A newly reported study has found that roughly 90% of surveyed NHS staff use artificial intelligence tools in their work, with administrative and workflow tasks the leading applications. The same research indicates that most surveyed patients are comfortable with AI being used in healthcare, but only where privacy protections, governance and clinical oversight are clear.[1]
The headline is less about a future NHS rollout than the possibility that AI is already embedded in day-to-day work through bottom-up adoption. Staff may be using tools to draft documents, organise information, summarise material or reduce repetitive administrative work before their employers have fully standardised which products are approved, what data can be entered, how outputs must be checked and how benefits are measured.
By the numbers
- About 90%: Share of surveyed NHS staff reported to use AI tools at work.
- Most patients surveyed: Reported to be receptive to healthcare AI use when privacy, governance and clinical oversight are maintained.
- Two leading use cases: Administrative and workflow tasks, rather than autonomous clinical decision-making.

AI adoption appears to be happening from the bottom up
The reported staff figure matters because it suggests AI use may no longer be confined to formal pilots, specialist data-science teams or centrally procured clinical systems. Modern generative AI is accessible through consumer and enterprise software, often requiring little more than a browser, a workplace account or a feature added to an existing productivity suite. That changes the adoption pattern.
Previous waves of health IT were generally deployed through major programmes: electronic patient records, imaging archives, e-prescribing systems and clinical portals typically involved lengthy procurement, integration and training cycles. Generative AI can enter workflows much more quietly. A member of staff may use it to restructure meeting notes, draft a non-clinical letter, turn a long policy document into an action list, create a spreadsheet formula or prepare a first version of routine communications.
Those uses can create immediate value. NHS staff work in a system where administrative burden, fragmented records and staffing pressure remain persistent operational problems. If AI reduces the time required to prepare routine material, it can potentially return time to patient-facing work. But the same accessibility makes it difficult for an organisation to know which tools are being used, with which settings, and whether sensitive information is leaving approved systems.
The study’s emphasis on workflow and administrative work is therefore significant. It points to a near-term role for AI as a support layer around care delivery, rather than evidence that staff are broadly delegating diagnosis or treatment decisions to models. That distinction should shape both policy and procurement.
The safety boundary depends on the task and the data
“AI use” covers a broad range of technologies with very different risk profiles. A tool that reformats generic text or produces a meeting agenda is not equivalent to a model that summarises a patient record, recommends a triage priority or generates a discharge communication. The first may have limited consequences if it is wrong; the latter can affect confidentiality, continuity of care and clinical safety.
Generative models also have technical limitations that matter in healthcare. They can produce plausible but inaccurate text, omit important context, misinterpret ambiguous prompts and provide answers that cannot be reliably traced to a source. An output can be useful as a draft, but it should not be treated as verified clinical information simply because it is fluent.
A workable governance model needs to classify uses by risk. Low-risk administrative applications can be evaluated around productivity, data handling and acceptable-use controls. Higher-risk applications involving patient-identifiable data, clinical pathways or decisions affecting care require stronger safeguards: validated performance in the intended setting, clear human review requirements, audit trails, incident reporting and explicit accountability for final decisions.
Data protection is central to this separation. Staff need practical guidance on whether they may enter personal, confidential or clinically sensitive information into a given service; whether the provider retains prompts or outputs; where data is processed; and whether the product has an NHS-approved contractual and security posture. A general warning not to use public AI tools is unlikely to be enough if staff have already found legitimate efficiency gains. Organisations need approved alternatives that are at least as usable as the tools employees would otherwise choose themselves.
Patient acceptance is conditional, not a blank cheque
The reported patient response offers an important corrective to assumptions that the public will automatically reject AI in healthcare. Patients may reasonably support technologies that reduce delays, help staff handle paperwork or make services easier to navigate. Acceptance is likely to be strongest when AI is visibly supporting staff rather than replacing access to qualified people.
However, the conditions attached to that acceptance are the substance of the story. Privacy, governance and clinical oversight are not communications add-ons. They are the operational requirements that determine whether a system deserves trust. Patients need to know when their information is used, what safeguards apply, whether an AI output has influenced a care process and which clinician or organisation remains responsible.
Trust will also depend on whether systems work fairly across populations. AI tools can perform unevenly when language, disability, local documentation practices or demographic representation differ from the data and testing environment used to develop them. An NHS-scale deployment cannot rely solely on vendor claims or results from another healthcare market. It needs evaluation in the specific trusts, care settings and patient groups where it will operate.
Procurement must catch up with everyday use
The gap between informal use and formal deployment creates a procurement problem. Traditional purchasing processes are designed to select a platform, negotiate contracts and implement it over months or years. AI products change rapidly, and a model’s capability, pricing, data policy or underlying provider may shift during a contract. Procurement teams need mechanisms that preserve due diligence without making approved tools arrive long after staff have adopted unapproved ones.
That does not mean abandoning central controls. It means making them more responsive. NHS organisations will need inventories of AI tools in use, clear approved-use lists, shared assessment frameworks and a way for frontline teams to propose new use cases. Procurement should test whether a product integrates with existing systems, supports appropriate identity and access controls, records usage, allows data to be governed and can be withdrawn if performance or contractual conditions change.
Measurement is equally important. Time saved is a useful metric, but it is not sufficient. Deployments should be assessed for error rates, staff rework, patient experience, effects on waiting times where relevant, equality impacts, data incidents and whether purported efficiency gains are actually realised. Without this evidence, AI can become another layer of software that shifts work rather than removing it.
What the finding means for the health technology market
For AI suppliers, widespread staff experimentation is both a market signal and a warning. Demand is likely to favour products that solve specific workflow problems, fit into established NHS software environments and provide strong controls around confidential information. Generic chat interfaces may be useful entry points, but sustainable deployments will require integration, permissions, auditability and support for local governance processes.
For established health IT vendors, the opportunity is to embed narrowly defined AI capabilities inside the systems staff already use. The competitive advantage will not come only from model quality. It will come from reliable implementation: secure data flows, transparent controls, evidence of performance and interfaces that reduce rather than add to clinical and administrative workload.
The study does not establish that AI use is uniformly safe, productive or formally authorised across the NHS. Nor does it show that patient receptiveness applies to every use case. Its more immediate value is in identifying a governance reality: adoption may be moving faster than the institutional mechanisms built to manage it. The next phase is not simply deploying more AI, but making existing use visible, safe and accountable.
Editor’s Take
I see this as a strong argument for treating staff-led AI use as a product and governance challenge, not as a compliance failure to be stamped out. If people are already using these tools to reduce routine work, a blanket prohibition will mostly drive the activity out of sight. The practical response is to give teams approved, secure tools for clearly defined jobs and make the safe path easier than the unofficial one.
What I would watch next is whether NHS organisations can turn this reported usage into measurable, repeatable workflows. The important proof points are not impressive chatbot demonstrations. They are audited reductions in repetitive work, clear rules for patient data, clinician review where it matters, and evidence that the gains are shared across trusts rather than captured only by well-resourced early adopters. The hype outruns the facts when AI is described as an autonomous clinical replacement; the near-term value is more concrete and more achievable: better operational software around the people providing care.
