hello@tonishatagoe.com Abu Dhabi · London · Accra · New York
AI Governance

Building a Strategy for AI in Healthcare

<p>Building a Strategy for AI in Healthcare — A Sovereignty Briefing article applying the TEE Method™ framework.</p>

THE SCENARIO

A national health ministry deploys an AI triage system across emergency departments. The system reduced wait times by 34% and flagged critical cases 19% faster. Clinicians praised it. Administrators celebrated. Then a sovereignty audit revealed every patient interaction was processed on servers in a jurisdiction whose data protection laws did not meet national regulatory standards. The system was saving lives. The strategy was surrendering sovereignty.

What happens when an AI system that saves lives also surrenders sovereignty?

The healthcare sector presents unique challenges for AI governance. Decisions made by AI systems in healthcare can have life-or-death consequences, making the temptation to prioritise efficiency over sovereignty particularly strong. Yet the stakes of sovereignty failure in healthcare are uniquely severe: patient data exposure, algorithmic bias affecting vulnerable populations, and the capture of national health infrastructure by foreign commercial entities.

The TEE Method — Test, Evaluate, Exit — is not a checklist. It is an architecture for sovereignty. It does not tell you what to do. It gives you a structure for deciding for yourself. This article applies the TEE Method to the specific challenges of AI in healthcare, showing how entities can build governance architectures that preserve sovereignty without sacrificing the benefits of AI innovation.


Part One: Understanding the Landscape

The progression from AI governance challenge to a structural sovereignty condition in healthcare occurs through a subtle systematic mechanism. It begins with framing: the issue is presented to decision makers as a clinical efficiency challenge or a patient outcome improvement opportunity rather than a sovereignty decision. The TEE Method rejects this framing categorically. This is a sovereignty issue that has AI governance implications, not an AI governance issue that has sovereignty implications. The distinction is structural and determinative. It determines whether the health ministry approaches the challenge from its governance red lines or from its clinical wish list. It determines whether the chief negotiator is a clinical specialist optimising for patient outcomes or a governance official optimising for autonomy. It determines whether the governance provisions are drafted by clinical specialists who understand patient care or by sovereignty experts who understand the architecture of technological dependency in health systems. The choice of framing is the choice of outcome. The entity that frames healthcare AI sovereignty as a clinical problem will receive a clinical solution that solves the wrong problem. The entity that frames it as a governance architecture will build the institutional capacity to govern whatever health technology arrives next.

The specific provisions that drive sovereignty erosion in AI governance for healthcare follow a consistent pattern observed across multiple jurisdictions and decades of health technology adoption. They are presented as enablers: efficiency, modernisation, compliance, standardisation, patient protection, innovation promotion, care access. They create structural dependencies that the adopting entity cannot easily reverse. They transfer governance authority to external parties through mechanisms that are legally binding but democratically opaque. The entity that understands this pattern before it engages can build countermeasures. The entity that discovers it after engagement has already surrendered. The pattern is not accidental. It is the structural logic of how asymmetric power converts technical capability into governance authority over health systems. The TEE Method requires health entities to recognise this pattern at the earliest possible stage at the framing stage not the procurement stage not the implementation stage and certainly not the remediation stage.

The TEE Method coordination mechanism the Sovereignty Caucus provides the only viable counterstrategy to structural framing in healthcare. No single health entity no matter how powerful can defeat structural framing alone. The coordinating power of dominant health technology vendors operates through divided engagement: they negotiate bilaterally they offer differentiated terms they prevent the formation of a unified coalition they use early agreements as templates for later ones they build a body of precedent that becomes the international standard. The Sovereignty Caucus defeats this strategy by forming the bloc before the negotiation begins. The Caucus operates on three principles: alignment before agreement entities develop common positions before entering negotiations stress tested against the sovereignty test matrix. Red lines before red pens: the Caucus identifies sovereignty non negotiables before any text is drafted before any concession is offered. Drafting power: the Caucus invests in the legal and technical capacity to actually write the procurement language rather than reacting to language written by vendors. The entity that writes the first draft sets the terms of the debate. The entity that only reacts inherits the assumptions of the drafter. This is not protectionism. It is the recognition that governance requires participation in the drafting.

The healthcare sovereignty impact matrix is the tool that makes structural framing visible to health leadership without requiring technical expertise. It translates domain specific jargon into sovereignty stakes. Every provision is evaluated across the five sovereignty domains: Political Economic Cultural Intellectual Technological. The matrix identifies the mechanism of erosion and the specific countermeasure for each provision. The red flag checklist operationalises the matrix into a binary diagnostic. The eight structural sovereignty traps are not degrees of concern they are binary tripwires. Source code carve out, data flow absolutism, mutual recognition asymmetry, ISDS without governance carve out, algorithmic non discrimination overreach, digital product non discrimination, standards body capture, regulatory cooperation without sovereignty guardrails. If three or more flags trigger the agreement contains structural sovereignty traps and the health entity must negotiate carve outs or refuse signature. The checklist is the tool that makes the sovereign decision binary: accept the trap or walk away.

