Blogs

Coalition for Health AI (CHAI) Releases AI Intake Playbook and Common Intake Controls
Share article

Get in touch

For all media enquiries, please get in touch via admin@chai.org

Coalition for Health AI (CHAI) Releases AI Intake Playbook and Common Intake Controls

1 October 2026

Healthcare delivery organizations are reviewing a growing volume of AI tools, but the information they receive at the start of that process is often incomplete, inconsistent, or difficult to compare. Vendors, meanwhile, may be asked to answer different versions of the same questions for every organization they approach. The result is more time spent gathering information and following up than assessing risk.

Feedback CHAI’s AI Intake Working Group underscores the scale of this challenge. Most participating institutions reported that approving a vendor AI solution can take between two weeks and two months, with reviewers spending more time gathering information and following up on missing documentation than conducting the assessment itself.

To address that need, CHAI today released its AI Intake Playbook and companion AI Intake Controls and Evidence Workbook, a draft framework developed by the AI Intake Working Group. Together, the resources provide a common, risk-proportional starting point for reviewing vendor AI solutions and connecting intake findings to risk assessment, contracting and operational safeguards.

The framework includes 57 draft controls across 11 domains. Those controls were synthesized from more than 800 questions drawn from approximately 16 questionnaires in active use across participating health systems and additional input from the CHAI Risk Workgroup. Each control is written as a plain-language yes-or-no statement and mapped to the evidence that can support it. Controls are applied according to the risk of the proposed deployment, and 40 percent can be satisfied through vendor attestation alone without individual artifact review. During the working group discussions, CHAI found that our Applied Model Card served as the basis for many of the AI specific questions in these questionnaires. This new Playbook takes that product into its next iteration.

  • Review the materials: Read through the AI Intake Playbook and AI Intake Controls and Evidence workbook.

  • Participate in the pilot: CHAI is seeking healthcare delivery organizations and AI vendors to participate in the pilot phase, particularly pairs already engaged in an active procurement and organizations representing different sizes and levels of governance maturity. The pilot will assess vendor burden, evidence sufficiency, review cycle time, attestation practices, Applied Model Card coverage and whether one submission can be reused across institutions. To express interest in the pilot or share feedback, contact greg@chai.org.

The resources are not intended to impose a single approval decision or replace each organization's judgment. Instead, they are designed to make the starting evidence more predictable and reusable while allowing each healthcare delivery organization to apply the controls according to the solution's risk, use case, patient population and local governance structure. CHAI will now pilot the draft framework with healthcare delivery organizations and AI vendors and revise it based on real-world use.

Hear from Members – University of North Carolina Health & Onboard AI:

To explore the common intake process in practice, CHAI spoke with Ada Tsoi, PhD, Senior Data Scientist at University of North Carolina (UNC) Health, and Troy Bannister, Founder & CEO at Onboard AI. Both Ada and Troy were key members that contributed to the launch of these materials, helping to support health systems in easing the evaluations of AI tools.

Why has AI intake become such a difficult part of the governance process?

Ada Tsoi: At UNC Health, requests for AI-enabled tools can require security, architecture and responsible AI review before deployment. Our responsible AI process begins with an intake form that helps determine whether a proposed use is low, moderate or high risk. Moderate- and high-risk tools receive a deeper review, and high-risk tools also require sign-off from an oversight body with representation across the health system, including legal, patient safety, advocacy and relevant clinical specialties. The challenge is getting complete, actionable information to the right reviewers. Sometimes the initial vendor contact is a sales representative who cannot answer detailed technical questions, or a vendor is reluctant to share information about areas such as the training population. Without that context, it is difficult to determine whether a tool is appropriate for our patients and intended use.

Troy Bannister: The volume and variety of AI entering health systems have changed the scale of the problem. Tools may come from startups, established enterprise platforms or teams developing solutions internally. Evaluation also happens at three levels: the organization, the product and the specific use case. The use case is often the hardest because the same platform can support many different applications, each with a different risk profile. Health systems generally want similar information, but their evidence requirements, staffing and review processes vary. That creates repeated work for vendors and makes it difficult for health systems to build a process that can handle increasing volume.

What does the new AI Intake Playbook provide?

Troy Bannister: The working group began by looking across intake forms already in use and identifying their common shape. From there, we worked control by control to determine what should be asked, which responses require evidence and what type of evidence is appropriate. A central goal was proportionality. A low-risk administrative use should not face the same evidence burden as an agentic system that affects clinical workflow. The framework creates a shared foundation while allowing the depth of review to increase with risk.

