Most healthcare AI governance conversations begin inside the institution. Leaders debate which models they can deploy, which guardrails they need to enforce, and how they can secure increasingly complex AI environments. The underlying assumption is that the healthcare organization remains the center of control.
Paul Swider, CEO of RealActivity and creator of the open-source patient agent Tula, argues that assumption is already becoming outdated. In this #shifthappens episode, he makes the case that the next phase of healthcare AI governance will be shaped by patients themselves. Once individuals can access their healthcare records, connect them to AI systems they control, and decide how those systems act on their behalf, governance can no longer stop at the hospital perimeter.
The result is a fundamental shift in how organizations think about ownership, security, trust, and accountability in agentic AI.
Healthcare's Governance Model Was Built for Centralization
Modern healthcare infrastructure was designed around centralized control. Healthcare organizations collect patient information, secure it inside enterprise platforms, and govern access through institutional policies. For years, that approach made sense because healthcare providers were often the only parties capable of storing and managing complex medical records.
According to Paul, legislation and technology have changed that equation. The 21st Century Cures Act gives patients the right to obtain and move their healthcare data, creating an environment where individuals can increasingly choose the tools they use to manage their own information. Once the patient downloads that data and grants an AI agent access to it, the governance conversation changes. The institution may still have responsibilities, but it is no longer the sole decision-maker.
That is the premise behind Tula, the patient-owned AI agent Paul built after connecting his own healthcare records with data from personal health devices and other sources. Rather than relying entirely on provider-controlled experiences, he wanted a system that could help him understand his health information in a way designed around his needs, not the institution's workflows.
This distinction matters because many current governance frameworks were designed for systems operating inside organizational boundaries. Agentic AI increasingly challenges those boundaries altogether.
Patient Ownership Creates New Security Assumptions
One of the most interesting aspects of Paul's argument is that patient ownership is not simply a governance question but also a security question.
Healthcare organizations often view centralization as the safest approach because it enables standardized controls, monitoring, and compliance processes. Yet centralized platforms also concentrate risk. Large electronic health record environments contain millions of records and remain attractive ransomware targets because of the value of the data they hold.
He argues that patient-owned agents change that calculus. A patient agent only needs access to one person's information. It does not need records belonging to thousands of other patients, nor does it need large amounts of administrative and billing information attached to every interaction. That narrower scope fundamentally changes what an attacker can gain from a compromise.
More importantly, it highlights a growing reality for governance teams: securing AI systems is not only about protecting infrastructure. It is also about understanding where data is moving, who controls it, and how trust is maintained once it leaves traditional enterprise environments.
The Wrong Standard is Slowing AI Adoption
Paul also challenges another assumption that appears frequently in AI governance discussions: the idea that AI should be held to a standard of perfection.
Healthcare leaders often focus on the possibility that an AI system could make a mistake. He does not dispute that risk. Instead, he believes organizations should compare AI performance against the healthcare system people actually experience today.
Healthcare already contains missed screenings, delayed diagnoses, administrative bottlenecks, and inconsistent outcomes. The relevant question is not whether AI can eliminate every error. Instead, Paul posits we should ask whether AI can improve upon existing outcomes. If technology helps reduce missed screenings, improve patient understanding, or surface actionable insights sooner, that improvement should be part of the governance discussion.
That perspective reframes governance from a conversation about perfection to one about measurable improvement.
What Individual-First Governance Looks Like in Practice
If healthcare is moving toward a future where patients increasingly own the agent, instead of debating whether we can stop that future we should ask ourselves how governance, security, and accountability need to evolve to support this evolution. The conversation surfaces several implications for healthcare leaders as patient-owned agents become more common.
Move Governance to Follow the Patient
Paul's central argument is that governance has to account for where data actually goes instead of where organizations wish it would stay. Traditional governance frameworks are built around institutional perimeters, but patient-controlled AI introduces a world where healthcare data moves across multiple systems under the individual's direction. Governance, therefore, must follow the patient throughout that journey rather than stopping at the provider's boundary.
Decentralize to Shrink the Attack Surface
Patient-owned agents also illustrate the potential security benefits of decentralization. When AI systems are scoped to a single individual's health information, organizations reduce the incentive created by large, centralized repositories. Paul argues that a patient agent containing one person's data represents a fundamentally different target than an enterprise environment containing millions of records, claims, and billing histories.
Benchmark AI Against Real-World Outcomes
Governance leaders should evaluate AI against the results healthcare delivers today. A system that reduces missed screenings, improves awareness, or accelerates access to information creates value even if it is not flawless. The benchmark should be whether outcomes improve, not whether errors disappear entirely. By shifting the conversation from theoretical perfection to measurable improvement, leaders can make more practical decisions about where AI can deliver the greatest impact.
Apply the Same Standard to Institutional AI
Paul points out that AI has already influenced healthcare decisions for years, particularly in administrative and prior authorization processes. He argues that organizations should scrutinize enterprise and payer-side AI with the same rigor they apply to patient-owned tools. Trust, transparency, and accountability should apply consistently regardless of who deploys the technology. If governance standards matter for patient-facing AI, they should matter equally for institutional AI that affects access to care and patient outcomes.
Return Control to the Patient
Ultimately, the shift is about ownership. Patient-owned agents allow individuals to manage, move, connect, and derive value from their own healthcare information. For Paul, that is not merely a product design decision. It is a necessary step toward improving access, health equity, and patient empowerment in a world increasingly shaped by AI. Empowering patients with greater visibility and control can unlock more personalized healthcare experiences.
Governance Must Follow the Data
Healthcare may be the first industry confronting the implications of patient-owned agents, but the underlying governance challenge extends well beyond healthcare. As AI becomes more personal, more autonomous, and more accessible, organizations will need governance models that account for what happens after data leaves traditional enterprise boundaries. Paul's argument is not that institutions become irrelevant. It is that governance must evolve alongside a world where individuals increasingly control how their data is accessed, analyzed, and acted upon. The organizations that adapt first will be the ones that understand governance is no longer just about protecting systems. It is about maintaining trust wherever the agent operates.
Soundtrack of Shift
Paul chose Dave Matthews Band's The Best of What's Around as his Soundtrack of Shift. The song reflects his belief that this moment in technology is less about waiting for the perfect solution and more about building with the capabilities already available. In the same way he approaches healthcare AI, his interpretation is grounded in action: Identify what creates value, put it to work, and keep moving forward.
Explore more Soundtracks of Shift and discover how today's leaders connect music, technology, and transformation to the ideas shaping the future.

Episode Resources
#shifthappens Research: 2026 State of AI
#shifthappens Insights:
- Prototype to Production: Who Owns AI Agents When They Break?
- When AI Agents Make Promises Your Business Can't Keep
- The AI Governance Blind Spot Leaders Are Missing
- Shadow AI Is the New Shadow IT: Why Governance Can't Wait
#shifthappens Podcasts:
- Governance Makes AI Work in Healthcare: Managing Privacy and Security in Real Workflows
- Agents, Governance, and the Discipline Behind AI That Actually Ships
- AI Readiness Starts Before AI: Identity, Endpoints, and Security First
- The Foundation of AI Adoption Success in Healthcare
Dux Raymond Sy on LinkedIn
Paul Swider on LinkedIn
RealActivity website