12 Things Health Agencies Need to Know About Enterprise AI

Lessons drawn from the frontlines of government AI development for state and territorial health agencies ready to move from curiosity to implementation.

June 23, 2026 | Ari Whiteman

Decorative.

Across the country, state and territorial health agencies are under growing pressure to modernize how they detect disease, analyze surveillance data, and communicate with the public. Artificial intelligence (AI) has emerged as a promising set of tools for this work. But the gap between promise and practice is wide, and the agencies that are actually succeeding offer a very different playbook than the finished products most vendors are selling. What follows is a set of lessons learned provided to ASTHO directly from Minnesota’s Department of Health, which actively implements AI for disease surveillance. These are insights, applicable to any jurisdiction interested in utilizing AI for public health operations, that can guide how health departments approach AI product development from a strategic standpoint, well before procurement.

Lesson 1: Invest in Staff Before You Invest in Products

The most consistent finding among agencies that have made meaningful progress with AI is that they hired builders before they bought tools. This is in contrast to purchasing products first and going on a “problem hunt,” trying to retrofit newly acquired technology onto problems it wasn’t designed to solve.

Before launching any AI pilot, agencies should have at minimum one data scientist embedded on the program side and one data engineer on the IT side. Infrastructure costs for a well-designed AI system can be surprisingly modest, often in the hundreds of dollars per month. The real investment is and always will be the people who build, validate, and maintain it.

Lesson 2: Make Data Security a Prerequisite Not an Afterthought

For agencies working with protected health information, no data should leave your environment: not queries, not outputs, not anything that could be used to train external models. This means creating a true walled garden, and it means having security engineers, not just product sales teams, vet the architecture before any sensitive data touches a new system.

This level of security review takes time and costs money upfront. It is also the foundation upon which everything else rests. Skipping this step could incur serious governance and trust challenges later, while investing in it early makes executive approval and stakeholder trust far easier to secure.

Lesson 3: Beware “AI-itis” and the Vendors Who Profit From It

There is currently a widespread compulsion to apply AI to every problem regardless of whether it’s the right tool, and vendors eagerly encourage this impulse. Agencies at every level, from program offices to executive suites, are being pitched products that promise to solve everything at once.

The discipline to push back matters enormously. Before approving any AI initiative, leaders should be able to answer clearly: why AI and not a simpler solution like Python? If the problem could be addressed with a conventional data pipeline or a well-structured SQL query, then it probably should be. Reserving AI for problems that genuinely require it is not timidity — it’s sound engineering judgment.

Lesson 4: Build Internal Capability, Don’t Just Buy a Black Box

Many agencies enter vendor relationships expecting to learn, but they discover quickly that technology companies are in the business of building products, not training the next generation of government technologists. If your agency’s goal is long-term, self-sustaining AI capability, you cannot outsource the learning. Those that took the harder path of developing in-house builders have found themselves able to iterate rapidly, keep costs low, and grow agency capability organically over time.

Lesson 5: Prioritize Large Language Model (LLM) Agnosticism Over Vendor Convenience

When selecting a cloud or AI platform, agencies should resist the pull toward whichever vendor already manages their existing infrastructure. The more important criterion is whether the platform allows you to swap out or compare LLMs as the field evolves, rather than locking you into a single provider’s preferred model. Look specifically for platforms that support LLM-agnostic deployment within a controlled environment. This is a feature worth prioritizing even when it means a steeper initial learning curve.

Lesson 6: Establish a Governance Framework Before You Write a Line of Code

Agencies that have built successful AI programs did not improvise governance as they went. They established policy frameworks, risk assessment processes, and cross-agency coordination structures before the technical work began. These structures do not exist to block progress; they exist to surface risks early and ensure that decision-makers at every level have the information they need to make sound judgments. For states without existing AI governance infrastructure, building one or joining a coalition working on one should be considered a prerequisite for any serious enterprise AI initiative.

