Multi-Year Investment Under Regulatory Constraint
The five-year AI budget the CFO approved has a single line that reads "ambient documentation platform, license, 2.4 million dollars." The chief health AI officer looks at it and knows the number is a fiction, not because it is too high but because it is missing four other numbers that dwarf it: the validation program that proves the tool works on this system's own population, the monitoring infrastructure that watches for drift and disparate performance after go-live, the governance apparatus that reviews and documents it, and the change management that gets twenty thousand clinicians to actually use it safely. The license is the visible tip. The rest is the iceberg. And every one of those hidden costs sits inside a regulatory environment whose deadlines are still moving. Funding a multi-year clinical AI program is the discipline of budgeting for the iceberg, sequencing the spend against rules that have not finished being written, and refusing to bet the entire program on one vendor or one unproven use.
The License Fee Is the Cheap Part
The single most expensive mistake in enterprise clinical AI budgeting is confusing the license fee with the cost. The license is what a vendor quotes and what a procurement team negotiates, and it is often the smallest line in the true total cost of ownership. The real cost of a clinical AI capability includes validation on your population before deployment, ongoing monitoring for drift and disparate performance after deployment, the governance structure that reviews and documents every tool, the disclosure and consent machinery that keeps you lawful across states, the integration and workflow engineering that embeds the tool in the EHR, the training that gets clinicians to a safe operating standard, and the audit and legal readiness that lets you prove all of it. A program funded as if the license were the cost will run out of money precisely where safety lives, and a safety-first transformation cannot afford to be broke in the validation line.
Consider the shape of the number. A tool with a modest annual license can carry a validation and monitoring burden many times larger, especially for a predictive model that must be checked for disparate performance across the populations the system serves and re-checked as the data shifts underneath it. The board that approves a program on the license number and is later asked for the monitoring budget experiences the second ask as a cost overrun, when in truth it was always part of the cost and was simply left off the page. The leader's job is to put the whole iceberg on the page from the start, even though the full number is less appealing than the license alone, because the alternative is a program that is underfunded exactly where it is most dangerous to be underfunded.
There is a further trap hidden in the license line itself, which is that it looks like a stable, known quantity while everything beneath it is variable and recurring. A license renews on a predictable schedule at a predictable price, so it feels like the safe part of the estimate. The costs it obscures behave in the opposite way. Validation scales with how many subpopulations you serve and how often the underlying data shifts. Monitoring scales with how many models are live and how consequential their outputs are. Governance scales with the size and complexity of the portfolio. Disclosure scales with how many states you operate in and how often their rules change. A budget anchored on the one line that does not move, while ignoring the several lines that move constantly, is not conservative. It is precisely backward, and it will surprise its owner every year that the program is alive.
The Five Hidden Cost Centers
It helps to name the hidden costs explicitly so they can be budgeted rather than discovered. First, validation: proving the tool performs on your population and workflow, not the vendor's benchmark, before it touches a patient. Second, monitoring: the standing infrastructure and staff time to watch for drift, disparate performance, and emerging failure modes after go-live, because a model that was safe at launch does not stay safe by default. Third, governance: the committee structure, the intake and retirement processes, the documentation, and the accountable owners that the accrediting-body guidance now effectively expects. Fourth, change management: the training, the workflow redesign, the clinician engagement, and the disclosure practices that determine whether the tool is used safely or worked around dangerously. Fifth, legal and audit readiness: the ability to produce, for a regulator, a surveyor, or a plaintiff, the record of what was validated, monitored, disclosed, and decided. None of these appear on the vendor quote. All of them are the cost.
