Back to blog

The hospital owns the model

29 July 2026· 7 min readaihospitalspolicy
The hospital owns the model

On Tuesday, Sheba Medical Center, Israel's largest hospital, became the first hospital outside the United States to join OpenAI's healthcare programme: early access to ChatGPT Health, encrypted and built for hospital security requirements; genuinely impressive. Read the announcement twice, though, and one line stands out. Sheba will integrate its own clinical protocols, treatment pathways and institutional guidelines into OpenAI's models. The hospital's accumulated judgement, the thing that makes it Sheba, moves into an asset somebody else owns.

Three days earlier, the industry had loudly declared the opposite. On Friday, Jensen Huang used his first ever post on X to share a letter urging Washington to avoid "premature restrictions" on open-weight models. His summary of why: open models "enable sovereignty". By Sunday the post had cleared eleven million views and the signatory list had doubled from 25 companies to 50, OpenAI and Google among the late arrivals. You have seen the takes by now, so I will spare you number 2,101. The cynics' version fits in one line anyway: free models sell GPUs, or as Joel Spolsky wrote in 2002, "smart companies try to commoditize their products' complements". An argument can be self-interested and still be correct.

The interesting thing is not the letter. It's that both bets, rent and own, were placed in public in the same 72 hours. Renting intelligence has stopped being the only option, and the moment something becomes a choice, a board can be held to it.

Residency is not sovereignty

Most European health organisations think geography settles this: the data sits in Frankfurt, the DPO signs, everyone moves on.

Residency is a claim about where the servers are. Sovereignty is a claim about whose law can reach them. The US CLOUD Act lets American authorities compel an American company to produce data held on European soil, so an "EU region" on a US cloud is a location, not a jurisdiction. For most businesses that's academic. For a hospital, a bank or a public authority, it often isn't.

You probably saw the Hugging Face story this month: attacked by OpenAI models that had escaped a training environment, the team first asked a frontier closed model for help, and its guardrails refused, unable to work out that Hugging Face was defending itself. They contained the attack with an open-weight Chinese model instead. Their lesson: "have a capable model you can run on your own infrastructure vetted and ready before an incident."

Transpose that to a ward. A model that declines a legitimate question about an overdose threshold, or a paediatric dose at the edge of the formulary, hasn't made anyone safer. It has imported a caution calibrated for a consumer chatbot into a clinical decision, and nobody in the building can change it. Sheba's plan to write its protocols into a rented model has the same shape: the judgement is yours, the off-switch isn't.

The receipts now come from buyers

On the HLTH Europe show floor in Amsterdam last month, sovereignty had already stopped being a disclaimer and become a pitch: Datum Agent selling EU-hosted GPUs with patient data processed inside EU jurisdiction, Berlin's aiomics running its verification layer across more than 30 German hospital sites. What changed this past week is who is holding the receipts.

Ireland stalled a Microsoft procurement potentially worth €1 billion after sovereignty questions in parliament. Airbus is migrating 70 critical applications from AWS to France's Scaleway. In healthcare specifically, the French government is moving its national Health Data Hub off Azure to the same sovereign provider, US clinical platform OpenEvidence has suspended service in Europe over EU AI Act uncertainty, and Mistral is building a healthcare business on exactly this gap: hospital pharmacists already run its open-weight models inside their own server perimeters, on their own hardware.

Even the holdouts had to declare themselves. Anthropic, one of the letter's two conspicuous absences alongside Amazon, published a formal position on Monday: it has "never advocated for a ban on open-weights models" and wants mandatory safety testing of all sufficiently capable models instead, open and closed. And on the vendor side of the rent-or-own question, US startup actAVA launched a trillion-parameter healthcare-specific model with a pitch that could have been this edition's title: hospitals should "stop renting generalized AI", because roughly 90 percent of enterprise workloads can run on open-weight or commodity models.

None of this requires frontier intelligence, and most hospital work has never been at the frontier. The capability gap keeps thinning regardless: Moonshot's Kimi K3, released on 16 July, beats leading American systems on some benchmarks while still trailing the frontier, and this week someone fine-tuned a 9-billion-parameter open model for $500 and beat frontier systems on a narrow review task.

The caveats I'd put in the same board pack

Open weight is not open source. You get the weights, not the training data or the recipe, so you can host and tune a model without auditing how it was built. This month a researcher poisoned an open-weight model for under $100. A genuine risk, and not the clean argument for closed models it looks like: nobody can show a proprietary model wasn't poisoned either, because nobody outside is allowed to check.

Running a model of this class is also not a laptop job. Inference operations, batching and compliance logging are real engineering, and "we downloaded the weights" is the start of a project, not the end. Sovereignty is a spectrum, and your own infrastructure sits further along than an API key.

So what

For a CIO this turns a budget line into an ownership decision with a jurisdiction attached. For a DPO it changes "where does the data live" into "whose court could order it moved". For clinicians it decides whether the tool answers at 3am or refuses. For patients it's whether their record is governed by the hospital's law or somebody else's foreign policy. And for vendors, the sovereignty claim is about to be audited rather than admired, with the EU AI Act's enforcement powers over general-purpose models live from 2 August: this Sunday.

Here's the test I'd run before summer is out. Pick one workflow that never needs frontier intelligence: discharge letters, referral triage, turning a consent form into plain language. Run it twice: once on your current vendor, once on an open-weight model on infrastructure you control. Compare quality honestly, then compare what each costs you in dependency. If your hospital already bought the wrong AI, this is the cheapest way to find out.

Then ask your vendor one question and time the answer: if we asked you to move this on-premise next year, could you?

There's a particular fan noise my laptop makes when it's thinking without the internet. I get it when I run small open-weight models locally: no API key, no network call, nothing leaving the machine. The answers come slower and a shade less polished than a frontier model on a good day. That was never the point. The point is that the weights sit on my own disk, and nobody outside the room decides what it will and won't answer. It's also why I'm working with the Isaree Clinical Innovator Community, a European team building clinical agents on open-weight models that run on the clinician's own device. This week that stopped being a hobbyist's comfort and became one side of a choice your board will have to defend. Sheba just picked the other side. Which one is your hospital on?

💥 May this inspire you to find out whether your AI strategy is a purchase or a tenancy.