Ada Tsoi: One of the most useful features is the use of direct control statements that can be answered yes or no and supported with evidence. Open-ended questions can produce responses that leave reviewers unsure whether a requirement is actually met, which creates more follow-up. The playbook also gives examples and explains the reasoning behind the controls. That context can help vendors understand what reviewers need and help health systems apply the questions more consistently.

How is this different from the CHAI Applied Model Card?

Ada Tsoi: The Model Card helps an organization understand the AI solution itself, including its intended use, development, performance and known limitations. Intake has to go further and ask whether and how that solution can be deployed responsibly in a particular environment. That includes whether the organization can manage the risk, whether users have the right information and training, how the tool will be monitored, and what responsibilities need to be addressed in contracting and operations. In healthcare, adding a human reviewer does not resolve every concern. Organizations still need to consider the workload placed on that person, the time available for review and what happens when the tool is wrong or uncertain.

The playbook maps each control to the Applied Model Card wherever possible so that vendors can reuse information rather than recreate it. In the draft framework, a completed Applied Model Card fully satisfies 12 controls and partially addresses 29 more, meaning it provides at least some of the information needed for 72 percent of the common intake controls. Additional evidence is concentrated in operational areas such as lifecycle governance, security operations, resilience, integration, feedback and ongoing monitoring.

From your vantage point across multiple health systems, what will it take for a common intake process to become widely adopted?

Troy Bannister: The value of a common intake process grows as more health systems agree to use it. If a vendor completes a standardized evidence package once but only one organization accepts it, the benefit is limited. If many organizations can use that submission as the starting point for review, it can meaningfully reduce duplication and friction. Reaching that point will require broader adoption, continued refinement through real-world use and, eventually, a trusted way to verify that vendors' evidence and attestations meet the common requirements. This framework is an important first step toward building that consensus.

How could a common intake process improve the experience for health systems and vendors?

Ada Tsoi: Health systems are often asking for fundamentally similar information in different formats. A common starting point could reduce the time vendors spend responding to duplicative requests and the time reviewers spend clarifying incomplete answers. It also allows organizations to learn from one another as the field changes. No single organization will encounter every issue first, so bringing those experiences together helps the community ask better questions about emerging areas such as generative and agentic AI.

Troy Bannister: The long-term opportunity is similar to what happened in information security, where common evidence and widely recognized frameworks reduced the need for every organization to begin every review from zero. Healthcare AI is not at that endpoint today, but consensus on a common intake is an important first step. If a vendor can prepare a structured evidence package once and multiple health systems can use it as the starting point for their own review, both sides benefit. The more organizations that use and refine the framework, the more valuable that reuse becomes.

What information matters most once an organization moves from transparency to an adoption decision?

Ada Tsoi: Trustworthiness depends on more than a general description of the model. We need to understand whether the training population is relevant to our patients, what performance has been validated, how the solution will be maintained and how feedback will be handled over time. Generative AI introduces additional complexity because outputs can vary and may contain hallucinations. The deployment decision therefore has to account for the workflow around the model, including what users are expected to verify and whether that expectation is realistic in clinical practice.

Troy Bannister: Performance and subgroup fairness evidence are often among the hardest materials for vendors to produce, but workflow evidence is equally important. A product may perform well in testing and still create risk if consent, escalation, monitoring or other operational controls are not designed into the use case. Intake should surface both dimensions: whether the technology works as intended and whether the proposed deployment can operate safely in the real environment.

What happens next?

Ada Tsoi: The framework is already informing how we think about our own process, including questions we may add before full implementation. Operationalizing a common form still takes work. Organizations need a practical way to receive submissions, route evidence to evaluators and consolidate decisions. For health systems with fewer dedicated resources, having a shared starting point can be especially valuable because they do not have to build every question and evidence expectation on their own.

Troy Bannister: Adoption will take time, and the draft will need iteration. The next step is to test the controls with real vendor and implementer pairs, identify where questions create confusion or unnecessary burden, and see whether a standardized package reduces review time and follow-up. The framework will become stronger as more organizations use it, provide feedback and help establish the level of evidence they can consistently trust.

To learn more, check our CHAI AI Intake Playbook, a companion to the Subdomain 4.4: Third Party Management Playbook in the CHAI AI Governance Playbook series. It covers the first two phases of third-party management: AI intake and risk assessment.

We use cookies to improve your experience. By your continued use of this site you accept such use.