Most organizations I talk to are trying to solve an AI adoption problem. Michael Barber has the opposite problem.
He is Senior Director of Responsible AI at Highmark Health, and his group reviews every AI use case that goes to production across an enterprise that is a payer and a provider at the same time: six or seven million members in six states, Allegheny Health Network’s 16 hospitals, United Concordia Dental, and about 50,000 employees.
Highmark approved its first AI use case in September 2022. As of the day we recorded, 380 are in production. One hundred and four of those, 30 percent of the total, landed in the last six months.
We are now seeing a new request for an AI use case every day on average. So it’s one a day now.
The role did not exist until the volume forced it
AI governance at Highmark used to sit inside the data governance group. It outgrew that. Michael’s position, and the three positions under it, were created about two and a half years ago specifically because the volume of AI requests could no longer be absorbed as a side responsibility.
That is the useful signal for anyone benchmarking their own org. The question is not whether you need a dedicated responsible AI function. The question is what request volume forces one, and Highmark’s answer was somewhere on the path to one a day.
One design decision worth copying: when AI is involved in a use case, Michael’s group handles the data governance review too, rather than sending teams to two separate committees. Fewer gates, same standard.
The wins are unglamorous, and that is the point
Ask what AI is doing for a large payer and you will get a lot of answers about clinical decision support. Michael’s list starts somewhere else.
Thousands of faxes a day, still arriving in 2026, read and turned into discrete data elements. Systems that pull the relevant medical policy and chart sections in front of a claims reviewer so nobody has to page through a thousand documents to find three that matter.
And a hard line underneath all of it:
I’ll say right up front we would never use AI as the sole determinant for any adverse determinations. It’s not what we do. It’s illegal.
On the provider side, the durable wins are ambient listening and imaging triage. His framing of why:
The way we view AI, especially in the clinical setting, is that it doesn’t replace human judgment. It simply allows people to work at the top of their license.
He makes the value concrete. If a tool lifts the bottom quartile, usually newer employees still learning the landscape, up to the midpoint, that is real. It lets someone operate as if they had been there a year.
Ambient listening is a standardization layer, not just a scribe
This was the part I did not expect, and it is the part interoperability people should sit with.
Highmark runs one ambient listening system across AHN. Michael’s argument is that its value is not only that clinicians stop typing. It is that hundreds of clinicians now go through one intermediary that behaves the same way every time, instead of each entering notes into the EMR their own way with their own abbreviations.
Now we’ve got one thing that does something the same way every time in between hundreds of clinicians and our EMR system.
He is realistic about why that matters. Earlier in the conversation he described trying to combine EMR data across 16 cancer infusion clinics:
If you’ve seen one, you’ve seen one.
Same Epic instance. Subtly different local workflows. Same fields used for different purposes. Anyone who has built quality measures or a provider data warehouse knows exactly what that costs downstream.
If the standardization argument holds, ambient AI is a data quality intervention that happens to also save clinicians time. That reframes it from a documentation tool to infrastructure.
Five thousand people complaining about the data
My own view is that AI governance cannot happen without data governance, and at the same time it forces data governance to happen. Michael gave the best illustration of that I have heard:
Five years ago we had my group of 26 data scientists and software engineers complaining about the data. Now we’ve got 5,000 people complaining about the data.
Data quality problems used to be a specialist grievance that was easy to defer. Once you hand an LLM to 50,000 employees, bad data becomes everyone’s problem, visibly, immediately, and with executive attention attached. That is the forcing function a decade of data governance decks could not produce.
Access is broad on purpose, and education is the actual work
Highmark built an internal wrapper called Sidekick that sits on Gemini inside their secure environment and is available to all 50,000 employees. It includes a retrieval layer over their corporate policies, thousands of them, that returns a summary plus hyperlinks to the real policy. Paid Gemini Enterprise and M365 Copilot licenses sit on top of that, allocated at VP discretion.
That is more open than most enterprises, which tend to ration licenses to engineers and a few analyst teams. But the access is not the interesting part. The scaffolding is: roughly 100 AI ambassadors embedded in business functions as super users, an AI center of excellence with consultants who help teams find a solution even when the answer is that they do not need AI, and a lot of time in departmental meetings and town halls.
Michael’s summary of where that lands him:
I’ve met with other companies and frequently the question is, how do we drive adoption? My problem is the opposite of that. How do we get people to calm down just a little bit?
He also names the failure mode most enterprises are walking into right now: applying AI to a workflow that should not exist. Speeding up a broken process is not the win. The win is asking what you would do if you did not have the process at all.
The vendor position is stricter than the law requires
This is the section I would send to anyone negotiating AI vendor contracts.