Phased framework for healthcare: Phase one Assessment weeks one to four maps every dependency across the seven layer stack completes the Sovereignty Test Matrix for each identifies sovereignty traps using the red flag checklist. Phase two Strategic Planning months two to three develops withdrawal protocols for the three highest risk dependencies identifies and pilots alternative solutions begins knowledge transfer programmes to reduce knowledge concentration negotiates contractual protections including data portability transparent pricing and genuine exit provisions builds the Sovereignty Caucus or joins an existing one. Phase three Implementation months four to twelve executes multi provider strategies for critical dependencies to prevent single vendor lock in implements open format standards for all new data and workflow systems establishes continuous monitoring infrastructure for dependency indicators with automated threshold escalation conducts regular exit testing to verify withdrawal capability operationalises governance driven retraining authority. Phase four Institutionalisation months thirteen to eighteen embeds sovereignty assessment into all health technology procurement and adoption decisions builds internal capacity for independent evaluation and audit develops sovereign alternatives for critical health infrastructure where economically viable participates in the drafting of health technology governance frameworks achieves Level three or higher on the Adaptive Governance Maturity Model for all critical health systems. The framework recognises that sovereignty is not a destination it is a discipline. The same Test Evaluate Exit cycle that governs technology must govern the governance framework itself.

The TEE Method provides the architecture for governance by design in healthcare. The choice is not between AI governance and sovereignty it is between governance by design and governance by accident. The health entity that chooses governance by design enters every engagement with its sovereignty red lines drafted its coalition aligned its drafting capacity ready its fallback positions clear its political leadership briefed on the sovereignty stakes of every provision. The health entity that chooses governance by accident enters the engagement with a clinical outcome wish list and leaves with an AI governance framework it did not write dispute mechanisms it cannot win data flows it cannot govern and standards it did not write. The TEE Method provides the architecture for governance by design. The Sovereignty Caucus provides the coalition. The sovereignty impact matrix provides the map. The red flag checklist provides the compass. The phased framework provides the road. The choice belongs to those who lead. The question is not whether the next health technology engagement will contain governance provisions it will. The question is whether the health entity has built the governance architecture to negotiate from sovereignty or will simply accept the governance architecture that the engagement imposes. The answer to that question is the difference between a health system that governs its technological future and a health system that is governed by someone else’s technological past.

The seventh challenge is managing mixed sovereignty profiles in health systems. Most health entities will find that they are sovereign at some layers of their technology stack and dependent at others. A national health service may run sovereign infrastructure on its own data centres while depending on a foreign cloud provider for disaster recovery. A private hospital group may have sovereign financial systems while depending on a foreign AI platform for diagnostic imaging. A medical university may have sovereign research infrastructure while depending on commercial journal platforms for publication. Mixed profiles are not failures. They are realistic starting points. The TEE Method does not require sovereign capability at every layer immediately. It requires honest assessment of the current profile, deliberate governance of the dependency layers, strategic prioritisation of sovereignty investments, and continuous improvement over time. The health entity that recognises its mixed profile honestly can plan its sovereignty journey. The health entity that demands perfect sovereignty before beginning any journey will never begin. The TEE Method is designed for real health entities with real constraints, real budgets, real political pressures, and real dependencies. It is a practical governance architecture, not an ideological purity test. The phased framework allows health entities to begin their sovereignty journey at their current capability level and progress systematically toward greater strategic autonomy.

The eighth challenge is the cultural dimension of sovereignty in healthcare. Sovereignty is not only a technical or legal condition. It is a cultural capacity. A health entity that has surrendered its technological decision-making to external parties over a sustained period loses the institutional knowledge, the specialised expertise, and the governance confidence to reassert control. Cultural sovereignty requires deliberate investment in human capital, in governance education, in institutional memory, and in the narrative that frames sovereignty as capability rather than constraint. The TEE Method addresses this through the human institutional layer of the seven-layer audit, which explicitly evaluates expertise concentration, contractual constraints on clinical staffing, and the entity capacity to operate health systems independently. The framework also requires that sovereignty assessments be conducted by internal clinical and technical staff supported by external experts working to build internal capacity rather than replace it. Over time, this investment in human capital transforms sovereignty from an externally imposed requirement into an internally recognised capability. The health entity that governs its technology develops the cultural identity of a governance actor rather than a compliance recipient. This cultural transformation is perhaps the most difficult but also the most durable outcome of the TEE Method process in healthcare.

