is a signature, not a safeguard. Meeting these mandates is an engineering problem before it is a policy one, and that is the gap we wrote this guide to close.” The guide breaks the human oversight requirement into the parts that make it real in software:
- Decision traceability: Capture the inputs, model version, and reasoning behind each recommendation so a reviewer, and later an auditor, can reconstruct it.
- Audit logging: Keep tamper-evident records retained in line with HIPAA and state record-keeping rules.
- Bias monitoring: Run it continuously, not once at validation, because model performance drifts as data and populations change.
Vendor oversight: Because many organizations buy rather than build their AI, and the new laws hold the deploying organization accountable no matter who wrote the model.
Each of these is a design decision that is far cheaper to build in from the start than to retrofit under a regulator’s deadline. The guide also addresses where these controls have to live. In modern healthcare platforms, governance cannot be a separate dashboard bolted on after the fact. Traceability and logging have to be wired into the same workflows clinicians and reviewers already use, so that oversight happens in the natural course of work rather than as an extra step people are tempted to skip. When governance sits outside the workflow, it becomes the first thing sacrificed under pressure, which is exactly when it matters most.
Built on compliant healthcare work
The guide is written for the technical and compliance leaders who have to turn a legal mandate into a working system. Its recommendations are vendor neutral and focus on architecture rather than any single product.
Taction Software brings direct experience to the subject. The company has delivered EHR and EMR integration for Voyant Health, built a behavioral health platform for CHIPSS, and developed an FDA Class 1 application for Revive Ease. This work required the same disciplines the new laws now demand: secure data handling, defensible record keeping, and systems designed to keep clinicians in control of clinical decisions.
“Every serious healthcare project we take on already lives inside HIPAA and FDA constraints, so building for traceability and human oversight is not new territory for us,” Suri added. “What is new is that these practices are moving from best practice to legal baseline. Organizations that treated governance as optional are about to find out it was load bearing.” Taction Software is offering the guide at no cost to healthcare organizations assessing their exposure to the new requirements. The guide is available at Taction’s AI governanceresource page.
About Taction Software
Taction Software is a Chicago-based healthcare IT and custom software development company founded in 2013. The firm builds HIPAA-aligned digital health platforms, EHR and EMR integration, telemedicine and remote patient monitoring systems, and custom healthcare software for organizations across the United States. Led by CEO Arinder Singh.
Suri, who brings more than 20 years of personal experience in software and healthcare technology, Taction focuses on secure, compliant, and scalable healthcare solutions. Learn more at tactionsoft.com.