Introduction

The development and integration of Artificial Intelligence (AI) solutions into the activities of CSH Surrey has the potential to revolutionise the services it provides.  AI can support the delivery of patient care, the administration and management of services and the development of intelligence to assist the strategic development and delivery of care. 

CSH recognises the transformative potential of AI in the workplace and the vital role our teams will play in harnessing its benefits. This policy and its associated processes are designed to ensure that AI is used ethically, responsibly, proportionately, and effectively.

While AI can reduce certain risks and streamline routine tasks, it may also introduce new challenges that require thoughtful management. By engaging with these tools responsibly, users across CSH can make a real, positive impact, enhancing decision-making, improving efficiency, and freeing up more time to focus on delivering high-quality care and support.

The UK Government has defined 10 common principles to guide the safe, responsible and effective use of artificial intelligence.

  • Principle 1: You know what AI is and what its limitations are
  • Principle 2: You use AI lawfully, ethically and responsibly
  • Principle 3: You know how to use AI securely
  • Principle 4: You have meaningful human control at the right stage
  • Principle 5: You understand how to manage the AI life cycle
  • Principle 6: You use the right tool for the job
  • Principle 7: You are open and collaborative
  • Principle 8: You work with commercial colleagues from the start
  • Principle 9: You have the skills and expertise needed to implement and use AI
  • Principle 10: You use these principles alongside your organisation’s policies and have the right assurance in place

https://www.gov.uk/government/publications/ai-playbook-for-the-uk-government/artificial-intelligence-playbook-for-the-uk-government-html

Purpose

The purpose of the AI policy at CSH is to establish a clear and supportive framework for the responsible, ethical, and secure use of artificial intelligence across the organisation. It is designed not only to ensure compliance and good governance but also to empower colleagues to confidently explore and adopt AI tools that can streamline their day-to-day work, reduce repetitive tasks, and unlock more time for value-added activities.

As AI technologies become more integrated into healthcare, administrative, and operational processes, it’s essential that we define how these tools are assessed, implemented, and governed. This ensures they remain aligned with CSH’s values, clinical safety standards, and legal obligations, while also enabling staff to drive innovation and efficiency in their roles.

The policy aims to promote transparency, accountability, and trust by setting standards for data quality, privacy, bias mitigation, and decision-making support. It ensures AI is used to enhance, not replace human judgment, particularly in clinical and patient-facing contexts. Additionally, it provides guidance on procurement, risk assessment (e.g., DPIAs), staff training, and continuous evaluation of AI tools.

By implementing a robust AI policy, CSH can harness the benefits of innovation while safeguarding patient safety, staff welfare, and data protection. It also demonstrates a proactive commitment to meeting ethical and regulatory standards, such as UK GDPR and NHS guidance on digital technology. Ultimately, the policy serves as a foundation to ensure AI supports CSH’s mission to deliver high-quality, patient-centred care in a transparent and responsible manner.

Scope

AI will impact on potentially all services provided by CSH. Any service deploying an AI solution will need to follow the requirements of this policy and associated processes to ensure safe development, implementation and use to realise its full potential benefits. 

All staff (including interim/off payroll workers and bank staff) will be subject to this policy and the associated requirements on the use of AI tools utilised in the support of work-based productivity and capacity.

The overall aim of the policy is to foster a culture of controlled and responsible AI use where benefits are maximised, risks are minimised and the workforce is made to feel confident about exploring how AI can help them streamline their day-to-day working processes. 

Definitions

Artificial Intelligence (AI) & Generative AI
The theory and development of computer systems able to perform tasks normally requiring human intelligence, such as visual perception (e.g. spotting concerns on clinical images), speech recognition, decision making and translation between languages (e.g. translating as an output that mirrors someone speaking in their first language). 

Generative AI is a subset, referring to an intelligent machine that can learn from inputted data or its knowledge and by looking for apparent commonalities in the data, producing new linked or completely unique information or data.  This can be outputs such as text content, images, audio/video or synthetic data.  It could be used to write reports, policies or assessments/referrals.

Machine learning (ML) (including Deep learning models)

The use and development of computer systems able to learn and adapt without following explicit instructions, by using algorithms and statistical models to analyse and draw inferences from patterns in data.  Machine learning algorithms are trained on data sets to create models that enable machines to perform tasks that would otherwise only be possible for humans.  These tasks include categorising images, analysing data, predicting price fluctuations, etc.

