Sector playbooks
CQC AI Guidance: What Care Providers Must Be Able to Show
Yes, care providers can use AI, and the CQC actively encourages it — but there is no CQC-approved AI tool and there is not going to be one. In its position statement, last updated 21 May 2026, the regulator says plainly that it does not assess or approve specific technologies; instead it sets 11 principles of good use and maps them to regulations you are already assessed against. Meanwhile 70% of UK homecare providers surveyed for a report published on 2 July 2026 already use AI, and only 66% have a policy governing it.
By Jason Long · August 2026 · 7 min read
The short version
- There is no CQC-approved AI tool and there will not be one. The CQC’s position statement, last updated 21 May 2026, says it does "not assess or approve specific technologies" — it regulates the care, not the software.
- What it does set is 11 principles of good use of AI, mapped back to regulations it already enforces: Regulation 9 (person-centred care), 10 (dignity and respect), 11 (consent), 12 (safe care and treatment) and 17 (good governance).
- The adoption gap is real. In a survey of 122 UK homecare providers published on 2 July 2026, 70% already use AI and around half use it to shape care itself — care plans and risk assessments — while only 66% have a formal policy governing it. The most-used tool is ChatGPT, at 63%.
- Do not repeat the claim that AI improves your rating. The CQC states directly that "the absence or presence of AI does not predict a specific rating". It also names inappropriate AI use in a CQC registration application as a risk that "can lead to wrong decisions".
- The timing matters. The CQC is piloting its new sector-specific assessment frameworks between June and October 2026, with final evaluation in November 2026. Governance you write down now is what the new frameworks will be applied to.
The question we are asked most often by care providers is a version of "is there a CQC-approved AI?" The answer is no, and it is worth understanding why, because the reason tells you exactly what you will be asked for instead.
In Artificial intelligence in health and social care: CQC's role, expectations and plans, last updated 21 May 2026, the regulator states: "We do not assess or approve specific technologies but have a role in ensuring that technology including AI contributes to safe, effective and equitable care across all settings and services." It goes on to describe its registration role as ensuring providers meet the fundamental standards "regardless of technology".
That is not a gap in the rules. It is the whole design. The CQC regulates the care you deliver, not the software you deliver it with. So nobody will ever ask whether your tool is approved. They will ask what it did, who checked it, and how you would know if it went wrong.
The gap the numbers show
Adoption has run ahead of governance, and the sector's own data says so. A survey of 122 UK homecare providers, published on 2 July 2026 in a report titled Moving Faster than the Rules: AI, Care Quality and the Homecare Sector in 2026, found that 70% already use AI in some form, rising to a projected 85% within a year. Around half use it to shape care itself, including care plans and risk assessments.
The governance figure is the one to sit with: 66% have a formal policy covering it. Roughly a third of providers are using AI on care documentation with nothing written down at all.
And the tools in use are consumer-grade, not care-grade: ChatGPT 63%, Microsoft Copilot 47%, Google Gemini 38%, Grammarly 35%. The report's own description of those tools is that they are "the least governed tools in use, typically adopted informally and without the audit trail a purpose-built care system would carry". Note the source: this is a survey published by a homecare technology vendor, so read the direction of travel rather than treating the percentages as official statistics. The direction of travel is not in doubt.
The practical version
If a member of staff pastes a service user's notes into ChatGPT to tidy up a care plan, you have a Regulation 17 governance question, a Regulation 10 privacy question and a UK GDPR question — all at once, and all before anyone asks about AI. That is what your policy exists to prevent.
This is the same pattern we described in shadow AI across UK firms: the risk is rarely the technology a firm chose. It is the technology nobody chose.
The five regulations that already apply
The CQC does the mapping for you. Its statement names the regulations most engaged by AI use:
- Regulation 9, person-centred care — "giving people the right information to make choices".
- Regulation 10, dignity and respect — "protecting privacy and treating everyone fairly".
- Regulation 11, consent — "making sure staff who obtain consent have the necessary knowledge of the care and/or treatment they are asking people to consent to".
- Regulation 12, safe care and treatment — "ensuring equipment, for example AI is safe".
- Regulation 17, good governance — "adhering to regulation, effective risk management systems, and monitoring outputs".
Regulation 12 is the one providers underestimate. The CQC is treating AI as equipment. You already know what you are expected to show for equipment: that it is fit for purpose, that staff are trained on it, that it is maintained, and that you notice when it stops working properly. Apply those four tests to a language model and most of your policy writes itself.
The 11 principles, and the four that bite
The statement sets out 11 principles of good use of AI: AI to support, not to replace; human oversight; transparency and choice; safety and reliability; security; fairness and impartiality; AI readiness and training; effective governance; a Data Protection Impact Assessment; accountability; and procurement in line with relevant regulatory standards. The CQC says it aligned these with principles published by the BMA (2024) and the WHO (2024).
All 11 are reasonable. Four are the ones an inspector can test against a real file, so start there:
- AI to support, not to replace. The CQC's wording is that AI "can enhance, but not replace human decision making". If a care plan or risk assessment was drafted by a model, the file needs to show which named person reviewed it and what they changed. A signature is not a review.
- Transparency and choice. People using services must have "appropriate information to make informed decisions about their care, including the role of AI in care pathways", and the CQC expects "non-digital routes to care" to be offered where needed, taking account of digital skills and connectivity. In practice: a plain-English line in your service user guide, and a route that does not require an app.
- A Data Protection Impact Assessment. The CQC names the DPIA explicitly as a principle. If you process personal care data through an AI tool and have no DPIA, you have failed a stated CQC expectation and a UK GDPR one in the same breath.
- Accountability. "There are clear mechanisms for addressing issues or harm caused by AI." Name the person, not the department. If the answer to "who is accountable for this tool?" is a job family rather than a job title, it is not a mechanism.
The claim to stop repeating
Vendors are selling AI into care on the promise that it lifts ratings. The same July 2026 survey reported that 59% of providers re-inspected since adopting AI saw their rating improve, and 76% said AI had improved the quality of care they deliver. Those are interesting numbers. They are not a regulatory position, they come from a vendor-published survey, and association is not causation — providers investing in technology tend to be investing in other things too.
The CQC's own line is unambiguous. Under how it rates services, the statement says: "the absence or presence of AI does not predict a specific rating."
Read that as protection rather than discouragement. It means a well-run service that uses no AI at all is not disadvantaged, and it means AI cannot be used to paper over a weak evidence base. What moves a rating is the quality of care and the strength of your governance around it — which is where the AI question actually lands.
A specific warning about your registration application
One item on the CQC's own list of AI risks is easy to miss and unusually direct. Among the risks it names is that "when used inappropriately, for example when applying for CQC registration, AI can lead to wrong decisions".
The regulator has effectively told providers that it is alert to AI-assisted applications that misdescribe a service. The same reasoning covers statutory notifications, provider information returns and evidence submitted during an assessment. Using a model to help you write more clearly is fine. Letting it assert facts about your service that you have not checked is the failure mode, and the accountable person is the registered manager.
The rest of the CQC's risk list is worth reading in full with your management team — it includes AI increasing health inequalities, mistakes that are "difficult to spot, sometimes only after people experience harm", de-personalisation of care, de-skilling, staff lacking confidence to check outputs, human oversight increasing workload, hallucination presenting untrue information "authoritatively as fact", and privacy and confidentiality risk.
Why the next three months are the moment
The CQC is rebuilding how it assesses everyone, and the work is live right now. Following the Better regulation, better care consultation, which stopped collecting responses on 11 December 2025, the CQC published draft sector-specific assessment frameworks in March 2026 and ran a further feedback survey that closed on 12 June 2026. The frameworks include references, where appropriate, to encouraging innovative use of technology including artificial intelligence as part of ensuring timely access to care.
Then, in an update published 4 June 2026, the CQC confirmed a structured programme of pilots and testing running between June and October 2026, with final evaluation in November 2026. Pilot assessments run alongside — not instead of — existing inspections, participation is voluntary with "no regulatory consequence" for declining, and "pilot judgements have no legal standing and will not affect regulatory status or rating".
