OBJECTIVES: Hospital artificial intelligence (AI) is increasingly embedded in electronic health record workflows, cloud inference pipelines, imaging, medication review, triage, early warning, documentation, and operational management. This paper proposes a risk-tiered governance framework and implementation pathway for hospital AI applications that are integrated into clinical and operational workflows. METHODS: We conducted a narrative review and framework synthesis of peer-reviewed evidence, reporting guidelines, regulatory and policy sources, implementation studies, and applied governance case reports relevant to hospital AI. Sources were used according to their evidence type: systematic and scoping reviews identified recurring risks and barriers; empirical studies and trials illustrated bounded implementation patterns; case reports informed organizational design; and reporting or regulatory frameworks informed documentation, validation, change control, and oversight elements. RESULTS: The proposed framework has four components. First, a use-case inventory tags AI applications by decision influence and workflow coupling. Second, a six-domain risk taxonomy addresses clinical safety, privacy and data security, ethics and fairness, transparency and explainability, system stability and resilience, and compliance and accountability. Third, a four-tier risk scheme links the level of oversight to potential harm, automation, reversibility, and operational coupling. Fourth, a governance architecture assigns responsibilities to an AI governance committee, clinical owners, risk-control functions, and independent assurance. A patient-safety-oriented lifecycle pathway is proposed across initiation, local validation, shadow mode, controlled go-live, monitoring, change control, retirement, and organizational learning. To support feasible adoption, we also provide barriers, first steps, and a maturity-based ramp-up model. CONCLUSION: Hospital AI governance is best framed as proportional lifecycle control rather than one-time go-live approval. The proposed framework is an adaptable scaffold, not a universal mandate. It is intended to help clinical informatics leaders, quality and safety teams, and hospital executives prioritize oversight according to risk, resources, and organizational maturity.
Zhu et al. (Thu,) studied this question.