Natural language processing (NLP)

Refers to a branch of computer science/AI concerned with enabling computers the ability to understand text and spoken word in much the same way human beings do.

Robotic Process Automation (RPA)

A form of business process automation using technology to mimic back-office tasks, such as extracting data, filling in forms and moving files (e.g. automatic filing of ‘normal’ results in patient records).  It deploys scripts that emulate human processes and autonomously executes various activities and transactions across unrelated software systems.  It uses rule-based software to perform tasks at a high volume, freeing up staff to prioritise more complex tasks.  RPA is not strictly AI, the two are different.  RPA is process driven, whereas AI is data driven.

Algorithm

A set of rules or instructions given to an AI system to help it learn from data and make decisions.

Bias

Systematic errors in AI outputs due to imbalanced or flawed training data, which can result in unfair or discriminatory outcomes.

Training Data

The dataset used to teach an AI model how to recognise patterns or make decisions.

Inference

The process by which an AI model applies what it has learned to new data to make predictions or decisions.

Model

The mathematical representation of patterns that the AI system has learned from data.

Black Box

A term used when the internal workings of an AI model are not easily understandable or explainable.

Explainability

The ability to understand and interpret how and why an AI model makes decisions.

Automation

Using technology to perform tasks without human intervention, often enhanced by AI to adapt and optimise processes.

Ethical AI

The practice of designing and using AI systems in ways that align with ethical principles such as fairness, transparency, and accountability.

GDPR (General Data Protection Regulation)

A UK and EU law governing how personal data is collected, used, and protected, applicable to AI that processes personal data.

DPIA (Data Protection Impact Assessment)

A required assessment under GDPR to evaluate the risks of processing personal data, particularly relevant when using AI.

Synthetic Data

Artificially generated data used to train AI models, often to avoid using real personal data.

Human-in-the-Loop

A model of AI use where humans remain involved in decision-making, especially for oversight and risk management.

Use Case

A specific scenario or purpose for which AI is applied, such as automated triage or predictive scheduling.

Responsible AI

An approach to designing and deploying AI that prioritises safety, fairness, and compliance with laws and standards.

Responsibilities

Implementation of AI solutions will put responsibilities on all staff as well as some specific responsibilities on key roles.  These are set out in the following section.

CSH Board

  • Ensure AI solutions comply with all applicable laws, regulations, and NHS standards, including data protection (GDPR), clinical safety, and procurement requirements.
  • Approve and oversee the implementation of robust AI governance frameworks, including ethical use policies, risk assessments, and assurance processes.
  • Maintain accountability for AI deployment decisions, ensuring they align with organisational values, patient safety standards, and strategic objectives.
  • Monitor and challenge AI-related risks and mitigations, receiving regular assurance reports on compliance, performance, and impact.
  • Promote transparency and public trust in AI use, ensuring patients, staff, and partners are informed about AI applications and their safeguards.

End-Users/our workforce:

  • Utilise AI solutions in accordance with established CSH guidelines and processes
  • Highlight any AI solutions that fall within the scope of requiring consultation and approval before use.
  • Make the DPO aware of an AI solution tender/procurement requirement.
  • Are responsible for the use of any output of AI solutions that they use, checking that the output is accurate, appropriate and usable.
  • Provide feedback and insights on the effectiveness, usability and impact of AI solutions
  • Report any concerns or incident related to AI solution safety or performance via existing CSH incident/near miss procedures.

Senior Information Risk Owner (SIRO):

  • Take responsibility for the overall governance and management of the information risks associated with AI solutions, ensuring that such risks are subject to effective assessment and mitigation actions.
  • Provide oversight and strategic direction to ensure the responsible use of AI solutions and ensure appropriate stakeholder engagement.

Caldicott Guardian:

  • Ensure use of AI solutions are aligned with the Caldicott principles.
  • Ensure any use of confidential patient information is ethical and appropriate.
  • Provide advice and guidance on application of Caldicott principles to the use of AI solutions.

