You adopted an AI note tool several months ago. It works. Your clinical staff use it in every session, documentation time is down, and patients haven't raised concerns. What you haven't done is set up a formal governance structure around it. No hazard log. No named clinical safety officer. No staff training record. No documented process for telling patients AI is involved in their care.
CQC's new sector-specific assessment framework pilot began in June 2026 and runs through October 2026, with final evaluation planned for November 2026. AI governance sits inside the well-led inspection domain. If an inspector walks in this year and asks how you govern your AI tools, "it works well" is not the answer they are looking for.
Here is what they will actually check.
Why this is live now, not later
CQC updated its official AI guidance on 21 May 2026 (cqc.org.uk). The guidance sets out 11 principles that all registered providers using AI must follow, covering everything from human oversight to procurement standards to data protection. Alongside that, CQC published GP Mythbuster 109 in July 2025, which gives specific inspection criteria for AI use in registered services.
The mythbuster is written for GP services, but CQC's broader principles apply to all registered providers: independent psychology groups, dental practices, physiotherapy clinics, therapy centres. The same regulations underpin every inspection, and the same inspection questions follow from them.
CQC is clear on one point: the absence or presence of AI does not predict a specific rating. Using AI tools is not penalised and is not required. But using AI tools without governance will show up in a well-led assessment, and that does affect ratings. The time to build the paper trail is before the inspection, not during it.
If you are being inspected in the pilot window (June to October 2026), these questions are live now.
The regulations that govern AI use
CQC does not have a standalone AI regulation. Instead, AI use is assessed against the existing fundamental standards. Five regulations are directly relevant when a registered practice uses AI tools:
Regulation 9 (Person-centred care): patients must have appropriate information to make informed decisions about their care, including the role AI plays in it. Regulation 10 (Dignity and respect): privacy protection and fair treatment across all population groups must be demonstrable. Regulation 11 (Consent): staff obtaining consent must understand the care or treatment involved, including any AI component. Regulation 12 (Safe care and treatment): equipment and tools, including AI systems, must be safe. Regulation 17 (Good governance): effective risk management systems must exist, with monitoring of AI outputs included.
The implication for your practice: AI governance is not a separate compliance exercise sitting outside your normal inspection preparation. It runs through the same framework as everything else. If your governance in any of these five areas has a gap because of an AI tool you are using, the inspection finding reflects that gap.
The 10 specific checks
CQC's GP Mythbuster 109 (July 2025) sets out exactly what inspectors will look for when a registered practice uses AI. Here is each check, translated into independent practice context.
1. Procurement and governance documentation
Any AI tool in clinical use should have been procured against published regulatory standards. For clinical tools, this means: the vendor holds DCB0129 compliance (the clinical safety standard for developers); your practice holds DCB0160 compliance as the adopter (the standard for deploying health IT systems safely); and if the tool influences clinical decisions, MHRA registration should be in place and verifiable. For tools procured through an NHS framework, you can assume developer standards were met, but you still need evidence of deployment in line with intended use.
The practical question CQC will ask: can you show that you reviewed the vendor's regulatory documentation before you started using the tool?
2. Risk assessment and hazard log
Your practice should have a completed risk assessment for each AI tool in use, including a hazard log: a documented record of the potential risks the tool introduces, how those risks are mitigated, and what actions were taken. If you trialled a tool and rejected it, that risk assessment still counts as evidence of appropriate governance.
The practical question: is there a written record of the risks you assessed when you decided to adopt this tool?
3. Named clinical safety officer
The DCB0160 standard requires practices adopting digital health technologies to nominate a clinical safety officer (CSO). The CSO must be a senior clinician with current professional registration and sufficient training in digital clinical safety and clinical risk management. NHS England's digital clinical safety training programme is the standard route. Small practices without in-house expertise can seek support from an integrated care system digital lead or a third-party provider of this service.
The practical question: who is your named CSO, and is there a record of their relevant training?
4. Human oversight and monitoring
Inspectors will check that AI is operating as a support tool, not a replacement for clinical judgement. You need to demonstrate ongoing monitoring and evaluation of AI outputs, with evidence in the form of audits or a significant incident log. This does not mean reviewing every AI output. It means showing there is a process to catch problems, and that the process is documented and followed.
The practical question: what is your process for monitoring AI outputs, and where is it recorded?
5. Learning from errors
If something goes wrong with an AI tool, CQC expects established systems for reporting, investigation, and learning. For clinical AI tools, significant incidents should be reported through MHRA's Yellow Card scheme and, where patient safety is involved, through the NHS Learn From Patient Safety Events (LFPSE) service. Internally, lessons should be shared with the CSO and through staff channels. The governance evidence here is a documented pathway, not an absence of incidents.
The practical question: has your practice defined how it would respond if an AI tool generated a harmful or inaccurate output?
