#91. The Clinical Safety Gap

Two things landed in my reading pile this week that, at first glance, sit in different worlds. One is a sobering piece of UCL research in BMJ Innovations warning that the NHS 10 Year Health Plan “risks propagating patient harm at an unprecedented scale.” The other is the MHRA-established National Commission’s blueprint for regulating AI in healthcare.

Both tell a similar story, but from different points of view.

First, the numbers.

Across 239 NHS trusts and ICBs, researchers found 14,848 digital health technologies in active use. Seventy per cent had no documented safety assurance. Only 17% were fully assured - despite formal clinical risk assessment being a statutory requirement under the Health and Social Care Act 2012.

The follow-up analysis asked why, and the answer is depressingly mundane: capacity.

On average roughly one full-time Clinical Safety Officer per organisation (1.3 FTE in trusts, 0.4 in ICBs) and even those figures flatter reality, because CSO duties are almost always bolted onto a wider day job. In eleven organisations the CSO function sat with an associate medical director, CCIO or chief nurse.

As the authors put it, safety oversight lands with the people who have the least time to do it, which reduces effective capacity and stops anyone building real experiential expertise.

Now hold that against the AI blueprint.

The National Commission’s 44 recommendations, built on evidence from more than 12,000 people, push decisively away from one-off, point-in-time approval towards lifecycle regulation: staged authorisations for new models, continuous real-world monitoring after deployment, public searchable information on device safety and adverse incidents, and stronger enforcement powers. It frames safe deployment as a responsibility of the whole healthcare system, not the regulator alone.

So, one report says we can’t reliably assure the static technology we already have, while the other says the technology arriving next is dynamic, adaptive, and needs assurance continuously.

Read together, these two reports set a clear agenda for anyone leading a large-scale digital health programme. Six strategic reponses worth considering:

  • Safety is an adoption strategy - Clinicians adopt what they trust, so every pound/euro spent making assurance visible and credible buys you faster uptake later. Organisations that treat safety as the brake rather than the steering are the ones who end up stalled.
  • Senior ownership means nothing without capacity beneath it. Naming a clinical safety owner and then funding them in hours snatched from a demanding clinical job is how you manufacture the illusion of assurance. Capacity is what creates authority: an owner with a real, funded team shapes design decisions early, builds the evidence that lets leaders deploy with confidence, and becomes the reason technology reaches patients sooner rather than later.
  • Assure the care pathway, not the product. While harm can originate in the software itself, it most often emerges where technology meets workflow, data quality and human factors across organisational boundaries. Safety scoped only to an individual component or boundary will miss almost everything that matters.
  • Build for continuous assurance, because the technology no longer stands still. The Commission’s shift to lifecycle monitoring is a direct challenge to how most health systems are funded and structured. We buy point-in-time approval and annual reviews, but adaptive technology needs standing capability, not periodic projects.
  • Transparency is now a design requirement, not a communications afterthought. The Commission’s recommendations on telling patients when AI is used in their care, and on publishing safety information, move transparency from goodwill to expectation. Systems that retrofit it will look defensive; those that build it in will look confident.
  • Speed is a safety outcome, not a trade-off against it. The Commission’s framing is deliberate: a framework must be safe, fast and trusted - fast meaning responsible innovation and timely access to beneficial technology. Delay has a patient cost too, and it rarely appears on a risk register. Organisations that can assure well are the ones that can deploy quickly and confidently.

In conclusion - one report tells us the foundations are thinner than we admit. The other tells us what we’re about to build on top of them. Neither is an argument against digital transformation - both are arguments for doing it properly. The organisations that invest in assurance and safety capability now won’t be the ones slowed down by AI regulation; they’ll be the ones able to adopt faster, deploy with confidence, and prove it when asked.

Read more:


Originally published on LinkedIn.