Leading the change for AI in healthcare

The challenge

Healthcare executives are being asked to adopt AI while the regulatory floor is still being poured under them. The European Commission’s 2025 study on the deployment of AI in healthcare reports that most hospitals are not prepared for the AI Act, that leadership is named more often than technology as the blocking factor, and that in-house AI expertise is close to absent. The session had to be useful to people already using AI informally, without either alarming them into inaction or endorsing what they were doing.

How we worked

  • A diagnostic built on the European Commission’s 2025 deployment study rather than on vendor material
  • A four-level organisational maturity model — informal, functional, integrated, strategic — with each level mapped to the regulatory exposure it actually carries
  • Four governance pillars: strategy, data, architecture, accountability, each reduced to a decision someone has to own
  • Kotter’s change sequence adapted to health AI, and six evaluation criteria for assessing a proposed AI solution
  • A live self-assessment exercise: participants placed their own organisation on the model during the session

Leading the change for AI in healthcare

What came out of it

The model separates the level of the technology from the level of the governance around it, which is where the risk sits: level-3 tooling under level-1 leadership is unmanaged exposure, not progress. Each level names the specific regulatory consequence — silent GDPR exposure at level 1, no DPIA and no named supervisor at level 2, AI Act Article 26 at level 3, eligibility for EHDS secondary use at level 4 — so the question stops being “are we doing AI” and becomes “what are we exposed to, and who owns it”.

4 levels — A maturity model executives applied to their own organisation, live