Nine in Ten NHS Staff Are Using AI at Work

TL;DR: A new survey reveals 90% of UK healthcare staff use AI for work, often with unsanctioned tools. This signals a huge market for health-tech but also creates major data security and compliance risks for the NHS.
Key facts
- Category
- AI
- Impact
- High
- Published
- Source
- TechRadar
Full summary
A new survey finds 90% of UK healthcare staff use AI for work, creating huge opportunities and major security risks.
A new report based on a survey of 1,000 UK healthcare professionals indicates that 90% are already using artificial intelligence tools to assist with their work. According to the reporting by TechRadar, staff are primarily turning to AI to handle administrative tasks and improve their workflows, aiming to reduce the significant burden of paperwork. The survey also suggested that most patients are positive about the use of AI in their care. This widespread adoption reveals a grassroots movement by frontline workers to leverage modern technology, even in the absence of officially provided or sanctioned systems within the National Health Service (NHS).
The specific AI tools being used were not detailed, but the scale of adoption strongly suggests that many NHS staff are using publicly available, consumer-grade generative AI platforms like ChatGPT or Gemini. This phenomenon is a classic example of “shadow IT,” where employees use technology without explicit approval or oversight from their IT departments. This typically happens when official software is outdated, inefficient, or non-existent, and staff find faster, more effective solutions on their own. In this case, the immense pressure and administrative overhead in healthcare are driving professionals to seek any tool that can provide relief and efficiency, even if it operates outside of official channels.
For CTOs, IT leaders, and security teams, this situation presents a significant challenge. The use of unsanctioned AI tools for work involving sensitive patient information creates a massive compliance and data security risk. Entering any patient-identifiable data into a public AI model could violate UK GDPR and breach patient confidentiality, as that data may be used to train the model and is outside the NHS's secure environment. For founders and developers in the health-tech space, however, this is a powerful market signal. It confirms a desperate, unmet need for intelligent tools that can automate admin and streamline clinical workflows. The demand is proven; the opportunity lies in building a secure, compliant, and genuinely useful product that hospitals can safely procure.
The broader business impact extends far beyond the NHS, serving as a case study for all regulated industries like finance, law, and government. Employees will inevitably gravitate towards the most effective tools available to do their jobs, regardless of official policy. A strategy of simply banning AI is unlikely to succeed and will only drive its use further into the shadows. The key takeaway for business leaders is the urgent need for a proactive AI strategy. This involves establishing clear acceptable use policies, evaluating and providing secure, enterprise-grade AI tools, and training staff on data privacy and the responsible use of AI. Organizations that fail to address this will be exposed to significant data breach risks, while those that embrace it can unlock major productivity gains.
Looking ahead, this grassroots adoption will likely force a rapid response from both NHS leadership and government regulators. We can expect a push for the development and procurement of healthcare-specific AI platforms that are designed with data security and clinical safety as core principles. This will accelerate the market for auditable, transparent, and compliant AI solutions tailored for medical environments. For developers, this means the features that will win enterprise deals are not just performance and usability, but robust security architecture, data privacy controls, and clear compliance with healthcare regulations. The race is on to replace unsanctioned consumer tools with officially adopted, enterprise-ready systems.
Related on Notifire
Related stories
Primary source: TechRadar