AI in Care - The Opportunity and the Responsibility
Administrative tasks that consume care workers' time - care notes, scheduling, risk flagging - can be assisted by AI tools, freeing up capacity for direct, human-led care. The Government's 10-Year Health Plan for England commits the NHS to becoming a leading AI-enabled health system, with AI, data, genomics, wearables, and robotics identified as five transformative technologies at the centre of structural reform.
But opportunity and responsibility are inseparable, as AI tools move into care settings, they process some of the most sensitive personal data that exists in the form of health records, medication histories, mental health information, and details of daily living. The stakes of getting data governance wrong are high not just in regulatory terms, but in terms of the trust that care relationships depend upon.
GDPR Still Applies
One of the most important things to understand about AI in care is that the UK General Data Protection Regulation (UK GDPR) applies to AI systems in exactly the same way it applies to any other form of data processing. The ICO has been clear on this point, saying that existing UK GDPR obligations, including lawful basis, data minimisation, purpose limitation, accuracy, and accountability, apply fully to AI systems and cannot be treated as inapplicable simply because AI introduces probabilistic or opaque decision-making.
This matters because some organisations may assume that AI operates in a different regulatory space, when in reality, it does not. Any AI tool that processes personal data which, in a care context, will almost always be the case, must comply with the same data protection principles that govern all other data processing activities.
Health Data Is Special Category Data
In a care context, this point carries a particular weight.
Health data is classified as special category data under UK GDPR Article 9, which means it attracts a higher level of protection and requires an additional lawful basis for processing beyond the standard Article 6 conditions. The ICO notes that even inferences or predictions made by AI can count as personal data if they can be linked to an individual and that some AI-generated inferences, such as those revealing protected characteristics, may themselves constitute special category data.
Where AI is being used to inform a health or care professional's decision about an individual's care, NHS Digital guidance for information governance professionals indicates that UK GDPR condition 9(2)(h) – health or social care - will generally apply as the lawful basis.
However, care organisations must assess this carefully for each use case, and the purpose for which data is used must be clearly defined and agreed before any processing takes place.
The DPIA
A Data Protection Impact Assessment (DPIA) is a legal requirement before implementing AI-based technologies. NHS Digital's guidance for information governance professionals says that a DPIA must legally be completed prior to implementing AI-based technologies, in order to manage and mitigate the likelihood and severity of any potential harm to individuals. The DPIA also supports organisations in demonstrating how they are meeting the accountability principle of UK GDPR, as well as data protection by design and default.
The ICO's updated guidance on AI and data protection, restructured around the UK GDPR's core principles, sets out what a DPIA for AI should include, among them, evidence that less risky alternatives were considered and why they were not chosen. The ICO has also published an AI and Data Protection Risk Toolkit to help organisations assess and mitigate risks across the full AI lifecycle, from initial project scoping and data collection through to model training, deployment, and ongoing monitoring.
Decision-Making and Human Oversight
Where AI is used to make or inform decisions about individuals, Article 22 of UK GDPR is relevant. Individuals subject to solely automated decisions that have legal or similarly significant effects have the right to contest a decision and request human review. The ICO requires organisations to audit any solely automated decision-making with significant effects on individuals for compliance with Article 22, and to either establish a valid exemption or document the human oversight mechanism in place.
The Data (Use and Access) Act 2025 (DUA Act), which received Royal Assent on 19 June 2025, introduces further nuance here. The Act introduces Article 22A, which clarifies that a decision is ‘solely automated’ only where there is no ‘meaningful’ human involvement and it is mandatory to consider the extent to which any decisions have been reached in reliance on automated profiling when assessing whether human involvement is meaningful.
This places a renewed emphasis on demonstrable human oversight. Any bodies using AI or algorithmic tools must ensure that human review is substantive and not merely symbolic.
For care organisations, this is a practical as well as a legal consideration. AI-generated outputs, whether a care plan recommendation, a risk score, or a medication flag, should never be acted upon without careful review by a qualified professional.
Compliance with data protection law is necessary, but may not be sufficient.
When AI is used in care, it must also uphold the values that define what good care looks like. This grounded in statute and in the professional obligations that care organisations carry.
The Care Act 2014 - A Legal Duty to Promote Wellbeing
The Care Act 2014 is the primary legislation governing adult social care in England. At its heart lies the Wellbeing Principle, set out in Section 1, which requires that all decisions, assessments, and interventions actively promote a person's dignity, physical and mental health, safety, independence, relationships, living environment, and ability to participate in society. This duty is a legal requirement that applies across the full care journey, from assessment and care planning through to review and safeguarding decisions.
The main principle of the Care Act is to improve people's independence and wellbeing and for care providers to promote a person-centred approach to the care and support they provide. The core purpose of adult care and support is to help people achieve the outcomes that matter to them in their life.
When an AI tool is introduced into a care setting, it becomes part of how care is delivered. That means the Wellbeing Principle applies to how that tool is used. An AI system that produces outputs which undermine a person's dignity, reduce their control over their own care, or fail to account for their individual circumstances is not consistent with the Care Act's requirements, regardless of how technically sophisticated it may be.
A Sector-Wide Definition of Responsible AI
The care sector has been working to define what responsible AI use looks like in practice. In March 2025, the first AI in Social Care Summit brought together over 150 participants - care providers, social care staff, individuals drawing on care and support, technology suppliers, local authorities, academics, and regulators - to address this question directly.
The summit, co-led by the Institute for Ethics in AI at Oxford University and the Digital Care Hub, produced a shared definition, that the responsible use of AI in social care means that the use of AI systems in the care or related to the care of people supports and does not undermine, harm, or unfairly breach fundamental values of care, including human rights, independence, choice and control, dignity, equality, and wellbeing.
