CQC & ComplianceFebruary 2026 · 7 min read

CQC and AI: what inspectors are asking for in 2026

Article

There is no AI section in the CQC's assessment framework, and providers waiting for one are waiting for the wrong thing. AI tools are assessed the way every other aspect of a service is assessed: through the quality statements, against the evidence the provider can show. An inspector does not need to understand how a model works to find a governance gap around it. They need only ask the questions they already ask about any system that touches care, and notice when the answers are thin.

Where AI surfaces in the framework

Under Safe, the statements on safe systems and pathways, on learning culture and on medicines lead directly to any tool that drafts records, supports triage or informs prescribing. Under Effective, the statements on assessing needs and delivering evidence-based care reach any tool whose output shapes a care plan. Under Well-led, the statement on governance, management and sustainability is where the whole question of accountability for AI sits, and the statement on capable leaders reaches whether the people in charge understand what they have deployed.

An inspector who learns that a service uses AI-assisted documentation, or an AI rostering tool, or a system that flags deterioration, will locate the questions in those statements without any need for a bespoke framework.

What the questions are

Based on the framework and on how inspectors approach any system in use, a provider using AI tools should expect to be asked, in some form, the following.

  • What tools are in use, for what purpose, and who decided to introduce them.
  • Who is accountable for each tool, by name, and what that accountability consists of.
  • How staff were trained, and how the service knows they understand what the tool does and does not do.
  • How the output is checked before it affects care, by whom, and where that check is recorded.
  • How incidents and near misses involving the tool are captured, and what has been learned from them.
  • What assurance the service obtained before deployment: the vendor's regulatory status, the DCB0160 clinical safety case, the data protection impact assessment.
  • How people using the service, and where relevant their families, were told that AI is involved in their care and what it does.

An inspector does not need to understand the model. They need to see who is accountable for it.

The evidence that answers them

None of these questions requires a new document type. They require the documents a well-governed service already holds to have been extended to cover the tools in use.

  • An inventory of AI tools with purpose, owner, date of introduction and regulatory status.
  • A written statement of intended purpose for each, matching the vendor's and matching actual use.
  • A DCB0160 clinical safety case where the tool is health IT deployed in a clinical setting, and the vendor's DCB0129 case alongside it.
  • A data protection impact assessment for each tool processing personal data.
  • Training records that show what staff were taught about the tool, not only that they attended.
  • An incident log in which events involving AI tools are identifiable, with the learning recorded.
  • Minutes or notes showing the tool was reviewed since introduction, and by whom.

Where services are weakest

The gaps inspectors find are rarely technical. They are the inventory that does not exist because tools arrived informally; the training record that says a session was held but not what it covered; the incident log in which an error caused by a drafting tool is recorded as a documentation error with no mention of the tool; and the accountability that turns out, when asked, to be nobody in particular. Each is a governance finding, categorised under Well-led, regardless of whether the tool itself worked.

The joint regulators' position

The CQC works alongside the MHRA, NICE and the HRA through the AI and Digital Regulations Service, and its published position is that existing regulation applies to AI as it applies to anything else in a health or care setting. Providers should not expect a separate standard to arrive and should not defer governance until one does. The framework already asks the questions. The only variable is whether the service can answer them.

This article sets out Novatib's advisory position. It is not legal or regulatory advice.

Next

Hold the evidence before the inspector asks for it.

Cadence Compliance keeps the inventory, the safety cases, the training records and the incident log current, mapped to the quality statements they answer.