At Vega Health, we’ve assembled a network of collaborators including team members, advisors, investors, and allies with decades of experience making healthcare technology actually work for clinicians and operators. Vega Conversations is a series highlighting their perspectives: what brought this group together, what we’re doing differently, and how we believe AI can structurally improve healthcare.
Keo McKenzie has spent her career at the intersection of law and emerging technology. Because of her science background in undergrad, Keo first went into intellectual property law, working in London and Dallas before transferring to Washington, D.C. to work alongside her firm’s FDA regulatory team. It was then, around 2017, as FDA was pioneering new approaches to regulating software as a medical device (SaMD), that Keo became interested in the emerging space.
After leading SaMD and global clinical trials across more than 100 countries in-house at Apple, Keo moved back into private practice just as ChatGPT became freely available to consumers. The need for legal counsel on the use of generative AI and AI governance exploded. She’s now a partner at Baker & McKenzie with a practice focus on AI and digital health matters.
She’s also a Vega Health advisor. She met co-founder and CEO Mark Sendak through the Health AI Partnership (HAIP), a multi-stakeholder collaborative empowering healthcare organizations to use AI safely, effectively, and equitably through community-informed, up-to-date standards.
Keo became a leader at HAIP early on, serving on the leadership council and helping shape guidance for health systems. Her knowledge of how to navigate healthcare law and regulation made her an invaluable leader in HAIP, and now for Vega Health.
“During my time launching and helping lead Health AI Partnership, I came to appreciate that health systems across the country were struggling to keep abreast of the regulatory, legal, and compliance challenges related to AI,” Mark said. “The challenges have only gotten worse since we launched Vega Health last year. There is more ambiguity than ever at the federal level, and an increasingly fragmented state regulatory landscape is creating new compliance challenges.”
He continued: “To be the best partner possible, Vega Health needs the best regulatory, legal, and compliance experts behind us. That is Keo McKenzie. Keo served on the leadership council of Health AI Partnership for nearly two and a half years. She has worked at the intersection of healthcare, technology, and law for over 15 years, working within and advising developers and healthcare delivery systems. She’s sharp and pragmatic. We’re thrilled to have her lending her expertise to support Vega Health and our partners as we turn AI investments into measurable results.”
Keo recently shared her thoughts on some of the most relevant issues in healthcare AI with Vega Health. Below, we present her insights as five considerations that healthcare operators should think about when determining how to implement AI.
1. Most of your “AI questions” are broader than just AI
When clients come to Keo with an AI problem, the answer is often not based in AI-specific law. It’s usually a privacy question, a product liability question, or a question about privileged communications that AI happened to surface. Treating every issue as a brand-new category of risk means re-litigating problems the law has already worked through, when the faster path is often recognizing which familiar question you’re asking.
That’s part of why AI governance resists a tidy playbook. The work touches nearly every part of an organization (legal, clinical, IT, compliance, operations), and each function tends to see a different piece of the risk. Getting a workable answer means pulling all those perspectives into the same room rather than routing the question to a single department and waiting for a verdict. The organizations that struggle most, in her experience, are the ones that hand AI questions to one team in isolation instead of treating them as the cross-functional work they are.
2. Reducing bias is an easy goal to agree on, but harder to put in practice
Regulators, legislators, and industry bodies are increasingly focused on how healthcare organizations identify and address bias in AI, often without providing a clear standard for what testing should look like or what “good” means in each context. Through her work helping build HAIP’s bias-testing framework, Keo saw that an acceptable standard at one health system, with its own patient population and resources, doesn’t automatically translate to another. Agreeing that bias matters is the easy part. Defining a standard specific enough to act on is much harder.
Keo joined HAIP’s leadership council just a few months after the group was founded, when the first task was figuring out who the group was even trying to help. That early groundwork led to a governance guide for health systems, and later to a deeper look at what it means to test for bias, and how to translate a legal instruction like “don’t discriminate” into something a data science team can execute against. Much of that research came from Duke’s technical team; her role was pressure-testing it against a simple question: if this doesn’t make sense to the person doing the work, it isn’t going to hold up.
3. “Off-the-shelf” is a myth
A model that performs well at one health system can fall short at another, not because the underlying science is wrong, but because it hasn’t been adapted to a different patient population, workflow, or data environment. That localization work is where much of the legal and practical risk actually lives, and it’s also where the real value gets created.
It’s also, in Keo’s view, the reason so many strong clinical models never leave the place where they were built. The internal benefit can be significant, but that benefit tends to stay contained within the same place it was developed, because adapting models to work well in another environment is hard work. It means fitting it into workflows it wasn’t designed around, which takes time, expertise, and individuals who have done that work before. Without that, health systems are stuck reasoning through the same problems from scratch, one institution at a time.
4. Decide if AI is the right tool for the problem
Keo advises health systems to work through procurement in two distinct stages and warns that conflating them can create paralysis. The first stage is a values question: should we be doing this at all, given the resources and attention it will require. The second is a narrower, practical question about which specific tools are worth that investment.
Health systems often hesitate on predictive or clinical decision support tools because they’re unsure how the tool would be classified under FDA rules, or because it hasn’t gone through a clearance process they recognize. FDA regulates medical devices but generally does not regulate the practice of medicine. That distinction creates an important question for health systems: when is software functioning as a regulated medical product, and when is it supporting a clinician in practicing medicine?
Understanding classification early can unblock a decision that might otherwise stall for months.
5. If you can’t defend the ROI, you can’t defend the tool
Health systems don’t have unlimited time or money to spend evaluating every promising tool, so the ones that can show a defensible return, direct or indirect, are the ones that make it past the first year and keep their support. That matters even more now. The initial rush to experiment with AI has shown that deploying it successfully can be harder than expected, and not every tool has delivered on its early promise. As health systems move beyond experimentation, they are becoming more selective about where they invest and looking more closely at whether a tool can demonstrate real value in their own environment.
Freed-up nursing time, reduced burnout, or better staff retention all count, even though it can be harder to put on a spreadsheet. Defining those measures before deployment makes it much easier to assess later whether the tool is actually delivering the expected value. But a vendor’s claims about “soft” ROI have to hold up when the finance team starts asking questions.




