GDC's Guidance on child protection and vulnerable adults, the document every registered dental professional in the UK is expected to know, was last updated in November 2013. That is a decade and a half before AI scribes, AI phone agents, and AI-drafted referral letters became something a two-site dental group might actually be evaluating. Read it today and you will not find the word "AI" anywhere in it, because it was written before there was any reason to.

That would be a historical curiosity if the two newer documents that should have picked up the thread had done so. They haven't. CQC's dental-specific safeguarding guidance is silent on AI. So is BDA's own AI advice page. Three organisations, three current documents, and not one of them connects artificial intelligence to the safeguarding duty a dental practice already carries. This piece sets out what each document actually says, and what a practice, particularly one running more than one site, needs to put in place while the gap stays open.

What GDC's safeguarding guidance actually says

GDC's guidance points registrants to Standards for the Dental Team 8.5.1 and 8.5.2: "You must raise any concerns you may have about the possible abuse or neglect of children or vulnerable adults," and "You must find out about local procedures for the protection of children and vulnerable adults." It defines a vulnerable adult as someone over 18 who needs community care services and cannot protect themselves against significant harm or exploitation, and it lists the injury patterns a dental professional is specifically placed to notice: bruising, burns, bite marks and eye injuries, and injuries to the head, eyes, ears, neck, face, mouth and teeth.

None of that has been rewritten since 2013. The document carries no AI-specific clause, no mention of AI scribes or AI-assisted charting, and no guidance on what happens when the tool capturing a consultation is software rather than a person taking notes by hand.

So what for you: the duty to notice and raise a concern sits with you as the registrant, in exactly the same terms it did in 2013. An AI tool doesn't dilute that duty, and it doesn't discharge it either. Nothing in GDC's own wording currently tells you how the two interact, which means the practice has to work that out itself.

CQC's dental safeguarding rules are just as quiet

CQC's Dental mythbuster 28, safeguarding adults at risk, last updated 29 April 2024, is the practical companion to GDC's standard. It ties safeguarding directly to Regulation 13 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014, safeguarding service users from abuse and improper treatment, and sets out what CQC checks on inspection: a designated safeguarding lead, staff competence at the right level, and evidence the practice engages actively with local safeguarding procedures. It cites the Care Act 2014, GDC's 2013 Standards, and the August 2018 intercollegiate guidance on safeguarding competencies. It does not mention AI once.

Compare that with CQC's separate guidance on AI itself, "Artificial intelligence in health and social care: CQC's role, expectations and plans," last updated 21 May 2026. That page names five regulations providers should consider when using AI: Regulation 9 (person-centred care), Regulation 10 (dignity and respect), Regulation 11 (consent), Regulation 12 (safe care and treatment), and Regulation 17 (good governance). Regulation 13 isn't on the list. CQC has also published GP mythbuster 109, specifically on AI use in general practice, telling GPs they must disclose AI use and demonstrate it supports rather than replaces human oversight. As of this research, no dental equivalent of that AI-specific mythbuster exists.

So what for you: CQC has one current document about dental safeguarding and one current document about AI, and neither cites the other. If you're waiting for an inspector's checklist to tell you exactly how Regulation 13 applies to your AI phone agent, that checklist hasn't been written yet.

BDA's AI guidance doesn't fill the gap either

BDA added its own advice page, "Using artificial intelligence in dental practice," in May 2026. It's a useful document as far as it goes: it covers GDPR risk, the danger of AI "hallucinations" (misleading or overly agreeable outputs), and the accountability point that if AI advice turns out to be wrong, responsibility sits with the dentist, not the AI provider. What it does not mention, anywhere in its public overview, is safeguarding, child protection, or vulnerable adults. BDA's downloadable AI Use and Governance Policy template, which might go further, sits behind Expert membership and wasn't independently reviewed for this piece, so treat that gap as provisional rather than final.

This is a genuinely different result from the consent question. On consent, GDC's Standard 3.1 is silent on AI but binding, while BDA's guidance says more, even if it isn't statutory. On safeguarding, neither side of that same statutory-versus-advisory split says anything at all. There's no membership-body document quietly doing the work GDC and CQC haven't got to yet.

So what for you: don't wait for a professional-body update to hand you an AI safeguarding checklist. As of September 2026, nobody, statutory or advisory, has written one for dentistry.

Where this actually bites in a growing practice

None of this is abstract once you picture the workflow. An AI phone or scheduling agent takes the call when a parent, or a vulnerable adult patient, says something concerning while booking an appointment, and no one has defined whether or how that transcript gets flagged for review. An AI charting or imaging tool tuned to spot caries and periodontal disease has no reason to flag the injury patterns GDC's own guidance names, bruising, bite marks, eye injuries, because that isn't what it was built to detect, and nothing in its marketing claims it can. An AI-drafted referral letter or recall summary optimises for clinical content; a safeguarding note buried in the original consultation can quietly disappear from the version the AI produces.

For a practice moving from two sites to three, the same risk multiplies rather than doubles. Whichever associate or hygienist is on duty at the new site needs the same safeguarding lead, the same escalation route, and the same expectation that any AI tool gets checked for this specifically, not assumed to inherit good practice from site one just because the software is identical.

So what for you: treat "does this AI tool ever sit near a safeguarding disclosure" as its own question, asked and documented separately for every tool and every site, rather than folded into a general data-protection or clinical-accuracy review.

What to put in place, in order

First: name Regulation 13 explicitly in the risk assessment or hazard log for every AI tool the practice uses. None of GDC's, CQC's, or BDA's current guidance will do that naming for you, so the practice's own documentation has to.

Second: add a specific safeguarding clause to whatever policy governs each AI tool. State who reviews an AI phone transcript, an AI-drafted note, or an AI recall summary for safeguarding content, on what timescale, and who covers that review if the named person is unavailable.

Third: before extending an AI tool to a new site, confirm the safeguarding lead and escalation route are consistent with the existing sites, not set up fresh and slightly differently. This is CQC's Regulation 17 governance point applied specifically to AI rollout, not just to staffing.

Fourth: treat a vendor's compliance or safety page as a starting point, not a substitute. It is not a compliance document, and it was not written with Regulation 13 in mind. For the parallel finding on AI and dental consent, where GDC's statutory silence and BDA's advisory guidance pull in different directions, see GDC's consent standard is binding. BDA's AI guidance isn't. A psychology practice facing the same structural gap between CQC's AI rules and Regulation 13 is covered in CQC names 5 regulations for AI. Safeguarding isn't one.

If you want an independent read on where your own practice's safeguarding documentation actually stands against this gap before adding another AI tool, the AI Opportunity & Growth Assessment™ includes a governance review as part of its scope. You're also welcome to book a 20-minute call to talk through what that would look like for a multi-site group specifically, before committing to anything.

The single most important thing to take from this

None of the three organisations here have got this wrong so much as not got to it yet. GDC's document predates AI by over a decade. CQC is mid-transition between its AI guidance and its long-standing safeguarding framework. BDA is one advice page into a fast-moving area. But until the three documents connect, the connecting work is the practice's, not the regulator's. Regulation 13 was never suspended for AI tools. It was just never mentioned alongside them.

The Clinical AI Briefing

One practical AI insight for healthcare practices every week. No hype. Evidence and outcomes only.

Related articles