The single most useful discipline for exposing these costs is to force every line into one of two buckets: one-time or recurring. A one-time cost is paid once to stand up a capability. A recurring cost is paid every year the tool remains live. Most budgeting failures come from misfiling a recurring cost as a one-time cost, because a one-time cost can be absorbed into an implementation project and forgotten, while a recurring cost must be carried in the operating budget forever. The table below shows how the five cost centers split. Notice that almost every cost center has a recurring component, and that the recurring components are the ones a license-based budget systematically misses.
| Cost center | One-time component | Recurring component |
|---|---|---|
| Validation | Initial validation on your population and workflow before go-live | Revalidation when data shifts, the model updates, or a new subpopulation is served |
| Monitoring | Standing up the monitoring infrastructure and dashboards | Ongoing staff time and compute to watch for drift and disparate performance every period |
| Governance | Designing the committee, intake, and retirement processes | The committee's continuing review, documentation, and accountable-owner time |
| Change management | Initial training and workflow redesign at rollout | Retraining as staff turn over, workflows evolve, and disclosure practices update |
| Legal and audit readiness | Building the record-keeping system and disclosure templates | Re-disclosure and re-documentation as state rules and intended-use boundaries move |
Read the right-hand column as the part of the iceberg that never surfaces on a vendor quote and never goes away. A leader who can point at that column and say which fiscal year owns each recurring line has a real budget. A leader who cannot has an implementation estimate wearing a budget's clothes.
The license fee is what you pay the vendor. The total cost of ownership is what it takes to run the tool safely: validation, monitoring, governance, change management, and audit readiness. Budget the first and you have bought a liability. Budget the whole thing and you have bought a capability.
Sequencing Against a Moving Regulatory Map
A multi-year program is funded and executed inside a regulatory environment that is still in motion, and pretending otherwise is how a program commits capital to a use case just before the rules change under it. The map has several moving pieces. The FDA regulates AI as a medical device, with more than 1,350 AI/ML-enabled devices authorized by early 2026, roughly double the 2022 count, and radiology dominating the authorizations; clearance defines an intended use, it does not promise safety in your workflow or your population. The ONC HTI-1 rule reshaped decision support: certified health IT had to meet the new Decision Support Intervention criteria by the end of 2024, with ongoing maintenance from January 2025, a USCDI v3 baseline by January 2026, and a predictive-DSI transparency regime that lets you demand source attributes for any AI in your certified EHR. HTI-2 is still in development. State disclosure law is a live patchwork: California's AB 3030 in force since January 2025, Texas TRAIGA effective January 2026, and Colorado's regime evolving toward a 2027 effective date. And the Joint Commission and CHAI RUAIH guidance, released September 2025, is voluntary today but positioned to inform future accreditation.
The practical consequence is that investment must be sequenced against regulatory readiness, not just against clinical value or vendor availability. A use case whose regulatory footing is settled, ambient documentation with a mature human-in-the-loop workflow and clear state-disclosure obligations, is a safer early investment than a use case sitting on rules that are still being written. Sequencing does not mean waiting for perfect certainty, which will never come; it means putting the capital that is hardest to reverse behind the cases whose rules are most settled, and keeping the cases with unsettled rules smaller, later, and structured so that a regulatory change is a course correction rather than a write-off. A leader who sequences well spends where the ground is solid and keeps a light footprint where it is still shifting.
The Timeline Is a Budgeting Input, Not Just a Compliance Note
Leaders tend to file regulatory dates in a compliance binder and financial dates in a budget model, as if the two do not touch. They touch constantly. A state disclosure requirement that takes effect in the middle of a rollout is a change-management and workflow cost that has to be funded in that fiscal year, not discovered in it. An ONC maintenance obligation that begins after an initial certification deadline is a recurring line, not a one-time project. An FDA intended-use boundary that a use case is quietly drifting past, using a cleared tool for something adjacent to its authorized purpose, is a legal exposure that no license fee accounts for. The discipline is to lay the regulatory calendar and the budget calendar on the same timeline and read them together, so that every rule with a date has a funded owner and every funded initiative has a regulatory status. A program that budgets time and money against a single, honest timeline is far harder to surprise than one that keeps two calendars that never meet.
This is also where the difference between a one-time cost and a recurring cost becomes financially decisive. Validation is not only a pre-deployment event; a model that drifts must be revalidated, and a rule that changes may require re-disclosure and re-documentation. The multi-year program that treats validation, monitoring, disclosure, and governance as recurring operating costs, funded every year, is modeling reality. The program that treats them as one-time implementation costs is modeling a fantasy in which the tool, the population, and the law all stand still. They do not. Budgeting for the moving map means budgeting for the fact that the map keeps moving, and building a program flexible enough to absorb the next deadline without a crisis and the next rule without a write-off.
