Advise / Resolve / Learn

NHS Resolution guidance on scheme coverage and liability issues concerning the use of Artificial Intelligence (AI)

1. What is AI?

AI is not new and there is no single agreed definition of what constitutes an AI tool or programme. The UK Government AI Playbook uses the definition of AI adopted by OECD countries:

An AI system is a machine-based system that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. Different AI systems vary in their levels of autonomy and adaptiveness after deployment.

In general terms, this can be thought of as tasks done by machines which were previously done by humans and can include:

  • Diagnostic tools (e.g. image recognition for radiology or dermatology)
  • Predictive analytics (e.g. identifying patients at risk of deterioration)
  • Decision support systems (e.g. treatment recommendations, consenting)
  • Administrative and operational tools (e.g. triage, note taking, chat bots)

AI systems may vary on a spectrum from Assistive (supporting clinicians in decision making) to Autonomous (making recommendations or decisions without direct human oversight). AI should be considered a tool to support clinical practice and decision making rather than a substitute for clinical judgement, unless explicitly authorised otherwise.

2. Is medical care provided involving the use of AI covered by NHS Resolution’s existing indemnity schemes?

Yes, NHS Resolution’s schemes cover the full range of clinical services provided by the National Health Service (NHS).

It is important to recognise that where harm arises from the failure or malfunction of an AI system, the manufacturer may be liable under product liability law. However current product liability law may not cover delayed harm – and depending on the purpose of the AI device, it might not be clear that harm has occurred for several years.

Organisations should therefore ensure that their contracts require the manufacturer to hold an appropriate level of indemnity cover and establish a clear route of recovery in the event of a claim. Alternatively, where members choose to contract on the basis that they will carry this risk themselves, they should be aware that doing so could expose them to additional liability.

Irrespective of any product liability issues, all clinicians using AI for the purposes of care, diagnosis or treatment owe the patient a duty of care under the law of negligence (see section 4). NHS Resolution’s indemnity schemes provide cover against negligence claims, subject to the usual terms and conditions of those schemes.

3. We are about to adopt an AI tool – what do we need to consider?

When adopting an AI tool, there are additional considerations beyond those that apply to implementing other software. The UK Government AI Playbook provides general guidance on implementing AI. In a clinical context, you also may want to consider what sector-specific regulation applies, for example:

  • it may be a medical device: see Medicines and Healthcare products Regulatory Agency (MHRA) guidance and the Medical Device Regulations 2002;
  • it may be profiling or Automated Decision-Making: see ICO guidance and Article 22 of the UK GDPR (note the ICO is planning to update the ‘Automated Decision Making (ADM) and Profiling Guidance’ – the final version of the updated guidance is due for publication in Summer 2026);
  • other UK legislation or standards may apply such as DCB0129 and DCB0160 or General Product Safety Regulations.

NHS and Government frameworks are often used to purchase AI and software products. Organisations should ensure that the contracts are also appropriately configured to include appropriate requirements, liability levels, standards and warranties for AI. You may need to be able to evidence application of good governance frameworks, alongside compliance with information law, including transparency notices, Data Protection Impact Assessments (DPIAs) and processes to address profiling and automated decision making (where applicable) along with evidence of relevant staff education and training.

Failure to have appropriate contracts in place may result in the organisation being responsible for additional liabilities. The documentation and evidence that could be relevant in the event of litigation involving AI tools depends on the tool, its function and the nature of the claim.

4. How is liability assessed in the event of a clinical negligence claim involving AI?

This will depend upon the precise facts of the case. The law governing breach of duty in clinical negligence claims continues to centre on the leading judgments of Bolam and Bolitho. However, the law around standards of care delivered using AI tools is developing and has not yet been clarified by relevant case law. As with any other test or result, clinicians should always check the results of an AI process if and before a clinical decision is being made, to ensure they are satisfied it is clinically appropriate. It is far more likely that medical negligence claims will be pursued against the treating NHS organisation than the developers or manufacturers of AI programmes or products.

