Coalition for Health AI (CHAI) Releases Version 3 of its Risk Categorization Tool to Support AI Governance
2 September 2026
As healthcare organizations evaluate a growing number of AI solutions across clinical, operational and administrative settings, one question consistently surfaces before implementation ever begins: How much governance does this AI system require? Today, CHAI is profiling Version 3 of its Risk Categorization Tool, developed by the Risk Work Group. This is the final output in a recently announced series of resources from CHAI’s H1 2026 collaborative work groups.
Over the past year, health system leaders, AI developers, researchers, implementers and governance experts have worked together to evolve the Risk Categorization Tool through multiple iterations:
Originally launched in Q4 2025 with a focus on Life & Patient Safety as the prioritized risk domain
Expanded in Q1 2026 to incorporate Technology & Data as the next risk domain
Subsequently stress-tested and refined throughout H1 2026 using feedback from CHAI's collaborative work groups
The result is a practical, vendor-agnostic resource that reflects an evolving, consensus-driven approach to AI governance. Version 3 aims to help organizations consistently identify the relative risk of AI solutions before deployment, providing a structured starting point for risk-tiered governance activities while supporting alignment with broader industry frameworks. The tool does not assume a fixed level of risk, but rather encourages organizations to consider their individual risk tolerances across different risk modifiers, and their ability to effectively mitigate those risks internally or in partnership with their vendors/internal development teams.
Risk Categorization Tool (v3): A practical tool designed for health systems of any size and teams responsible for pre-deployment risk assessment. The tool supports AI governance by helping organizations categorize AI systems as low, medium or high risk across key risk modifiers spanning two foundational domains – Life & Patient Safety and Technology & Data. Rather than replacing comprehensive risk assessments, the tool provides an initial categorization that helps determine where additional assessment, mitigation, and ongoing monitoring should be prioritized.
Mapping of Risk Categorization Tool (v3): A supplemental crosswalk that maps the Risk Categorization Tool's risk modifiers to the NIST AI Risk Management Framework (AI RMF) and the European Union AI Act. This resource helps organizations understand how early risk categorization can complement existing risk frameworks, reducing duplication of effort while supporting more consistent and transparent AI governance across the AI lifecycle.
Evolution of the Tool
Unlike comprehensive risk assessments that occur later in the AI lifecycle, the Risk Categorization Tool is intended to support an organization's early governance decisions. By identifying key risk modifiers before procurement or deployment, organizations can better determine where more rigorous review, testing and oversight should be focused, while applying proportionate governance to lower-risk solutions.
The evolution of the tool mirrors the evolution of AI governance itself. Version 1, released in Q4 2025, established a common approach to categorizing Life & Patient Safety risks. Version 2, released in Q1 2026, expanded the Risk Categorization Tool to incorporate Technology & Data considerations as organizations increasingly evaluated AI solutions that relied on complex data flows, interoperability and evolving technical infrastructure. Throughout H1 2026, members of CHAI's collaborative work groups then stress-tested the Risk Categorization Tool against real-world implementation scenarios spanning emerging healthcare use cases, such as AI solutions to support patient scheduling and ambient scribes. Those discussions informed Version 3, helping refine both the underlying risk modifiers and the practical applicability of the tool across a growing range of AI technologies.
The accompanying mapping resource extends the tool's value by illustrating how CHAI's risk modifiers correspond with established risk frameworks, including the NIST AI Risk Management Framework (AI RMF) and the European Union (EU) AI Act. Rather than introducing a competing risk framework, the mapping demonstrates how organizations can integrate the Risk Categorization Tool into existing governance processes while maintaining alignment with broader regulatory and industry standards.
Importantly, the Risk Work Group views risk categorization as a key starting point for responsible AI governance, given that a risk-based approach can help reduce governance burden and improve scalability of associated processes. The current tool represents the first phase of CHAI's broader governance roadmap. The work group is currently focusing on efforts related to Risk Mitigation, and future work will build upon this foundation through dedicated efforts focused on Risk Assessment and Risk Monitoring, helping healthcare organizations develop governance programs that mature alongside both AI technologies and the rapidly evolving regulatory landscape.
