Article
The phrase “responsible AI” appears in almost every government consultation, NHS framework document and vendor proposal published in the past three years. It is a useful phrase where it was developed: in large trusts with dedicated information governance teams, clinical safety officers and the structure to run a complex framework.
For a 12-bed care home, a two-site GP practice or a community mental health provider it lands differently. The frameworks assume resources and governance infrastructure that most independent providers do not have. Applied without adaptation they do not produce responsible adoption. They produce compliance theatre: documents that satisfy an auditor without reducing risk.
The gap the frameworks do not address
The NHS AI Lab guidance and most published work on healthcare AI governance take the trust as the reference organisation: a clinical governance committee, a Caldicott Guardian, a data protection officer, staff with protected time. The typical independent provider has a registered manager, a deputy and a care team already at capacity. Governance matters to them; inspection and registration are existential. It is simply done with different resources and a different risk profile.
The question is not whether small providers can adopt AI responsibly. They can. The question is whether the frameworks they are handed were designed for them. Most were not.
The risk of irresponsible adoption is not lower in a small organisation. In some respects it is higher. A trust has several layers of oversight that can catch a problem before it reaches a patient. A care home with one registered manager and an AI tool producing subtly unreliable output has fewer.
What responsible adoption actually requires at this scale
Six things. None requires a committee or a governance team. All require deliberate decisions and written accountability.
1. A stated intended purpose for every AI tool
What it is used for, which decisions it informs, and what it is not used for. Without this you cannot assess risk, train staff, or judge whether the tool is doing what you thought. The MHRA's guidance on software as a medical device makes intended purpose central to classification; a home that records that its scheduling tool is administrative and not clinical has made a decision that protects residents and the organisation.
2. A named accountable person for each tool
In a trust this might be spread across an informatics team, a procurement committee and a chief clinical information officer. In a care home it is one person, usually the registered manager. That is a clarity larger organisations often lack. It has to be explicit and written down, and the person has to know what the tool does, where it is weak, and how to escalate.
3. Training matched to the actual use
A care worker using an AI documentation tool needs to know that its output is a draft requiring review before it enters a record. They do not need to understand model architecture or Article 22. Training proportionate to the risk and folded into induction and supervision beats a comprehensive framework on a shelf.
4. A written answer to “what do I do if it is wrong?”
Every AI system produces incorrect output. The question is whether the organisation has a simple route from a staff member's doubt to a decision. It does not need to be an incident management system. It needs to be one clear paragraph everyone has read.
5. Periodic review, not one-off assessment
The tool changes, its inputs change, the regulation changes. A structured quarterly question suffices: is it still doing what we thought, and is it still appropriate for how we use it?
6. An exit
What happens if the vendor closes, reprices or changes the product? Small providers often adopt tools through individual initiative without noticing the dependency they have created. A written answer to “what if this stops tomorrow?” is governance, not contingency planning.
Where to start
Not with a framework. With an honest inventory of what is already in use, formally or informally, and whether each item has a stated purpose, a named owner and basic oversight. In small organisations AI arrives through individuals rather than procurement: a clinician's transcription app, an administrator's scheduling tool, a manager's report template. None is a problem in itself. All of them need governing.
Responsible adoption begins with knowing what is already in use, not with frameworks for what might be adopted later.
This article sets out Novatib's advisory position. It is not legal or regulatory advice.