The Digital Care Hub's guidance for care providers reinforces this, identifying three key areas of focus for any AI deployment:
- Data protection - AI tools must comply with UK GDPR requirements
- Ethics - AI must be used in ways that uphold the core values of care
- Bias - AI systems can inherit biases from their training data
Risks identified by the sector include data privacy breaches, misinformation from AI systems that generate inaccurate outputs, and bias, particularly around ageism and discrimination, which could undermine trust in new technologies.
The guidance also emphasises a principle of humanity, that AI in social care must never lose sight of the human element. It should enhance, not replace, the human touch that defines the sector.
The Call for Government Action
The Digital Care Hub and its partners have called on the Department of Health and Social Care to ensure that its promised National Standards around the use of technology in social care are ethically informed and aligned with existing legal frameworks, including human rights and equality law, and the Wellbeing Principle established in the Care Act 2014.
This call reflects a broader recognition that sector guidance, however well-developed, needs to be underpinned by clear government standards and accountability structures.
Legal Duties and AI Laws
At the time of writing this there is no dedicated AI law in the UK. The government has taken a principles-based, sector-led approach to AI regulation, requiring existing regulators to take responsibility for promoting and overseeing responsible AI within their sectors. For care organisations, this means compliance requires navigating several overlapping frameworks simultaneously.
- UK GDPR and the Data Protection Act 2018 remain the primary data protection framework. The ICO is the principal data protection regulator for AI in the UK, and its rules apply to any organisation that uses AI to process personal data. The ICO has published detailed guidance on AI and data protection, an AI and Data Protection Risk Toolkit, and in collaboration with the Alan Turing Institute joint guidance on explaining decisions made with AI, to help organisations provide meaningful explanations to individuals affected by automated processes.
- The Data (Use and Access) Act 2025 amends but does not replace the UK GDPR and the Data Protection Act 2018. For adult social care providers, a key change is a new legal duty on the government to set information standards for health and social care IT systems (Section 121 of the Act).
- The Act amends Section 250 of the Health and Social Care Act 2012 to make clear that these information standards apply to private providers registered with the Care Quality Commission (CQC), meaning care homes, homecare agencies, and supported living services must ensure their digital systems comply with national standards once introduced. The Act also introduces ‘recognised legitimate interests’ as a new lawful basis under UK GDPR for certain disclosures, including safeguarding and protecting public health. The Digital Care Hub has published a dedicated briefing explaining how the Act applies to adult social care.
- The Care Act 2014 establishes the legal duty to promote wellbeing and places person-centred care at the centre of all care functions, a duty that extends to how technology is used in care delivery.
- The Medicines and Healthcare products Regulatory Agency (MHRA) regulates AI systems that qualify as software-based medical devices, requiring clinical validation and post-market surveillance. In September 2025, the MHRA launched the National Commission on the Regulation of AI in Healthcare, bringing together global AI leaders, clinicians, and regulators to advise on the development of a new regulatory framework for AI in healthcare. The Commission's recommendations are expected to be published in 2026.
- The ICO's AI and Biometrics Strategy sets out the ICO's priorities on GDPR compliance in the AI space, including the development of a statutory Code of Practice on AI and Automated Decision-Making, required under the Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026. This code, when finalised, will be a pivotal document for organisations seeking to understand their compliance obligations.
For care organisations, the absence of a single AI law does not create a compliance gap, it creates a compliance obligation to understand and apply multiple frameworks together. In 2025, organisations face a complex regulatory landscape that balances innovation with accountability, requiring careful navigation of guidance from the ICO, the MHRA, NHS Digital, and sector-specific bodies such as the Digital Care Hub.
This means care providers should consider:
- Conducting a DPIA before deploying any AI tool that processes personal data, and review it regularly as the tool evolves.
- Establishing a clear lawful basis for processing, particularly where health data is involved, and document this decision.
- Meaningful human oversight of any AI-assisted decisions, particularly those that affect an individual's care, safety, or wellbeing.
- Assessing AI tools against the Care Act's Wellbeing Principle, asking whether the tool supports or undermines the person's dignity, independence, and control.
- Monitoring for bias and inaccuracy, and put in place processes for reviewing AI-generated outputs before they are acted upon.
- Keeping records of AI use, including how tools are used, what decisions they inform, and how human review is applied.
- Staying informed as the regulatory landscape develops, including the ICO's forthcoming Code of Practice and the MHRA Commission's recommendations.
Using AI in Social Care Responsibly
AI has a meaningful role to play in supporting care delivery in the UK, helping care workers manage administrative demands, improving the flow of information across care settings, and enabling more responsive, data-informed care. But that potential can only be realised responsibly if care organisations approach AI adoption with the same rigour they bring to any other aspect of care governance.
The key points from this article are clear. AI tools must comply with UK GDPR in full, health data is special category data, DPIAs are a legal requirement, and human oversight of automated decisions is not optional.
When AI is used in care, it must uphold the values that the Care Act 2014 places at the centre of all care functions: dignity, wellbeing, independence, and person-centred practice. And while there is no single AI law in the UK, care organisations are not operating in a regulatory vacuum, they must navigate a layered framework of data protection law, sector-specific guidance, and emerging standards, all of which carry real compliance weight. The regulatory landscape will continue to evolve, with the ICO's Code of Practice and the MHRA Commission's recommendations both expected to bring greater clarity. In the meantime, the organisations best placed to use AI well are those that treat compliance and care values not as separate concerns, but as two sides of the same commitment to the people they support.
AU & NZ
SG
MY
US
IE
