CQC's AI guidance page, last updated 21 May 2026, sets out exactly which regulations apply when a registered provider uses artificial intelligence: Regulation 9 (person-centred care), Regulation 10 (dignity and respect), Regulation 11 (consent), Regulation 12 (safe care and treatment), and Regulation 17 (good governance). Five named regulations, cross-referenced against the British Medical Association's and World Health Organisation's own AI principles.
Regulation 13, safeguarding service users from abuse and improper treatment, does not appear on that list. Neither does CQC's separate safeguarding quality statement, published under its Safe key question, make any reference to AI at all. Two CQC pages, both current, both directly relevant to any psychology practice using AI, and neither one connects the two topics.
For most independent practices, that gap would be a footnote. For a psychology group, it is not. Safeguarding, not documentation or data storage, is the concern that sits closest to the therapeutic relationship: a client discloses risk of self-harm during a session an AI tool is transcribing, or an AI-powered intake form fails to flag a response a human intake coordinator would have caught immediately. CQC has not yet written a specific answer to that scenario into its AI guidance. This piece sets out what does apply right now, and what four things a psychology practice needs in place while the regulatory picture catches up.
Why safeguarding sits outside CQC's current AI framework
CQC is explicit that its five listed regulations are not an AI-specific rulebook. They are the fundamental standards, applied to a new context. Regulation 9 covers giving people the right information to make choices, including about AI's role in their care. Regulation 17 covers governance and risk management, the hazard logs and named clinical safety officers that most AI governance checklists focus on. None of the five speaks to what happens when an AI system is present at the moment a safeguarding concern arises.
That is not an oversight so much as a sequencing problem. CQC published its AI position in May 2026 while still developing the sector-specific assessment frameworks that came out of its "Better regulation, better care" consultation, with drafts issued for engagement in March 2026 and further rollout continuing through 2026/27. Safeguarding sits in a well-established, separate part of CQC's framework, and the two workstreams have not yet been merged in guidance. CQC itself says the absence or presence of AI does not predict a rating, and that it will keep AI-specific guidance under review as its frameworks evolve.
So what for you: do not assume that because your practice has ticked the five AI-related regulations, safeguarding is automatically covered. It sits in a different part of CQC's framework, and until the two are formally connected, the practice has to make that connection itself.
What Regulation 13 actually requires, and where AI intersects it
Regulation 13 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 requires registered providers to protect service users from abuse and improper treatment, take proper account of individual needs and circumstances, and respond appropriately to any allegation of abuse. It applies to every registered psychology practice regardless of what technology is in the room.
Three points of AI contact are worth naming specifically. First, transcription and note-taking tools: a disclosure of risk is captured accurately by the AI, but sits in a summary that no clinician reviews until the following week. The information existed; the safeguarding response did not follow it in time. Second, chat-based or automated intake tools: a client's written response during triage contains a red flag that a trained receptionist would recognise and a scripted chatbot might not. Third, monitoring drift: clinicians who trust an AI note tool to "catch everything" may pay closer attention to the conversation itself and less to reviewing what the AI produced, which inverts the intended safety benefit.
So what for you: each of these is a governance failure under Regulation 13, not a technology failure. The fix is a documented human-review process with a defined time window, not a better AI model.
The evidence pushing this up the agenda
This is not a theoretical risk. Research on AI chatbot safety, including the VERA-MH safety evaluation study published in 2026, found that both general-purpose and mental-health-specific AI models perform inconsistently when tested against simulated conversations involving suicide risk, with clinician reviewers rating the models' responses as unreliable in a meaningful share of cases. In the United States, that evidence has already moved into legislation: California's Senate Bill 243, which took effect in October 2025, was introduced specifically in response to cases where AI companion chatbots failed to respond appropriately to users expressing distress, and now requires disclosure that a user is interacting with AI plus documented protocols for handling self-harm-related content.
Those cases involve consumer companion chatbots, not clinical note-taking or practice-management tools used by registered psychology practices, and the two categories should not be conflated. But the underlying failure mode, an AI system that does not treat a disclosure of risk with the urgency a trained clinician would, is the same category of risk regardless of which product it shows up in. UK regulators are watching this closely: the MHRA's National Commission into the Regulation of AI in Healthcare is reviewing exactly this kind of cross-cutting risk, and the British Psychological Society has called specifically for psychologists to maintain oversight, auditing, and safeguarding responsibility wherever AI is used therapeutically.