Lesson 7: Start Unglamorous, Build the Muscle Before the Showcase

The agencies with the strongest AI programs today didn’t start with LLMs. They started years earlier with output validation workflows and basic data quality improvement work. None of it was exciting, yet all of it was essential. This kind of capacity building gives staff on both the technical and program sides grounded intuition about where AI tools help and where they fall short. It also helps identify pilot projects with the right scope to take a first swing at using a retrieval augmented generation model or other AI tooling. Skipping this phase and jumping straight to complex implementation tends to reveal gaps at the worst possible moment.

Lesson 8: Choose Your First Pilot Team Deliberately

Not every program team is ready to be an AI pilot partner, and budget and organizational clout are poor selection criteria. The qualities that actually matter are: 1) a use case narrow enough that success can be clearly defined and measured, and 2) a team with a demonstrated willingness to try new approaches but walk away from them honestly if they don’t work. That second quality, comfort with productive failure, is rarer than it sounds and it is arguably more important than technical sophistication.

Lesson 9: Pre-Negotiate Your Exit Criteria With Leadership

One of the hardest things to do in government is shut down a project that isn’t working. Budgets get committed, reputations get attached, and inertia does the rest. Agencies that have navigated this well did something counterintuitive: before the pilot launched, they sat down with their executive teams and explicitly defined the conditions under which they would walk away. This is the discipline that makes genuine experimentation possible. When the conditions for stopping are agreed upon in advance, pulling the rip cord becomes a professional act rather than a political one and allows resources to be rescued before they’re wasted.

Lesson 10: AI Literacy Is a Training Problem, Not a Communications Problem

The dominant understanding of AI as “a better Google” is not ignorance; it’s a reflection of what most people have actually encountered. This creates a serious gap between what decision-makers think they’re approving and what technical teams are actually building.

Bridging this gap requires sustained investment in AI literacy training, not just communications. Staff need working vocabulary (e.g., AI vs machine learning, deterministic vs. probabilistic outputs, what a LLM actually does, why “hallucination” occurs), before they can meaningfully participate in governance validation or oversight. Budget for training should be included as a line item, not as an afterthought. When staff truly understand what’s being built, they provide the most valuable insights into what is working and what isn’t, helping to grade the successes and failures of the project with objectivity.

Lesson 11: Find the Champion Who Bridges IT and Programs

Across successful AI implementation, there is typically one person (often an informatics expert) who is rigorously committed to the mission, understands the technology well enough to translate it, and has the drive to convene the people who need to be in the room together.

Without this person, projects get outsourced siloed or quietly deprioritized. With them, collaboration across organizational boundaries becomes possible. Identifying and protecting this champion, giving them time, authority, and executive support, is one of the highest-leverage investments agency leadership can make.

Lesson 12: Understand Your Funding Risks Before You Start

State and territorial health agencies depend significantly on federal funding. For some, shifts in federal priorities, grant timelines, or political conditions can disrupt technology projects with little warning. Agencies that have experienced this firsthand describe significant project delays caused by uncertainty over whether grant funds could be spent and when. Before committing to vendor contracts or dedicated staff hires, be clear about the stability and timeline of the funding and build contingency plans into your project from the beginning, not as a response to crisis.

There is no shortcut for this work. The agencies making real progress have been building quietly for years, investing in staff, tolerating early failure, and approaching proposals with healthy skepticism and scrutiny. The good news is that the infrastructure and training required to increase your staff’s capacity to develop tools for themselves is more accessible than it has ever been, and growing every day. The key is in the willingness to build slowly, deliberately, and with genuine humility about how much there is still to learn.

The agencies that figure this out will not just build better surveillance tools. They will develop something more durable and foundational: organizational capacity to keep learning as the technology changes around them.

This post reflects perspectives gathered directly through peer learning and technical assistance activities. It does not represent official policy guidance from any federal state or territorial agency.

Reviewed by Tabatha Offutt-Powell, Vice President, Public Health Data Modernization and Informatics; and Greg Papillion, Senior Director, Public Health Partnerships and Innovation.