Every major digital health company building in 2026 is either using AI tools in clinical workflows or planning to. Clinical documentation AI, diagnostic support algorithms, patient triage chatbots, prescribing recommendation engines — the category is exploding. And almost none of the founders deploying these tools have asked a question that sits at the center of CPOM doctrine: when the AI makes a clinical recommendation, who is practicing medicine?

The answer matters because CPOM prohibits non-physician entities from practicing medicine or directing medical care. An AI tool is owned by a corporate entity — typically the MSO in an MSO-PC structure. If that AI tool is making or substantially directing clinical decisions, the non-physician corporate entity behind it may be practicing medicine through an algorithm. That is a CPOM violation regardless of whether a physician signs off at the end of the workflow.

This analysis does not mean all AI in healthcare creates CPOM risk. It means founders need to understand where the line is — and there is a clear framework for doing that.

The Core CPOM Question Applied to AI

CPOM doctrine prohibits corporations from practicing medicine. Practicing medicine means making clinical decisions about patient diagnosis, treatment, and care. When we apply this to AI, the analysis turns on a simple question: is the AI tool making clinical decisions, or is it giving licensed physicians better information with which to make their own clinical decisions?

An AI system that analyzes a patient's lab results and tells a physician "this pattern is consistent with Type 2 diabetes, and based on current guidelines, metformin is typically the first-line treatment" is giving the physician information. That physician still decides whether to diagnose, what to prescribe, and whether the guidelines apply to this specific patient.

An AI system that automatically sends a prescription order to the pharmacy when a patient's intake form scores above a certain threshold — with the physician's role limited to not intervening within a 4-hour window — is making clinical decisions. The physician's role is inverted from independent judgment to passive ratification. That is the CPOM risk zone.

Three AI Use Cases and Their CPOM Risk Profile

Risk Level: Low — AI-Assisted Documentation

Clinical documentation AI — ambient scribing, automated SOAP note generation, coding assistance — creates minimal CPOM risk. These tools observe or process physician-patient interactions and generate documentation. The physician reviews and approves every note. No clinical decision is being made by the AI; it is summarizing decisions the physician already made.

Best practice: ensure the physician attestation workflow is genuinely substantive. A physician who signs 400 AI-generated notes per day without reading them is creating malpractice risk more than CPOM risk — but a workflow designed to make substantive review impractical should be redesigned.

Risk Level: Moderate — AI-Driven Patient Triage and Routing

Triage AI that determines which patients are routed to which clinical pathways sits in a gray zone. If the AI is sorting patients into waiting queues or scheduling slots, that is administrative. If the AI is determining which patients are eligible for specific treatments or prescriptions based on intake criteria, that is clinical — and the CPOM analysis sharpens.

The key variable is reversibility and override. Can the physician reviewing the case actually change the AI's routing decision without the platform fighting back? Is the physician who sees the patient given full clinical context, or only the context the triage algorithm selects to show? A triage AI that pre-screens and limits what physicians see is more controlling than one that provides full information and a recommended pathway that the physician can accept or override.

Risk Level: High — AI-Generated Treatment Recommendations

AI systems that generate specific treatment recommendations — prescribing suggestions, dosing algorithms, diagnostic conclusions — carry the highest CPOM risk when those recommendations are designed to be followed rather than reviewed. This is the fastest-growing category of clinical AI, and it is the one that regulators are beginning to examine most carefully.

The risk is compounded when the recommendation engine is owned and controlled by the MSO (as it almost always is in a digital health platform) rather than the PC. Under that structure, a non-physician corporate entity's algorithm is directing the clinical decisions of the physician PC — which is exactly what CPOM prohibits, substituting "the algorithm" for "the corporation."

The CPOM question for AI is not whether a physician is present in the workflow. It is whether the physician's judgment is genuinely independent of the AI's recommendation — or whether the platform's design makes physician override impractical, unlikely, or professionally penalized.

Colorado's AI Act: The First Hard Deadline

Colorado is the first state to create explicit, enforceable obligations for AI systems used in high-risk decisions — including healthcare. The Colorado AI Act took effect for general-purpose AI in August 2025, with enforcement for high-risk AI beginning June 30, 2026.

For healthcare companies operating in Colorado, the law requires:

These requirements are operationally significant for any Colorado digital health company using AI in patient-facing workflows. They also create a compliance documentation trail that regulators could use in future CPOM analysis — if your records show the AI making decisions that physicians consistently follow without deviation, that is the kind of evidence that supports a CPOM violation finding.

Across the Country: The Broader AI Regulatory Landscape

Colorado is not alone. By 2025, more than 250 AI-related healthcare bills had been introduced across 34 states. Most have not yet passed, but the legislative energy is clear. The Manatt Health AI Policy Tracker identified dozens of active state-level AI healthcare bills covering transparency requirements, bias audits, and clinical AI governance frameworks.

Federal movement has been slower, but the FDA has issued guidance on AI-based Software as a Medical Device (SaMD), which covers AI tools that meet the definition of a medical device. For clinical AI that crosses into diagnostic territory, FDA SaMD guidance and CPOM analysis may both apply simultaneously — creating a dual compliance obligation.

How to Structure AI Clinical Tools for CPOM Compliance

Govern AI Through the PC, Not the MSO

Clinical AI policies — what the AI recommends, when, and what physicians are expected to do with those recommendations — should be developed and periodically reviewed by the PC's physician leadership. The MSO can build the technology. The PC should govern how it is used in clinical contexts. Document this governance in writing, with dated records of physician review and approval of AI use policies.

Design for Genuine Override, Not Nominal Override

Every AI clinical recommendation workflow should be designed so that physician override is the expected norm, not the exception. That means making override options prominent and easy to use, not hidden behind multiple confirmation screens. It means not tracking physician override rates in ways that create peer pressure against deviation. It means ensuring physicians have full patient information, not just what the algorithm selected to display.

Document the Physician-in-the-Loop

For every AI recommendation that touches clinical care, your medical records should show that a specific licensed physician reviewed the recommendation and made an independent clinical judgment. That record cannot be satisfied by a passive timeout — a physician who failed to respond within four hours is not the same as a physician who reviewed and agreed.

Put AI Use Policy Language in Your MSA

Your MSA between the MSO and PC should explicitly address the use of AI clinical decision support tools. The agreement should specify that the MSO provides AI infrastructure and the PC governs AI clinical use policy, that physicians are not required to follow AI recommendations, and that clinical outcomes related to AI recommendations are the clinical responsibility of the PC's physicians. This language creates the governance paper trail that supports a substance-over-form CPOM analysis in your favor.

Conduct a State-by-State AI Compliance Mapping

Beyond CPOM, AI clinical tools may trigger state-specific telehealth AI transparency requirements, medical practice act provisions, or licensing board guidance. Colorado's requirements are the most developed, but over a dozen states have enacted or are considering similar frameworks. If you operate in multiple states, map your AI tools against each state's current requirements.

The Bottom Line for AI-Enabled Health Companies

The question is not whether to use AI in clinical workflows — AI tools make healthcare more efficient, more accurate, and more accessible, and the competitive pressure to deploy them is real. The question is how to deploy them within a structure that keeps clinical judgment genuinely in physician hands.

Founders building AI-enabled health platforms need to think about their AI tools the same way they think about their MSO-PC structures: the form matters, but the substance matters more. An AI system that nominally allows physician override but practically routes physicians toward a predetermined clinical conclusion is as much a CPOM problem as an MSO that nominally says the physician controls the PC but practically directs every clinical decision.

Build AI that supports physician judgment. Document the governance trail. Apply CPOM analysis to your AI architecture the same way you applied it to your corporate structure.