What Every dental team member needs to know before it's too late
By Sam Shah, specialist dental surgeon, medico-legal advisor and solicitor
Let me be direct with you. AI is already in your surgery. You may not have chosen it consciously, but the caries detection tool embedded in your imaging software, the app your associate downloaded last month, the ambient scribe your practice manager trialled on a free account — these are AI. And right now, across the dental profession, the vast majority of these tools are being used without anyone asking a single governance question.
That needs to change. Not eventually. Now.
The Evidence Is Already In
Earlier this year, at UCL we published a national study in the Journal of Medical Internet Research that quantified, the scale of digital clinical safety non-compliance across NHS England. We analysed 14,747 digital health technology deployments across 204 NHS organisations. The results were stark: over 70% of deployed tools had no documented clinical safety assurance whatsoever. In a typical NHS trust, three out of four digital tools influencing patient care did not meet minimum legal requirements.
Let that land for a moment. These are large, well resourced hospital trusts with dedicated digital governance teams and compliance departments. And three in four still got it wrong. If that is the picture there, what is the picture in a two surgery high street practice where the principal is also the treatment coordinator, the HR department and the person fixing the autoclave?
I think we both know the answer.
What the Law Actually Requires?
There are two NHS clinical safety standards that most dentists have never heard of: DCB0129 and DCB0160. They have been mandatory under the Health and Social Care Act 2012 since, you guessed it, 2012. They are not optional guidelines for the NHS in England. They are law.
DCB0129 places responsibility on the manufacturer of a digital health tool to demonstrate that clinical risks have been identified and mitigated. DCB0160 places responsibility on you, the deploying organisation, the CQC registrant, the practice, to carry out your own local clinical risk assessment before going live with any digital tool that could affect patient care. You should be asking every AI vendor for their DCB0129 Clinical Safety Case Report before you sign a contract. Most of them will not know what you are talking about. That, in itself, tells you something important.
The AI Scribe Problem: Brilliant in Theory, Dangerous in Practice
I want to spend a moment on AI scribes because they are proliferating faster than any other AI tool in dentistry, and they represent perhaps the most visible example of governance free adoption in the profession.
The pitch is compelling: the AI listens to your consultation, drafts the clinical note, structures the record, and frees you to focus on the patient. I understand the appeal. I work in a practice. I know what twelve hours of clinical dentistry feels like when you still have an inbox full of notes to write.
But here is what happens when governance is absent. The AI transcribes ‘no LA required’ as ‘LA required.’ It inserts a clinical finding you never made. It records a patient’s voice, biometric data under UK GDPR, and routes it to a server of unknown provenance under terms and conditions nobody read. And you countersign the output because it looks professional, because you are tired, and because there is no alert to tell you something went wrong. That note is now your note. That consent record is your consent record. And when the complaint arrives, nobody is interested in the fact that the algorithm wrote it.
NHS England now classifies AI scribes that summarise clinical consultations as medical devices. If your scribe is not properly assessed and on the NHS Ambient Voice Technology Supplier Registry, you are using an unregulated medical device on NHS patients. The GDC’s Standards require that your records are accurate, contemporaneous and attributable. An AI hallucination in your notes is a GDC compliance problem, not just a technology inconvenience.
The High Street Architecture Problem
Most hospital AI governance frameworks assume an employment relationship: the trust deploys the tool, accountability flows upward. Dentistry does not work like that.
In most high street practices, associates are self-employed, businesses in their own right, often acting as independent data controllers for their patients. When an associate downloads an AI tool onto a personal device, connected to the practice Wi-Fi, processing the principal’s patient data, without a processor agreement, a joint controller arrangement, a Privacy Notice update or a DPIA; who is legally responsible? The honest answer, in most current cases, is that nobody has asked. The ICO does not accept ‘I didn’t know’ as a lawful basis for processing.
A Checklist: Before You Say Yes to Any AI Tool
As a practitioner and as a lawyer, here is the minimum I expect any responsible practice to check before deploying AI in clinical use in NHS settings:
- Is it a medical device? Ask the vendor in writing. If it influences clinical decision making or generates documentation, the answer is very likely yes.
- Is it on the NHS AVT Supplier Registry (if a scribe)? If not, do not use it with NHS patients and question whether you can really want to use it in private settings.
- Request the DCB0129 Clinical Safety Case Report. If the vendor cannot provide one, walk away.
- Complete a DCB0160 local safety assessment. A Clinical Safety Officer can be contracted externally
- Complete a Data Protection Impact Assessment. Confirm whether patient data trains the vendor’s model. Update your Privacy Notice.
- Map your data controller position. Document any joint controller or processor arrangement with associates formally.
- Check your cybersecurity. Is your DSPT current? Is the AI vendor named in your incident response plan?
- Establish a clinical governance policy on automation bias. The AI recommends; the clinician decides. Document overrides. Feed incidents into your learning system.
The Bigger Picture
There is a profound question forming at the edge of all this. Right now, blindly following an AI recommendation without applying professional judgement is poor practice, the GDC expects a clinician to think, not just click. But what happens when AI assisted detection consistently outperforms unaided human diagnosis? At what point does not using AI become a departure from the standard of care?
That moment is coming. The profession that is best prepared will be the one that engaged with governance early.
The dental AI revolution is not a future event. It is today’s reality. The question is not whether you are using AI. The question is whether you can prove it is safe.