Generative AI broke the old vendor model. A vendor used to own its model and run it in a known environment. Now, as Michael puts it, everything is an API call to somewhere else, and the work is figuring out what happens two or three layers down.
Highmark does not allow vendors to train on its data. It does not allow Google or Microsoft access to its data. And it goes further than HIPAA requires:
Even de-identified, we don’t allow vendors to improve their general product with our information. It has business value.
His reasoning is commercial, not legal. Once data is de-identified under safe harbor or expert determination, HIPAA is out of the picture and vendors often assume they can do what they like. Michael’s position is that the data still has value, and if a vendor wants to use it to improve a product they sell to competitors, Highmark should get something back.
Anything externally facing gets red teaming and prompt injection testing before it ships.
Fifty states writing fifty AI laws
The most pointed part of the conversation.
Michael testified before two Pennsylvania house committees last spring while they were drafting the state’s AI act. They asked for a list of every AI use in the enterprise.
I said, well, what are you going to do with that? At the time we had 330 use cases. I’m going to give you a list of 330 things, what are you going to do with it? What is the problem you’re trying to solve?
He told them his list would look like everybody else’s, because everyone is doing the same things for the same reason: they work. Every hospital system in the state is using ambient listening.
His objection is not to oversight. It is that roughly 90 percent of what state AI acts cover is already federal law, and the genuinely new part is reporting. Maryland and New York are asking for enterprise-wide inventories, including what data systems were trained on. That is administrative cost added to an industry that is supposed to be reducing cost, in exchange for a document nobody reads.
Pennsylvania removed the reporting requirement from its draft bill and replaced it with something closer to what he proposed: confirm that the entity has a governance process, rather than collect a list. He called that a big win, and the bill has not reached the House floor yet.
He also lived through the version where this gets expensive. Under the original Colorado AI Act, Highmark had to carve Colorado members out of a program making positive outreach to people being discharged from hospitals. Colorado residents did not get the benefit. Colorado has since retreated from that position and those members are back in.
The line I keep thinking about
Benji asked whether legislators simply do not understand the technology. Michael’s answer:
If you’re looking for votes, it’s a nice thing to say. We’re going to protect you against the big bad AI. I said, I wouldn’t want to go to a doctor who is anti-AI. Would you?
I pushed back on some of this in the episode, because I think there is a real category of harm worth regulating. California’s law focused on adverse outcomes, including what chatbots tell teenagers in crisis, seems to me like the right shape: regulate the outcome, monitor the harm, do not demand an inventory.
Michael’s answer on that was practical. Every externally facing use case at Highmark gets tested for exactly those scenarios. What happens if someone says they are having chest pain. What happens if an employee asks Sidekick something in a bad moment. His observation is that the frontier labs have already built a lot of that in. The last time he tested it, Sidekick not only declined to give the wrong kind of advice, it surfaced the employee assistance services actually available to Highmark employees. Nobody programmed that.
Where I landed
Two things I am taking from this conversation.
First, the governance story and the data quality story are the same story. Highmark did not fix its data and then deploy AI. It deployed AI broadly, which made the data problems visible to 5,000 people instead of 26, which is now driving the data work. That is backwards from how most of us have been taught to sequence it, and it appears to be working.
Second, the patient is still the last to see the benefit. I said this to Michael and I will keep saying it. I have spent a long time in this industry and the person whose data it is still retypes their history into a 40 page form. Michael’s answer, that consumer expectations set the bar and healthcare has to at least stay in the game, is the right instinct. The gas pump screen knows where you are going on vacation. The scheduling system still does not know you had that colonoscopy.
That gap is the work.
Chapters
00:00 Welcome, and how we met in Pittsburgh
01:04 The Responsible AI job that did not exist
02:42 Where AI is actually paying off at a payer
04:14 Never the sole determinant, and the fax problem
05:29 The FHIR guy pulls a thread on structured data
08:47 Working at the top of your license
12:11 Ambient listening as a standardization layer
15:36 From 26 people complaining about data to 5,000
17:20 Sidekick, and giving an LLM to 50,000 employees
20:55 380 use cases, and one new request every day
27:03 What does the patient actually get out of this
32:47 Guardrails, vendor contracts, and your data
38:31 Fifty states writing fifty AI laws
42:16 “I wouldn’t want to go to a doctor who is anti-AI”
Michael Barber is Senior Director of Responsible AI at Highmark Health, where he leads the group that reviews and approves every AI use case that reaches production across the enterprise. Benji Graham co-hosted.
If you are working on AI governance inside a payer or health system and want to compare notes, reply to this email or find me on LinkedIn.
This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit evestel.substack.com/subscribe