Named Regimes as Sequencing Inputs
Sequencing gets concrete only when you attach the moving pieces to specific cases. Take three examples and treat each regime as a sequencing input rather than a compliance footnote. First, the FDA intended-use boundary. A cleared imaging tool authorized for one intended use is a settled foundation for exactly that use, so heavy capital there is defensible; but the same tool pointed at an adjacent, unauthorized purpose is a legal exposure that no license fee covers, and that adjacency should be sequenced late, small, and only after the intended-use question is resolved. Treat clearance as defining a lane, not a promise of safety in your lane. Second, the ONC transparency regime. Because certified health IT had to meet the Decision Support Intervention criteria by the end of 2024, with maintenance obligations running from January 2025 and a USCDI v3 baseline by January 2026, a case that leans on the predictive-DSI source-attribute transparency, the nutrition-label-style facts you can now demand for AI in your certified EHR, sits on relatively firm ground and can be sequenced earlier. Third, the state disclosure patchwork. A case deployed only in a state whose disclosure rule is already in force, such as California under AB 3030 since January 2025, has a settled disclosure obligation you can build and fund now; the same case expanding into Texas under TRAIGA from January 2026, where the attorney general can seek penalties in the ten-thousand to two-hundred-thousand-dollar range, or into a Colorado regime still evolving toward a 2027 effective date, carries disclosure obligations you must fund as they arrive. Verify each of these dates and figures against the primary source before you repeat them; do not repeat them blindly.
The pattern across all three is the same. Where the regime is settled, you can commit hard-to-reverse capital and build permanent infrastructure. Where the regime is still moving, you keep the footprint light and the commitment reversible, so that the next deadline is a scheduled expense and the next rule is a course correction. Sequencing is not a legal exercise bolted onto a finished budget. It is the order in which the budget spends, chosen so that the program is spending most heavily exactly where the ground is most solid.
Do Not Bet the Program on One Bet
The other way a multi-year program dies is concentration: betting the whole thing on one vendor or one unproven use case. Single-vendor concentration is seductive because it simplifies procurement, integration, and the relationship, and vendors work hard to make it comfortable. It is also how a health system ends up with its entire clinical AI capability hostage to one company's roadmap, pricing power, security posture, and survival. The obligation to verify, disclose, and stay accountable never transfers to that vendor no matter how deep the integration, but the system's ability to change course does erode with every process built exclusively around one platform. A resilient program keeps the operating model, the governance, the validation standard, and the accountability structure vendor-independent, so that a tool can be swapped without rebuilding the capability. The capability is the asset; the vendor is a supplier to it, and a program that inverts that relationship has quietly handed its future to a third party.
Single-use-case concentration is the same failure in a different dimension: pouring the program's credibility and capital into one unproven, high-visibility clinical use, so that if it stumbles, the whole transformation stumbles with it. The disciplined alternative is a portfolio. Fund a mix of settled, high-value, lower-risk cases that reliably return value and build organizational muscle, alongside a smaller, contained set of higher-risk, higher-reward cases run as genuine pilots with real evidence gates. The portfolio protects the program in both directions: the reliable cases keep value flowing and trust intact while the ambitious cases are still proving themselves, and no single failure is large enough to take the whole program down. Betting everything on one vendor or one moonshot is not boldness; it is fragility dressed as conviction.
The Portfolio Matrix and Evidence Gates
A useful way to hold the portfolio in mind is a simple matrix with two axes: how settled the regulatory footing is, and how proven the clinical value is. Cases in the settled-and-proven quadrant, ambient documentation with a mature human-in-the-loop workflow being the canonical example, earn the largest and most durable investment; they return value reliably and build the organization's validation and monitoring muscle. Cases that are settled but not yet proven, or proven but not yet regulatorily settled, get contained pilot funding behind an evidence gate. Cases that are neither settled nor proven get, at most, a small exploratory allocation, and often nothing at all until one axis moves. The matrix is not a scoring gimmick; it is a way to make sure the capital is weighted toward the quadrant where both the rules and the results are known, and that the exciting but unproven quadrant cannot quietly consume the program.