Data Protection Officer (DPO):

  • Ensure any use of AI solutions is compliant with data protection legislation and any related guidance from the Information Commissioner’s Office.
  • Provide advice and guidance on data protection related to AI solutions
  • Support the development of Data Protection Impact Assessments for AI solutions where personal data is used. DPIAs will continue to be subject to the approval process documented in CSH IG policies.
  • Serve as the point of contact for data subjects and supervisory authorities regarding any data protection concerns related to AI solutions.
  • Investigate and address any incidents related to use of personal data in AI solutions (jointly with other key staff as required).

Clinical Safety Officer (CSO):

  • Assess any clinical safety risks associated with AI solutions, with reference to any relevant clinical safety standards in place at that time (e.g. DCB0129 and DCB 0160).
  • Assess whether the proposed solution requires checking and compliance with Medical and Healthcare Products Regulatory Agency (MHRA) guidance, Medical Device Regulations and guidance from the National Institute for Clinical Excellence (NICE).
  • Produce and maintain any required clinical safety reports for AI solutions that support, influence or impact clinical care.
  • Investigate and address any incidents related to clinical safety in AI solutions (jointly with other key staff as required.)
  • Establish any safety protocols and guidelines required for the safe utilisation of AI solutions supporting clinical care.

Digital Services & Business Intelligence staff:

  • Ensure the proper configuration, security and compatibility of AI solutions.
  • Ensure assessment of cyber security requirements of AI solutions.
  • Support the implementation, integration and maintenance of AI solutions.

Human Resources/People:

  • Support for any HR/People issues identified in implementation of an AI solution, facilitate the implementation of any required impact assessment/equality impact assessment, where appropriate if the AI solution is likely to significantly impact on roles within CSH or any proposals to use AI in relation to staff and staff data.

Procurement

  • Procurement in conjunction with Digital Services are responsible for ensuring AI tools meet NHS Digital Technology Assessment Criteria (DTAC), conducting due diligence on clinical safety, data protection, and security, engaging stakeholders, verifying supplier credentials, maintaining audit trails, and ensuring contracts include compliance clauses, ethical standards, and provisions for ongoing monitoring and risk management.

Policy details

Assessment of AI solutions

Staff with designated responsibilities (outlined in the consultation section below) will work collaboratively to utilise or develop appropriate assessment tools to support the procurement, development, and implementation of AI solutions. Wherever feasible, these assessments will be integrated with existing processes, such as Data Protection Impact Assessments (DPIAs), digital clinical safety assessments, and cyber security evaluations, aligned with the NHS Digital Technology Assessment Criteria (DTAC).

Each AI solution will also be evaluated through an ethical and fairness lens, considering the potential for algorithmic bias, as well as ensuring transparency and explainability, so that users can understand how the technology functions. Furthermore, the assessment will confirm that a clear and evidence-based use case exists for the proposed AI solution.

Any AI solution will also adhere to the AI Safety Principles set out in Appendix B to this policy

Acceptable use of AI solutions without consultation

AI will be applied across a broad spectrum of use cases. It is neither practical nor necessary for CSH to formally assess every individual use of AI. Staff will be clearly informed of the types of AI usage that are considered acceptable without requiring formal consultation or approval.

Staff are encouraged to use AI tools without prior consultation where:

  • The AI tool does not involve the input or upload of any confidential, sensitive, or personal data (including personal data of others or commercially sensitive information).
  • The AI tool is used solely to generate non-decisional content, such as text for documents or images, and is not relied upon for clinical, operational, or business decision-making.

Consultation on potential use of an AI solution

Any team, service, or individual staff member considering the use of an AI solution where the content may include confidential, sensitive, or personal data, whether procured, internally developed, or freely available must consult with the following key roles:

  • The Caldicott Guardian should be consulted to ensure that any use of AI appropriately safeguards patient confidentiality and aligns with data sharing principles.
  • Data Protection Officer to determine whether personal data will be processed.
  • Clinical Safety Officer to assess any clinical implications or uses of the AI solution.
  • Digital Services lead to review software implementation and technical alignment.
  • Cyber Security Lead to evaluate the security of the software and any external systems involved.
  • Human Resources / Voice Representative to consider potential impacts on the workforce.

While not every AI solution will require a detailed assessment by all the above roles, each area must be considered and recorded appropriately—even if a “no action required” decision is reached. This ensures full transparency and documentation of risk considerations.

