hello@tonishatagoe.com Abu Dhabi · London · Accra · New York
AI Governance

Why We Need to Talk About AI in Healthcare

<p>Why We Need to Talk About AI in Healthcare — A Sovereignty Briefing article applying the TEE Method™ framework.</p>

AI in healthcare promises faster diagnoses, better outcomes, lower costs. But who controls the algorithms that decide treatment paths? Whose data trains the models that shape clinical decisions? And what happens when a system designed in one context is deployed in another — with lives at stake?

THE SCENARIO

A national health service in Southeast Asia deployed an AI-driven clinical decision support system developed by a multinational technology company. The system was trained on electronic health records from hospitals in North America and Western Europe. Within months, clinicians noticed that the system consistently under-predicted cardiac risk for local patients — not because the algorithm was broken, but because the training data did not include the genetic markers, dietary patterns, and environmental factors prevalent in Southeast Asian populations. The system was making confident, statistically validated, clinically dangerous recommendations. The health service had not conducted a population validation study before deployment. It had assumed that a globally-tested system would perform globally. That assumption was wrong — and patients paid the price.

— SOVEREIGN: Who Owns the Future?

This scenario is not hypothetical. It is a composite of documented patterns across multiple healthcare systems. A nation that values oral tradition may find itself deploying a system that privileges written documentation. A health system whose patients speak languages the training data never encountered may find itself using a diagnostic tool that systematically misinterprets symptoms. The problem is not that AI in healthcare is dangerous. The problem is that the conversation has not yet happened — the conversation about who controls it, who benefits from it, and who bears the risk.

This article does not argue against AI in healthcare. The benefits are too significant to dismiss: earlier disease detection, reduced diagnostic error rates, expanded access to specialist-level care in underserved regions, and administrative efficiencies that free clinicians to spend more time with patients. AI can extend the reach of healthcare systems that are already stretched beyond capacity. But these benefits are not unconditional. They depend on who designs the systems, whose data trains the models, whether local populations have been validated before deployment, and whether the institutions deploying these systems maintain genuine governance authority over the tools they use. The sovereignty question in healthcare AI is not about rejecting technology. It is about ensuring that the communities served by these systems retain the capacity to govern them — to validate them against local populations, to challenge their outputs, to exit them if they cause harm, and to build alternatives that reflect local needs and values.


The Question

AI in healthcare raises a question that most clinical technology assessments never ask: Who controls the algorithms that decide treatment paths?

When a doctor in a public hospital in Lagos, Nairobi, or Jakarta opens a diagnostic AI tool, the recommendation that appears on screen has been shaped by decisions made thousands of kilometres away — by engineers who chose the training data, by executives who set the business model, by regulators in a different jurisdiction who approved the system for a different population. The doctor may believe they are using a neutral tool. They are using a system embedded with the assumptions, priorities, and biases of its creators.

This question has clinical consequences. A system trained on patient records from one demographic may systematically misdiagnose conditions prevalent in another. A triage algorithm that prioritises patients based on risk models derived from one healthcare system may deprioritise patients whose conditions present differently in another. A drug interaction checker that relies on pharmaceutical databases maintained in one jurisdiction may miss interactions documented only in regional pharmacovigilance systems. The question of control is not abstract. It determines who lives and who dies, who receives treatment and who is sent home, whose health outcomes improve and whose deteriorate.

The sovereignty framework insists that this question be asked before deployment, not after harm has occurred. It demands that health systems evaluate not only whether an AI system works, but for whom it works, under whose governance it operates, and at what cost to the system’s autonomy.

Part One: The Hidden Architecture of Healthcare AI

The AI systems entering healthcare are not monolithic. They operate at multiple levels, each with distinct sovereignty implications, risk profiles, and governance requirements. Understanding this layered architecture is the first step toward governing it.

