Key Points
- The NHS needs better safety infrastructure to aid the government’s digital transformation plans, according to researchers at University College London (UCL).
- The study, published in the journal BMJ Innovations, revealed a lack of adherence to the existing standards for digital safety in NHS organisations in England.
- 163 out of 239 NHS organisations provided data about Clinical Safety Officer (CSO) appointments.
- The average number of CSOs in NHS organisations was 1.1 FTEs and 0.4 FTEs in integrated care boards (ICBs).
- There was no consensus on what was considered to be a “digital health technology”—as few as <10 and as many as >1,100 per trust were reported.
- There isn’t a common approach to storing all safety details digitally in many NHS organisations, which makes it difficult to obtain fundamental safety details.
- Procurement processes were also found to be regularly inadequate to ensure legal safety requirements are met, and manufacturers were often not providing the necessary risk documentation.
- The study urges the Government to urgently develop a new digital safety architecture or else the risks it outlines in its 10 Year Health Plan for England published in July 2025 will be exacerbated.
- There is a need for a professionalised CSO workforce, tighter enforcement of regulations, and embedding digital safety into national quality frameworks, according to researchers.
England (Britain Today News) August 19, 2026 — Lack of compliance with safety standards means the NHS’s ambitious digital transformation agenda risks causing patient harm on an “unprecedented scale,” according to new research from University College London published this week in the journal BMJ Innovations. The study concludes that the government’s 10 Year Health Plan for England, which places digital transformation at the heart of NHS reform, is being pursued without the safety architecture required to protect patients from the risks posed by new digital health technologies.
- Key Points
- What Does the New Research Say About NHS Digital Safety?
- Why Is the NHS Pursuing Digital Transformation?
- What Are NHS Organisations Legally Required to Do Under the Health and Social Care Act 2012?
- How Many NHS Organisations Provided Data on Clinical Safety Officers?
- How Many Clinical Safety Officers Does the Average NHS Organisation Employ?
- Why Is There No Consensus on What Counts as a Digital Health Technology?
- Do NHS Organisations Keep Proper Digital Safety Records?
- Do NHS Procurement Processes Comply With Safety Standards?
- What Do the Findings Mean for the Government’s 10 Year Health Plan?
- What Are Researchers Recommending to Fix the System?
- What Happens Next for NHS Digital Safety Reform?
What Does the New Research Say About NHS Digital Safety?
The study, published on Tuesday in BMJ Innovations, examined how NHS organisations across England are complying with existing digital clinical safety standards. According to the research, NHS organisations are “systematically failing to comply with legislated digital safety standards,” a finding the study authors describe as posing a direct threat to the safe rollout of new technologies across the health service.
The authors were explicit about the scale of the risk. As stated by the study authors in the research paper,
“Before the UK government pursues its ambitious digital future for the NHS, a new digital safety architecture must be established.”
The researchers further warned that, without such reform,
“the digital transformation envisaged in the 10 Year Health Plan risks propagating patient harm at unprecedented scale and speed.”
Why Is the NHS Pursuing Digital Transformation?
Shifting the NHS from analogue to digital systems is a central feature of the government’s 10 Year Health Plan for England, published in July 2025. The plan sets out ambitions to modernise the health service through the rapid adoption of frontier technologies, including artificial intelligence, genomics and robotics, as part of a broader push to improve efficiency and patient outcomes across NHS trusts and integrated care systems.
However, the UCL researchers argue that this digital ambition is running far ahead of the safety systems needed to support it. The study found that current NHS infrastructure is already struggling to meet existing legal obligations, raising serious questions about its capacity to safely absorb a further wave of digital innovation.
What Are NHS Organisations Legally Required to Do Under the Health and Social Care Act 2012?
Under the Health and Social Care Act 2012, NHS organisations carry a statutory duty to manage the clinical risks posed by digital health technologies. This legal obligation requires organisations to obtain records from the manufacturers of any health IT system demonstrating that the technology meets recognised risk management standards before it is deployed in a clinical setting.
The research suggests that this statutory duty is not being consistently fulfilled. Many organisations, the study found, are neither obtaining nor retaining the documentation required to demonstrate that digital technologies in use meet the necessary risk management thresholds.
How Many NHS Organisations Provided Data on Clinical Safety Officers?
To assess compliance, researchers contacted 239 NHS organisations across England requesting information on their Clinical Safety Officer (CSO) arrangements. Of these, 163 organisations subsequently provided data on CSO appointments, giving the researchers a substantial dataset from which to assess the state of digital safety governance across the health service.
How Many Clinical Safety Officers Does the Average NHS Organisation Employ?
