In 2026, six of the world’s most serious cybersecurity agencies did something they almost never do. CISA, the NSA, the Australian Signals Directorate, the Canadian Centre for Cyber Security, NCSC-UK, and NCSC-NZ, the full Five Eyes intelligence alliance’s cyber arms, published a single joint guidance document together. Its subject was not a nation state hacking group or a ransomware gang. It was agentic AI in healthcare, and its opening tone read less like routine advice and more like a warning.
This post is part of our larger guide on the myth of healthcare dependence on AI. That guide argues AI in medicine works best as a second opinion a clinician can weigh, not an authority that quietly takes over. Agentic AI is the sharpest test of that argument yet, because it is specifically designed to reduce how often a human has to weigh in at all.
What agentic AI actually means inside a hospital right now
Agentic AI is different from the AI most people already picture in a clinical setting. A traditional clinical decision support tool follows a fixed rule: if this lab value is abnormal, flag it. Agentic AI instead reasons toward a goal, breaking it into steps, coordinating across multiple systems, and adjusting its approach based on what it finds along the way, largely without a human approving each individual step.
The scale of adoption is no longer theoretical. At the HIMSS 2026 conference, Epic, the electronic health record company that already sits underneath a majority of American hospital systems, revealed that more than 85 percent of its customers are now actively using Epic AI in some form. Epic used the conference to unveil Agent Factory, a platform letting health systems build and monitor their own custom AI agents, alongside a new family of foundation models called Curiosity, trained on anonymized real world patient records specifically to predict how a patient’s care journey will unfold. Epic’s architecture now runs on three pillars, an agent called Art for clinicians, one called Penny for back office administrative work, and one called Emmie built to interact directly with patients.

Outside Epic’s own ecosystem, a wave of well funded agentic health startups is already operating at meaningful scale. Hippocratic AI, valued at roughly 3.5 billion dollars, reports more than 115 million patient interactions through its patient facing voice agents, and is marketed as having the largest safety record in that specific category. Abridge, valued at 5.3 billion dollars and recognized as a KLAS Market Leader in ambient AI, is deployed across major hospital systems including Mayo Clinic, UPMC, Yale New Haven Health, Emory Healthcare, and Sutter Health. Cohere Health’s agentic prior authorization platform, which gathers clinical evidence from a patient’s chart, determines the right submission pathway, prepares the justification, and submits it to an insurer with minimal human involvement, reports up to an 8x return on investment and 94 percent provider satisfaction. Qventus focuses on real time hospital operational decisions. Nabla, valued similarly to Abridge at roughly 5.3 billion dollars, has expanded from ambient documentation into a broader agentic platform with particular strength in European health systems. None of this is a pilot program anymore. It is production infrastructure, already touching a meaningful share of patient care in the United States.
It is worth separating two different categories of risk hiding inside that adoption number, because they are not the same problem. A documentation agent like Abridge, listening to a clinical conversation and drafting notes, carries a very different risk profile than a patient facing agent like Hippocratic AI’s voice system or Epic’s Emmie, which interacts directly with a patient with no clinician in the room at all, or an agentic prior authorization system like Cohere Health’s, which can independently determine whether a patient’s treatment gets approved. The industry survey’s R0 through R3 risk tiering exists precisely because lumping all of these together under one label, agentic AI, obscures how differently they can fail and how differently a failure in each category actually reaches a patient.
Hospital IT and compliance leaders are beginning to respond to that distinction directly. Coverage from the HIMSS 2026 conference noted that AI governance is quickly becoming a formal vendor requirement rather than a nice to have, with chief information officers and compliance leaders starting to demand vendor attestations about agent identity, authorization scope, and audit capability as a standard part of procurement contracts heading into 2027. That is a meaningful, concrete step toward closing the exact gap the cybersecurity agencies flagged, agent permissions that get granted once and never meaningfully reviewed again, though it is still an emerging practice rather than an industry standard.
The gap between the marketing and what is actually happening
Here is where the story gets more complicated, and more reassuring, than the raw adoption numbers suggest on their own.
A 2026 qualitative study presented at the ACM Conference on Fairness, Accountability, and Transparency, based on interviews with twenty stakeholders spanning developers, implementers, and clinical end users, found that despite the industry’s marketing language around autonomous agents, these systems currently operate under near total human oversight in practice. The researchers described this as an autonomy contradiction, where commercial promises of independent clinical reasoning exceed what safety, regulatory, and liability constraints actually allow to be deployed in high stakes environments today. In plainer terms, when a hospital says it is using an autonomous AI agent, what is usually running underneath is a system a human is still actively supervising at nearly every meaningful decision point, whatever the sales materials imply.
That is genuinely good news, for now. It is also exactly why the warning from the cybersecurity agencies, and the accountability question underneath it, matters so much. The gap between where these systems are today and where they are being built to go is narrow, and it is closing quickly.
Related Post
What the cybersecurity agencies are actually warning about
The Five Eyes guidance, titled Careful Adoption of Agentic AI Services, singled out a specific technical risk as the reason for its unusually blunt tone: agentic systems are typically given broad permissions when they are first set up, and those permissions rarely get scaled back later. Because agents act across multiple connected systems at once, the electronic health record, the imaging archive, the scheduling system, and various third party tools, a single overprivileged agent that gets compromised can look completely normal in an audit log while quietly doing damage. The guidance specifically names privilege creep, confused deputy attacks, where one system is tricked into misusing another system’s trusted access, and identity spoofing as the leading risks health systems are not yet equipped to catch with traditional security controls.
For a hospital, this is not an abstract IT problem. An agent with broad access across a patient’s chart, imaging, and scheduling is, by design, positioned to make or influence decisions that affect real clinical care. A security failure in that kind of system is a patient safety failure wearing a cybersecurity costume.
