AI Pulse

OpenAI Just Connected to 325 Million Patient Records. CrowdStrike Built a Certification Track for AI Agents. The September 2 Pulse.

By Felix Maru · September 2, 2026 · 6 min read

The conversation about AI in enterprise settings shifted in two ways at once this week. On September 1, OpenAI connected ChatGPT to the world's largest electronic health record system. A day earlier, CrowdStrike built a formal certification layer for AI agents deployed inside enterprise environments. Read them together and you see a pattern that is forming across industries: the question is no longer only what AI can access, but what it should be allowed to do, and how you prove it.

Here is what happened, what the design choices actually mean, and how both decisions translate to the teams building AI into support and operations stacks right now.

OpenAI's Epic Integration: What Read-Only Actually Means

On September 1, OpenAI launched a new integration for ChatGPT for Healthcare, giving clinicians read-only access to patient records held in Epic Systems. TechCrunch and FierceHealthcare both confirmed the launch. Epic serves more than 325 million patients. The integration also adds a Healthcare Public Data plugin connecting directly to PubMed, DailyMed, and CMS Coverage inside ChatGPT. UCSF Health is the named pilot partner.

The design constraint is the story: read-only. The AI can pull appointment notes, lab results, medications, specialist documentation, and surface patterns across a patient record. It does not write anything back. Nothing the AI surfaces becomes part of the official record unless a clinician explicitly makes it so.

That is not a limitation of the technology. It is a deliberate design choice.

Why the Constraint Is the Feature

When OpenAI built the Epic integration, they drew a clear line: remove the ability to act, and make the AI powerful for reasoning and surfacing. The risk surface collapses on one dimension. There are no AI-written medical records. The clinician remains accountable for every entry in the system. The AI is a research assistant with access to every record, not a doctor making decisions.

This is the design pattern I reach for first whenever I wire a new AI integration into a support or operations stack: separate reading from writing. The moment AI can act, the accountability question gets harder. Who is responsible when the AI closes the wrong ticket, sends the wrong customer reply, or modifies a record incorrectly? The read-only model sidesteps that problem entirely while still delivering a large share of the value.

Most of the early gains in AI-assisted work come from surfacing and summarizing. Agents spend less time hunting through a CRM for prior customer history. Support reps stop re-reading the same ticket context from scratch. The AI reads faster than any human and pulls the relevant details. A human then decides what to do with them. That is a genuine productivity gain with almost no accountability risk, because the human is still deciding and still acting.

The write access comes later, after the read-only integration has built team trust and you have watched how the AI handles your full range of queries, including the edge cases that will inevitably arrive.

CrowdStrike: Building a Certification Track for AI Agents

The day before, on August 31 at Fal.Con 2026 in Las Vegas, CrowdStrike announced its AI Partner Specialization within the Accelerate Partner Program. The program creates four paths for partners working with AI on the Falcon platform: Deliver (design and deploy AI agent implementations), Resell (sell AI-powered security to customers), Manage (run CrowdStrike AI as a managed service), and Build (develop and publish AI agents on the platform).

The Build path is where the governance story lives. CrowdStrike is introducing a Verified Agent certification: a formal validation that partner-built AI agents meet the company's requirements before they are distributed to enterprise customers. Multiple sources including CrowdStrike's own press release confirm the launch. The company is framing this around what it calls the "agentic enterprise," where AI agents take autonomous actions across enterprise systems, and where the trust question is no longer hypothetical.

The Verified Agent certification is a trust signal that the enterprise market is asking for: this agent was reviewed before you deployed it. Partners cannot simply build and publish. A defined validation process stands between development and customer access.

The Pattern: Two Companies Solving the Same Problem

Pull these two announcements together and the same architecture appears in both.

OpenAI's answer in healthcare is bounded access: the AI gets a read scope, it cannot execute, and humans remain responsible for every action. CrowdStrike's answer in security is certification: the agent must prove itself against defined requirements before it ships, and a human validation process stands at the gate.

Both approaches keep a human decision-point in the critical path. In the OpenAI model, the clinician is that decision-point: they take the AI's output and choose what to act on. In the CrowdStrike model, the certification team is that decision-point: they review the agent before customers ever see it. The AI capability is real and expanding in both cases. The control layer is explicit and non-negotiable.

This is not a coincidence. It is the governance architecture that enterprise AI actually needs to work at scale: capability on one axis, bounded accountability on the other, with humans at every point where accountability matters. The teams that deploy AI without this structure are not moving faster, they are deferring a problem that tends to surface at the worst possible moment.

What This Means If You Are Deploying AI Today

The scale of OpenAI and CrowdStrike is not a requirement to apply the same principles. The decisions translate directly to a support team or an IT operation of any size.

Read before write. When you evaluate a new AI integration, separate the reading capabilities from the writing capabilities and start with read-only. Let the AI surface information and draft suggestions for humans to review. Keep humans on every action that modifies a record, sends a message to a customer, or closes a ticket. Expand write access only after you have a track record across a range of real queries, including the edge cases. The Epic integration is the same playbook at a much larger scale.

Ask what the vendor's validation process looks like. If you are deploying an AI agent from a vendor, ask directly: what testing and validation happens before the agent ships to customers? If the answer is effectively "we deployed it and you can report issues," that is beta testing at your cost. CrowdStrike's Verified Agent certification gives their enterprise customers a clearer answer. Your vendors should be able to give you one too.

Name who is accountable for the edge cases. In the Epic model, clinicians are accountable for what goes into patient records. In the CrowdStrike model, the certifying team is accountable for what ships. In your support stack, your operations lead or QA team needs an explicit view of what the AI is doing and defined ownership over the edge cases. "The AI handled it" is not an accountability framework, it is an unanswered question waiting for a bad day to surface.

The goal is not to limit what AI can do indefinitely. The goal is to earn the right to expand its scope through a track record of bounded, verifiable performance. The teams building that track record now are the ones who will move faster in 2027 because they will have the data and the trust to justify it.

Verdict on both stories: MUST-READ. Not for the specific technologies, but for the governance design embedded in each.

Sources

How are you handling the read versus write question in your own AI deployments? Drop me a note and let me know what you are working through.

Share 𝕏 in

Comments