CQC published its position on artificial intelligence on 21 May 2026, and the headline is that there is no separate AI framework. Existing regulation already applies. CQC encourages AI where it benefits people, but sets three conditions: care decisions stay under human control, governance around the tool must be sound and demonstrable, and the provider remains accountable. You will not be assessed against an AI standard — you will be assessed against the standards you already have, with an AI tool in the picture.
What CQC actually said
In Artificial intelligence in health and social care: CQC's role, expectations and plans, the regulator sets out four things worth reading carefully.
1. It encourages AI — with a condition attached
CQC encourages innovative technologies including AI where the technology benefits people and results in more effective and efficient services. That conditional clause is the whole position. Efficiency alone is not the test; benefit to people is.
2. There is no AI-specific framework, and that is deliberate
Rather than build a separate assessment process, CQC is clarifying how existing regulation already applies to AI tools. It works alongside NICE, the MHRA and the HRA through the AI and Digital Regulations Service.
This is the most commonly misread part. Providers keep waiting for an AI standard to comply with. It is not coming as a separate thing — the fundamental standards and the assessment framework already cover it.
3. Human control is not negotiable
AI can assist with analysing information, identifying patterns and automating routine tasks — but clinical and care decisions must remain under human control. Assistance is fine; delegation of judgement is not.
4. Governance must be demonstrable
Not merely present. Demonstrable. Which is the same word the whole assessment framework turns on — and the same failure mode we see everywhere else: providers who have done the thinking but cannot produce the evidence of it.
What this means in practice
If AI is not assessed separately, then AI use is assessed through the existing key questions. That gives you a usable checklist.
| Key question | What an assessor could reasonably ask about an AI tool |
|---|---|
| Safe | What happens when it is wrong? Who notices, and how quickly? What is the fallback? |
| Effective | What evidence do you have that it improves outcomes rather than just saving time? |
| Caring | Do the people using your service know it is being used? Were they told, or did they find out? |
| Responsive | Does it work equally well for everyone, or better for some groups than others? |
| Well-led | Who owns it? Who signed it off? How is it monitored? Where is that written down? |
Notice that none of those are technical questions. They are governance questions, which is precisely why CQC did not need a new framework to ask them.
The specific risk nobody plans for
The most likely way an AI tool causes a regulatory problem is not a dramatic failure. It is a record that cannot be explained afterwards.
An assessor asks why a decision was made. The answer involves a tool. The tool cannot show what it based the output on, nobody can identify who reviewed it, and there is no record of the review happening. Nothing went wrong clinically — but the governance is unevidenced, and unevidenced governance is a well-led finding whether or not harm occurred.
This is the same pattern as everywhere else in regulation: services fail assessments not because they did not improve, but because they cannot prove they did.
What to do
- Write down where AI is used. A simple register: which tool, which process, what it does, who owns it, when it was signed off. Most providers cannot currently produce this, and it is the first thing that will be asked for.
- Record the human step explicitly. Not "a clinician reviewed it" as a policy statement — an actual, timestamped record that a named person reviewed this output.
- Require the tool to cite its source. If an output cannot be traced to the record it came from, it cannot be checked, and an unverifiable output is a liability rather than an efficiency.
- Decide your disclosure position. Whether and how you tell people using the service that AI is involved. There is no prescribed answer, but "we never thought about it" is a poor one under the Caring key question.
- Check it works for everyone. Equity in experience is a quality statement in its own right. A tool that performs unevenly across groups is a Responsive problem.
- Do not wait for AI-specific guidance. CQC says it will keep the need for it under review, and may develop sector-tailored guidance in future. Meanwhile the existing standards apply.
What is coming
CQC has said new assessment frameworks will be rolled out alongside supporting guidance for providers, and that it will keep requirements for AI-specific guidance and training under review — potentially developing guidance tailored to different sectors and settings. For what those frameworks change generally, see our guide to CQC's new assessment frameworks.
There is also sector-specific material already: CQC's GP mythbuster 109 covers the use of AI in GP services.
Frequently asked questions
Does CQC have a separate framework for AI?
No. CQC is clarifying how existing regulation applies to AI rather than creating a separate AI-specific framework or assessment process, working alongside NICE, the MHRA and the HRA.
Is CQC against providers using AI?
No — it encourages innovative technologies including AI where the technology benefits people and produces more effective and efficient services.
Can AI make care decisions?
No. CQC is explicit that clinical and care decisions must remain under human control. AI may assist with analysis, pattern identification and routine tasks.
What will an assessor ask about our AI tool?
Governance questions rather than technical ones: who owns it, who signed it off, what happens when it is wrong, how the human review is evidenced, and whether it works equally well for everyone.
Do we have to tell people we use AI?
There is no single prescribed rule, but transparency sits within the Caring key question and a considered, documented position is far stronger than none.
Related: AI in healthcare compliance: the 2026 state of play · questions to ask any AI vendor · what the CQC is and how it regulates
Sources: CQC, Artificial intelligence in health and social care: CQC's role, expectations and plans (published 21 May 2026); CQC, GP mythbuster 109: use of artificial intelligence in GP services. The key-question table is our own reading of how existing standards apply, not CQC's wording. Last reviewed: 30 July 2026.

