England’s plan to move the National Health Service “from bricks to clicks” could unintentionally create a new and largely invisible patient-safety crisis, researchers warn. In an analysis published in BMJ Innovations, experts argue that the NHS is preparing to deploy artificial intelligence, genomics, robotics and other digital technologies at unprecedented speed without the safety infrastructure needed to manage their clinical risks. Unless the system changes course, they say, digital transformation could allow errors to spread across entire health networks far more rapidly than conventional clinical mistakes.
The warning focuses on England’s NHS 10 Year Plan, which places digital transformation at the centre of future healthcare delivery. The strategy envisages more care delivered in communities, greater use of remote services and data-driven decision-making, and accelerated adoption of advanced technologies. Yet the researchers say that formal clinical safety assessment is not being consistently monitored or enforced. Under requirements associated with the Health and Social Care Act 2012, digital health technologies are expected to undergo structured risk management in accordance with two national standards: DCB0129, which applies to manufacturers and developers, and DCB0160, which applies to organisations deploying technology in clinical settings.
These standards are designed to identify hazards before a system is used with patients and to control risks throughout its operational life. A clinical safety case should normally describe how a technology might cause harm, the likelihood and severity of possible failures, the safeguards in place, and the evidence supporting its safe use. The process also requires organisations to monitor incidents, reassess risks when software or workflows change, and ensure that staff understand how the technology affects clinical decisions. The researchers say that this system is failing in practice. In an earlier freedom of information survey of 239 NHS trusts and integrated care boards, they identified 14,848 digital health technologies in use. Seventy per cent had no documented safety assurance, while only 17% were reported to be fully assured.
The new analysis examined why compliance was so poor. The researchers reanalysed free-text responses from the original survey and assessed previously unpublished information about the capacity of Clinical Safety Officers, or CSOs. These are clinicians tasked with overseeing the management of risks associated with digital systems used in patient care. Among 211 organisations that provided relevant information between February and March 2025, the average reported deployment was approximately one full-time-equivalent CSO per organisation. However, only 163 organisations supplied data about the number of hours actually devoted to digital clinical safety, making the headline figure difficult to interpret.
The difference between formal staffing levels and real working capacity appeared particularly important. NHS trusts reported an average of 1.3 full-time-equivalent staff, whereas integrated care boards reported less than half a post, or approximately 0.4 full-time-equivalent staff. Written responses suggested that these numbers often overstated the resources available because CSO responsibilities were commonly added to existing clinical or managerial jobs. Twenty-two organisations could not quantify the time allocated to implementing the safety standards. In 11 organisations, the CSO role formed part of a senior executive’s duties, including those of an associate medical director, chief clinical information officer or chief nurse. Senior leadership can give safety work influence, the researchers acknowledge, but it can also place responsibility in the hands of people with the least time to conduct detailed assessments or develop specialist expertise.
The responses also exposed weaknesses in the basic infrastructure needed to understand what technologies are being used. Thirty-seven organisations claimed statutory exemptions from the freedom of information request. Cost and the time required to retrieve information were among the most frequently cited reasons, while others reported that their data were inaccessible or that they had no central register of digital tools. The researchers say these explanations may be valid, but they also point to immature governance. Without a reliable inventory, an organisation cannot easily determine which systems influence diagnosis, treatment, prescribing, triage or patient monitoring, let alone whether those systems have been assessed after updates or changes in clinical use.
Some exemptions raised an additional concern. A number of organisations referred to provisions involving the prevention or detection of crime or health and safety. The researchers interpret this as evidence that some organisations may not understand the specific meaning of clinical safety in digital healthcare. Clinical safety is not limited to cybersecurity, physical security or the prevention of deliberate wrongdoing. It includes unintended clinical consequences such as an algorithm generating systematically biased risk scores, an interface encouraging a prescribing error, an alert system producing so many warnings that clinicians ignore them, or a data integration failure causing information to be assigned to the wrong patient. These hazards can emerge even when a system is functioning exactly as its designers intended.
Thematic analysis identified four mutually reinforcing causes of non-compliance: poor understanding of the standards, immature governance and oversight, ineffective assurance processes, and the treatment of the CSO role as an additional task rather than a professionalised safety function. The researchers describe this as a system-level failure rather than a problem attributable to individual clinicians. If staff lack training, organisations lack technology registers, assurance processes are treated as paperwork, and CSOs have little protected time, each weakness amplifies the others. A clinical risk assessment completed once at the point of procurement cannot provide continuous protection when software is updated, datasets change, workflows are redesigned or a tool is deployed in a new population.
The risk could grow as the NHS adopts technologies that are more complex and more deeply embedded in clinical decisions. Artificial intelligence systems may be trained on data that do not represent every patient group and may perform differently after changes in clinical practice. Genomic tools can produce results whose interpretation depends on evolving scientific evidence, while robotic and automated systems can create new interactions between software, hardware and human operators. The planned shift from hospitals into community and primary care could extend these risks to smaller organisations with fewer specialist resources. At the same time, NHS services increasingly involve private, voluntary and other external providers, creating the possibility of accountability gaps when responsibility for a digital system is divided between a developer, commissioner and frontline service.
The researchers propose stronger oversight by the Care Quality Commission, inclusion of DCB0129 and DCB0160 compliance within the patient-safety section of the NHS Oversight Framework, and a formal career pathway for Clinical Safety Officers based on tiered competencies. They also call for mechanisms to share evidence about common deployment hazards, near misses and clinical incidents across the NHS. Their conclusions are limited by the nature of the data: the survey did not provide the depth or opportunity for clarification available through interviews, and it excluded primary care and adult social care, where compliance remains unknown. Even so, the authors argue that the findings reveal a national gap between the NHS’s ambitions for digital innovation and its ability to control clinical risk. They conclude that England needs a new digital safety architecture combining central assessment, local risk management, professionalised safety expertise, regulatory enforcement and integration of digital governance into routine quality standards. Without it, digital transformation could spread unsafe practices at the same scale and speed as the technologies themselves.
Subject of Research: People
Article Title: Unfit for the future? Revisiting the national cross sectional study of digital clinical safety in England’s NHS to identify drivers of low compliance and implications for the 10 Year Health Plan
News Publication Date: 18-Aug-2026
Web References: https://www.gov.uk/government/publications/10-year-health-plan-for-england-fit-for-the-future
References: BMJ Innovations, DOI: 10.1136/6/bmjinnov-2025-001544
Keywords: NHS digital transformation, clinical safety, digital health, Clinical Safety Officers, DCB0129, DCB0160, artificial intelligence, patient safety, healthcare technology, NHS 10 Year Plan