The ninth challenge is the temporal dimension of sovereignty governance in healthcare. Health technology moves in months. Clinical governance moves in years. Treaties move in decades. This temporal mismatch is exploited by health technology vendors who release new capabilities before governance frameworks can respond. The TEE Method addresses this through continuous monitoring and threshold alerts rather than point-in-time assessments. The health entity that assesses sovereignty once a year will always be behind the technology curve. The health entity that monitors continuously can detect dependency drift before it becomes structural entrapment. This requires institutional infrastructure: automated dependency indicators, quarterly sovereignty audits, annual exit rehearsals, and governance committees with the authority to halt procurement when thresholds are breached. The TEE Method builds this infrastructure into the phased implementation framework as a permanent organisational capability, not a project deliverable.

The tenth challenge is the geopolitical dimension of health technology sovereignty. Health technology governance is not purely domestic. Cross-border health data flows, jurisdictional arbitrage, export controls on medical AI, foreign investment screening in health infrastructure, and international health standards bodies all shape the sovereignty space available to any health entity. The TEE Method incorporates geopolitical awareness into the seven-layer audit by explicitly evaluating jurisdictional dependencies at each layer. Health data residency requirements, cloud provider headquarters locations, medical standards body membership structures, treaty obligations, and health alliance commitments all constrain or enable sovereignty options. The health entity that ignores the geopolitical dimension will find its domestic governance choices overridden by international obligations it did not fully understand when it signed. The TEE Method requires that geopolitical assessment be integrated into every sovereignty test, not treated as a separate workstream.

The eleventh challenge is the economic dimension of sovereignty investment in healthcare. Building sovereign health capability costs money. Maintaining redundant health infrastructure costs money. Running clinical exit rehearsals costs money. The health entity that views sovereignty as a cost centre will underinvest and be captured. The health entity that views sovereignty as a strategic investment will build capabilities that compound over time. The TEE Method provides the economic framework for this calculation. Phase One Assessment quantifies current health dependency costs including switching costs, pricing exposure, and clinical operational risk. Phase Two Strategic Planning models the return on sovereignty investment including avoided vendor lock-in, negotiating leverage, and clinical innovation capacity. Phase Three Implementation measures actual cost savings from multi-provider strategies and open-format standards. Phase Four Institutionalisation embeds sovereignty ROI into annual health technology budgeting. The economic case for health sovereignty is not speculative. It is calculable, measurable, and when tracked over the full clinical technology lifecycle, it is positive for health entities that commit to the discipline.

The twelfth challenge is the accountability dimension of sovereignty governance in healthcare. Who within the health entity is responsible for technology sovereignty? The CIO? The CMIO? The Board? The answer in most health entities is: nobody specifically. Sovereignty falls through the cracks between clinical operations, security compliance, legal review, and strategic planning. The TEE Method solves this by making sovereignty a named executive responsibility with defined responsibilities, required reporting, and budget authority. The healthcare sovereignty owner chairs the governance committee, owns the seven-layer audit, authorises the red flag escalation, and reports to the Board quarterly. This is not a new role. It is an existing role with clarified authority. The health entity that assigns sovereignty ownership creates accountability. The health entity that does not creates the vacuum that external vendors will fill. The TEE Method makes governance ownership explicit, not implicit.


The Seven Layer Stack Audit for Healthcare

The Seven Layer Stack Audit: The TEE Method requires a systematic audit across seven layers of the health technology stack. Layer one Hardware Compute: who owns the physical health infrastructure, where are the clinical data centres located, under what jurisdiction do they operate, what are the power cooling and connectivity dependencies for health operations. Layer two Network: who controls the health data pathways, which internet exchange points does clinical traffic traverse, what are the routing dependencies for emergency systems, are there single points of failure in the clinical network path. Layer three Operating System Virtualisation: who controls the base clinical software layer, is it open source or proprietary, what are the update and patch dependencies for medical devices, can the health entity run its own builds. Layer four Middleware APIs: who governs the clinical integration layer, are the APIs open standards like FHIR or vendor proprietary, what are the versioning and deprecation policies for medical device interfaces, can the health entity build its own adapters. Layer five Application AI: who controls the clinical intelligence layer, are the models open weight or closed, what are the fine tuning and customisation capabilities for clinical use cases, what are the inference dependencies for real-time clinical decisions. Layer six Data Governance: who sets the rules for patient data use, where does clinical data reside at rest and in transit, what are the jurisdictional implications of health data flows, who has access under what legal authority including HIPAA GDPR and national health privacy laws. Layer seven Human Institutional: who has the clinical expertise to operate audit and replace the health system, what are the knowledge concentration risks in clinical informatics, what are the contractual constraints on clinical staffing and skills development. Each layer represents a distinct sovereignty decision point. Dependency at any layer propagates upward constraining choices at every layer above it.