LayerExamplesSovereignty Risk
Diagnostic AIRadiology image analysis, pathology screening, dermatology classification, retinal scanningTraining data drawn from non-representative populations; validation studies absent for local demographics; false negatives concentrated in underserved groups
Clinical Decision SupportTreatment pathway recommendations, drug interaction alerts, risk scoring, sepsis predictionAlgorithmic logic opaque to clinicians; cannot be interrogated or overridden meaningfully; treatment protocols may embed foreign clinical standards
Patient Data AnalyticsPopulation health management, predictive modelling, resource allocation, disease surveillancePatient data stored on foreign servers; jurisdictional control over sensitive health information ceded; population health intelligence flows to provider
Administrative AIScheduling, billing, triage, prior authorisation, medical coding, staffing optimisationWorkflow decisions embedded in proprietary systems; institutional processes become dependent on external platforms; switching costs increase over time
Personal Health AIChatbots, symptom checkers, wearable analytics, mental health support, medication remindersDirect-to-consumer health advice bypasses clinical oversight; user data feeds commercial models; privacy protections may not meet local standards
Pharmaceutical and Research AIDrug discovery, clinical trial matching, genomic analysis, biomarker identificationIndigenous genetic data becomes proprietary research asset; benefit-sharing absent; local research priorities subordinated to global commercial interests

At each layer, sovereignty takes a different form. At the diagnostic layer, sovereignty means the capacity to validate a system against local patient populations before deployment — not after patient harm has occurred. At the clinical decision support layer, it means that clinicians can understand, challenge, and override algorithmic recommendations without institutional resistance. At the data layer, it means that patient health information remains under the governance of the health system, not the technology provider. At the administrative layer, it means that the institution’s critical workflows are not locked into a single provider’s proprietary ecosystem. At the personal health layer, it means that patients are not surrendering their most intimate health data to commercial entities whose interests are not aligned with their wellbeing. And at the research layer, it means that the health system’s genetic and epidemiological data are not extracted as raw materials for products that the system must later purchase at premium prices.

The sovereignty question at each layer is the same: Can the health system govern this technology, or does the technology govern the health system?

“A nation that values oral tradition may find itself deploying a system that privileges written documentation.”

— SOVEREIGN: Who Owns the Future?, Chapter 2: The Soul of Systems

Part Two: The Data Sovereignty Problem in Healthcare

Healthcare data is among the most sensitive information any individual possesses. It reveals not only medical conditions but genetic predispositions, lifestyle patterns, mental health history, reproductive decisions, familial relationships, and — increasingly — biometric identifiers that cannot be changed once compromised. When healthcare AI systems process this data on foreign servers or share it with third-party model trainers, the sovereignty implications are profound and irreversible.

Consider the data flows in a typical AI-powered clinical system and what each reveals about the underlying power dynamic:

  • Training data: The model was trained on health records from populations that may not reflect the demographics, genetics, or disease patterns of the local population. This creates systematic accuracy gaps that disproportionately affect minority and non-Western patient groups. The cost of this gap is borne entirely by patients who receive incorrect diagnoses or inappropriate treatment recommendations.
  • Inference data: Every patient case processed by the system becomes part of the provider’s operational data, potentially improving the provider’s models for future use — including use by competitors, insurance companies, or in other jurisdictions. The health system receives no compensation for the value its patients’ data generates.
  • Feedback data: When clinicians correct or override system recommendations, that feedback is logged and analysed, revealing patterns of clinical judgment that the provider can use to refine its algorithms — or to understand how local clinicians make decisions. This creates an intelligence asymmetry: the provider learns how the health system thinks, while the health system has no equivalent visibility into the provider’s operations.
  • Aggregated data: Population-level health data — disease prevalence, treatment outcomes, resource utilisation, seasonal patterns — flows to the provider, giving it insights into the health system that the health system itself may not possess in equivalent detail. The provider becomes the de facto repository of the system’s institutional knowledge.
  • Genomic and biomarker data: For AI systems involved in precision medicine, genetic sequencing, or biomarker discovery, the data flow includes the most intimate and permanent biological information a person possesses. Once extracted, this data cannot be recalled, and its value — to pharmaceutical companies, researchers, insurers, and governments — far exceeds the clinical value of the individual test.

The TEE Method identifies this as an asymmetric exchange: the health system receives a clinical recommendation, but the provider receives patient data, clinical judgment patterns, population health intelligence, and ongoing leverage over the system’s operations. This asymmetry is not necessarily exploitative — many providers operate in good faith. But it is structurally unbalanced, and it becomes dangerous when the provider’s commercial interests and the patient’s clinical interests diverge. A provider that derives revenue from pharmaceutical advertising, for example, has a structural incentive to recommend branded treatments over generic alternatives — even if the recommendation is algorithmically subtle and clinically deniable.

