AI Governance Institute
← News

Utah Healthcare AI Sandbox Sets a Governance Template With Real Teeth

What happened

Utah's Office of Artificial Intelligence Policy signed master agreements with Intermountain Health and University of Utah Health. The agreements establish binding data privacy and AI governance terms. These serve as conditions for piloting healthcare AI tools within the state's regulatory sandbox, as reported in AI may soon be in more healthcare processes in Utah under new state agreements. Three pilot programs were approved under this structure: telehealth dermatology, postpartum physical therapy, and prescription refill support. Each program requires independent third-party evaluators and mandatory human oversight built into its compliance design. The Utah Medical Licensing Board criticized earlier sandbox activity for lacking adequate input from healthcare professionals and affected stakeholders. In response, the office broadened participation and added accountability mechanisms before proceeding.

Why it matters

  • ·Sandbox governance is contractual, not statutory. Health systems under master agreements with a state AI office face governance obligations that may be harder to audit, enforce, or escalate than those under established law. Compliance teams need to map those obligations explicitly.
  • ·The built-in third-party evaluator requirement sets a precedent: regulators are beginning to treat independent clinical AI review as a baseline condition for deployment approval, not an optional enhancement. The AI Billing Tools Added $942M in Unwarranted Healthcare Costs, Insurer Study Finds case illustrates why regulators are moving in this direction.
  • ·The Medical Licensing Board's earlier objections show that AI sandbox programs can be challenged on procedural grounds if clinical stakeholders are excluded from governance design. Organizations building their own sandbox or pilot frameworks need documented stakeholder engagement records, not just technical governance artifacts.

Governance controls affected

What to do now

  • ☐If your organization participates in any state or federal AI sandbox program, obtain and review the governing master agreement to identify all compliance obligations, evaluation timelines, and human oversight requirements that apply specifically to your deployments.
  • ☐Ask your legal and clinical teams whether your current human oversight workflows for AI-assisted healthcare decisions meet the standard implied by the Utah model: a designated reviewer who can intervene before the AI output reaches a patient or prescriber.
  • ☐Confirm that any third-party evaluator engaged for a sandbox pilot is operationally independent from both the AI vendor and the clinical team deploying the tool, and document that independence in your vendor governance files.
  • ☐Review your stakeholder engagement records for any AI pilot program to confirm that affected clinical professionals, licensing bodies, or patient representatives were consulted before deployment, not after.
  • ☐Flag the Utah model to your compliance and government affairs teams as an emerging template for state-level healthcare AI oversight, and track whether your state's licensing boards or health regulators are moving toward similar sandbox conditions.

What to watch next

Compliance teams should monitor whether other state AI offices adopt the Utah master agreement model. Key conditions to watch include mandatory third-party evaluator and human oversight requirements for sandbox participation in other sectors. The utah-artificial-intelligence-policy-act-sb149-2024 provides the statutory backdrop for Utah's sandbox authority, and any amendments or guidance issued under that act will affect how broadly these obligations extend. The EU AI Office Inspections Target Hiring, Credit, and Healthcare AI pattern suggests regulators across jurisdictions are converging on healthcare AI as a priority enforcement area. Proactive governance documentation is increasingly urgent regardless of sandbox participation.

Related Coverage

Research2026-09-28

Taxonomy Confusion Is Leaving Agentic AI Governance Without a Foundation

The Center for Strategic and International Studies published [Lost in Definition: How Confusion over Agentic AI Risks Undermines U.S. Governance Frameworks](https://www.csis.org/analysis/lost-definition-how-confusion-over-agentic-ai-risks-governance) in January 2026. The paper argues that inconsistent definitions of agentic AI are undermining U.S. governance, procurement, and evaluation programs. CSIS recommends a capability-based taxonomy built around workflow position, delegated authority, and accountability structure.

Research2026-10-01

ECB Requires Bank AI Cyber Action Plans by October 31, 2026

The European Central Bank expects banks to assess AI-enabled cyber threats and submit structured action plans by October 31, 2026. Plans must cover governance, asset mapping, vulnerability management, detection, response, recovery, resilience testing, and oversight of technology providers. The requirement applies to supervised institutions across the eurozone.

Enforcement2026-09-30

SBA's AI Fraud Pilot Never Classified as High-Impact, OIG Finds

The SBA's Office of Inspector General found that a Palantir-powered AI fraud detection pilot for COVID-19 loan programs was never classified as a high-impact use case under OMB guidance. As a result, required safeguards including impact assessments, human oversight mechanisms, and borrower appeals processes were never put in place. The OIG issued six recommendations, including establishing a formal process for identifying and documenting high-impact AI use cases.