Skip to main content
NSAG / Insights
Governance Insights

What institutions are getting wrong. What they could get right.

Governance problem spotlights, policy briefings, and module-specific intelligence. Grounded in primary sources. No institution names. Written for practitioners who want to understand the wider governance landscape, beyond their own institution's score.

M11 · Medical Technology Governance Problem Spotlight

Your hospital is using a risk-stratification algorithm that has never been independently assessed for your patient population.

71% of US hospitals use EHR-integrated predictive AI. Only 57% evaluate all or most models for demographic bias. (Chang et al., 2025 — ASTP/ONC Data Brief No. 80)

In 2019, Obermeyer et al. published in Science what is now the definitive case study in clinical AI governance failure: a commercial algorithm used for approximately 200 million patients to identify high-risk candidates for care management was using healthcare cost as a proxy for health need. Because structural barriers reduce Black patients' healthcare spending relative to white patients with equivalent illness severity, the algorithm systematically underestimated Black patients' needs. The verbatim finding: remedying this disparity would increase the percentage of Black patients receiving additional help from 17.7% to 46.5%.

The algorithm was not designed to discriminate. It was commercially deployed, widely used, and embedded in the EHR infrastructure of health systems across the country. Its bias was detectable — through demographic stratification of outcomes data — and was not detected because the governance infrastructure to detect it did not exist.

Six years later, the ONC's 2025 hospital AI governance survey found that 71% of hospitals now use EHR-integrated predictive AI, while only 57% evaluate all or most models for demographic bias. The governance gap that allowed the Obermeyer algorithm to operate at scale is the governance gap that most US hospitals still have today.

The governance question goes beyond whether your AI tools have been FDA-cleared or commercially validated. What matters is whether your institution has established its own demographic impact assessment standard, specific to your patient population, applied before and after deployment, independent of what any vendor or regulator reports. Most have not.

Governance Implication

M11 governance requires: documented AI tool inventory, independent demographic impact assessment before adoption and annually post-adoption, human override protocols without coercive documentation burden, and defined disparity thresholds that trigger governance response.

Obermeyer et al. (2019) doi:10.1126/science.aax2342 · Chang et al. (2025) healthit.gov
Go to M11 Module →
M9 · Cannabis Healthcare Visibility Governance Problem Spotlight

There is a patient on warfarin in your clinical system whose cannabis use is undocumented. Their INR is drifting and no one knows why.

35.1% of primary care patients reported implicit medical cannabis use. EHR documented rate: 4.8%. (Lapham et al., 2022 — JAMA Network Open)

Lapham et al. (2022) published what is now the verified primary source for the cannabis documentation gap: in 1,688 primary care patients, 35.1% reported implicit medical cannabis use while only 4.8% had documentation in the electronic health record — from the same patient population, measured simultaneously. That is a 7:1 gap between what patients are doing pharmacologically and what their providers can see.

Cannabis is metabolized through cytochrome P450 pathways (CYP3A4, CYP2C9, CYP2C19, CYP1A2) shared with warfarin, antiepileptic medications including clobazam and phenytoin, antidepressants, antifungals, and immunosuppressants (VanDolah, Bauer & Mauck, 2019). Cannabis can both induce and inhibit these pathways depending on dose, frequency, and route, producing clinically significant alterations in the effective concentration of co-administered medications.

The governance failure sits in institutional design. Tavabi et al. (2023) found in 370,087 patients across 23 million clinical notes that documentation disparities track racial and socioeconomic lines independent of use prevalence — meaning the documentation gap is not evenly distributed. The populations with the greatest documentation barriers are the same populations already facing the greatest healthcare equity gaps.

The institution's intake process, EHR architecture, and disclosure safety design are either mitigating or amplifying those barriers. Most are amplifying them by default, because institutions have avoided designing cannabis documentation governance in the first place.

Governance Implication

M9 governance requires: validated cannabis screening instrument at every patient contact, EHR structured data fields with ≥85% completion target, written disclosure safety policy communicated at intake, provider training in CYP450 interactions, and cannabis documentation rate as a tracked QI metric.