“The platform’s definitions became the region’s definitions. The platform’s risk model became the region’s risk model. And when the region sought to exercise sovereign regulatory judgment, it discovered that the cost of divergence — international non-compliance, correspondent banking withdrawal, credit rating impact — was engineered to be prohibitive.”

— SOVEREIGN: Who Owns the Future?, Chapter 13: Standardisation as Risk

Part Three: The Sovereignty Test Matrix for Healthcare AI

The TEE Method Sovereignty Test Matrix evaluates AI systems across five domains, each scored from 1 (critical sovereignty risk) to 5 (full sovereignty). For healthcare AI, the matrix provides a structured framework for assessing whether a system serves the health system’s interests or deepens its dependency. Each domain addresses a fundamental sovereignty question that every health system should answer before deploying any AI tool.

Domain1 — Critical Risk2 — High Risk3 — Moderate4 — Managed5 — Sovereign
Territory
Where is the data and who has jurisdiction?
Patient data stored and processed in foreign jurisdiction with no local governance protections; provider subject to foreign data access lawsData stored offshore but subject to contractual data protection clauses with limited enforcement mechanismsData stored in region with bilateral data protection agreements and recognised adequacy decisionsData stored locally with sovereign encryption keys and contractual prohibition on foreign disclosureFull local data residency with independent audit, sovereign encryption, and statutory protections that cannot be overridden by contract
Exchange
Who captures the value generated?
Health system receives limited functionality; provider captures all patient data, clinical patterns, and population intelligence for commercial useProvider captures most value; limited contractual restrictions on data use; health system receives only the clinical outputValue exchange is partially balanced; health system receives some aggregated analytics and benchmarking data in returnProvider and health system share data value through joint governance of derived insights and revenue-sharing agreementsHealth system retains full ownership of all data and derived intelligence; provider is compensated for service only, with no data rights
Enforcement
Can the health system hold the provider accountable?
Contract governed by provider’s home jurisdiction; health system has no realistic enforcement capacity; cost of action exceeds value of claimDispute resolution available but impractical for most claims due to jurisdiction, cost, and legal resource asymmetryContract includes local arbitration clause with reasonable enforcement mechanisms and capped costsHealth system has demonstrated enforcement capacity, maintains legal readiness, and has tested dispute resolution mechanismsContract governed by health system’s domestic law; enforcement is practical, affordable, and regularly exercised
Evaluation
Does the system work for local populations?
No local validation study conducted; system deployed based on foreign certification or marketing materials aloneSuperficial local evaluation conducted by provider without independent oversight or population-specific testingLocal validation conducted by health system or independent third party using representative patient data and clinically meaningful endpointsContinuous evaluation with independent clinical oversight, population-specific metrics, and transparent publication of resultsEvaluation framework is open-source, independently audited by multiple stakeholders, and includes longitudinal patient outcome tracking
Evolution
Can the health system adapt, exit, or replace?
No governance review schedule; no exit plan; no local alternative development; full dependency accepted as permanentAnnual review without enforcement authority; exit plan exists in document form but is not budgeted or testedQuarterly governance reviews with escalation authority; exit plan documented, budgeted, and reviewed annuallyMonthly operational reviews; exit plan tested annually with simulated migration; parallel capability in development for critical functionsFull adaptive governance lifecycle: continuous monitoring, quarterly tested exit capacity, independent alternative in production use alongside primary system

A health system that scores 1 or 2 in any domain should not proceed with deployment until structural modifications are made. The risk of harm — clinical, financial, and strategic — is too high for any single domain to go unaddressed. A system that scores 3 across all domains may proceed with caution and a mandated improvement plan, subject to quarterly review by an independent governance body. A system scoring 4 or above demonstrates genuine sovereignty alignment and can be deployed with confidence, though continuous monitoring remains essential.

The TEE Method does not require a health system to achieve Level 5 across every domain on day one. Such a standard would exclude many systems that offer genuine clinical benefit. What it requires is that the health system knows its score in each domain, understands the risks that each low score represents, and has a documented plan to improve each score over time. Governance is not a binary threshold. It is a trajectory.

