Why governance in healthcare isn't optional
In healthcare, the consequences of an AI system that underperforms are felt directly. A matching algorithm that doesn't provide the patient with the right information, a model that quietly drifts from what it's supposed to do, or a process that can't show how a decision was made: behind each of these risks is a patient who experiences the consequences firsthand. Models simply make mistakes, which is why managing risk is crucial.
AI systems in healthcare are by nature subject to considerably stricter requirements than non-health related applications due to the data they encompass, and those requirements don't stop once a system goes live. They call for demonstrable control throughout the system's entire lifecycle.
From policy document to daily practice
For many organisations, translating legislation into workable processes is the hardest part. Writing a policy is one thing; getting it to land in the collaboration between legal and product is another. Who's responsible when a model gets updated? How do you make sure compliance isn't bolted on afterwards, but built into how teams build and manage AI?
That's exactly what Janiek Meppelink, General Counsel at myTomorrows, and Maarten Stolk, CEO of Deeploy, dig into during Data Expo: how legal and product collaborate on AI implementations, how to translate EU AI Act requirements into workable processes, and which governance structures do and don't scale as an organisation grows.
What does and doesn't scale
A risk classification on paper, or a one-off review by the compliance department, works fine for a single model. Once an organisation has multiple AI systems running in production at the same time, each with its own risk profile and its own team around it, that approach no longer holds. Governance that scales isn't about more documents, it's about continuous visibility into what a system is actually doing: monitoring that flags deviations, evidence that's collected automatically, and processes that grow with the organisation instead of trailing behind it.
That's also where an AI governance platform like Deeploy comes in: it enables continuous registration and monitoring of AI systems, including the audit trail that comes with it, so teams can demonstrate that a system is doing what it's supposed to do, and get an immediate signal when it isn't.
→ Want to hear how myTomorrows and Deeploy put this into practice?
Wednesday, 13:45 - 14:15, Lecture Hall 5: Janiek Meppelink (General Counsel, myTomorrows) and Maarten Stolk (CEO, Deeploy) share how they've put AI governance into practice in the session "Keeping control of AI at scale: Runtime Governance at Healthtech myTomorrows." The session is relevant for anyone responsible for, or working on, AI implementations, from legal and compliance to product and engineering.
This blog post is a contribution from Deeploy, the AI governance platform that lets organisations continuously register, monitor, and stay compliant across their AI systems and agents, even as they scale. Want to know more? Visit deeploy.ai or drop by the booth during Data Expo 2026 (September 9-10, Jaarbeurs Utrecht).
![]()