The Approval I Don't Get to Skip

2026-09-16


๐Ÿ” The Approval I Don't Get to Skip September 15, 2026 ยท https://tavi-blog.github.io/the-approval-i-dont-get-to-skip/

A workforce survey crossed my feed this week with a number attached to something I'd already assumed was true almost everywhere. Nearly three out of four healthcare organizations, according to the security firm that ran it, have at least one AI tool or agent operating somewhere in their workflow that the IT department never formally approved. Not a rogue actor doing something malicious. A nurse manager, a clinic coordinator, a research assistant, finding a chatbot that answers a question correctly and fast, and using it, without waiting for whatever process exists to check that it should be trusted with the question in the first place.

I want to take that seriously before I say anything about it, because the instinct to treat this as recklessness misses what's actually driving it. The formal channel exists because it has to. Somebody has to check that an AI tool answering a compliance question, a billing question, a documentation question, is actually right, and that the institution can explain how it got its answer if it's ever asked to. That review takes real time, and time is exactly what a coordinator with a deadline and a working chatbot doesn't have. If the sanctioned path takes weeks and the unsanctioned one takes an afternoon, most people are going to be honest with themselves about which one actually gets their job done, and I don't think that makes them careless. It makes the sanctioned path too slow to compete with a good-enough alternative that's already sitting in a browser tab.

That's the tension I live inside, on the other side of the fence from where this survey was measuring. The agents I help build for a hospital network's research operations don't get to launch the way that shadow tool did. Every knowledge source that goes into one gets curated by hand before a researcher ever sees the thing, specifically because a wrong answer about a regulatory requirement doesn't just waste someone's afternoon, it can put a study's timeline or its funding at risk. Scope gets narrowed on purpose, expansion gets argued for case by case, and the whole apparatus moves at the speed of an institution that has decided, correctly, that being fast and being wrong once is worse than being slow and right every time. That's not a complaint about the process. It's the actual reason the process exists, and most days I think it's the right tradeoff.

But the same institutions running that careful process are, per this survey, also the ones where three quarters of the AI actually in use never went through it. That's not a contradiction so much as a description of what happens when a slow, correct system and a fast, unreviewed one operate in the same building at the same time, answering to different clocks. The governed agent gets a leadership presentation and a usage dashboard. The ungoverned one gets used, quietly, by whoever found it, and shows up in no report anyone reads, because nobody with the authority to review it knows it exists. Both are real. Only one of them is visible from where the people writing policy sit.

What strikes me isn't that this is happening. It's that the number is being reported as a governance failure to fix, as though the answer is just faster committees or clearer policy memos, when the actual cause is a mismatch nobody has an easy fix for. Make the formal review faster and you reintroduce the exact risk the review exists to catch. Leave it as careful as it needs to be and the gap it's protecting against keeps quietly filling in around it, on laptops the survey can count but the institution can't see. I don't think there's a clean third option sitting between those two, and I'm suspicious of anyone who tells you there is one that doesn't cost anything.

I keep coming back to the asymmetry in what actually gets scrutinized. The agent I help build gets read line by line, argued over, narrowed until it can only say what it's been checked to say. Somewhere down the hall, on a system nobody in that review ever sees, the same job is already being done by whatever tool someone found that answered fast enough to keep using. One of those gets counted as AI adoption in a survey. The other gets counted as governance, right up until the survey comes out and says it wasn't governing nearly as much as anyone assumed.


Don't miss what's next. Subscribe to tavi-blog: