CQC AI Principles: What Care Providers Must Do Before Adopting AI Tools
CQC does not approve or endorse specific AI tools; care providers must apply existing Regulations 9-12 and 17 to any AI-enabled technology, with human oversight and a Data Protection Impact Assessment required before deployment.
Care-monitoring sensors, AI-enabled rostering tools and predictive risk models are moving from pilot projects into everyday use across UK care settings. Before any registered manager signs a contract, one question matters more than the vendor's sales pitch: does this tool fit inside the regulatory framework the Care Quality Commission already enforces. CQC has been explicit that it does not approve, certify or endorse specific AI products. Instead, it expects every provider to demonstrate that an AI tool is deployed safely under the regulations that already govern care quality, principally Regulations 9 to 12 and Regulation 17 of the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014.
That distinction matters. There is no separate "AI approval" process to complete and no shortcut that substitutes for the day-to-day compliance work registered managers already do. If anything, introducing AI adds a layer of due diligence on top of existing obligations, not instead of them.
What CQC's AI principles actually say
CQC has set out its position on AI in health and social care through published guidance rather than new legislation, and it has been direct about the core idea underpinning that guidance: AI can enhance, but not replace, human decision making. Providers who adopt an AI tool remain fully accountable for the decisions made about a person's care, whether or not an algorithm contributed to that decision.
In practice, this principle translates into a handful of expectations providers should be ready to evidence at inspection:
- AI tools are used to support staff judgement, not to substitute for it — for example, a falls-risk sensor generates an alert, but a trained care worker still assesses the person and decides on the response.
- Outputs from AI systems are continuously monitored and reviewed, rather than deployed once and left unchecked.
- People using services, and where appropriate their families, understand that AI is involved in their care and retain a non-digital option wherever practical.
- Providers can explain, in plain terms, how a given tool reaches its outputs and what safeguards exist if it gets something wrong.
Because these expectations are principles rather than a fixed checklist, providers cannot simply wait for a rulebook. The responsibility sits with the registered manager to interpret how existing regulation applies to each specific tool before it goes live.
How Regulations 9 to 12 and 17 apply to AI tools
CQC has confirmed that AI-enabled tools — whether that is a wearable sensor, an AI-assisted rostering system or a predictive risk-scoring tool — are assessed under the same regulations that already apply to any other aspect of care delivery.
Regulation 9: person-centred care
Regulation 9 requires that care and treatment reflect each person's needs and preferences. An AI rostering tool that optimises for efficiency but ignores a person's preference for a consistent, familiar carer would sit uneasily with this regulation, regardless of how well the algorithm performs on paper. Providers introducing AI-enabled scheduling or care-planning tools should read our detailed guide to Regulation 9 person-centred care before assuming any efficiency gain outweighs individual choice.
Regulations 10 and 11: dignity and consent
Regulation 10 (dignity and respect) and Regulation 11 (need for consent) both bear directly on monitoring technology. A care-monitoring sensor that tracks movement, sleep or bathroom use inside someone's home raises real questions about privacy and dignity that a vendor's data sheet will not answer. People, or their legally authorised representative, must give informed consent to being monitored by AI-enabled equipment, understand what is being collected, and know how to withdraw that consent. Staff training on how to have that consent conversation is not optional; see our guide to informed consent training for healthcare staff for a practical framework.
Regulation 12: safe care and treatment
Regulation 12 covers the safety of equipment, including AI-enabled equipment, and requires providers to identify and mitigate risks such as false negatives from a predictive risk tool, sensor malfunction, or an algorithm trained on a population that does not reflect the people it is now monitoring.
Regulation 17: good governance
Regulation 17 is where most of the practical AI due diligence lands. Providers need documented policies covering procurement, staff training, incident reporting when an AI tool gets something wrong, and regular audit of whether the tool is still performing as intended. Good governance also means keeping a clear audit trail of who decided to adopt a given tool and on what evidence.
Before you switch anything on: a practical checklist
Ahead of any AI deployment, registered managers should be able to answer the following:
- Has a Data Protection Impact Assessment (DPIA) been completed and documented before the tool goes live, covering what personal and special category data the tool collects, processes and stores.
- Is there a named person accountable for the tool's ongoing performance and for acting on any incident or near-miss it produces.
- Have staff received training on both how to use the tool and how to override or escalate when its output looks wrong.
- Is there a plan for what happens if the tool fails, loses connectivity or is temporarily withdrawn, so care does not depend entirely on the technology working.
- Has consent been captured and documented for every person affected, in a form they or their representative can understand.
A DPIA in particular is not a box-ticking exercise. GDPR and UK data protection law require one wherever a new technology is likely to result in high risk to individuals' data, and AI-enabled monitoring in a care setting will almost always meet that bar. Providers still building out their wider data protection processes may find it useful to start with our overview of GDPR and data protection training for healthcare staff, since the same governance habits that keep routine records compliant apply directly to AI data flows.
What's changing over the next year
CQC published draft sector-specific AI assessment frameworks for consultation in the first part of 2026, with further sector-specific guidance and training for providers expected to follow through 2026 and into 2027. Providers should treat this as a moving target rather than a finished rulebook: the underlying regulatory duties are already fixed, but the detail of how CQC inspectors will assess AI-specific evidence is still being shaped through consultation. The safest approach for registered managers is to build AI governance into existing quality assurance and audit cycles now, rather than waiting for finalised sector guidance to arrive.
Frequently Asked Questions
Does CQC approve or certify specific AI tools for care providers?
No. CQC has been explicit that it does not approve, endorse or certify individual AI products or vendors. Responsibility for choosing, deploying and monitoring an AI tool sits with the provider, who must be able to demonstrate compliance with existing regulations, principally Regulations 9 to 12 and 17.
Which CQC regulations apply to AI-enabled care technology?
The same regulations that apply to any other aspect of care delivery apply to AI: Regulation 9 (person-centred care), Regulation 10 (dignity and respect), Regulation 11 (need for consent), Regulation 12 (safe care and treatment) and Regulation 17 (good governance). There is no separate AI-specific regulation at this stage.
Do we need a Data Protection Impact Assessment before introducing an AI monitoring tool?
Yes. CQC expects providers to complete and document a DPIA before deploying AI tools that process personal data, which covers most care-monitoring sensors, predictive risk tools and AI-assisted care planning systems.
Can AI make care decisions on its own?
No. CQC's stated position is that AI can enhance, but not replace, human decision making. A trained member of staff must remain responsible for interpreting AI outputs and making the final decision about a person's care.
Is CQC's AI guidance final, or will it change?
It is still developing. CQC published draft sector-specific assessment frameworks for consultation in 2026, with further sector guidance and training planned through 2026 and 2027, so providers should expect the detail to evolve even though the underlying regulatory duties already apply.
Getting AI governance right takes the same disciplined approach as any other area of regulatory compliance: clear policies, trained staff and evidence you can produce at inspection. Learnsignal's healthcare compliance and CPD courses help registered managers and their teams build exactly that foundation, covering the regulatory knowledge and practical skills needed to adopt new technology safely. Explore our healthcare CPD courses to see how your team can get ahead of CQC's evolving expectations.
This page was last updated:
Learnsignal Education Team
Expert Tutor at Learnsignal
Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.
View all posts by Learnsignal Education Team