Part Two: The Sovereignty Test Matrix

The Sovereignty Test Matrix scores five domains from one critical dependency to five full sovereignty. Political Sovereignty: can the health entity make independent clinical governance decisions, documented decision rights, veto authority, policy independence from platform or vendor governance frameworks. Economic Sovereignty: does the health entity control the economic terms of the relationship, contractual pricing control, competitive alternatives, cost predictability for health technology procurement. Cultural Sovereignty: does the system respect the health entity clinical context, values and priorities, including localisation capability for clinical workflows, value alignment with institutional mission of patient care, community acceptance. Intellectual Sovereignty: does the health entity understand the system at a level sufficient to govern it independently, internal audit capacity for clinical algorithms, independent evaluation capability, knowledge distribution across the clinical organisation. Technological Sovereignty: can the health entity build adapt or replace the technology, open clinical formats, portability of patient data, alternative deployment capability for clinical workflows. Mixed profiles are the norm. The goal is not perfect scores but an honest actionable profile that reveals where governance investment is needed most.


Part Three: Red Flag Checklist

Red Flag Checklist for Healthcare. Single Vendor Critical Clinical Function: a core clinical function depends entirely on one health technology vendor with no viable alternative identified or tested. Proprietary Patient Data Lock In: patient clinical data is stored in a format that cannot be exported without transformation, data loss, or significant cost. No Clinical Withdrawal Protocol: there is no documented tested plan for transitioning away from the dependent health technology even in a clinical emergency. Vendor Dependent Clinical Expertise: the health entity relies on the technology vendor for all clinical troubleshooting, customisation, and optimisation because internal clinical staff lack the knowledge to operate independently. Unilateral Clinical Pricing Power: the vendor has exercised significant price increases on clinical modules or the health entity cannot predict future clinical pricing due to opaque licensing models. Clinical Governance Capture: the vendor terms certifications or clinical compliance frameworks have become the health entity de facto governance standards. Health Market Consolidation Risk: the vendor operates in a consolidating clinical market creating uncertainty. Cross Border Health Jurisdictional Risk: the vendor operates under a different legal jurisdiction with health data access laws that may conflict with the health entity sovereignty interests. If three or more of these eight indicators apply, the health entity is in a critical dependency position and should initiate an urgent TEE Method assessment across all five sovereignty domains.


Part Four: Phased Implementation Framework

Phased Implementation for Healthcare. Phase One Assessment weeks one to four: complete the Sovereignty Test Matrix for all critical clinical dependencies across the seven layer stack, map all single vendor dependencies, conduct a comprehensive clinical audit, develop the red flag checklist for healthcare, establish sovereignty assessment as a standing clinical governance item. Phase Two Strategic Planning months two to three: develop clinical withdrawal protocols for the three highest risk dependencies, identify and pilot alternative clinical solutions, begin clinical knowledge transfer programmes, negotiate contractual protections including patient data portability, transparent clinical pricing, and genuine clinical exit provisions, build or join a Healthcare Sovereignty Caucus. Phase Three Implementation months four to twelve: execute multi vendor strategies for critical clinical systems to prevent lock in, implement open clinical format standards for all new health systems, establish continuous clinical monitoring infrastructure, conduct regular clinical exit testing to verify withdrawal capability remains operational. Phase Four Institutionalisation months thirteen to eighteen: embed sovereignty assessment into all health technology decisions, build internal clinical capacity for independent evaluation, develop sovereign alternatives for critical health infrastructure where economically viable, participate actively in the drafting of national and international health technology governance frameworks. The phased framework acknowledges that sovereignty is not achieved in a single project. It is built through sustained disciplined investment across the full clinical technology governance lifecycle.


The Closing Question

What happens when an AI system that saves lives also surrenders sovereignty?

The transition from adoption to governance requires deliberate structure, sustained commitment, and frameworks making sovereignty measurable rather than aspirational. The TEE Method provides that structure. The choice belongs to those who lead. This article draws on the TEE Method framework from SOVEREIGN: Who Owns the Future? For the complete framework, including detailed TEE Method assessment protocols, layer by layer auditing procedures, and sovereignty test matrices for health organisations of all sizes, see tonishatagoe.com.

Keep Reading

Related Articles

Get in Touch
LEC Magazine

Join Our Community

Exclusive insights & inspiration

Welcome to LEC!

Account created. Refreshing…

LEC Magazine

Join Our Community

Exclusive insights & inspiration

Welcome to LEC!

Account created. Refreshing…