AI Scribes in Health and Care: A Staff Guide to Safe Use
What NHS England guidance says about AI scribes, including the risks and what health and care staff must do to use them safely.
A clinician finishes a consultation and, instead of typing notes, reads a short summary that an AI tool has already written from the conversation. It is quick, tidy and saves time. It may also contain a detail nobody actually said. As AI scribes spread through health and care, staff need to know what they are, what the risks are, and who is responsible for the output.
This guide summarises NHS England's guidance on the use of AI-enabled ambient scribing products in health and care settings. We refer to Version 2 of the guidance, which does not show a publication date and says that further documents will follow in early 2026. It applies to England, so check the position in your own country and your organisation's own policies.
What AI scribes are
NHS England uses several names for the same group of products: ambient scribes, AI scribes and ambient voice technologies. They turn speech into text and other outputs with very little work from the user. The outputs can include summaries, letters, clinical codes and populated health records.
The guidance is written for health and care settings that are planning to put a specific product in place. Its main audience is chief information officers and chief clinical information officers, with an appendix for technical and product teams. It is not aimed at tools used outside the supervision of the setting, so it does not tell you what to do if you are tempted to use an unapproved tool. If your service has no approved tool, ask your manager before using any AI product with information about people you support.
Is an AI scribe a medical device?
NHS England says the answer depends on the product's intended purpose and what it does. Products that only produce transcriptions are likely not to be medical devices. Using generative AI to summarise, however, would likely make a product a medical device. A medical device needs a UK Conformity Assessed (UKCA) certificate, and the guidance says a valid CE mark is equally acceptable until 30 June 2028. The NHS England supplier registry for these products requires suppliers to hold at least Medicines and Healthcare products Regulatory Agency (MHRA) Class 1 registration.
What organisations must do before using one
The guidance sets out several steps for the setting, most of which are decided above frontline level but matter to every user:
- Data protection: complete a data protection impact assessment and make sure UK GDPR is met, along with the Data Security and Protection Toolkit and Cyber Essentials.
- Clinical safety: complete the DCB0160 clinical safety documentation, including a safety case, a hazard log and a monitoring framework. Suppliers must complete DCB0129.
- Information governance: involve information governance and cyber security colleagues early.
- Procurement: the supplier registry is not a commercial framework, so organisations should not enter agreements with suppliers without checking they meet national and local requirements. Pilots should be time-limited, to a maximum of four months, and must not bypass these checks.
Telling people how their information is used
The guidance says organisations should be transparent about how information is used and shared, and should explain use before the processing takes place, giving people the chance to object. It does not state a consent requirement. Instead it lists whether consent is needed as a question the organisation has to work out. It also says staff should be educated on how to gain permission from patients to use ambient scribing. In practice, that means you should know what your organisation has decided and be able to explain it in plain words.
Risks the guidance names
- Errors, including inaccurate or incomplete documentation.
- Misreading context, for example treating a hypothetical comment as a confirmed diagnosis.
- Over-reliance on the tool, known as automation bias.
- Bias, because the tools may work less well for some accents, dialects, speech disorders and people speaking English as a second language.
- Unintended functions from generative AI and from instructions that users add.
- Data leakage and cyber security risks, including prompt injection.
- Poor fit with workflows, and effects on the interaction between patient and clinician.
Your responsibilities as a user
The clearest message for staff is that the human stays responsible. NHS England says users must review and approve any product output before further action, and that practitioners should review and revise outputs, as an ongoing responsibility. It also says organisations should train staff on the appropriate and approved use of products, and that this training can include guidance on dictation.
The guidance does not set out checklists for frontline staff, so the points below are practical suggestions, not NHS England requirements:
- Read every generated note before it goes into a record, and correct names, doses, dates and anything that was only discussed rather than decided.
- Do not rely on the summary to remember what happened. If something looks wrong, go back to your own account of the conversation.
- Only use tools your organisation has approved, and only for the purposes it has approved.
- Tell the person you support how the tool is used if that is your organisation's process, and respect an objection.
- Report errors and near misses through your usual incident process so they can be fed into the safety monitoring.
Our guides to AI governance in care homes, the CQC's AI principles for care providers and HIQA's national guidance on AI in health and social care in Ireland cover the wider regulatory picture.
Training and CPD
AI tools change quickly, so training needs refreshing. Keep a record of what you learn for your own development, and browse professional development options on our CPD pages.
Key points to remember
- AI scribes turn speech into notes, summaries and letters with little input from the user.
- Generative AI summarisation would likely make a product a medical device.
- Settings need a data protection impact assessment, clinical safety documents and information governance input before use.
- Users must review and approve outputs. The responsibility does not pass to the tool.
- People should be told how their information is used, with a chance to object.
Frequently asked questions
Can I use an AI scribe my service has not approved?
The guidance covers products that a setting has chosen and supervises. It does not say what staff should do with unapproved tools, so ask your manager and follow your organisation's policy before using any AI tool with information about the people you support.
Who is responsible if the AI makes a mistake in a note?
NHS England says users must review and approve outputs before further action, and that practitioners' responsibility to review and revise is ongoing.
Does the guidance require patient consent?
It does not state a consent requirement. It says organisations should be transparent and explain use before processing, giving people the chance to object, and it lists whether consent is needed as a question to settle locally.
This guide is for general information and is not a substitute for clinical advice, legal advice or your organisation's policies.
This page was last updated:
Learnsignal Healthcare Education Team
The Learnsignal Healthcare Education Team creates CPD and compliance training content for nurses, allied health professionals, and care providers, drawing on current regulatory guidance from bodies including NMBI and equivalent professional regulators.
View all posts by Learnsignal Healthcare Education Team