“Dependency scoring reveals four systems at 16+ (critical dependency): customs AI (18/20), tax analytics (17/20), health surveillance (16/20), and the banking surveillance system (16/20). Each of these systems has no identified alternative, high criticality, and minimal exit readiness.”

— SOVEREIGN: Who Owns the Future?, Chapter 24: Mapping Your Universe

Part Four: The Red Flag Checklist for Healthcare AI Procurement

Before any health system commits to an AI platform, the following red flags must be investigated. If any are present, deployment should be paused until the issue is resolved through contractual amendment, independent validation, or governance restructuring. These flags represent structural risks that no amount of clinical enthusiasm should override.

#Red FlagWhy It MattersRequired Response
1Training data does not include local patient populationsThe system may produce systematically inaccurate results for your patients — with clinical consequences that include misdiagnosis, delayed treatment, and inappropriate therapyCommission independent local validation study before deployment; redesign or restrict if accuracy gap exceeds clinically acceptable threshold
2Patient data leaves the health system’s jurisdiction for processing or storageYou lose governance control over the most sensitive data your institution holds; foreign data access laws may applyRequire local processing and storage as condition of deployment; negotiate contractual prohibition on extraterritorial data transfer
3The provider retains rights to use patient data for model training or product improvementYour patients’ data becomes a commercial asset for a foreign entity — without consent, compensation, or governance oversight by the health systemRemove data usage rights from contract; require explicit opt-in for any secondary use with independent ethics review
4Algorithmic logic is proprietary and opaque (black box decision-making)Clinicians cannot interrogate or challenge recommendations they are expected to rely on for patient care; accountability for errors becomes impossible to assignRequire explainability as a contractual term; mandate independent algorithmic audit by qualified third party; ensure override mechanism that is clinically and legally effective
5No independent local validation study has been conductedForeign certification is not a substitute for population-specific testing; clinical standards, drug formularies, and disease prevalence differ fundamentally across jurisdictionsConduct or commission independent validation using local patient data, local clinicians, and locally meaningful clinical endpoints before deployment
6The contract is governed by foreign law with no local arbitration optionIf the system causes harm — misdiagnosis, data breach, treatment delay — you may have no practical path to accountability or remedy in your own legal systemRequire local governing law and arbitration; ensure that any remedy available under foreign law is also available under domestic framework
7Exit provisions are absent or superficialIf you need to leave the provider — due to harm, cost escalation, acquisition by a competitor, or strategic change — you may be unable to do so without disrupting patient careNegotiate comprehensive exit provisions including data export in standard formats, workflow migration support, and guaranteed transition period
8No alternative provider or domestic system exists for the same functionYou have zero leverage; the provider can change terms, pricing, or features at will, and you cannot walk away without compromising patient safetyRequire multi-provider compatibility as a design principle; invest in domestic alternative development for critical functions
9Clinicians were not consulted in the procurement or deployment processThe people who will use the system and who bear clinical responsibility for its outputs were excluded from the decision; adoption resistance and workaround behaviours are predictableEstablish clinician-led procurement review panel with veto authority over AI deployments that affect clinical workflow
10The system’s cost model creates long-term financial dependency (per-patient pricing, volume-based escalation, switching penalties)As patient volume grows, so does the cost — and the provider’s leverage over your budget; cost may become prohibitive within the contract termNegotiate fixed pricing or cost caps with inflation adjustment; ensure that volume growth does not create perverse incentives or budget crises
11The provider has access to the system’s override and feedback logsEvery time a clinician overrides or corrects the system, that data reveals clinical judgment patterns, areas of disagreement, and potential vulnerabilities in the health systemRequire that override and feedback data remain the property of the health system; prohibit provider use of this data for model training or product improvement without explicit consent
12No patient consent framework exists for AI-mediated clinical decisionsPatients may not know that an algorithm contributed to their diagnosis, treatment recommendation, or triage priority — and cannot consent to or challenge that involvementDevelop and implement patient disclosure and consent protocols for all AI-mediated clinical decisions; ensure right to human review

The Action Plan: From Dependency to Sovereign Healthcare AI

Health systems that recognise the sovereignty risks of AI do not need to reject the technology. They need to govern it. The following action plan provides a structured path from dependent adoption to sovereign deployment, organised in five phases that build on each other progressively.

