Scan QR code to view the full leaflet online
The development and integration of Artificial Intelligence (AI) solutions into the activities of CSH Surrey has the potential to revolutionise the services it provides. AI can support the delivery of patient care, the administration and management of services and the development of intelligence to assist the strategic development and delivery of care.
CSH recognises the transformative potential of AI in the workplace and the vital role our teams will play in harnessing its benefits. This policy and its associated processes are designed to ensure that AI is used ethically, responsibly, proportionately, and effectively.
While AI can reduce certain risks and streamline routine tasks, it may also introduce new challenges that require thoughtful management. By engaging with these tools responsibly, users across CSH can make a real, positive impact, enhancing decision-making, improving efficiency, and freeing up more time to focus on delivering high-quality care and support.
The UK Government has defined 10 common principles to guide the safe, responsible and effective use of artificial intelligence.
https://www.gov.uk/government/publications/ai-playbook-for-the-uk-government/artificial-intelligence-playbook-for-the-uk-government-html
The purpose of the AI policy at CSH is to establish a clear and supportive framework for the responsible, ethical, and secure use of artificial intelligence across the organisation. It is designed not only to ensure compliance and good governance but also to empower colleagues to confidently explore and adopt AI tools that can streamline their day-to-day work, reduce repetitive tasks, and unlock more time for value-added activities.
As AI technologies become more integrated into healthcare, administrative, and operational processes, it’s essential that we define how these tools are assessed, implemented, and governed. This ensures they remain aligned with CSH’s values, clinical safety standards, and legal obligations, while also enabling staff to drive innovation and efficiency in their roles.
The policy aims to promote transparency, accountability, and trust by setting standards for data quality, privacy, bias mitigation, and decision-making support. It ensures AI is used to enhance, not replace human judgment, particularly in clinical and patient-facing contexts. Additionally, it provides guidance on procurement, risk assessment (e.g., DPIAs), staff training, and continuous evaluation of AI tools.
By implementing a robust AI policy, CSH can harness the benefits of innovation while safeguarding patient safety, staff welfare, and data protection. It also demonstrates a proactive commitment to meeting ethical and regulatory standards, such as UK GDPR and NHS guidance on digital technology. Ultimately, the policy serves as a foundation to ensure AI supports CSH’s mission to deliver high-quality, patient-centred care in a transparent and responsible manner.
AI will impact on potentially all services provided by CSH. Any service deploying an AI solution will need to follow the requirements of this policy and associated processes to ensure safe development, implementation and use to realise its full potential benefits.
All staff (including interim/off payroll workers and bank staff) will be subject to this policy and the associated requirements on the use of AI tools utilised in the support of work-based productivity and capacity.
The overall aim of the policy is to foster a culture of controlled and responsible AI use where benefits are maximised, risks are minimised and the workforce is made to feel confident about exploring how AI can help them streamline their day-to-day working processes.
Artificial Intelligence (AI) & Generative AIThe theory and development of computer systems able to perform tasks normally requiring human intelligence, such as visual perception (e.g. spotting concerns on clinical images), speech recognition, decision making and translation between languages (e.g. translating as an output that mirrors someone speaking in their first language).
Generative AI is a subset, referring to an intelligent machine that can learn from inputted data or its knowledge and by looking for apparent commonalities in the data, producing new linked or completely unique information or data. This can be outputs such as text content, images, audio/video or synthetic data. It could be used to write reports, policies or assessments/referrals.
Machine learning (ML) (including Deep learning models)
The use and development of computer systems able to learn and adapt without following explicit instructions, by using algorithms and statistical models to analyse and draw inferences from patterns in data. Machine learning algorithms are trained on data sets to create models that enable machines to perform tasks that would otherwise only be possible for humans. These tasks include categorising images, analysing data, predicting price fluctuations, etc.
Natural language processing (NLP)
Refers to a branch of computer science/AI concerned with enabling computers the ability to understand text and spoken word in much the same way human beings do.
Robotic Process Automation (RPA)
A form of business process automation using technology to mimic back-office tasks, such as extracting data, filling in forms and moving files (e.g. automatic filing of ‘normal’ results in patient records). It deploys scripts that emulate human processes and autonomously executes various activities and transactions across unrelated software systems. It uses rule-based software to perform tasks at a high volume, freeing up staff to prioritise more complex tasks. RPA is not strictly AI, the two are different. RPA is process driven, whereas AI is data driven.
Algorithm
A set of rules or instructions given to an AI system to help it learn from data and make decisions.
Bias
Systematic errors in AI outputs due to imbalanced or flawed training data, which can result in unfair or discriminatory outcomes.
Training Data
The dataset used to teach an AI model how to recognise patterns or make decisions.
Inference
The process by which an AI model applies what it has learned to new data to make predictions or decisions.
Model
The mathematical representation of patterns that the AI system has learned from data.
Black Box
A term used when the internal workings of an AI model are not easily understandable or explainable.