The other risk: what happens when the AI itself, not a hacker, is simply wrong
Separate from the security warning, a distinct body of 2026 research has focused on what happens when multiple AI agents work together and one of them makes an ordinary mistake, no attacker required. When agents interact sequentially, the output of one becomes the input for the next, and researchers studying this dynamic have documented a phenomenon they call error propagation, where the reliability of the entire chain is limited by its single weakest link. A related industry survey proposed a four level risk tiering system, from R0, administrative errors with low direct patient impact, up to R2 and R3, where an agent’s error can influence diagnosis, triage, or treatment planning even when a clinician technically signs off on the final step, because the clinician is often reviewing an output built on several upstream AI judgments they never independently checked.
This is the honest, unglamorous version of the accountability problem. It is rarely one dramatic failure. It is a quiet chain of smaller AI judgments, each individually plausible, compounding into a recommendation that looks correct by the time a human reviews it.
The legal question nobody has answered yet
This is where the story becomes genuinely unresolved, not just technically but legally. Healthcare liability has long relied on something called the learned intermediary doctrine, which traditionally shields a device manufacturer from direct liability because a physician is presumed to exercise independent judgment before acting on any tool’s output. Legal researchers writing on agentic AI in 2026 have pointed out that autonomous systems threaten to erase that shield entirely. If an agent executes a multi-step action with minimal human review, the physician’s independent judgment, the very thing the doctrine depends on, may no longer be meaningfully present in the process, potentially exposing AI vendors to direct liability they have never had to carry before, and leaving health systems, vendors, and supervising clinicians in an unsettled three way dispute over who actually answers for a bad outcome.
Regulators have not resolved this either, and if anything the picture is getting more fragmented, not less. State legislatures, California most aggressively, passed a large wave of new AI oversight laws in 2026, while at the federal level, Executive Order 14365 directed the Department of Justice to challenge state AI laws directly, setting up a preemption fight between state and federal authority with no settled outcome yet. Researchers tracking this regulatory landscape have specifically flagged prior authorization denials, clinical documentation and triage support, discharge planning, and inpatient monitoring as the agentic use cases carrying the highest regulatory risk, precisely because each one either directly affects a patient’s access to care or compounds into a downstream clinical decision a human reviews only after several AI judgments have already shaped it. One healthcare regulatory attorney, asked directly where enforcement risk would show up first, answered without hesitation that class action litigation would lead, followed by more class action litigation, then state attorneys general. Medical malpractice attorneys, according to the same reporting, are already watching agentic AI closely for exactly this reason, and plaintiffs’ firms that built their practice on website tracking and disclosure lawsuits are reportedly beginning to shift their focus toward ambient AI and wiretapping style claims instead.
For an organization operating across a dozen states with a dozen different, sometimes conflicting AI statutes, compliance experts note the realistic answer is not to chase every individual state law as it passes, but to build a governance floor strict enough to satisfy the most demanding jurisdiction and treat everything else as already covered. That is a pragmatic operational answer. It is not the same thing as a settled legal answer, and for now, no single one exists.
What this means if you are the patient, not the vendor
If you are a patient rather than a hospital administrator, the honest, current takeaway is this. Agentic AI is very likely already touching some part of your care, whether that is a documentation agent, a prior authorization agent, or a patient outreach agent, and the safety research so far suggests a human is still closely supervising the parts of that process most likely to affect your actual treatment. The risk is not that this is happening invisibly today. The risk is that the accountability structure, who is responsible when an agent’s error, security compromise, or upstream mistake finally does slip past that human oversight, is still being fought out in courtrooms and statehouses rather than settled in advance. That is worth knowing, and it is a reasonable thing to ask about directly if a hospital or clinic tells you an AI system played a role in a decision about your care.
The larger pattern
This is the same pattern that shows up across AI in healthcare more broadly, which is the whole argument of our pillar guide on the myth of healthcare dependence on AI. Hospitals are not dependent on autonomous AI making unsupervised decisions today, current research is fairly clear on that point. What they are dependent on is a level of human oversight that the industry’s own commercial incentives are actively working to reduce, faster than the legal and security frameworks needed to make that reduction safe have been built.
Frequently asked questions
Agentic AI refers to systems that can reason toward a goal, break it into multiple steps, and coordinate across different hospital systems such as the electronic health record, imaging archive, and scheduling platform, largely without a human approving each individual step. This differs from traditional clinical decision support, which follows fixed, predefined rules.
In 2026, six cybersecurity agencies from the Five Eyes alliance, including the NSA and CISA, published joint guidance warning that AI agents in healthcare are typically given broad system permissions that are rarely reduced later, creating risks including privilege creep, confused deputy attacks, and identity spoofing that traditional security tools are not built to catch.
Peer reviewed research presented at the 2026 ACM Conference on Fairness, Accountability, and Transparency found that despite marketing language suggesting full autonomy, agentic AI systems in healthcare currently operate under near total human oversight in practice, due to safety, regulatory, and liability constraints.
This remains an unresolved legal question. Traditional healthcare liability law relies on the learned intermediary doctrine, which shields device makers because a physician is presumed to exercise independent judgment. Legal researchers have noted that autonomous, multi-step AI actions may undermine that doctrine, potentially exposing AI vendors, health systems, and supervising clinicians to a three way liability dispute that courts have not yet settled.
Error propagation describes what happens when multiple AI agents work in sequence and one agent’s output becomes the next agent’s input. Researchers have found that a mistake introduced early in that chain can compound, and the reliability of the entire system ends up limited by its single weakest link, even when a clinician signs off on the final recommendation.


