Back to Evidence & Guides

AI in Private Clinics: Your Responsibilities Now, and What the Commission Proposes Next

By Faisal Ali, AAISM, CISM, CRISC, Founder and Principal Consultant, ELSA AI

Published 7 October 2026. Reviewed 7 October 2026. Regulatory position stated as at this date and focused on England. Next review: 7 January 2027, or earlier following a material regulatory or service change.

If a clinician in your practice is drafting patient correspondence through a general-purpose AI assistant on a personal account, three people may eventually ask you about it: your DPO, a CQC inspector asking how the practice assures new technology, and a patient who wants to know what happened to their information.

The answer "we were trialling it informally" is the one you do not want to give. This article covers what already applies to a private clinic using AI, what the National Commission proposes next, and the five questions that turn either into a decision someone owns.

What already applies

Existing responsibilities apply when a clinic introduces AI. The following areas deserve review before deployment.

Registration and governance. CQC-registered providers in England must meet the fundamental standards, including safe care and treatment under Regulation 12 and good governance under Regulation 17. Regulation 17 requires systems to assess, monitor and improve quality and safety, and accurate records. A tool that shapes a clinical record or patient correspondence sits inside that scope whether or not anyone filed it as a governance matter. This article focuses on England. Providers elsewhere in the UK need to check their own regulatory arrangements. See CQC’s Regulation 17 guidance.

Data protection. Where material from a consultation identifies a patient and contains or reveals information about their health, it is special category data under UK GDPR Article 9 and needs an Article 9 condition alongside a lawful basis. The common law duty of confidentiality also needs to be addressed. The clinic’s adviser should review the proposed use against applicable data protection principles, including minimisation, accuracy, retention and security.

Do not assume your AI supplier is your processor. Whether a supplier acts as processor, independent controller or joint controller turns on who determines the purposes and means, and it can differ between activities inside one product. Returning a draft note to you, and using consultation content to improve the supplier’s own model, do not necessarily sit in the same category. Article 28 contract terms apply where the supplier is a processor. Establish and document the status for each activity before go-live; contractual labels alone do not settle it. See the ICO’s controller and processor guidance.

DPIA. A DPIA is required where processing is likely to result in a high risk to individuals. The ICO’s published list requires a DPIA for innovative technology, including AI, when combined with another specified criterion, such as sensitive data. Large-scale processing of special category data also requires a DPIA. Document the screening decision and complete any required DPIA before processing starts. The clinic retains responsibility for that decision, supported by its DPO or data protection adviser. See the ICO’s DPIA guidance.

Is an AI scribe a medical device

MHRA guidance published on 29 July 2026 gives examples of administrative transcription, summarisation and letter drafting for clinician review that do not qualify as medical devices. Its non-device coding example matches explicitly stated clinical terms; it does not infer diagnoses from implicit information.[1]

Products intended for diagnosis, treatment or other medical purposes require a different assessment. The manufacturer’s intended purpose, including its instructions, labelling and promotional claims, matters. Calling a feature “administrative” does not settle the position if other claims and functions indicate a medical purpose.

The guidance clarifies existing law. Non-device status does not establish that a product is safe to deploy in your clinic. Confirm the intended use, human review arrangements and supplier evidence, and obtain specialist determination where the position is unclear.[1][2]

Professional responsibilities and indemnity

Using AI to prepare a draft does not remove professional responsibilities for accurate records, confidentiality and communication with patients. The clinic needs a defined review and approval process. GMC Good medical practice, paragraphs 69–71 and GDC Principle 4 set out record-keeping and information responsibilities.

One more that gets missed. Ask your indemnity provider directly whether AI-assisted documentation changes anything about your cover, and get the answer in writing before rollout.

What the Commission proposes

The MHRA-established National Commission published 44 recommendations on 10 September 2026. Professor Alastair Denniston chaired it, with Professor Henrietta Hughes OBE as Deputy Chair. It proposes lifecycle regulation, system-wide responsibility, and greater trust and transparency.[3]

The proposals create no new duties by themselves. The report says a separate government response will follow.

For providers, Recommendation 24 addresses responsibility across the lifecycle; Recommendation 28 addresses contractual allocation of required risk controls and regulatory commitments; Recommendation 35 addresses patient transparency, including opt-out where possible or appropriate. See Chapter 2 sections 2.1 and 2.2, and Chapter 3’s Recommendation 35.[3]

The report also describes perceived “liability sinks”, where clinicians and providers can bear responsibility without sufficient recognition of product and system design. This supports clarifying responsibilities and escalation arrangements before deployment.[3]

Read Recommendation 28 as a signal about your next contract renewal. A clinic that already knows which risk controls it holds will have a shorter conversation than one working it out at the table.

Five questions that produce decisions

Each question below ends in a decision with a named role.