PhaseTimelineActionOutcome
Phase 1: AssessMonth 1–2Conduct a full AI inventory: every system in use or under consideration across all six layers (diagnostic, decision support, data analytics, administrative, personal health, research). Apply the Sovereignty Test Matrix to each. Identify critical dependencies, red flags, and gaps in governance coverage. Publish findings transparently.Complete picture of AI sovereignty position, with prioritised risk list and governance gaps identified
Phase 2: ProtectMonth 2–4Impose moratorium on new AI procurement without sovereignty review. Renegotiate existing contracts to include local data residency, independent validation requirements, enforceable exit provisions, and prohibition on secondary data use. Establish procurement review panel with clinical and legal authority.Governance controls in place; no new ungoverned deployments; existing contracts strengthened
Phase 3: ValidateMonth 3–6Commission independent local validation studies for all deployed diagnostic and clinical decision support AI. Use representative local patient data and clinically meaningful endpoints. Publish results transparently — including systems that pass and systems that fail. Where systems fail local validation, suspend or restrict their use pending remediation.Clinicians and patients can trust that deployed systems work accurately for their populations
Phase 4: BuildMonth 6–18Invest in domestic healthcare AI capability. Partner with local universities, research institutions, and teaching hospitals. Develop or commission systems that reflect local clinical standards, disease patterns, cultural practices, and data sovereignty requirements. Prioritise the most critical functions where dependency is highest.Sovereign capacity increases; dependency on foreign systems decreases; local AI ecosystem emerges
Phase 5: GovernOngoingEstablish a permanent Healthcare AI Governance Committee with clinical, technical, legal, patient, and ethics representation. Mandate quarterly reviews using the Sovereignty Test Matrix. Require annual exit testing for all critical systems. Implement continuous population monitoring to detect accuracy drift over time.Sustainable governance infrastructure ensures ongoing sovereignty alignment and adaptive capacity

Closing: Why the Conversation Must Happen Now

AI in healthcare is not coming. It is here. The systems described in this article are deployed today — in radiology departments, emergency rooms, primary care clinics, public health agencies, and research institutions around the world. The decisions being made about which systems to adopt, whose data to use, whose populations to validate, and whose interests to prioritise are being made now, by procurement teams and technology vendors, often without the scrutiny that the stakes demand.

The cost of not talking about AI in healthcare is not theoretical. It is the patient who receives a wrong diagnosis because the algorithm was not trained on their demographic. It is the health system that discovers it cannot access its own patient data after switching vendors. It is the nation that finds its clinical standards quietly replaced by standards embedded in a foreign platform. It is the clinician whose professional judgment is overruled by a system they cannot interrogate. It is the indigenous population whose genetic data becomes a proprietary asset without consent or benefit-sharing. It is the health ministry that learns, too late, that its population health intelligence is now a commercially licensed product.

The sovereignty framework does not oppose AI in healthcare. It demands that AI in healthcare be governed — validated for local populations, accountable to local clinicians, subject to local law, transparent in its logic, designed for exit as well as adoption, and structured so that the value generated flows back to the health system and the patients it serves. These are not anti-technology positions. They are pro-patient positions. They are pro-clinician positions. They are pro-sovereignty positions.

The question is not whether AI will be used in healthcare. It will be, and it should be — the potential for good is too great to ignore. The question is whether health systems will govern it, or be governed by it. That decision is being made today, in procurement meetings, contract negotiations, and deployment decisions that are happening without the public conversation they demand. This article is an invitation to start that conversation.


SOVEREIGNWho Owns the Future? . TEE Method Perspective . v1.0
Article ID: 23 . Domain: AI Governance . Topic: Healthcare AI Sovereignty
Licensed under CC BY-NC-SA 4.0 . sovereignscore.nousresearch.com

Keep Reading

Related Articles

Get in Touch
LEC Magazine

Join Our Community

Exclusive insights & inspiration

Welcome to LEC!

Account created. Refreshing…

LEC Magazine

Join Our Community

Exclusive insights & inspiration

Welcome to LEC!

Account created. Refreshing…