Explainability
The ability to understand and interpret how and why an AI model makes decisions.
Automation
Using technology to perform tasks without human intervention, often enhanced by AI to adapt and optimise processes.
Ethical AI
The practice of designing and using AI systems in ways that align with ethical principles such as fairness, transparency, and accountability.
GDPR (General Data Protection Regulation)
A UK and EU law governing how personal data is collected, used, and protected, applicable to AI that processes personal data.
DPIA (Data Protection Impact Assessment)
A required assessment under GDPR to evaluate the risks of processing personal data, particularly relevant when using AI.
Synthetic Data
Artificially generated data used to train AI models, often to avoid using real personal data.
Human-in-the-Loop
A model of AI use where humans remain involved in decision-making, especially for oversight and risk management.
Use Case
A specific scenario or purpose for which AI is applied, such as automated triage or predictive scheduling.
Responsible AI
An approach to designing and deploying AI that prioritises safety, fairness, and compliance with laws and standards.
Implementation of AI solutions will put responsibilities on all staff as well as some specific responsibilities on key roles. These are set out in the following section.
CSH Board
End-Users/our workforce:
Senior Information Risk Owner (SIRO):
Caldicott Guardian:
Data Protection Officer (DPO):
Clinical Safety Officer (CSO):
Digital Services & Business Intelligence staff:
Human Resources/People:
Procurement
Staff with designated responsibilities (outlined in the consultation section below) will work collaboratively to utilise or develop appropriate assessment tools to support the procurement, development, and implementation of AI solutions. Wherever feasible, these assessments will be integrated with existing processes, such as Data Protection Impact Assessments (DPIAs), digital clinical safety assessments, and cyber security evaluations, aligned with the NHS Digital Technology Assessment Criteria (DTAC).
Each AI solution will also be evaluated through an ethical and fairness lens, considering the potential for algorithmic bias, as well as ensuring transparency and explainability, so that users can understand how the technology functions. Furthermore, the assessment will confirm that a clear and evidence-based use case exists for the proposed AI solution.
Any AI solution will also adhere to the AI Safety Principles set out in Appendix B to this policy
AI will be applied across a broad spectrum of use cases. It is neither practical nor necessary for CSH to formally assess every individual use of AI. Staff will be clearly informed of the types of AI usage that are considered acceptable without requiring formal consultation or approval.
Staff are encouraged to use AI tools without prior consultation where:
Any team, service, or individual staff member considering the use of an AI solution where the content may include confidential, sensitive, or personal data, whether procured, internally developed, or freely available must consult with the following key roles:
While not every AI solution will require a detailed assessment by all the above roles, each area must be considered and recorded appropriately—even if a “no action required” decision is reached. This ensures full transparency and documentation of risk considerations.
The consulted roles will determine whether further engagement is required with the Senior Information Risk Owner (SIRO) and/or Caldicott Guardian.
Where appropriate, consultation may also extend to:
It is essential that the purpose, expected benefits, and rationale for deploying any AI solution are clearly defined and agreed upon before it is put into operational use.
If an AI proposal involves the use of personal data, it will be subject to screening through CSH’s Data Protection Impact Assessment (DPIA) process. Where a full DPIA is required, it will identify the appropriate legal basis for processing personal data and assess any associated risks related to its use.
The procurement of any AI solution must not begin until consultation with all relevant stakeholders (as outlined above) has been completed, or at minimum, each stakeholder has confirmed they are satisfied for procurement to proceed. This is especially important where a stakeholder will contribute directly to procurement activities, such as defining technical specifications or other key requirements and must adhere to the Digital Technology Assessment Criteria (DTAC).
When CSH is involved—either independently or in partnership with others in the development of an AI solution, the staff leading the initiative must ensure alignment with the NHS AI and Digital Regulations Service guidance (available at: Home - AI and Digital Regulations Service for health and social care, innovation.nhs.uk). Development activities must also adhere to all relevant current standards and regulations, including those specific to the nature and context of the solution, such as Digital Clinical Safety Standards and Medical Device Regulations, where applicable.
Any AI solution developed by or with the involvement of CSH will be subject to the same governance and compliance requirements outlined in this policy as those applied to procured or freely available solutions, such as the completion of a Data Protection Impact Assessment (DPIA) and consultation with designated stakeholders.
This policy does not address broader aspects of AI development, such as intellectual property rights, collaboration agreements, or contractual arrangements with external partners. These matters should be governed under separate legal and operational frameworks.
A wide range of freely accessible AI tools are available, many of which do not require local installation or integration. However, before any such tool is used, it must undergo the assessment process outlined in this policy.
We take Policy non-compliance very seriously. Information security is reported and managed through our governance mechanisms, which ultimately include reporting under the Information Governance Framework Policy.