So what for you: your AI note tool is not a wellness chatbot. But the regulatory and clinical evidence base for AI safeguarding failure is real, current, and no longer confined to speculative risk. Treat it accordingly.
The ICO's angle: fairness and vulnerable groups
The ICO's updated guidance on AI and data protection extends its fairness requirement to explicitly cover the protection of vulnerable groups, a direct response to industry requests for clarity on what fairness in AI actually means in practice. For a psychology practice, the implication is specific: a Data Protection Impact Assessment for any AI tool processing session content should not stop at data security and encryption. It should document how the tool's design, and the human-review process wrapped around it, specifically protects clients who disclose risk, distress, or safeguarding concerns during a session.
This is a materially different DPIA question from the one most practices have already answered for their existing AI note tools. Where is the data stored, and is it encrypted, is a data protection question. What happens to a safeguarding disclosure captured by this tool, and how quickly does a human see it, is a fairness and vulnerable-groups question. Practices that completed a DPIA before this update was published are unlikely to have answered the second question at all. For the underlying compliance rules around Special Category data and consent in therapy settings, see AI note tools in therapy: the compliance rules that now apply.
So what for you: update your existing DPIA to add a specific vulnerable-groups and safeguarding section, rather than treating the ICO's fairness principle as already satisfied by your data security measures.
What the British Psychological Society expects
The BPS has published guiding principles for psychologists working with AI, built on its existing ethical code: respect, competence, responsibility, and integrity. The central message is that AI must be evaluated and regulated as part of a socio-technical system, meaning the tool plus the clinician plus the practice's processes together, not as a standalone product that can be assessed on its own. Practically, this places the responsibility for safeguarding, oversight, and auditing of any AI used therapeutically squarely with the psychologist and the practice, not with the vendor.
So what for you: a vendor's safety claims about their AI tool are a starting point, not a substitute for your own safeguarding review. The BPS position and CQC's Regulation 17 (good governance) both point the same way: the practice owns the outcome.
What this means for your practice
Four actions, in order of priority.
First: add an explicit safeguarding risk assessment for every AI tool that touches session content, separate from the general hazard log built around CQC's five named AI regulations. Name Regulation 13 directly in the documentation, since CQC's own AI page does not, and record how a safeguarding disclosure captured by the tool gets escalated to a human.
Second: define and document a review window. Someone must read every AI-generated note or transcript within a set time, same day at minimum, specifically checking for safeguarding content the AI summary may have understated or buried. Record who is responsible and what happens if that person is unavailable.
Third: if any AI tool in your practice performs intake, triage, or has any client-facing conversational function, test it against known safeguarding scenarios before deployment and after any update, and keep a record of the results. Passive note-taking tools carry lower risk here than anything client-facing.
Fourth: update your DPIA to add a distinct vulnerable-groups and safeguarding section addressing the ICO's fairness principle, not just data storage and security. If you completed your DPIA before mid-2026, this section will not currently exist.
None of this requires replacing an AI tool that is otherwise working well. It requires building the specific bridge between AI governance and safeguarding that CQC, the ICO, and the BPS have each gestured toward but not yet fully joined up. For a practice that has already worked through CQC's broader AI governance checklist, see the 10 AI governance checks CQC will look for in 2026, this is the piece that checklist does not yet cover.
If you want an independent view of where your practice's safeguarding documentation actually stands against this gap, the AI Opportunity & Growth Assessment™ includes a safeguarding-specific review as part of its governance component. You can also book a 20-minute call to talk through where your practice sits before committing to anything further.
The single most important thing to take from this
CQC's current AI guidance is not wrong. It is incomplete, and it says so itself: guidance will be kept under review as the sector-specific frameworks roll out through 2026 and 2027. Until that review closes the gap, the practices that will struggle at inspection, or worse, in an actual safeguarding incident, are the ones that assumed the five named AI regulations were the whole picture. Regulation 13 was never suspended. It was just never mentioned.
The Clinical AI Briefing
One practical AI insight for healthcare practices every week. No hype. Evidence and outcomes only.