The VA Trustworthy AI Framework The framework described below consists of six principles, which are illustrated in the outer hexagons in the figure to the left. These principles were selected and refined by examining relevant existing trustworthy AI frameworks and aligning elements to the mission and values of VA. Details on the construction of this framework can be found in the Supplemental Appendix.

WASHINGTON, DC — VA policy to minimize the barriers preventing employee use of artificial intelligence (AI ) might be resulting in higher risks for veterans, according to a recent VA Office of the Inspector General report. An investigation found that the agency failed to acknowledge the extent to which providers are using AI chat tools in patient care.

While the tools are considered minimally risky for veterans, their use in the clinical field qualifies them as “high-impact” the report argued. OIG considered the danger significant enough that it released an advisory to VA physicians in February based on its preliminary findings.

In hearings before Congress, VA leaders have described VA’s emerging policy to “aggressively deploy” AI technology within the department. This is in line with Office of Management and Budget guidance released in April 2025 that directed agencies to “remove unnecessary and bureaucratic requirements that inhibit innovation and responsible adoption.”

According to one VA AI leader interviewed by OIG for the report, this guidance has been interpreted as a directive to “push risk management down to the lowest reasonable level.”

The OMB memorandum requires agencies to identify high-impact use cases and “implement minimum risk management practices” for employee use of that technology. When it comes to VA, an AI project is considered high-impact when it serves “as a principal basis for decisions or actions with legal, material, binding or significant effect on human health and safety.”

For example, VA’s Ambient AI Scribe, which listens to clinical visits and drafts medication notes, is considered a high-impact tool. Currently in the pilot stage, project safeguards include: conducting predeployment testing; completing AI impact assessment, conducting ongoing monitoring for performance and potential adverse impacts; ensuring adequate training; providing additional human oversight; offering consistent remedies and appeals; and incorporating feedback from end users and the public.

VA GPT and Microsoft Copilot Chat—both broadly available to VA staff—have not been classified high-impact. However, OIG’s investigation found that both are being used in clinical-care situations. Of 135 prompts shared on an AI-focused VA Teams site, 79 were identified as clinical in nature (56 for clinical notes, 17 for summarization and 6 for another purpose).

Studies of generative AI use in the medical field have found that poor prompt technique can result in output errors such as hallucinations—when an AI system presents false information as factually accurate. This can lead to incorrect information being placed in the patient record that impacts patient diagnosis and management.

The investigation also found that the Joint Patient Safety Reporting system used to capture medical errors, close calls and near misses did not have an AI-specific labelling process.

“Without a way to tag or trace AI-generated documentation, VA cannot readily detect patterns, investigate AI-generated safety events or implement quality improvement processes that may lead to safer prompting,” the report stated.

VA has responded to OIG’s findings by working with the Defense Health Agency to enable tagging of AI-related events. It’s also taken steps to increase communication between its AI-focused programs and the National Center for Patient Safety (NCPS).

According to VA, NCPS acknowledges the need to recognize when AI is a contributing factor during root causes analysis and will develop an education campaign to encourage recognition and reporting of AI-related patient safety events.

As for adverse events that have already occurred, a search by OIG investigators of the Joint Patient Safety Reporting system found no mentions of AI, and according to the report VA does not have a means of identifying records created with AI to retroactively identify potential patient safety concerns.

“It’s very tricky,” one NCPS AI lead told investigators. “We don’t have the best answer yet.”

According to VA, as of January 2026, the agency had 367 AI use cases in its inventory, with 253 existing within VHA. Of those, 68% were considered high-impact.