NE Times
Health

NHS digital safety gaps could amplify patient harm as AI use expands, researchers warn

A new analysis of NHS digital clinical safety data says existing safeguards are too inconsistently applied for the scale of technology adoption envisaged in England's 10 Year Health Plan.

Sophie Bennett

Culture & Features Editor ·

4 min read
A computer workstation on a hospital ward
Researchers say most NHS digital deployments lacked documented safety assurance · Illustrative image

Why it's trending

An analysis published in BMJ Innovations on 18 August found that 70% of the digital technologies reported by 239 NHS trusts and integrated care boards had no documented safety assurance, and warned the 10 Year Health Plan could scale that risk.

Researchers writing in BMJ Innovations have warned that weak compliance with mandatory digital clinical risk standards could allow patient harm to spread faster as the NHS expands its use of artificial intelligence, genomics, robotics and other connected technologies. The paper, published on 18 August, revisits a national freedom-of-information study involving 239 NHS trusts and integrated care boards and examines why compliance with DCB0129 and DCB0160 remains low.

At a glance

  • BMJ Innovations: The analysis examines low compliance with the mandatory DCB0129 and DCB0160 digital clinical safety standards in England's NHS.
  • BMJ Group / EurekAlert: The paper was published on 18 August 2026 and warns that rapid digital expansion could propagate harm at unprecedented scale and speed.
  • UCL: The research draws on a national freedom-of-information exercise covering 239 NHS trusts and integrated care boards.
  • UCL: The researchers report that about 70% of captured technology deployments lacked documented safety assurance, while 17% were fully assured.
  • BMJ Innovations: The authors identify weaknesses in understanding, governance, assurance processes and the capacity or status of Clinical Safety Officers.
  • DCB0129 and DCB0160 set mandatory clinical risk-management expectations for health IT manufacturers and NHS organisations.

The safety rules already exist

The central problem identified by the paper is not the absence of standards. DCB0129 governs clinical risk management for organisations that manufacture health IT, while DCB0160 applies when health organisations deploy and use it. Together they are intended to ensure hazards are identified, recorded and controlled before technology affects care. The researchers' concern is that mandatory status has not translated into consistent evidence of compliance. That distinction matters: creating a new AI safety slogan would not fix a governance process that is already supposed to operate across digital systems.

Compliance gaps point to governance weakness

UCL's summary says the underlying exercise covered 239 trusts and integrated care boards and found widespread missing assurance documentation. The new analysis looks behind that result, identifying poor understanding of the standards, fragmented governance and inconsistent assurance processes. In some organisations, the Clinical Safety Officer role appears to have been treated as an additional duty rather than a properly resourced safety function. This makes the issue organisational as much as technical: a safe product can still be introduced badly, and a useful system can become risky if changes are not assessed.

AI increases speed as well as capability

The 10 Year Health Plan makes digital transformation a core route to higher productivity and more personalised care. That creates obvious opportunities, but it also changes the scale of possible failure. A flawed paper process may affect one team; a centrally deployed algorithm can influence thousands of decisions quickly. BMJ Group's release uses the warning that harm could propagate at unprecedented 'scale and speed'. The point is not that AI is inherently unsafe, but that rapid deployment magnifies the consequences of weak controls, incomplete hazard logs or unclear accountability.

Clinical Safety Officers are a bottleneck

The paper gives particular attention to Clinical Safety Officers, the people expected to translate clinical risk into formal safety cases and controls. If the role lacks protected time, training, authority or a clear career pathway, compliance can become a paperwork exercise performed late in procurement. The researchers argue for a more formal workforce model. That would make safety expertise easier to identify and give boards a clearer line of responsibility when systems cross organisational boundaries.

Researchers want oversight with consequences

Among the proposals highlighted by UCL are stronger regulatory scrutiny, inclusion of digital clinical safety in NHS oversight and better sharing of hazards between organisations. The aim is to make assurance visible enough that boards and regulators can tell whether standards are being followed, rather than relying on local declarations. Any new enforcement regime would have to avoid paralysing useful innovation, but the authors' argument is that speed without dependable assurance is a false economy if failures later create clinical harm, recalls or loss of trust.

What happens next

The practical test will be whether NHS England, regulators and provider boards turn the paper's recommendations into measurable assurance requirements as the 10 Year Health Plan is implemented. Procurement rules, inspection frameworks and Clinical Safety Officer capacity will be the clearest signs of whether digital safety is becoming an operational priority rather than a compliance document.

Sources & verification

  • BMJ Group — primary reporting and official updates
  • Reporting reviewed on 23 August 2026; figures as published at that time

Filed under Health · Written by Sophie Bennett