Shadow AI and policy creation
Staff may already be using AI independently. Digital teams will have to identify this activity and roll out appropriate policies to moderate usage. 44% of the NHS professionals say they’re already using AI in their daily roles, with some paying out of their own pocket for subscriptions. (9) These include ChatGPT, Copilot, Grok, Heidi, Claude, Poe, Otter.ai, and Gemini.
The National Cyber Security Centre has issued security warnings for using LLMs in the public sector. It recommends not including sensitive information, such as patient information, in queries. Digital teams will need to gain visibility on how LLMs are used in Trusts, and define what the Trust would consider appropriate usage. Plus, identify what information is available to the vendor. The NCSC highlights that even if an LLM provider is considered safe for healthcare now, data privacy may change if it’s acquired.
(9) Block (2025)