6. Data protection: DPIAs and processing agreements
CQC will check how third-party vendors have met data assurances. This means: a Record of Processing Activities (ROPA) covering AI tools that process patient data; a completed Data Protection Impact Assessment (DPIA) for tools that handle Special Category data; and cybersecurity evidence from the vendor. Under UK GDPR, health data is Special Category data. Any AI tool that processes patient health records requires a DPIA as a legal requirement, not a recommendation.
Psychology practices carrying mental health records, risk assessments, and session notes face the highest bar here. For more on DPIAs and Special Category data in therapy and psychology contexts, see AI note tools in therapy: the compliance rules that now apply.
The practical question: is there a signed Data Processing Agreement with each AI vendor, and has a DPIA been completed and documented?
7. Consent and patient disclosure
This is the area where most practices are currently non-compliant, often without knowing it. CQC's guidance (GP Mythbuster 109, July 2025) is specific: you do not need explicit consent from patients before using an AI scribe for tasks that deliver individual care. Implied consent under the common law duty of confidentiality is sufficient for clinical note tools. But you must tell patients that AI is being used. That notification is not optional.
The ICO's position reinforces this: transparency is a legal requirement even where explicit consent is not. The minimum standard is a notice in your waiting room or a sentence in your patient information leaflet stating that AI tools may support clinical documentation. A verbal statement at the start of each session also satisfies this, provided it is consistent practice.
The practical question: how and when do you inform patients that AI is involved in their care, and is that process consistent across all staff?
8. Staff training records
Staff using AI tools must have received appropriate training and must be competent in using them. CQC will look for training records. A demonstration given informally when the tool was set up does not constitute a training record. Each staff member using an AI tool should have a dated record of what training they received and who delivered it.
The practical question: if CQC asked for training records for each staff member using your AI note tool, could you produce them today?
9. Equity of access
AI should not create a two-tier service. Practices must offer a non-digital route to care for any patient who cannot or does not want to use AI-enabled services. Inspectors will look for evidence that you have considered digital skills, connectivity, and accessibility in your patient group. For most independent practices using AI note tools, this is low-risk: AI documentation tools do not create access barriers for patients. The standard is met by having a policy, even a simple one, that states how patients can decline AI involvement in their care.
The practical question: if a patient declined to have an AI tool involved in their care, what is your practice's process?
10. Managing bias
AI tools can produce less accurate outputs for certain patient groups, depending on the training data used to build them. CQC expects providers to have sought assurance from their vendors that known biases have been identified and steps taken to mitigate them. For clinical decision-support tools, this means reviewing the vendor's bias documentation. For AI note and transcription tools, the risk is lower but not zero: transcription accuracy varies by accent, first language, and speech pattern.
The practical question: what do you know about how your AI tool performs across different patient groups, and where is that vendor assurance documented?
What this means for your practice
The pattern across these 10 checks is consistent: CQC is not assessing whether AI works. It is assessing whether the governance around AI is documented, owned, and followed. Most practices using AI tools informally, without a CSO, without a hazard log, and without consistent patient disclosure, are below the expected standard. Not because the tools are wrong, but because the paper trail does not exist.
Setting this up retrospectively is achievable. It does not require an external compliance consultant for most practices. It requires roughly three to four hours of structured work across four actions:
First: nominate a named clinical safety officer. If you are a senior clinician and registered with your professional body, that can be you. Record the nomination and the date.
Second: complete a basic risk assessment and hazard log for each AI tool in use. Your AI vendor should be able to provide a template. The NHS DCB0160 guidance includes worked examples.
Third: confirm that each AI vendor has a signed Data Processing Agreement in place with your practice. If you do not have one, request it. No reputable AI vendor will refuse. If they do, stop using the tool.
Fourth: introduce a consistent patient disclosure process. A sign in your waiting room and a sentence in your intake documentation is sufficient. Make it standard, and brief your staff.
Practices planning to implement AI tools, rather than those already using them, are in a better position: governance built from the start is significantly easier than governance retrofitted after the fact. If you want to understand your current governance position before your next inspection, the AI Opportunity and Growth Assessment includes a structured governance review as part of the CARE Framework. You can also book a 20-minute call to discuss where your practice sits before committing to a full audit.
The single most important thing to take from this
CQC does not score practices on whether they use AI. It scores them on whether the AI they use is governed safely. The 10 checks above represent the current expected standard for any registered provider using AI tools. They are achievable by any independent practice that treats AI governance the same way it treats any other clinical governance process: documented, owned, and reviewed on a defined cycle.
The practices that will struggle at inspection are those using AI tools informally, without records, without named ownership, and without a patient-facing disclosure. The remedy is administrative, not clinical. The naming of a CSO and the creation of a hazard log are the two actions that make everything else possible. Start there.
For context on how the broader UK data protection framework applies to AI tools in psychology and therapy, see AI note tools in therapy: the compliance rules that now apply. For a look at the implementation failures that undermine even well-chosen AI tools, see why 73% of AI tools bought by healthcare practices go unused.
The Clinical AI Briefing
One practical AI insight for healthcare practices every week. No hype. Evidence and outcomes only.