If approved, use should still be approached with caution, particularly in clinical or sensitive contexts, where the accuracy, reliability, and appropriateness of outputs may directly impact decision-making. Responsibility for reviewing and validating outputs lies with the staff member using the tool.
Staff must adhere to the following specific requirements:
With appropriate engagement from designated key roles and relevant stakeholders, any proposed use of AI—whether involving a procured product, a locally developed solution, or a freely available tool—will follow a structured governance approval process, based on the nature and impact of the proposed application. The following governance groups will be involved, as applicable:
In situations where there is an urgent operational requirement to adopt an AI tool, typically involving freely available software, a fast-track review process will be initiated. This process will involve rapid assessment and agreement by key leads, including representatives from the CSH Board, Digital Services, Cyber Security, the Data Protection Officer, Caldicott Guardian (if applicable), and the Senior Information Risk Owner (SIRO).
A formal process flow will be maintained to guide these approvals, and all approved AI tools will be logged in a central Organisational AI Register for oversight, audit, and ongoing review purposes by the CSH Board.
There is no training or competency tools related to this document.
Adherence to the requirements of this policy will be monitored in the following ways:
The IG Steering Group will be alerted to any significant issues identified from any monitoring activities and have responsibility for identifying and undertaking any remedial or improvement actions.
An Artificial Intelligence Steering Group will be established to provide governance and oversight for the use of AI technologies across the organisation. The group will comprise representatives from digital, quality and governance, clinical, and non-clinical functions to ensure a balanced, multidisciplinary approach.
Its responsibilities include reviewing AI proposals, assessing alignment with clinical priorities and organisational strategy, ensuring compliance with legal and regulatory frameworks, and evaluating ethical, safety, and equity considerations.
The group will also oversee risk management, promote staff engagement and education, and act as an approval and escalation point for AI deployment. This ensures accountable, transparent, and safe use of AI.
There are no audits / quality assurance activities associated with this document.
When using AI in healthcare, robust quality assurance (QA) is essential to ensure safety, effectiveness, legal compliance, and ethical alignment. QA must address clinical, technical, ethical, data protection, and cybersecurity risks.
This document will be subject to review after three years or at any stage at the management’s request or because of a change in legislation or national guidance.
All new recruits to CSH Surrey will be informed through their induction that all its policies and procedures are available in the Blink.
Evidence standards framework (ESF) for digital health technologies
Information Governance Framework Policy
Information Governance Policy
IG and Data Protection Incident Management Policy and SOPs
Data Protection Policy
Data Protection Impact Assessment (DPIA)
Individual Rights Policy
Records Management Policy
To ensure the ethical, legal, and safe application of Artificial Intelligence within CSH, the following activities are explicitly restricted or prohibited. Any breaches of these restrictions may result in serious consequences, including disciplinary action under CSH policies, personal fines, loss of professional registration, and potential criminal prosecution for both the individual and the organisation:
1. Use of AI for Cognitive or Behavioural Manipulation
AI must not be used to manipulate, influence, or exploit human behaviour, especially among vulnerable individuals or groups. This includes, but is not limited to:
2. Use of AI in a Manner That Infringes Privacy
AI must respect individual privacy and data confidentiality at all times. The following practices are strictly not permitted:
Individuals may object to such processing under their rights as data subjects, and objections will be addressed in line with current data protection legislation.
3. Use of AI That Contradicts Safety or Technology Guidance
AI must comply with organisational safety protocols and technology regulations. This includes:
4. Use of AI That Negatively Impacts Individual Welfare
AI must not cause harm, distress, or disadvantage to any individual. For example:
5. Use of AI in Critical Infrastructure Without Fail-Safes
AI must not be integrated into critical infrastructure (e.g., clinical systems, operational logistics) without appropriate safeguards, which must include:
6. Use of AI to Modify Legally Binding Documents Without Controls
AI must not be used to alter, delete, or overwrite legally binding or sensitive records (e.g., clinical notes, diagnostic results, legal documents) without:
7. Use of AI to Determine Access to Services
AI must not be used as the sole mechanism for determining eligibility or access to services. This includes:
8. Use of AI to Engage Individuals Without Oversight
AI must not send messages of a personal, sensitive, or confidential nature without human validation. This includes:
9. Use of AI to Relay Critical Information Without Professional Oversight
AI-generated content involving medical, legal, or critical personal information must be reviewed by qualified professionals to ensure accuracy, appropriateness, and safety.
10. Use of AI in Recruitment That Risks Discrimination
AI tools used in recruitment or screening must be reviewed for fairness and non-discrimination. Specifically:
11. Use of AI for Purely Automated Decision-Making
AI systems must not make final decisions without human involvement. All decisions impacting individuals must be subject to:
12. Use of AI to Replicate a Person’s Likeness
Staff must not use AI to create voice, image, or video-based replicas of individuals—particularly those in senior, public-facing, or financial decision-making roles—due to the significant cybersecurity and impersonation risks involved.
13. Promoting Openness and Transparency in AI Use