Areas of challenge may include:

  • Did the clinician appropriately rely on the AI, or fail to apply their own judgment?
  • Was the AI used in accordance with guidance, training, and regulatory approval?
  • Were any known limitations / performance concerns of the AI system disregarded?

5. Will Clinical Negligence Scheme for Trusts (CNST) cover apply if we participate in research or pilot projects involving AI?

Cover is available where trials involve the diagnosis, treatment or care of NHS patients delivered by the CNST member. Cover likewise applies if the member is treating a private patient, provided such treatment constitutes an income-generation activity for the member (as opposed to the clinician(s) involved).

6. What happens if staff use AI in ways not approved or outside governance processes?

Indemnity will still apply where AI is used for the diagnosis, treatment or care of NHS patients in the course of the individual’s employment. However, where there is wilful departure from processes which amounts to actual, or alleged, gross negligence, NHS Resolution’s schemes do not cover the defence of such criminal charges.

7. How should we prepare for potential claims involving AI?

Organisations should maintain governance frameworks, ensure clear contractual terms with suppliers and keep a comprehensive log of contracts and permitted uses of AI, and build staff confidence in documenting clinical reasoning alongside AI use. Organisations should ensure that they have access to comprehensive records of which tools are in use at a particular time, and what version of that tool, in line with industry best practice. This should include reference to the specific literature the tool points to, particularly if patient facing. This information may be crucial to defending any claims which arise from their use.

AI frequently involves processing confidential and personal data. Where relevant, records of consent should be logged. The documentation associated with meeting UK GDPR and the Data Protection Act 2018 may be key in the event of a claim e.g. DPIAs, Transparency Notices, Data Processing agreements or contracts. Evidence of processes meeting profiling and Automated Decision Making (ADM) controls may also assist.

It may also be relevant to consider how DPIA risks and outcomes will be recorded, reviewed and fed into risk management systems to facilitate early detection of any issues. Approaches may include algorithmic auditing as noted by the MHRA and BS30440.

Staff will need training not only on how to use AI tools, but also on their limitations and potential risks. Staff training should be clear on the purpose of the tool, the data it uses and how to use the tool in conjunction with their processes and what communications are necessary with the patient. Records of such governance and training can be helpful in the event of a claim.

Appropriate monitoring and oversight of AI tools should be put in place. Models may experience ‘drift’ over time, and the details of the metrics and the thresholds in place to monitor this may be helpful. The monitoring and governance should include escalation processes for reporting of issues and governance over amendment of thresholds. Documentation detailing the same may help evidence appropriate governance being in place.

8. How do we evidence safe use of AI in the event of a clinical negligence claim?

In addition to the advice given in answer 7, it is important to keep clear audit trails, including records of how AI outputs were considered, and document any reasons for following or overriding AI recommendations.

For AI tools to be used safely, organisations need to ensure where such a tool has made a recommendation or decision, that this is interpretable by the clinician (just as with any other tool used in healthcare) and that the appropriate assurance processes for oversight and monitoring of the tool are in place (along with proper notification, where required, to patients). In this way, if a claim is made, decision making processes and responsibilities can be properly understood and clinicians understand how to flag concerns with tool output or performance.

Organisations should also ensure they are properly logging risks and issues including reporting back to the MHRA where organisations are using AI which constitutes a medical device. 

Evidence of patient consent, where required, must be clearly recorded on file, where consent is the lawful basis for using AI. In circumstances where a patient has been referred to a consenting tool / app to support their own decision making, this should also be referenced in the notes.

9. How should incidents involving AI be reported to NHS Resolution?

Given that AI in clinical practice is still relatively novel from a claims perspective, potential claims involving avoidable harm caused by the use of AI should be reported to NHS Resolution at an early stage for pro-active management.

Published:

Awards and accreditation badges