AI Governance in the NHS

by Amber Williams

What 100 NHS cyber and digital leaders told us and what it means

The NHS is deploying AI at a pace that reflects genuine ambition. Governing it safely is one of the hardest challenges cyber and digital leaders are currently navigating, and most are doing it without a clear picture of where their peers stand.

We commissioned this research to give them one.

100 senior NHS cyber and digital leaders, CISOs, CIOs, and CDIOs from across Trusts, ICBs, NHS England, and the MHRA, shared an honest assessment of where their organisations currently stand on AI governance.

The findings cover visibility, board engagement, maturity, incident detection, clinical accountability, and where budget is going.

The data is self-reported and we present it as such. What it offers is a genuine peer benchmark, and in places, a candid picture of where the work still needs to happen.

Key Findings

  • Visibility

    41% have full visibility of shadow AI, 54% mostly visible. 21% also flag visibility as the top current challenge

  • Board engagement

    58% cite lack of board mandate as their top barrier

  • AI governance maturity

    89% rate maturity as either high or medium

  • Incident detection

    Only 38% said they would definitely know within 24 hours if an AI tool caused a patient safety incident

  • Clinical Accountability

    No dominant answer across the sector at where accountability sits

  • Regulatory Readiness

    43% are very prepared, 51% getting prepared. Only 6% just starting the journey

Three practical priorities for the next 12 months

Build the board case in operational terms.

Frame AI risk in the language the board already uses: patient safety, regulatory exposure, and reputational risk.

Pressure-test incident detection.

59% would only probably detect an AI-linked patient safety incident. A tabletop exercise is a
practical starting point.

Treat AI procurement assurance as a distinct capability.

Existing processes were not built for model behaviour, data provenance, or clinical safety. Add AI-specific assurance steps rather than replacing what works.

Read the full report

See how your organisation compares against 100 NHS cyber and digital leaders on AI governance, visibility, board engagement, and clinical accountability.