Read the full output here to learn more about the evolved Risk Categorization Tool.
Hear from our work group participants:
“CHAI’s Risk Work Group provided a valuable forum for healthcare providers, technology vendors, and other stakeholders to exchange perspectives on how they approach AI risk assessment and the practical challenges they encounter,” said Ivan Pan, ML Engineer, AIML at Memorial Sloan Kettering Cancer Center. “Those discussions helped bridge the gap between responsible AI principles and the realities of operationalizing risk assessment. The Risk Categorization Tool and supplemental mapping provide a practical foundation that organizations can connect with existing frameworks and governance processes, while the broader community creates an important opportunity for continued learning as AI and its associated risks evolve.”
“Healthcare AI offers extraordinary potential, but also requires thoughtful attention to the broad range of risks it can introduce, including clinical, operational, privacy, and cybersecurity concerns,” said Joseph Izzo, MD, Chief Medical Information Officer at San Joaquin General Hospital. “It has been a pleasure to contribute to the CHAI Risk Work Group and to work with and learn from those at the forefront of this field. I especially value the opportunity to bring together perspectives from across the healthcare ecosystem around a shared goal of developing practical approaches to understanding and managing these evolving risks.”
“The CHAI Risk Work Group has brought together a diverse group of healthcare organizations to create a more consistent and practical approach to evaluating digital health solutions,” said Amber L. Schuetz, Director, IT Clinical Systems at Boys Town National Research Hospital. “The Risk Categorization Tool (v3) and supplemental mapping provide a valuable framework that helps streamline risk assessments, improve collaboration between stakeholders, and support more informed decision-making. The work CHAI has done in this space is helping organizations balance innovation with appropriate governance and oversight.”
The Risk Categorization Tool reflects CHAI's broader mission to convene the healthcare community around practical solutions to shared challenges. Through collaborative work groups, clinicians, health systems, technology developers, researchers, patient advocates, policymakers and other stakeholders work together to develop consensus-driven guidance that helps organizations deploy AI responsibly and with confidence. CHAI looks forward to continuing to evolve these governance resources alongside the healthcare community as AI technologies, governance practices and regulatory expectations continue to mature.
Thank you to our members who made this work possible:
Eric Henry, Brooke & Associates
Ashley Beecy, Sutter Health
Shubham Goel, Sutter Health
Nicoleta Economou, Duke
Christina Silcox, Duke
Lindsay Mico, Providence
Vivek Tomer, Providence
Taylor Anderson, Stanford
Todd F. Dardas, Wolters Kluwer; UpToDate
Howard Strasberg, Wolters Kluwer
Noelle Vidal, University of California
Joshua Miller, University of Rochester Medical Center
Larry Vernaglia, Foley & Lardner LLP
Teresa Luke, HealthPartners
Selvi Ramalingam, Emory Healthcare
Monica Kedzierski, Claritev
Gary Herrington, CareSouth
Sam Pinson, Nixon Law
Scott Ross, Opala
Kathleen Snyder, Lumeris
Alaap Shah, Epstein Becker & Green, P.C.
Taylor Rhoades, Mercy
Ruby Chen, Mercy
Brenna Loufek, Mayo
Ben Kaplan, Mount Sinai
Arash Kia, Mount Sinai
Jennifer Foster, San Joaquin General Hospital
Joseph A. Izzo, San Joaquin General Hospital
Christine Palermo, Encore Health
Ivan Pan, Memorial Sloan Kettering
Michael Blumental, HealthLeap
Mariana de Oliveira, Complear
Bita Behrouzi, MaineHealth Maine Medical Center; Tufts University School of Medicine
Joseph Seliski, Individual Contributor
