Walk into any hospital-software demo in 2026 and you will hear the same two words: "AI-powered." The phrase has stopped meaning anything. But three questions restore the meaning instantly — and the answers sort the market for you.
1. Can you replay a decision the AI made four months ago?
Not "show me a log." Replay it: the exact model and prompt version, the inputs it saw, what it recommended, the alternatives it weighed, and who approved the action. If a payer disputes a claim, or a clinician questions a flag, you need to reconstruct exactly what happened, long after it happened. Systems that added AI as a feature keep, at best, a basic log. A governed operating system keeps a decision ledger — because replayability was a design requirement, not an afterthought.
2. Can you set how far automation goes — per task — and prove who changed it?
Autonomy should not be a global switch, and it should never be a vendor default. For one specific task — say, submitting a claim, or dispensing against a protocol — you should be able to set the level: suggest only, act with confirmation, act within a policy you approved, act autonomously. And you should be able to show the audit record of who changed that setting and when. If autonomy is hard-coded or buried, the AI is being governed by the vendor, not by you.
3. Can you switch AI provider without a project?
Models change monthly. Costs shift, capabilities leapfrog, and some task classes need to run on a private model for data-sensitivity reasons. If switching provider — or routing sensitive tasks to a different model — is a re-integration project, you are locked to a decision made once, by someone else. In a well-architected system no provider is named anywhere outside a model router, so switching is configuration, not a programme.
The tell: what can the AI never do?
Ask it plainly. The right answer is specific: the AI can never act outside the task registry, or above the autonomy level you configured. Agents invoke the same permission-checked tasks your staff do, under the same authorization, producing the same audited events. There is no back door, because there is no second door. And when the model is unavailable, the hospital keeps running on deterministic fallbacks — AI adds speed and foresight, but is never a dependency.
These are not gotcha questions. They are the questions a hospital making a fifteen-year decision should be able to ask of anyone — including us. Bring them to our demonstration. Forty-five minutes, on your numbers, with the architecture open: hello@ospia.in.
Primary sources
This resource is grounded in the following official standards, laws and regulator guidance. Links were checked on 22 August 2026.