{"id":53141,"date":"2026-05-27T21:02:26","date_gmt":"2026-05-27T21:02:26","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/53141\/"},"modified":"2026-05-27T21:02:26","modified_gmt":"2026-05-27T21:02:26","slug":"agentic-ai-in-healthcare-is-a-risky-proposition","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/53141\/","title":{"rendered":"Agentic AI in Healthcare Is a Risky Proposition"},"content":{"rendered":"<p class=\"text-muted\">\n                                            <a href=\"https:\/\/www.govinfosecurity.com\/agentic-ai-c-940\" id=\"asset_topic_1_1\" rel=\"nofollow noopener\" target=\"_blank\">Agentic AI<\/a><br \/>\n                                                    ,<br \/>\n                                                            <a href=\"https:\/\/www.govinfosecurity.com\/artificial-intelligence-machine-learning-c-469\" id=\"asset_topic_1_2\" rel=\"nofollow noopener\" target=\"_blank\">Artificial Intelligence &amp; Machine Learning<\/a><br \/>\n                                                    ,<br \/>\n                                                            <a href=\"https:\/\/www.govinfosecurity.com\/governance-risk-management-c-93\" id=\"asset_topic_1_3\" rel=\"nofollow noopener\" target=\"_blank\">Governance &amp; Risk Management<\/a>\n                                                                                                                                                                                                                                    <\/p>\n<p>                    Health-ISAC Warns About Weak Governance and Credential Misuse<\/p>\n<p>                                                <a class=\"author-link\" href=\"https:\/\/www.govinfosecurity.com\/authors\/marianne-kolbasuk-mcgee-i-626\" rel=\"nofollow noopener\" target=\"_blank\">Marianne Kolbasuk McGee<\/a> (<a href=\"https:\/\/www.twitter.com\/HealthInfoSec\" rel=\"nofollow noopener\" target=\"_blank\">HealthInfoSec<\/a>)                                                    \u2022<br \/>\n                        May 27, 2026 \u00a0 \u00a0 <a href=\"https:\/\/www.cuinfosecurity.com\/agentic-ai-in-healthcare-risky-proposition-a-31794#disqus_thread\" rel=\"nofollow noopener\" target=\"_blank\"><\/p>\n<p>                <img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/05\/healthcare-leaders-warned-emerging-human-agentic-ai-risk-image_large-10-a-31794.jpg\" alt=\"Agentic AI in Healthcare Is a Risky Proposition\" class=\"img-responsive \"\/><br \/>\n                Humans delegating data, decisions and more to agentic AI in blended healthcare environments pose a variety of amplified risks, including cyber and patient safety, says a new report. (Image: Getty Images)            <\/p>\n<p>Humans make mistakes. They fall for phishing scams and click on malicious links. Machines aren&#8217;t necessarily better: Delegating decisions to agentic artificial tools can significantly intensify cybersecurity risks, warns a healthcare sector association.<\/p>\n<p>See Also: <a href=\"https:\/\/www.govinfosecurity.com\/know-thy-enemy-threats-to-cyber-resilience-a-31674?rf=RAM_SeeAlso\" rel=\"nofollow noopener\" target=\"_blank\">Know Thy Enemy: Threats to Cyber Resilience<\/a><\/p>\n<p>Over-permissioned accounts, weak governance and credential misuse &#8211; all are amplified by AI-enabled workflows, said Errol Weiss, chief security officer of the Health Information Sharing and Analysis Center. The center <a href=\"https:\/\/health-isac.org\/state-of-human-cyber-risk-report\/\" target=\"_blank\" rel=\"nofollow noopener\">published<\/a> Tuesday advice for managing agentic artificial intelligence risk in healthcare settings.<\/p>\n<p>The stakes aren&#8217;t restricted to data security and privacy risks, Weiss said. Patient safety and continuity of care need electronic health records and a functioning clinic. A rogue AI agent can interrupt the normal flow of medical care. &#8220;Disruptions to communications can slow care and increase errors,&#8221; he said.<\/p>\n<p>Organizations can be slow to perceive the risks of agentic AI. At first, AI use is often informal and unsanctioned. But much as they&#8217;ve progressed in raw capacity agents are still prone to wide swings in behavior &#8211; as a startup founder discovered earlier this year when an AI agent deleted three months of production data over nine seconds &#8211; despite being explicitly instructed to never guess about the consequences of its actions (see: <a href=\"https:\/\/www.govinfosecurity.com\/ai-agent-wipes-startups-data-in-9-second-api-call-a-31521\" rel=\"nofollow noopener\" target=\"_blank\">AI Agent Wipes Startup&#8217;s Data in 9-Second API Call<\/a>).<\/p>\n<p>&#8220;When AI agents are implemented without strong identity and policy controls, attackers only need one foothold to misuse delegated privileges,&#8221; Weiss said.<\/p>\n<p>The center advises organizations to adopt a framework that shifts traditional security awareness training to continuous risk management that encompasses human behavior and agentic AI risk. &#8220;The maturity model is clear &#8211; you can\u2019t manage what you can\u2019t see,&#8221; Weiss said.<\/p>\n<p>That includes treating human and AI-driven behavior as part of the enterprise attack surface and monitoring AI-agent activity such as its access privileges. Risk managers should govern AI agents as if they were &#8220;digital workers&#8221; with defined ownership, monitoring, logging and approved use cases.<\/p>\n<p>Compliance-based training is better supplanted by risk-based interventions and organizations should build cross-functional governance models that involves security and privacy officials as well as clinical leadership and human resources, the report says.<\/p>\n<p>&#8220;CISOs should manage workforce risk continuously and intervene based on observed risky behaviors and exposure, not generic completion metrics,&#8221; Weiss said.<\/p>\n<p>It&#8217;s not just the responsibility of healthcare CISOs and their teams to address these issues, he said. <\/p>\n<p>&#8220;Executives, clinical and operational leadership should treat cyber as patient safety and resilience planning,&#8221; he said. Leaders should sponsor downtime planning, ensure clinical managers participate in exercises and reinforce that safe workflows matter as much as technology, he said.<\/p>\n<p>Additionally, HR, compliance, legal and privacy departments should reinforce &#8220;ownership&#8221; of AI use, not just the rules, Weiss said. &#8220;Organizations must shift their culture from simple AI compliance to true AI ownership. Employees shouldn\u2019t just follow rules; they must be accountable for the behavior of the AI systems they deploy.&#8221;<\/p>\n<p>Chief information officers, IT managers and data owners should bake guardrails into tools and workflows, he said. &#8220;If healthcare adds agentic automation without matching governance and visibility, it can unintentionally make attacks faster, broader and more damaging.&#8221;<\/p>\n<p>            <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"Agentic AI , Artificial Intelligence &amp; Machine Learning , Governance &amp; Risk Management Health-ISAC Warns About Weak Governance&hellip;\n","protected":false},"author":2,"featured_media":53142,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[179,7493,31283,18234,428,31284,18445],"class_list":["post-53141","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-agentic-ai","tag-agentic-artificial-intelligence","tag-errol-weiss","tag-framework","tag-governance","tag-health-isac","tag-human-risk"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/53141","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=53141"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/53141\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/53142"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=53141"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=53141"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=53141"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}