← Back to blog
BLOG · MAY 2026

Grounding AI Governance in What NHS Organisations Already Know

A Values-Anchored Framework for Trustworthy AI Conduct in Practice - why sustainable AI governance starts with the values NHS organisations have already co-produced.
SARAH AMANI1 MAY 20265 MIN READ

Every NHS organisation already possesses the raw material of AI ethics: co-produced vision and values, developed with patients, carers, and staff. These documents are not aspirational posters. They encode what an organisation believes about dignity, safety, equity, and accountability.

This paper argues that sustainable AI governance in the NHS should begin there - and build upward. By mapping the established pillars of AI ethics onto existing organisational values, and then designing a runtime monitoring layer that accounts for real human behaviour rather than idealised compliance, NHS organisations can move from governance as language to governance as verifiable operation.

The question for NHS AI governance is not 'Do we have a policy?' It is: 'Can we show, at the point of clinical action, that only admissible conduct occurred - and that human oversight was genuinely exercised, not merely performed?'

The Problem: Language Without Operation

Most NHS AI governance frameworks are not inadequate. They are incomplete. They describe, document, audit, and reconstruct. What they rarely do is govern in real time - at the moment a clinical decision is made, a note is generated, or a triage recommendation is accepted.

Current frameworks typically provide:

  • Policies and standards (DCB0129, DCB0160, DSPT, NHSE AI framework)
  • Pre-deployment assessment and clinical safety cases
  • Post-hoc audit trails and dashboards
  • Vendor assurance documentation and governance committees

What they rarely provide is a live, computable layer that can demonstrate - at the execution boundary - that human oversight was genuinely present, that the system behaved within approved parameters, and that specific patient populations were not disadvantaged by automation patterns.

A clinician who accepts an AI-generated clinical note in three seconds has technically completed the 'human in the loop' step. But they have not exercised clinical judgment. Governance that cannot distinguish performed compliance from real oversight produces a false sense of assurance - and a genuine safety exposure.

Trust Values as Ethical Substrate

Every NHS organisation has co-produced values representing genuine engagement with patients, carers, clinical staff, and communities. For AI governance, they are the ethical ground truth - the answer to 'What does good look like here?' that no generic framework can answer. The translation requires no new values - only taking existing ones seriously as operational commitments.

Designing for Real Human Behaviour

This is the most neglected dimension of AI governance - and the most important. Every framework implicitly assumes a rational, attentive, unhurried clinician. This clinician does not exist at scale.

Automation Bias

Clinicians systematically favour AI recommendations over their own judgment under time pressure - an effect stronger with confidence scores, fatigue, or a track record of accuracy. Governance that does not monitor for it is not monitoring the right thing.

Rubber-Stamping

When review becomes a workflow step rather than judgment, it loses its protective function. Time-on-task, amendment rates, and override patterns are behavioural proxies for genuine oversight - system-level safety signals, not disciplinary data.

Alert Fatigue

A layer that fires too many alerts will be ignored. Alert mechanisms must be designed with clinical-decision-support discipline: precise, actionable, calibrated to interrupt only when it matters.

Gaming Under Pressure

Clinicians under capacity pressure find the path of least resistance. Governance must make the compliant path the easiest path - by design, not discipline.

Equity Blind Spots

Automation bias compounds inequality. If a system performs better for some populations and clinicians defer disproportionately for others with sparser records, the result is a governance-invisible harm. Equity monitoring must be designed in from the start.

Design for the clinician on a busy Friday afternoon - not the clinician in the pilot study. If the framework only works under ideal conditions, it does not work.

Honest Caveats

A framework that does not acknowledge its own constraints is not a framework - it is a pitch.

  1. Vendor API access is the critical dependency. EHR vendors do not routinely expose interaction-level data. This must become a standard procurement condition. Without it, runtime monitoring is impossible.
  2. Latency risk in emergencies. Any pre-execution step that adds delay is itself a safety risk. This framework operates via passive monitoring and post-hoc alerting - not execution blocking.
  3. Encoding ethics is hard and contested. Computable rules require precision, and precision exposes choices vague policies conceal. This needs clinical and IG leadership, not just technical teams.
  4. This space is not empty. NHS England's AI & Digital Regulations Service, MHRA's SaMD framework, and the NHS AI Lab are all active. Build from - and contribute to - these efforts.
  5. Workforce readiness is a precondition. A monitoring layer deployed into a team not involved in its design is experienced as surveillance. Clinical engagement is a safety requirement.

Three Asks for the System

Mandate vendor API transparency. Governance cannot monitor what it cannot see. Make interaction-level data a standard condition of NHS AI deployment contracts.

Commission a national equity monitoring standard. Trusts should not design this alone. Monitor AI performance disaggregated by ethnicity, age, deprivation, and gender - as a national minimum.

Build a shared computable policy library. Live governance rules mapped to DCB0129/0160, led by the clinical safety community.

Governance that cannot distinguish performed compliance from genuine human oversight is not governance. It is documentation. NHS patients deserve the difference.


TrustPoint Digital Health provides independent clinical safety governance for AI and digital health products under DCB0129 and DCB0160. Get in touch to discuss your safety case.

CLINICAL SAFETY & DIGITAL HEALTH & CLINICAL AI GOVERNANCE

TrustPoint provides independent clinical safety governance for digital health and clinical AI - DCB0129/DCB0160 safety cases, readiness reviews, and post-market surveillance.

Book a consultation ↗Email us ↗