The Coalition for Health AI (CHAI), a US-based body focused on responsible artificial intelligence adoption in healthcare, has convened a new work group dedicated to cybersecurity issues arising from the use of AI systems in clinical and health-related settings. The initiative reflects growing concern within the healthcare industry over how AI tools, increasingly embedded in diagnostics, patient data management and administrative workflows, can introduce fresh vulnerabilities that traditional IT security frameworks were not designed to address.
CHAI has positioned itself as a convener bringing together healthcare providers, technology developers, researchers and policy stakeholders to develop shared guidance on trustworthy AI deployment. The formation of a dedicated cybersecurity work group signals that AI-specific security risks, ranging from data poisoning and model manipulation to vulnerabilities in third-party AI integrations, are being treated as a distinct priority rather than folded into generic cybersecurity policy discussions.
While the coalition has not publicly detailed the full roster of participating organizations or a specific timeline for deliverables, the move follows a broader pattern across the healthcare sector, where AI adoption has outpaced the development of security standards tailored to machine learning systems. Hospitals and health networks have increasingly relied on AI for tasks such as image analysis, predictive risk scoring and clinical decision support, expanding the potential attack surface for bad actors seeking to exploit weaknesses in algorithms, training data, or the infrastructure supporting these tools.
Why the Effort Matters Beyond US Borders
Although CHAI is a US-anchored coalition, the cybersecurity challenges it aims to address are not confined to American healthcare systems. Gulf healthcare providers, many of which have been investing heavily in AI-driven diagnostics, telehealth platforms and digital patient records as part of broader national digital health strategies, face comparable exposure to AI-specific security risks.
The UAE and other GCC states have prioritized healthcare digitization as a component of wider economic diversification and smart-nation agendas, with hospitals and health authorities across the region adopting AI tools for everything from radiology support to hospital operations management. As reliance on these systems grows, so does the importance of security frameworks that account for the unique ways AI models can be attacked or manipulated, distinct from conventional network intrusions or ransomware.
Industry observers note that international efforts such as CHAI’s new work group often inform standards and best practices that ripple outward, shaping vendor requirements and procurement expectations even in markets where the coalition itself has no formal presence. Gulf healthcare institutions that source AI diagnostic tools or clinical software from US and European vendors may find that security benchmarks developed through initiatives like this one eventually factor into contractual or regulatory expectations locally.
Cybersecurity in healthcare has become a growing concern globally, given the sensitivity of patient data and the potential for disruptions to have direct consequences for patient safety. Ransomware attacks on hospitals and data breaches involving medical records have already prompted regulators in multiple jurisdictions, including in the Gulf, to tighten data protection and health-sector cybersecurity requirements. The emergence of AI-specific threat vectors adds a further layer of complexity that healthcare cybersecurity teams, including those in the UAE and wider GCC, will need to factor into their risk management strategies.
CHAI has indicated that further details on the work group’s scope and outputs are expected as the initiative progresses, with the broader goal of establishing guidance that healthcare organizations can apply to secure AI systems without impeding the pace of innovation in patient care.


