As 2026 begins, prior authorization is facing a credibility test. AI-driven automation has been promised for years, but recent developments show the industry is finally asking the harder questions: Is it accurate? Is it explainable? Can it be trusted at scale?

January brought a wave of activity around those concerns — from state reforms tightening oversight to new partnerships pushing real-time integration, and research highlighting the risks of moving too fast without the right guardrails.

"The prior authorization landscape is maturing rapidly. Speed matters, but buyers are increasingly focused on clinical accuracy, transparent decision-making, and regulatory alignment."

— Daniel Friedman, CEO, Ethermed

State Reforms Are Accelerating

Three states made significant moves this month, each tightening requirements around prior authorization timelines and accountability.

Massachusetts is advancing reforms to reduce administrative burden and speed up authorization decisions. The focus is on measurable outcomes. Providers expect to see actual reductions in delays, not just policy statements.

New York proposed reforms that tighten PA timelines and increase payer accountability. As state-level expectations rise, rapid rule updates and automated compliance reporting are becoming essential capabilities.

Alaska passed new legislation requiring PBM licensing and expanding PA rules. The law increases transparency and standardization, particularly for PBM-managed PA processes.

These are not isolated efforts. State reforms are setting the pace for what payers and providers must be able to deliver operationally, and they are not waiting for federal timelines.

Responsible AI Is Becoming the Standard

The conversation around AI in prior authorization is shifting. Governance, explainability, and risk management have become central concerns.

Stanford researchers published commentary this month highlighting persistent risks in AI-driven prior authorization: bias, error amplification, and lack of explainability. Without proper validation and oversight, automation can make existing problems worse.

At the same time, Deloitte's latest survey found that 93% of health plan executives expect AI to ease prior authorization friction, but they cite governance and integration as the primary barriers to adoption. Confidence is high, but so is caution.

Across the industry, responsible AI is emerging as a core requirement. Organizations are looking for systems that can demonstrate transparent logic, audit trails, and alignment with regulatory expectations.

Real-Time Integration Is the New Expectation

Providers are increasingly expecting prior authorization to happen inside their existing clinical workflows, without separate portals or manual handoffs. The question has shifted from "Can you automate this?" to "Can you do it invisibly, while we work?"

This expectation is reshaping the market. Embedded solutions that integrate directly into the tools clinicians already use are becoming the standard. Systems that require new logins, context switching, or process changes are falling out of favor.

The shift reflects a broader reality: prior authorization needs to disappear into the background, handled automatically as part of the normal care delivery process.

Policy and Oversight Continue to Tighten

On the federal side, the House Health Subcommittee held a hearing on H.R. 6361, which would restrict CMS from implementing AI-driven PA models in traditional Medicare without additional safeguards. The scrutiny is real. Vendors will need to show human oversight, transparent decision logic, and defensible governance structures.

Meanwhile, HHS Office for Civil Rights released updated guidance emphasizing security hygiene — patching, disabling unnecessary services, and aligning with NIST standards. As prior authorization systems handle more sensitive data, security posture is becoming a competitive differentiator.

NIST also published an overview of verifiable digital credentials, laying the groundwork for more robust identity verification in PA workflows. As interoperability standards mature, identity assurance — provider credentials, delegated authority, patient consent — will play a larger role in how authorization decisions are validated and shared.

Closing Thought

2026 is shaping up to be the year AI in healthcare has to prove itself. Organizations are looking for systems that are fast, transparent, clinically grounded, and built to withstand regulatory scrutiny.

At Ethermed, that is exactly where we have focused: automation that does not just work quickly, but works correctly, with the documentation and auditability that compliance and trust require.

The bar is rising. We are ready for it.