Skip to content

Chapter 6

Compliance, risk, and ethical guardrails

AI isn’t just a technology decision. It’s a trust decision.

44% of NHS professionals are uncertain about the risks AI can bring. However, AI’s dependence on data means strong cybersecurity has to be a key consideration for NHS Trusts. Some bad actors are using AI to launch more sophisticated attacks on healthcare organisations. 80% of NHS professionals believe the answer to staying secure could be incorporating AI into IT and cybersecurity. (8) Network teams will need to audit AI usage in their organisation, bolster cybersecurity defences, define policies that protect information, and educate users.

(8) Block (2025)

scroll down

Cybersecurity

Digital teams will need to assess how their Trust’s current cyber defences stack up and decide what security they need to be AI-ready.

Have you got these defences?

  • Micro-segmentation
  • Zero Trust access
  • Stress testing breach plans
  • AI-driven defences
  • Aligned cyber hygiene with policy and process
  • Vulnerability assessments
  • Automated data backups
  • MFA policy
  • Patch management
  • Strong password policy
  • User education
  • Layered defences

Key actions for digital teams

Data leakages and GDPR breaches
Provide a secure, isolated AI environment where data remains within the Trust’s control and isn’t used to train external models.

AI policies
Establish clear guidelines on what data can and can’t be put into AI models. Designate an accountable owner to oversee tools and monitor which services are being accessed across the network.

Human-approved processes
Ensure any AI taking important actions has a human expert to verify and approve the change before it’s implemented on the hospital network.

Data trust
Untangle legacy infrastructure so only clean, accurate, and reliable data is used to train or prompt AI.

Monitoring behaviour
Use AI to look for trends in network records, identifying unauthorised shadow usage patterns which could threaten clinical resilience.

Shadow AI and policy creation

Staff may already be using AI independently. Digital teams will have to identify this activity and roll out appropriate policies to moderate usage. 44% of the NHS professionals say they’re already using AI in their daily roles, with some paying out of their own pocket for subscriptions. (9) These include ChatGPT, Copilot, Grok, Heidi, Claude, Poe, Otter.ai, and Gemini.

The National Cyber Security Centre has issued security warnings for using LLMs in the public sector. It recommends not including sensitive information, such as patient information, in queries. Digital teams will need to gain visibility on how LLMs are used in Trusts, and define what the Trust would consider appropriate usage. Plus, identify what information is available to the vendor. The NCSC highlights that even if an LLM provider is considered safe for healthcare now, data privacy may change if it’s acquired.

 

(9) Block (2025)

Sustainability and net zero

Deploying power-hungry AI solutions while remaining cost-effective and environmentally conscious will be a challenge for digital teams. Here’s what to consider.

Assess energy consumption

Will your existing infrastructure be able to support AI’s increased power draw?

Consider what changes you may need to make to your network infrastructure, and consider if you’re able to do that without causing service instability or unexpected costs.

Sustainable data centre strategies

How can you prevent creep to your cloud costs?

Evaluate your predicted data usage with AI over the next decade. Are you prepared to budget for cloud costs or does it make more sense in the long term to bring everything on-prem? Or even take a hybrid approach?

Join forces with estates to prevent wastage

Where’s the cross-over between networks and estates teams?

Consider how your teams can work together. AI can help monitor physical environments, which may identify energy wastage you can quickly eliminate.