Lapham et al. (2022) doi:10.1001/jamanetworkopen.2022.11677 · Tavabi et al. (2023) doi:10.1038/s41746-023-00885-w
Go to M9 Module →
M8 · Burnout Recovery Infrastructure Governance Problem Spotlight

The wellness program you just implemented will not reduce burnout. The research has known this for twenty-five years.

Organizational interventions produce significantly greater and more durable burnout reductions than individual interventions. (Kiratipaisarl et al., 2024 — BMC Medical Education)

Maslach, Schaufeli, and Leiter established in the Annual Review of Psychology in 2001 what three subsequent decades of research have confirmed: burnout is fundamentally a mismatch between person and job across six organizational domains — workload, control, reward, community, fairness, and values. Individual-level interventions (resilience training, mindfulness apps, wellness programs) do not change the workload. They do not restore control. They do not improve community. They address the symptoms of a structural problem by optimizing the person's capacity to tolerate conditions that the evidence identifies as the root cause.

Kiratipaisarl et al.'s 2024 systematic review and meta-analysis confirmed: organizational interventions produce significantly greater and more durable burnout reductions than individual interventions. Thomas Craig et al. (2021) found this specifically for EHR-related digital burden: organizational interventions targeting technology optimization, documentation reduction, and team-based workflow improved burnout in 68% of eligible studies.

The governance failure has little to do with compassion for staff. It lies in the institutional response to documented burnout — wellness programs, mindfulness apps, Employee Assistance Programs — which the literature consistently shows does not produce durable results. The governance change that would actually work requires auditing the six person-job mismatch domains and redesigning the organizational conditions producing them. That requires workload governance standards. Documented autonomy scope. Formal fairness mechanisms. Values alignment assessment.

These are institutional governance decisions. They require leadership accountability, documented policy, and a board-level governance commitment. Most institutions have not made that commitment. The wellness programs signal that burnout has been acknowledged. Governing it is the further step most have yet to take.

Governance Implication

M8 governance requires: documented workload standards by role with formal reporting and required administrative response, autonomy governance, fairness review of workload distribution, community support infrastructure, and values alignment assessment.

Maslach et al. (2001) doi:10.1146/annurev.psych.52.1.397 · Kiratipaisarl et al. (2024) doi:10.1186/s12909-024-06195-3
Go to M8 Module →
M2 · AI Legal Navigation Governance Problem Spotlight

The bail hearing algorithm in this jurisdiction performs no better than chance. And it is wrong twice as often for Black defendants.

COMPAS accuracy: 65.2% vs. untrained lay prediction: 67.0%. Black defendants incorrectly flagged as high-risk at approximately 2× the rate of white defendants. (Dressel & Farid, 2018 — Science Advances)

Dressel and Farid published in Science Advances in 2018 what remains the most consequential empirical finding in algorithmic legal governance: COMPAS, the risk assessment algorithm used in bail, sentencing, and parole decisions across numerous US jurisdictions, achieved a predictive accuracy of 65.2%. Amazon Mechanical Turk workers given a 168-word description of each defendant achieved 67.0%. A two-feature linear model matched COMPAS's 137-feature model in performance. The algorithm performed no better than chance while producing racial disparities in false-positive rates: Black defendants were incorrectly flagged as high-risk at approximately twice the rate of white defendants.

Berk et al. (2024) identified why technical fairness corrections fail to resolve this: the bias originates in the training data itself. Arrest records — the primary data source for recidivism prediction — encode decades of racially disparate policing practices. An algorithm trained on this data reproduces racial disparities simply by accurately modeling a biased input, with no discriminatory design required. This is the bias-in-bias-out problem: fixing the algorithm without fixing the data produces a more sophisticated version of the same disparity.

Chouldechova (2017) proved formally that some fairness goals cannot simultaneously be achieved when base rates differ across groups. The governance response to this mathematical reality is transparency, human override authority, and community accountability, since better algorithms alone cannot resolve it.

