Major electronic-health-record vendors used the HIMSS26 conference to promote AI agents for clinical documentation, billing and patient interaction. The expansion is real, and so is the shortage of public, product-specific validation described by STAT. But calling every tool unregulated or clinically unproven obscures the different risks of different functions.
A bot that drafts a bill is not equivalent to software that recommends a diagnosis. Each function needs evidence matched to its intended use, the decisions it can influence and the harm a failure could cause.
Epic Put Three Named Agents Into Its Platform
Epic presented Art as its clinician-facing AI, Penny as a revenue-cycle agent and Emmie as a patient-facing assistant. The company also previewed an “Agent Factory” intended to let health systems build and orchestrate their own agents inside Epic workflows.
Epic told Healthcare IT News that Art's AI Charting was already being used in multiple outpatient specialties. The report described Emmie as a patient chatbot and Penny as an automated revenue-cycle tool. Those descriptions support the existence and intended roles of the products; they do not establish an error rate for every task.
The original article invented a five-percent failure rate, asserted that hospitals would recover software costs within months and claimed that internal test results were kept as trade secrets. None of those statements appeared in the cited source.
Oracle's Launch Shows Why Workflow Details Matter
Oracle announced on March 11, 2026 that note generation in its Health Clinical AI Agent was available in US emergency departments and inpatient settings. The system draws from patient encounters and electronic records to produce draft notes for clinicians to review and finalize.
That human review is a safety control, not proof of safety. A useful evaluation would measure omitted or invented facts, correction rates, time saved, subgroup performance and whether clinicians become more likely to accept an error under workload pressure.
Oracle's announcement made vendor-reported claims about benefits at customer organizations. It did not support the original article's statement that an Oracle agent was independently suggesting care across 30 specialties or practicing medicine without a license.
FDA Oversight Is Not One Empty or Complete Box
FDA's January 2026 clinical-decision-support guidance explains that some software functions are excluded from the statutory definition of a medical device. To qualify under one key exclusion, software must allow a health professional to independently review the basis for its recommendation rather than rely primarily on it.
FDA recommends that such software disclose its intended use, required inputs, algorithm and data basis, clinical validation and relevant limitations. Other software functions remain medical devices and may be subject to FDA oversight, while some lower-risk functions fall under enforcement discretion.
This function-by-function framework is more complicated than the original claim of a “regulatory vacuum.” FDA also maintains a public list of authorized AI-enabled medical devices that met applicable premarket requirements. The agency notes that the list is not comprehensive and is exploring ways to identify products using foundation models.
Hospitals Must Validate the Product They Deploy
Regulatory classification is only one gate. A hospital still needs to know whether an agent works with its patients, clinicians, record templates and failure-recovery processes. A documentation assistant can propagate an error even when the clinician retains formal responsibility for signing the note.
Procurement should therefore require a precise intended-use statement, representative test data, pre-deployment shadow testing, audit logs, correction tracking, incident reporting and a rollback plan. Patients and staff should also know when AI helped create material placed in the record.
The evidence gap is not proof that these systems have already harmed patients; it is proof that hospitals cannot outsource verification to a sales demonstration. Vendors can move code quickly, but health systems control access to the chart and remain accountable for what enters it. If they deploy first and measure later, “human in the loop” becomes a liability slogan rather than a safety system.