In a small practice, the registered manager, practice manager and clinical lead may share these responsibilities or one person may hold several roles. Record who performs each task and where specialist advice is needed.

1. What is this tool for, and what would "working" look like?

Write one sentence on the problem. For an ambient scribe: reduce documentation time without degrading the clinical record. For an administrative assistant: help reception draft appointment information.

Then set the measure, including the cost side. A scribe that saves six minutes of typing and adds four minutes of correction has saved two. Without that measure you cannot tell later whether the rollout worked.

Decision: the clinical lead approves the stated purpose and the success measure before procurement.

2. What AI is in use here?

Your procurement record is not your usage record. Staff use personal accounts. Suppliers switch AI features on inside platforms you already licence. Pilots outlive the person who started them.

A confidential role-level survey helps identify reported use and lets you reconcile it against leadership declarations and submitted evidence. It establishes what people tell you, not the absence of anything else. Where further discovery is needed, agree a separate technical scope with your IT or security provider. Endpoint and browser records can improve visibility within their coverage; staff privacy and monitoring arrangements need review before collection.

Decision: a named owner holds the AI use record and the date it was last refreshed.

3. Which functions are enabled, and who authorises a change?

Two clinics buy the same product and run it differently. One drafts notes for clinician review. The other enables functions the supplier markets for a medical purpose, which is a different regulatory conversation.

Record the configuration as deployed. Then handle the harder case: many suppliers ship updates that clinics cannot individually approve in advance. What you need is a process to identify material changes, review them and decide whether use continues.

Decision: the practice manager assigns a change owner and records the route for reviewing material changes and deciding whether use continues.

4. Where does patient information actually go?

Trace one consultation end to end. Captured where, transmitted to whom, processed in which jurisdiction, retained how long, accessible by which supplier personnel, returned to which system. Then ask whether content is used for any purpose beyond delivering the service to you.

A supplier page saying the platform is secure answers none of that. Retention configuration, sub-processor lists, data flow descriptions and the contract do.

Decision: the accountable clinic lead records the DPIA decision with advice from the DPO or data protection adviser, using the documented information flow.

5. Who reviews the output, and is the review performable?

Human review counts only if it is an activity someone can carry out. Specify who checks the draft, against what source, with what access, and when the record is approved as final.

Differentiate by content type. An appointment reminder and a letter explaining a treatment decision should not share one approval rule.

Decision: the clinical lead defines the review step per content type, and the rota reflects the time it takes.

Work through the twelve-question Clinic AI Self-Check for one named tool. It helps identify evidence gaps and assign actions. It does not establish safety, compliance or readiness.

Get the free self-check

What an evidence finding looks like

Illustrative sample using fictional clinic information. This is not a client case study.
FindingEvidence positionActionOwnerTarget date
Scribe retention setting unconfirmedSupplier documentation supplied; deployed setting not evidencedObtain configuration evidence and confirm the approved retention arrangementPractice managerAgreed date
Incident contact route undefinedContract names a general support address; no response commitment identifiedAgree a named contact and response time, or record the accepted positionPractice managerAgreed date
Review instruction inconsistent between cliniciansTwo clinicians reviewing full transcript, one reviewing summary onlyDefine the review step per content type and reissue the instructionClinical leadAgreed date

Each finding gives leadership a specific question to resolve. The action records what needs confirmation, who will obtain it and when leadership will review the result.

Where ELSA AI fits

ELSA AI works with private healthcare providers that procure and use third-party AI. We review governance evidence, identify gaps and prepare decisions for accountable leaders and their advisers. The Diagnostic does not include model testing or patient-record sampling.

The framework behind the evidence approach

GenAI Assure v2.1, authored by Faisal Ali and owned by ELSA AI LTD, contains 115 individually testable controls across 17 domains. It is publicly available under CC BY-ND 4.0 and addresses control applicability, ownership and evidence.

ELSA AI applies relevant framework requirements within agreed engagements. The clinic Diagnostic uses its own controlled 13-domain assessment; it does not apply every cross-industry control to every clinic or establish operating effectiveness through documents alone.

What the Diagnostic assesses

The thirteen assessment domains are:

  1. Governance ownership and decision authority.
  2. Inventory, shadow AI and reported use.
  3. Use-case description and referral routing.
  4. Patient-data exposure and DPIA readiness.
  5. Supplier and data-position evidence.
  6. Accounts, devices and access-exposure indicators.
  7. Clinical-use indicators and specialist routing.
  8. Professional accountability and record-use evidence.
  9. Human review, guidance and competence signals.
  10. Patient transparency and objection evidence.
  11. Reported output accuracy and limitations.
  12. Incident and concern-routing evidence.
  13. External question and evidence readiness.