The governance failure in most jurisdictions using algorithmic risk assessment is the absence of the governance infrastructure that makes the tool accountable: independent demographic impact assessment for the specific jurisdiction's population, human override protocols that do not coerce deference, plain-language notification to affected individuals, and community authority over adoption and discontinuation decisions.

Governance Implication

M2 governance requires: independent demographic impact assessment specific to the jurisdiction's population, human override protocols without coercive documentation burden, plain-language notification to affected parties, and community advisory authority over adoption and discontinuation.

Dressel & Farid (2018) doi:10.1126/sciadv.aao5580 · Berk et al. (2024) doi:10.1177/00491241231155883
Go to M2 Module →
M12 · Education Systems Governance Problem Spotlight

The classroom design of one school explains more variation in learning outcomes than most curriculum interventions. And almost no one is governing it.

Seven built environment parameters explain 16% of the variation in pupils' academic progress. (Barrett et al., 2015 — Building and Environment, n=3,766 pupils, 153 classrooms)

Barrett, Davies, Zhang, and Barrett published the HEAD Project in Building and Environment in 2015: a holistic, multi-level analysis of 153 classrooms across 27 UK primary schools involving 3,766 pupils. The finding: seven built environment parameters — Light, Temperature, Air Quality, Ownership, Flexibility, Complexity, and Colour — together explained 16% of the variation in pupils' academic progress over one year, after controlling for teacher quality and other factors.

Sixteen percent. That is approximately the same effect size as many curriculum interventions that receive far more governance attention and far more institutional investment. The difference is that curriculum decisions are made consciously, governed by standards, and measured against outcomes. Built environment decisions are made by facilities teams, governed by building codes and budgets, and rarely measured against learning outcomes at all.

Immordino-Yang and Damasio (2007) provide the neural mechanism: students in physiological threat states — produced by unsafe social environments, unpredictable transitions, noise above comfortable thresholds, temperature extremes, or inadequate light — are neurologically unable to engage the prefrontal cortical systems that support working memory, executive function, and abstract reasoning. The built environment is a determinant of whether the neural infrastructure required for learning is activated or suppressed.

Cantor et al. (2019) extend this to developmental stakes: brain development is experience-dependent, and educational environments during critical developmental periods literally shape the neural architecture of the students in them. The classroom design decisions made this year are having neurobiological consequences that will be measurable decades later. Most school governance frameworks have no mechanism for making those decisions accountable to those consequences.

Governance Implication

M12 governance requires: documented standards for lighting, acoustics, temperature, and air quality; psychological safety infrastructure with institutional accountability; transition and schedule governance; and annual quality assessment against evidence-based standards.

Barrett et al. (2015) doi:10.1016/j.buildenv.2015.02.013 · Immordino-Yang & Damasio (2007) doi:10.1111/j.1751-228X.2007.00004.x
Go to M12 Module →
M14 · Space Governance Governance Problem Spotlight

The last major space governance treaty was written in 1967 for robotic probes. It does not address the rights of a crew member about 240,000 miles from Earth.

The Outer Space Treaty (1967) establishes that states bear international responsibility for space activities. It does not define crew rights, medical ethics authority, mission control governance, or institutional accountability for commercial operators. (Treaty on Principles Governing Activities in Outer Space, 610 U.N.T.S. 205)

In 1967, the major space-faring nations signed the Outer Space Treaty — the foundational legal document governing human activity beyond Earth. It establishes that outer space is not subject to national appropriation, that states bear responsibility for their national activities in space whether governmental or commercial, and that astronauts are “envoys of mankind.” It does not define what rights those envoys hold while on a mission. It does not address who has final medical authority when a crew member requires treatment that mission control opposes. It does not address what governance obligations apply to a commercial operator whose crew sits about 1.3 seconds of signal delay from Earth each way.

Kanas and Manzey (2008), in the most comprehensive review of space psychology and behavioral health in spaceflight, identified interpersonal conflict, communication difficulties with mission control, and inadequate autonomy as the most significant predictors of mission risk in long-duration spaceflight. All three are governance problems. None of the three is addressed by the Outer Space Treaty, the Artemis Accords, or any bilateral space agreement currently in force.

