AI in Adult Social Care: Guidance is Welcome, But Where is the Regulation?

 

New guidance from the Department of Health and Social Care on the use of AI in adult social care is a welcome development. Alongside the Oxford Project guidance from the Digital Care Hub and the Adult Social Care Digital Skills Framework, it gives providers a useful starting point for responsible adoption.

However, guidance is not regulation. Providers are already using AI in a range of ways, yet there is no dedicated regulatory framework governing its use. Instead, providers must navigate a patchwork of data protection, safeguarding, equality, human rights, employment, commissioning and regulatory obligations.


The benefits and the risks

For a sector facing workforce pressures, rising acuity and financial constraints, AI may reduce administrative burdens, improve oversight and help identify risks earlier. But adoption without effective governance can expose providers to significant legal and operational risk.

Data protection is an obvious concern. AI systems may process sensitive information about health, disability, medication, safeguarding, finances and family circumstances. Providers should establish where data is processed, whether it is used to train models, what security safeguards and contractual protections apply, whether a Data Protection Impact Assessment is required, and how people will be informed.

Cybersecurity is equally important. Recent incidents involving advanced AI systems have highlighted continuing difficulties around control, authorised access and safeguards. Providers should therefore approach AI procurement with the same diligence applied to systems holding care records, medication information or workforce data.

Meaningful human oversight is essential. Generative AI can misunderstand context and produce convincing but inaccurate material. If an AI-generated care plan, investigation report or risk assessment contributes to harm, responsibility is unlikely to rest with the technology. Providers, registered managers and relevant professionals will remain accountable. AI can support professional judgement; it cannot replace it.

Providers must also consider bias and discrimination, particularly where AI influences care planning, admissions, staffing, resource allocation or risk assessments. They should be able to show that systems operate fairly and consistently with equality and human rights obligations.

Regulatory expectations

CQC has recognised its role in ensuring AI contributes to safe, effective and equitable care, but detailed expectations remain limited. Questions about governance, supplier oversight, cybersecurity, accountability, consent and quality assurance are nevertheless likely to feature increasingly in inspections, safeguarding enquiries, complaints, commissioning reviews and inquests.

The Digital Skills Framework also reinforces that safe adoption is not simply an IT project. Staff must understand approved uses, protect confidential information, challenge unreliable outputs and know when to escalate concerns.

What should providers do now?

Providers should not wait for further regulation. Practical steps include adopting an organisation-wide AI policy; mapping current use; carrying out data protection, cybersecurity, equality and safeguarding assessments; completing supplier due diligence; training staff; establishing human review and escalation processes; reviewing incident response arrangements; and ensuring board-level oversight and transparency for people drawing on care and support.

The providers best placed to benefit from AI will not necessarily be those that adopt it fastest, but those that adopt it most responsibly. The question is no longer whether AI will be used in adult social care, but whether providers are ready to govern it properly.

Relevant links:

 
Support Remote Digital