The evidence gate is what keeps a pilot honest. A genuine gate is a decision defined in advance: before a contained pilot can scale, it must clear specified thresholds on your own validation, show acceptable performance across the subpopulations you serve, demonstrate that monitoring catches the failure modes you worried about, and confirm that the disclosure and documentation obligations are met for every state in scope. A pilot without a gate is not a pilot; it is a slow, unmonitored launch. The gate is also a budgeting instrument: it is the point at which the program decides whether to convert exploratory dollars into durable capital or to stop and preserve the option. Portfolios protect programs only when the gates are real, because a gate that always opens is not a control, it is a formality that lets a single ambitious case grow until it is load-bearing after all.
A Worked Example: Two Budgets
Two health systems fund three-year clinical AI programs of similar size. System A builds its budget from vendor quotes: three platforms, their license fees, an implementation line, and a training line, summed into a clean number the board approves. There is no dedicated validation budget, because the vendors supplied benchmark accuracy and that seemed sufficient. There is no standing monitoring budget, because no one modeled the cost of watching for drift. Governance is an unfunded committee that meets when it can. The whole program is anchored on one flagship vendor whose platform threads through everything. Year one looks triumphant. Year two brings the reckoning: a predictive model is found to underperform for a subpopulation the benchmark never represented, there is no monitoring data to say when it started, remediation is unbudgeted, and because the flagship vendor is load-bearing across the program, renegotiating or replacing it would unwind half the portfolio. The program did not fail because the technology was bad. It failed because the budget was a fiction and the bet was concentrated.
System B builds its budget from total cost of ownership and sequences against regulatory readiness. Each use case carries its own validation, monitoring, governance, change-management, and audit lines, so the board sees the real number and funds it as the cost, not as a series of overruns. Capital is weighted toward settled cases like ambient documentation, with smaller, contained funding for a higher-risk predictive pilot held behind an evidence gate. Governance, validation, and accountability are built vendor-independent, so no single supplier is load-bearing. When the same subpopulation issue appears in System B's predictive pilot, monitoring catches it early, the remediation is already budgeted, disclosure and documentation are in place, and because the case was contained and the operating model was vendor-neutral, the fix is a course correction, not a crisis. Same technologies, same regulatory environment, opposite resilience. The difference was that System B budgeted the iceberg, sequenced against the rules, and refused the concentrated bet.
Put the two postures side by side and the divergence is not a matter of one system being smarter in the moment. It is baked into the structure of the budget on day one. System A's spreadsheet has three vendor rows and two supporting rows and sums to a confident total. System B's spreadsheet has, for each case, a validation row, a monitoring row, a governance allocation, a change-management line, and an audit-readiness line, with the recurring lines projected across all three years. System B's total is larger and less comfortable, and that discomfort is the entire point: it is the honest picture, and it is the only picture that leaves money in the account when the model drifts. The two systems did not diverge when the failure appeared. They diverged when they decided what a budget was.
A Worked Total-Cost-of-Ownership Breakdown
To make the iceberg concrete without pretending any single number is universal, walk through an illustrative TCO for one predictive case over its first three years. The figures below are round, illustrative placeholders chosen to show proportion, not benchmarks to quote; every organization's numbers differ, and you should build your own from your own quotes and staffing costs. What matters is the shape: how small the license is relative to the whole, and how much of the whole is recurring rather than one-time.