The governance gap is concrete. Stuster’s four decades of analog environment research — Antarctic stations, submarines, polar expeditions — consistently found that governance structures preserving crew autonomy, providing independent accountability mechanisms, and establishing clear authority boundaries produce significantly better behavioral health outcomes. The evidence for what space governance should look like exists. The governance frameworks implementing it do not.

The Artemis III crew was announced in June 2026. Their mission is scheduled for 2027. The governance infrastructure defining their individual rights in space, the scope of mission control authority over their medical decisions, and the accountability structure for their institutional employer in a commercial space context has not been built.

Governance Implication

M14 governance requires: documented legal framework addressing jurisdiction and applicable law for off-Earth operations; written crew autonomy protocol including the right to refuse mission directives on documented health grounds; clinical governance framework for autonomous healthcare decision-making beyond Earth-based consultation range; independent accountability mechanism external to the operational command structure.

Treaty on Principles Governing Activities in Outer Space (1967) 610 U.N.T.S. 205 · Kanas & Manzey (2008) doi:10.1007/978-1-4020-6770-9 · Stuster (2010) NASA TM-2010-216130
Go to M14 Module →
M15 · Isolation & Confinement Governance Problem Spotlight

The three things that consistently degrade human beings in isolated confined environments are all institutional governance decisions. Institutions are still treating them as individual character problems.

Interpersonal issues, monotony, and inadequate autonomy are the three most consistent predictors of adverse behavioral health outcomes across analog environments — Antarctic stations, submarines, polar expeditions, spaceflight. All three are institutional design variables. (Stuster, 2010 — NASA TM-2010-216130)

Stuster’s analysis of four decades of isolated confined environment research — covering Antarctic winter-over stations, submarine missions, polar expeditions, and early space missions — found that the same three factors appear consistently as the primary predictors of adverse behavioral health outcomes: interpersonal conflict, monotony, and inadequate autonomy. The research base is not new. The governance response to it is largely nonexistent.

Interpersonal conflict is a social cohesion governance problem. Institutions that place people in confined proximity without crew composition standards, conflict resolution protocols, or privacy governance frameworks produce interpersonal conflict reliably. Monotony is a temporal governance problem. Institutions that do not govern the structure of time — circadian rhythm protection, meaningful activity rotation, cognitive maintenance programming — produce monotony-related degradation reliably. Inadequate autonomy is an agency preservation problem. Institutions that do not preserve meaningful decision-making authority for individuals over their immediate personal environment produce learned helplessness reliably. These are design outcomes.

Kanas and Manzey (2008) added a fourth governance risk: the “Earth-out” phenomenon, in which crew members displace negative emotions away from mission control — where they cannot be expressed — and onto crewmates, who absorb the displaced hostility and produce escalating interpersonal conflict. This is a communication governance failure between the crew and the institutional command structure. It is predictable, documented, and unaddressed by most operational governance frameworks.

In an environment people cannot leave, every stressor is a governance choice. The acoustic environment of the spacecraft. The lighting schedule. The private space allocation. The work-to-rest ratio. The channel through which a crew member raises a concern without triggering institutional penalty. These are governance variables with measurable consequences for the people who live inside them, with no ability to exit.

Governance Implication

M15 governance requires: documented environmental standards (acoustic ≤45 dBA, lighting, thermal, air quality) with continuous monitoring; psychological health monitoring that does not penalize help-seeking; crew composition standards with pre-deployment cohesion assessment; formal privacy and personal space protocols; documented circadian rhythm protections; written emergency response protocol with defined mission abort triggers.

Stuster (2010) NASA TM-2010-216130 · Kanas & Manzey (2008) doi:10.1007/978-1-4020-6770-9 · Maslach et al. (2001) doi:10.1146/annurev.psych.52.1.397
Go to M15 Module →

Apply these insights — to your institution, your profession, or the systems you move through as a patient, client, or citizen.

Each spotlight has a module scope page setting out its evidence base, proposed governance dimensions, and implementation questions. Digital assessment collection is paused, so the scopes are published for reading and reuse rather than scoring.

M9 module scope M8 module scope M11 module scope All 15 Modules →