The consulted roles will determine whether further engagement is required with the Senior Information Risk Owner (SIRO) and/or Caldicott Guardian.

Where appropriate, consultation may also extend to:

  • Staff and the CSH Voice for internal engagement.
  • Members of the public to ensure transparency and accountability.
  • Partner organisations that may be affected by CSH’s use of AI technologies.

Purpose and legal basis

It is essential that the purpose, expected benefits, and rationale for deploying any AI solution are clearly defined and agreed upon before it is put into operational use.

If an AI proposal involves the use of personal data, it will be subject to screening through CSH’s Data Protection Impact Assessment (DPIA) process. Where a full DPIA is required, it will identify the appropriate legal basis for processing personal data and assess any associated risks related to its use.

Procuring AI solutions

The procurement of any AI solution must not begin until consultation with all relevant stakeholders (as outlined above) has been completed, or at minimum, each stakeholder has confirmed they are satisfied for procurement to proceed. This is especially important where a stakeholder will contribute directly to procurement activities, such as defining technical specifications or other key requirements and must adhere to the Digital Technology Assessment Criteria (DTAC).

Developing AI solutions

When CSH is involved—either independently or in partnership with others in the development of an AI solution, the staff leading the initiative must ensure alignment with the NHS AI and Digital Regulations Service guidance (available at: Home - AI and Digital Regulations Service for health and social care, innovation.nhs.uk). Development activities must also adhere to all relevant current standards and regulations, including those specific to the nature and context of the solution, such as Digital Clinical Safety Standards and Medical Device Regulations, where applicable.

Any AI solution developed by or with the involvement of CSH will be subject to the same governance and compliance requirements outlined in this policy as those applied to procured or freely available solutions, such as the completion of a Data Protection Impact Assessment (DPIA) and consultation with designated stakeholders.

This policy does not address broader aspects of AI development, such as intellectual property rights, collaboration agreements, or contractual arrangements with external partners. These matters should be governed under separate legal and operational frameworks.

Freely available AI solutions

A wide range of freely accessible AI tools are available, many of which do not require local installation or integration. However, before any such tool is used, it must undergo the assessment process outlined in this policy.

We take Policy non-compliance very seriously. Information security is reported and managed through our governance mechanisms, which ultimately include reporting under the Information Governance Framework Policy.

If approved, use should still be approached with caution, particularly in clinical or sensitive contexts, where the accuracy, reliability, and appropriateness of outputs may directly impact decision-making. Responsibility for reviewing and validating outputs lies with the staff member using the tool.

Staff must adhere to the following specific requirements:

  • AI tools must not be used to make decisions without the output being reviewed and validated by staff with appropriate skills and expertise.
  • When AI tools are used to assist in authoring any document, this use must be explicitly noted within the document. Given the risk of AI generating inaccurate, biased, or misleading content, all outputs must be thoroughly reviewed by a suitably qualified staff member.
  • Personal data or commercially or operationally sensitive information must not be entered into such tools without prior consultation with the appropriate roles identified in this policy (e.g. Data Protection Officer, Cyber Security Lead).

Routes to approval for use

With appropriate engagement from designated key roles and relevant stakeholders, any proposed use of AI—whether involving a procured product, a locally developed solution, or a freely available tool—will follow a structured governance approval process, based on the nature and impact of the proposed application. The following governance groups will be involved, as applicable:

  • The Finance, Digital, and Innovation Committee (FDIC) will act as a formal route of approval for AI solutions, ensuring alignment with financial, strategic, and digital governance standards.
  • Information Governance Steering Group – All AI proposals must be reviewed to assess the use and impact on personal and sensitive data.
  • Recruitment and Retention Focus group – Engagement is required where the AI solution may influence workforce roles, responsibilities, or staffing structures.
  • Quality & Safety Committee – Where the AI tool is intended for use in or has potential implications for clinical services or patient care.
  • Putting People First Committee (PPFC). – Where the AI product is designed to support or be implemented within a patient environment, internal approvals will be communicated accordingly. Final approval may also be subject to the customer’s own governance and assurance processes.