We assess these within the agreed scope and the evidence available. Findings distinguish documented positions, evidence gaps, uncertainties and questions requiring specialist referral.

Fixed scope and published prices

Clinical AI Exposure Diagnostic, Standard route: £5,500 + VAT. The nine-part pack is delivered by the end of Working Day 4 from the confirmed Evidence-Ready Start Date. The Standard scope covers one site, up to 60 staff, five AI tools or use cases, five suppliers and 25 evidence documents, across one clinical specialty. It excludes ambient scribe, AI transcription or consultation note-generation use, trial or plans, and NHS contractual or data-sharing arrangements in scope.

Diagnostic with Ambient Scribe Assessment: £8,500 + VAT. This is a separate six-working-day engagement from the confirmed Evidence-Ready Start Date. The scribe assessment runs through the evidence pack and reviews reported workflow, patient information and objection arrangements, retention and supplier evidence, clinician review and specialist referral needs.

Larger or more complex engagements are scoped and priced in writing before work begins. See full pricing and scope.

What your clinic provides and when the delivery clock starts

Your clinic completes the leadership intake and interview, supports and closes the confidential role-level Staff AI Use Survey, and supplies available evidence or formally confirms what is unavailable. Evidence can include supplier documents, policies, configuration records and workflow descriptions. Do not submit identifiable patient records, consultation audio or transcripts.

The Evidence-Ready Start Date is confirmed in writing after the engagement letter and initial payment requirements are satisfied, intake and interview are complete, the survey has closed with the required non-disciplinary assurance recorded, and evidence is submitted or formally confirmed unavailable. ELSA AI also confirms the route, scope, fixed fee and delivery dates in writing.

The four- or six-working-day period begins at that confirmed date, not at first enquiry. Missing documents do not have to delay the start indefinitely: confirmed absence becomes part of the evidence position. A 60-minute remote leadership readout follows pack delivery at a mutually agreed time.

The nine outputs your clinic receives

  1. AI Tool and Use Case Inventory.
  2. Board Findings Report.
  3. RAG Exposure Map.
  4. Ambient Scribe Assessment Sheet, recorded as not applicable with a reason for the Standard route.
  5. DPIA Readiness and Patient Data Exposure Note.
  6. Vendor Data Position and Evidence Tracker.
  7. MDO, PMI and Insurer Disclosure Readiness Note.
  8. 30-Day Priority Action Plan.
  9. Source and Guidance Mapping Appendix.

The findings and action plan connect the evidence position to actions, accountable owners and target dates. Explore the deliverables.

Implementation and maintenance after the Diagnostic

Clinical AI Safe Usage Launchpad develops the agreed governance baseline from accepted findings. Work can include policies, registers, staff guidance, patient information and incident processes; the fixed fee and timeline are confirmed before commitment.

AI Exposure Sentinel maintains an adequate governance baseline through quarterly review on an annual agreement. It addresses changes in tools, supplier information and reported use. A baseline created elsewhere requires an adequacy review before maintenance begins.

When should a clinic review its AI approval

Record both a review date and the changes that require earlier reconsideration.

Set the triggers: a new AI function, changed supplier terms, use with a different patient group, altered information flows, or an incident. Add a standing review of corrections, complaints and staff concerns, to identify emerging problems in practice.

Assign a person to assess each material change and record the resulting decision.

Discuss your clinic’s AI governance

If you already know where the gap is, a discovery call establishes which assessment route fits and whether we are the right firm for it.

Scope of our work

ELSA AI advises accountable leaders and their specialists. Our work does not replace legal or data protection advice, medical device classification, a completed or signed DPIA, clinical safety case sign-off or DCB0129 and DCB0160 authorship, certification or regulatory approval, or decisions by your insurer or indemnity provider. Where a finding needs one of those, we say so and set out what to put in front of that adviser.

References

[1] MHRA. Ambient voice technology-enabled products. Published 29 July 2026. Guidance.

[2] MHRA. MHRA clarifies regulatory status of ambient voice technologies used in the NHS. 29 July 2026. News.

[3] National Commission into the Regulation of AI in Healthcare. Recommendations for a future regulatory framework. GOV.UK, 10 September 2026. Full HTML report and numbered recommendations.

Additional primary references: CQC Regulation 17; ICO controller/processor and DPIA guidance; GMC Good medical practice paragraphs 69–71; and GDC Principle 4, linked in the relevant sections above. Sources checked on 7 October 2026.

ELSA AI’s interpretation is independent of the Commission. Citing the report does not imply endorsement by the Commission, the MHRA or government.

Faisal Ali is Founder and Principal Consultant at ELSA AI and author of the GenAI Assure Framework. He holds AAISM, CISM and CRISC, and has worked as a security architect across financial services, critical national infrastructure, healthcare and the public sector. LinkedIn.