| Line item | Type | Three-year illustrative share |
|---|---|---|
| Software license | Recurring, predictable | The visible tip, and the smallest major line |
| Initial validation on your population | One-time | A substantial pre-deployment block |
| Revalidation and drift response | Recurring | Grows with the number of models and data shifts |
| Monitoring infrastructure and staffing | One-time build, recurring run | Often rivals or exceeds the license over three years |
| Governance and accountable-owner time | Recurring | Scales with portfolio size and complexity |
| Integration and workflow engineering | Mostly one-time | Front-loaded at rollout, with maintenance after |
| Training and change management | One-time launch, recurring refresh | Recurs with staff turnover and workflow change |
| Disclosure, consent, and audit readiness | Recurring | Rises with the number of states and rule changes in scope |
The lesson of the breakdown is not any specific ratio. It is that the license, the one line a procurement team fixates on, is a minority of the true cost, and that the majority of the true cost recurs. A board shown only the license line is being shown the least representative number in the entire model. When a leader can present this breakdown, splitting one-time from recurring and projecting the recurring lines across every year of the program, two things become impossible: the false comfort of a license-only total, and the later ambush in which a necessary safety line arrives disguised as an overrun. The breakdown is the antidote to both, and building it is the first concrete act of funding a capability rather than a tool.
Ask of any multi-year AI budget: which lines recur, and which fiscal year owns each one? If the answer is only the license, the budget is a fiction. If every recurring safety line has a year and an owner, the budget is real.
Funding the Capability, Not the Tool
The deepest reframe of enterprise AI budgeting is that you are not funding tools; you are funding a durable capability that outlives any specific tool. Tools depreciate and get replaced every few years; the validation program, the monitoring infrastructure, the governance apparatus, and the trained workforce are assets that compound. A dollar spent building a reusable validation and monitoring capability pays off across every future tool that flows through it, while a dollar spent only on a license buys a tool that will be obsolete before the depreciation schedule ends. This is why the multi-year framing matters: the capability is built over years and amortized across a portfolio, and the systems that fund it that way end up with a lower true cost per safely-deployed use case than the systems that keep buying tools one license at a time and rediscovering the hidden costs each time.
It is also why regulatory constraint, properly understood, is not only a limit but a design input. A program built to satisfy the ONC transparency regime, the FDA intended-use discipline, the state disclosure patchwork, and the accrediting-body guidance is a program built to be defensible, and defensibility is durable value. The leader who treats regulation as an obstacle to route around builds a fragile program that a single rule change or a single survey can break. The leader who treats regulation as the specification the capability must meet builds something that bends with the rules instead of breaking against them. Fund the capability, budget the whole iceberg, sequence against the moving map, and spread the bet, and a multi-year clinical AI program becomes what it should be: not a gamble on a vendor, but an institution's durable, defensible ability to adopt each new tool safely, for years, without betting itself each time.
Key Takeaways
- The license fee is the cheap part; the total cost of ownership includes validation, monitoring, governance, change management, and legal and audit readiness, and a program funded as if the license were the cost runs out of money exactly where safety lives.
- Name the five hidden cost centers explicitly so they can be budgeted rather than discovered: validation on your population, standing monitoring for drift and disparate performance, governance, change management, and audit and legal readiness. None appear on a vendor quote; all of them are the cost.
- A multi-year program is funded inside a moving regulatory map: FDA device authorizations (1,350-plus by early 2026, clearance is intended-use not workflow safety), ONC HTI-1 DSI and predictive-DSI transparency, a state disclosure patchwork (AB 3030, TRAIGA, evolving Colorado), and voluntary RUAIH guidance likely to inform accreditation.
- Sequence investment against regulatory readiness: put the hardest-to-reverse capital behind cases whose rules are most settled, and keep cases with unsettled rules smaller, later, and structured so a regulatory change is a course correction, not a write-off.
- Do not bet the program on one vendor: keep governance, validation, and accountability vendor-independent so a tool can be swapped without rebuilding the capability. The capability is the asset; the vendor is a supplier to it.
- Do not bet the program on one unproven use case: fund a portfolio of settled, value-returning cases alongside a smaller, contained set of higher-risk pilots behind evidence gates, so no single failure takes the whole program down.
- The obligation to verify, disclose, and stay accountable never transfers to a vendor no matter how deep the integration, but a system's ability to change course erodes with every process built exclusively around one platform.
- You are funding a durable, defensible capability, not tools; the validation, monitoring, governance, and workforce assets compound across every future tool, and regulation treated as the specification the capability must meet produces something that bends with the rules instead of breaking against them.
Skill.re