In situations where there is an urgent operational requirement to adopt an AI tool, typically involving freely available software, a fast-track review process will be initiated. This process will involve rapid assessment and agreement by key leads, including representatives from the CSH Board, Digital Services, Cyber Security, the Data Protection Officer, Caldicott Guardian (if applicable), and the Senior Information Risk Owner (SIRO).

A formal process flow will be maintained to guide these approvals, and all approved AI tools will be logged in a central Organisational AI Register for oversight, audit, and ongoing review purposes by the CSH Board.

TRAINING AND RELATED COMPETENCY TOOLS

There is no training or competency tools related to this document.

MONITORING OF COMPLIANCE

Adherence to the requirements of this policy will be monitored in the following ways:

  • Initial AI proposal assessment and screening of AI proposals for Data Protection Impact Assessments and completion of full assessments where required. In line with existing IG policies and conducted via existing procedures.
  • Staff internet use monitoring for potential use of unapproved AI solutions available freely on the internet.
  • Incident & near miss monitoring for any mention or potential AI issues or threats.

The IG Steering Group will be alerted to any significant issues identified from any monitoring activities and have responsibility for identifying and undertaking any remedial or improvement actions.

Artificial Intelligence Steering Group

An Artificial Intelligence Steering Group will be established to provide governance and oversight for the use of AI technologies across the organisation. The group will comprise representatives from digital, quality and governance, clinical, and non-clinical functions to ensure a balanced, multidisciplinary approach.

Its responsibilities include reviewing AI proposals, assessing alignment with clinical priorities and organisational strategy, ensuring compliance with legal and regulatory frameworks, and evaluating ethical, safety, and equity considerations.

The group will also oversee risk management, promote staff engagement and education, and act as an approval and escalation point for AI deployment. This ensures accountable, transparent, and safe use of AI.

Associated Audits and Quality Assurance

There are no audits / quality assurance activities associated with this document.

Measured Standards

When using AI in healthcare, robust quality assurance (QA) is essential to ensure safety, effectiveness, legal compliance, and ethical alignment. QA must address clinical, technical, ethical, data protection, and cybersecurity risks.

  1. UK GDPR & Data Protection Act 2018 – Ensures personal data is processed lawfully and transparently.
  2. Data Protection Impact Assessment (DPIA) – Required for any AI system processing personal data.
  3. NHS Data Security and Protection Toolkit (DSPT) – Assesses organisational compliance with data protection standards.
  4. DCB0129 – Clinical Risk Management: Manufacturers of Health IT Systems (for developers of AI solutions).
  5. DCB0160 – Clinical Risk Management: Deployment and Use of Health IT Systems (for deploying AI solutions in clinical environments).
  6. NICE Evidence Standards Framework for Digital Health Technologies – Describes levels of evidence needed for clinical effectiveness and economic impact.
  7. MHRA Medical Device Regulations (UK MDR 2002) – If the AI tool qualifies as a medical device, it must be CE/UKCA marked and meet MHRA requirements.
  8. ISO 13485 – Quality management systems for medical device manufacturers.                                                                                                                                                                                                                                                          
  9. ISO/IEC 27001 – Information security management system (for infrastructure supporting AI).

REVIEW

This document will be subject to review after three years or at any stage at the management’s request or because of a change in legislation or national guidance.

DISSEMINATION AND IMPLEMENTATION

All new recruits to CSH Surrey will be informed through their induction that all its policies and procedures are available in the Blink.

ASSOCIATED DOCUMENTS AND REFERENCES

  1. NHS AI and Digital Regulations Service
  2. DCB0129 Standard
  3. DCB0160 Standard
  4. ICO Guidance on AI and Data Protection
  5. MHRA Guidance on Software and AI as a Medical Device (SaMD/AIaMD)
  6. AI Ethics Framework (Gov.uk Office for AI)

Related NICE Guidance

Evidence standards framework (ESF) for digital health technologies

Related CSH Surrey Documents

Information Governance Framework Policy

Information Governance Policy

IG and Data Protection Incident Management Policy and SOPs

Data Protection Policy

Data Protection Impact Assessment (DPIA)

Individual Rights Policy

Records Management Policy

Appendix A Prohibited and Restricted Uses of AI

To ensure the ethical, legal, and safe application of Artificial Intelligence within CSH, the following activities are explicitly restricted or prohibited. Any breaches of these restrictions may result in serious consequences, including disciplinary action under CSH policies, personal fines, loss of professional registration, and potential criminal prosecution for both the individual and the organisation:

1. Use of AI for Cognitive or Behavioural Manipulation

AI must not be used to manipulate, influence, or exploit human behaviour, especially among vulnerable individuals or groups. This includes, but is not limited to:

  • Prohibiting the use of automated chatbots to offer advice or support to vulnerable people without appropriate human oversight.
  • Ensuring all AI systems are designed to support users rather than exploit psychological vulnerabilities.

