Patient transparency gaps
These indicate that the clinic has not established clear patient-facing communication about its AI use.
- You are not told that a consultation is being recorded or summarised before it begins.
- Staff cannot explain the purpose of the tool when asked.
- There is nothing in the privacy notice about recording, transcription or AI-generated notes.
A well-governed clinic should be able to explain what tool is being used, what your data is used for and how you can decline, before the tool is activated. These are not technical questions. They are basic patient transparency requirements.
Supplier and data handling gaps
These indicate that the clinic may not have reviewed the terms under which its supplier holds and uses patient data.
- The clinic cannot name the supplier.
- The clinic cannot explain where data is stored or whether it leaves the UK.
- The clinic cannot confirm whether the supplier uses your data to train or improve AI models.
- The clinic cannot explain how long recordings and transcripts are retained.
A clinic with a governed supplier relationship holds this information centrally. If only one clinician has the supplier's contact details, or the information is held informally, the clinic does not have a central governance position on that tool.
Clinical oversight gaps
These indicate that AI outputs may be entering clinical records without adequate human review.
- The AI output appears to enter the record without the clinician having reviewed it.
- A letter or note contains obvious errors, misattributed statements, or symptoms not mentioned in the consultation.
- Staff describe the AI tool as making decisions rather than supporting a clinician.
The clinician is responsible for the accuracy of every note and letter in your record, including those drafted with AI assistance. Unreviewed AI outputs entering a medical record is a clinical governance failure, not a minor administrative issue. If you notice an error, you have the right to ask for a correction.
Shadow AI indicators
These indicate that staff may be using tools that have not been reviewed or approved by the clinic.
- Staff mention using a general-purpose AI tool for clinical notes or letters.
- Personal devices or unapproved apps appear to be used for recording during a consultation.
- Different staff give different answers about what tools are permitted.
Free consumer tools often have terms of service that allow the supplier to retain and use submitted data, including text entered by users. Their use with patient information is something the clinic's data protection lead should have reviewed before any clinical use begins. Inconsistent staff answers about permitted tools suggest that no clear position has been communicated.
What to do if you notice warning signs
You are not obliged to raise a concern formally. Some options:
- Ask to speak to the practice manager.
- Request a copy of the clinic's privacy notice and ask for the data protection contact's details.
- If the clinic cannot answer basic questions about a tool being used with your data, you are entitled to ask for the name of the person responsible for data protection.
If you believe your health data has been mishandled and you are not satisfied after raising the matter with the clinic, the Information Commissioner's Office handles data protection complaints in the UK. Their website is ico.org.uk.
This page does not determine whether a breach has occurred. That determination belongs to the clinic's data protection lead and, where appropriate, the ICO.
What this page is not
General information about governance indicators, not legal advice, a complaints service, or a judgement on any clinic.