The findings paint a picture of a thinly stretched safety workforce. On average, each NHS organisation employed just 1.1 full-time equivalent CSOs. This figure varied significantly by organisation type: integrated care boards (ICBs) reported an average of only 0.4 full-time equivalent CSOs per organisation, while NHS trusts reported a higher average of 1.3.
Given the scale and complexity of digital systems now in use across the NHS, the researchers suggest that this level of staffing is inadequate to properly assess and manage the associated clinical risks.
Is the Clinical Safety Officer Role Treated as a Dedicated Profession?
According to the research, the CSO function is, in practice, rarely treated as a dedicated professional post. Instead, the researchers found that the role was frequently absorbed as an ancillary responsibility into existing job functions, rather than being resourced as a distinct, specialised position. In some cases, organisations held no information at all on how much time was actually being dedicated to ensuring digital clinical safety standards were being met.
This lack of a clearly defined, protected role is identified by the study authors as a fundamental weakness in the current system, particularly as the volume and complexity of digital technologies used in clinical settings continues to grow.
Why Is There No Consensus on What Counts as a Digital Health Technology?
One of the more striking findings of the research relates to the sheer inconsistency in how NHS organisations define and count “digital health technologies.” The study found no shared consensus on this basic definitional question, with 22 trusts reporting fewer than 10 digital health technologies in use, while five trusts reported more than 500, and one trust reported using more than 1,100.
This wide variation, the researchers suggest, points to inconsistent interpretation of what falls within scope for safety assessment, meaning that some technologies actively used in clinical decision-making may be escaping scrutiny altogether.
Are NHS Organisations Applying Safety Standards Consistently Across All Technologies?
The research also found that some NHS trusts were applying digital safety standards only to electronic patient records, rather than extending them to other digital technologies used more broadly across clinical decision-making, referral management and operational support functions. This selective application of standards, according to the study, leaves significant gaps in oversight across technologies that directly influence patient care pathways.
Do NHS Organisations Keep Proper Digital Safety Records?
A further concern raised by the researchers relates to record-keeping. The study found that NHS organisations generally do not maintain centralised digital safety records, making it very difficult, in many cases, to retrieve even basic safety information about the digital technologies currently in use within an organisation. This absence of centralised documentation compounds the difficulty of assessing compliance and responding effectively should safety concerns arise.
Do NHS Procurement Processes Comply With Safety Standards?
The research also identified significant shortcomings in NHS procurement processes. According to the study, procurement practices frequently did not comply with digital safety standards, with many manufacturers failing to provide the risk management records legally required, and NHS organisations, in turn, failing to request such documentation at the point of purchase. This procurement gap, the researchers argue, represents a critical failure point, since it is at the point of purchase that safety compliance should first be verified.
What Do the Findings Mean for the Government’s 10 Year Health Plan?
The researchers warned that these findings carry immediate and significant implications for the government’s 10 Year Health Plan for England. The plan’s ambitions to rapidly adopt frontier technologies — including artificial intelligence, genomics and robotics — would, the study argues, require a highly skilled CSO workforce equipped with dedicated time to carry out thorough risk assessments.
Yet, according to the research, most NHS organisations currently lack the CSO workforce capacity needed to safely assess even their existing digital technology portfolio, let alone the substantial expansion envisaged under the government’s plan. This mismatch between ambition and safety capacity forms the central warning of the study.
Explore More about Technology:
UK and Google Test Flight Path Changes to Cut Aviation Contrails
Meta Smart Glasses Spark Privacy and Safety Concerns Among Users
What Are Researchers Recommending to Fix the System?
The study authors set out a series of recommendations aimed at closing the gap between NHS digital ambition and patient safety capacity. They recommended adopting a combination of centralised assessment and local risk management, arguing that this approach would help ensure equal prioritisation of both innovation and patient safety across the health service.
Specifically, the researchers called for:
- The development of a professionalised Clinical Safety Officer workforce, with dedicated time and recognised standing within NHS organisations.
- Empowered regulatory enforcement to ensure existing digital safety standards are properly applied and upheld.
- Integration of digital safety into national quality frameworks, so that safety compliance becomes a core measure of organisational performance rather than an ancillary function.
The researchers were unequivocal in their concluding assessment, stating plainly that NHS organisations in England
“are systematically failing to comply with legislated digital safety standards.”
They reiterated their central warning that, without meaningful reform,
“the digital transformation envisaged in the 10 Year Health Plan risks propagating patient harm at unprecedented scale and speed.”
What Happens Next for NHS Digital Safety Reform?
The findings are likely to add pressure on policymakers to address digital safety governance as the 10 Year Health Plan moves from strategy into implementation. With the plan’s technological ambitions reliant on wider adoption of artificial intelligence and other frontier tools across clinical settings, the researchers’ warning suggests that safety architecture reform may need to precede, rather than follow, further digital expansion if patient harm is to be avoided at scale.