2. Use of AI in a Manner That Infringes Privacy

AI must respect individual privacy and data confidentiality at all times. The following practices are strictly not permitted:

  • Tracking the physical location of any individual—patient, staff, or member of the public—without their informed, explicit consent.
  • Using AI technologies that rely on facial recognition or train on biometric data without a clear, lawful basis and regulatory approval.

Individuals may object to such processing under their rights as data subjects, and objections will be addressed in line with current data protection legislation.

3. Use of AI That Contradicts Safety or Technology Guidance

AI must comply with organisational safety protocols and technology regulations. This includes:

  • Avoiding the deployment of AI solutions that violate terms of service, contractual agreements, or internal policy (e.g., SCW or NHS standards).
  • Ensuring that any deviations from approved guidelines are supported by a documented research or pilot methodology.

4. Use of AI That Negatively Impacts Individual Welfare

AI must not cause harm, distress, or disadvantage to any individual. For example:

  • AI must not be used to generate media content (e.g., images, video, voice) of individuals without their explicit consent.
  • All AI implementations should be evaluated for potential psychosocial or reputational harm.

5. Use of AI in Critical Infrastructure Without Fail-Safes

AI must not be integrated into critical infrastructure (e.g., clinical systems, operational logistics) without appropriate safeguards, which must include:

  • Clearly defined fail-safe mechanisms and manual override capabilities.
  • Regular testing of backup systems to ensure reliability, availability, and resilience.
  • Inclusion of AI elements in business continuity and disaster recovery plans.

6. Use of AI to Modify Legally Binding Documents Without Controls

AI must not be used to alter, delete, or overwrite legally binding or sensitive records (e.g., clinical notes, diagnostic results, legal documents) without:

  • Human oversight and authorisation.
  • Full traceability and version control in compliance with data protection and records management policies.

7. Use of AI to Determine Access to Services

AI must not be used as the sole mechanism for determining eligibility or access to services. This includes:

  • Prohibiting AI from making automated decisions that could exclude individuals from care, support, or employment opportunities.

8. Use of AI to Engage Individuals Without Oversight

AI must not send messages of a personal, sensitive, or confidential nature without human validation. This includes:

  • Automated communications to patients or staff must be reviewed and authorised by trained personnel before release.

9. Use of AI to Relay Critical Information Without Professional Oversight

AI-generated content involving medical, legal, or critical personal information must be reviewed by qualified professionals to ensure accuracy, appropriateness, and safety.

10. Use of AI in Recruitment That Risks Discrimination

AI tools used in recruitment or screening must be reviewed for fairness and non-discrimination. Specifically:

  • AI must not process or be trained on protected characteristics in ways that could result in bias or discriminatory outcomes.
  • All recruitment-related AI usage must comply with equality, diversity, and inclusion (EDI) legislation and policies.

11. Use of AI for Purely Automated Decision-Making

AI systems must not make final decisions without human involvement. All decisions impacting individuals must be subject to:

  • Human review, approval, and accountability by appropriately trained staff.

12. Use of AI to Replicate a Person’s Likeness

Staff must not use AI to create voice, image, or video-based replicas of individuals—particularly those in senior, public-facing, or financial decision-making roles—due to the significant cybersecurity and impersonation risks involved.

13. Promoting Openness and Transparency in AI Use

  • All staff and partners are encouraged to embrace the Seven Principles of Public Life (Nolan Principles): selflessness, integrity, objectivity, accountability, openness, honesty, and leadership. Upholding these principles ensures our use of AI remains transparent, ethical, and focused on delivering the best outcomes for patients and colleagues.
  • CSH will commit to transparency around how AI is used within its services.
  • Clear communication channels will be maintained for staff, service users, and the public to raise questions or concerns regarding AI use.