Separately, the CQC says it is working with the MHRA's National Commission into the Regulation of AI in Healthcare, whose research, engagement and call-for-evidence findings were published on 11 June 2026, and that it will use the Commission's outputs in its own work.
The practical consequence: the assessment method you will be judged under is being finalised over the next few months, and the CQC has said it is considering AI implications for how it registers, assesses, rates, enforces and encourages improvement throughout 2026/27 and beyond. Providers who write their AI governance down now will simply have it ready. Providers who wait for AI-specific guidance will be building it during a live assessment.
What to do in the next month
- Find out what is actually in use. Not the procured systems — the personal accounts. Ask staff directly and without blame; the 63% ChatGPT figure did not come from a procurement process.
- Write the one-page policy. Approved tools, what data may never be entered, and which decisions always require a named human. Our one-page AI policy template is designed to be adopted in a week, and it is the document a CQC inspector asks for first under Regulation 17.
- Do the DPIA. The CQC names it as a principle in its own right. If personal data touches an AI tool, the DPIA is not optional and its absence is easy for anyone to spot.
- Add the AI line to your service user information. Transparency and choice requires people to know the role of AI in their care pathway, and a non-digital route where needed.
- Name one accountable person and record the tool-approval decision once. Doing this per branch or per manager is how inconsistency gets into files.
- Check your registration and notification submissions. If AI helped draft any of them, verify the factual claims about your service before they go anywhere near the CQC.
If the aim is to get value from AI as well as stay clear of trouble, our note on turning CQC evidence into a weekly briefing covers the operational side — using the systems you already run to surface staffing gaps, incident trends and evidence gaps before an inspector does. The wider discipline of being able to prove, on demand, that your AI use is governed is what we mean by AI audit readiness.
We work with CQC-registered providers on exactly this. Our care providers page sets out the sector work, and the 90-minute AI readiness audit tells you in plain English which of the CQC's 11 principles you could evidence today and which you could not. Book a call if you would rather find that out before your pilot report lands.
General information for UK care providers, not legal, regulatory or compliance advice. The CQC's position on AI and its assessment frameworks are both under active development; verify your obligations against the current CQC guidance and regulations, and take professional advice where needed. Last updated: 3 August 2026.
Sources
- Care Quality Commission, Artificial intelligence in health and social care: CQC's role, expectations and plans — page last updated 21 May 2026. Source of: "We do not assess or approve specific technologies but have a role in ensuring that technology including AI contributes to safe, effective and equitable care across all settings and services"; the five named regulations (9, 10, 11, 12, 17) and their parenthetical descriptions; the 11 principles of good use of AI; alignment with BMA (2024) and WHO (2024) principles; the risk list including "when used inappropriately, for example when applying for CQC registration, AI can lead to wrong decisions" and hallucination presenting untrue information "authoritatively as fact"; "Rate: the absence or presence of AI does not predict a specific rating"; registration applying "regardless of technology"; draft sector-specific assessment frameworks published March 2026; the 3 interlinked areas of work "throughout 2026/27 and beyond"; and CQC working with the MHRA National Commission — https://www.cqc.org.uk/about-us/transparency/artificial-intelligence-health-social-care-cqcs-role-expectations-plans
- Care Quality Commission, Piloting, testing and evaluation of new assessment method (published 4 June 2026) — "This will run between June and October 2026, with final evaluation in November 2026"; "Pilot assessments will run alongside - not instead of - existing inspections. Participation in a pilot is voluntary. If a provider chooses not to take part, there will be no regulatory consequence"; "Pilot judgements have no legal standing and will not affect regulatory status or rating"; draft framework survey "open until 12 June" — https://www.cqc.org.uk/about-us/improving-how-we-work/0626-update
- Care Quality Commission, Better regulation, better care: Consultation on improving how we assess and rate providers — "We stopped collecting responses on 11 December 2025"; sector-specific assessment frameworks and rating characteristics; further feedback sought on draft frameworks — https://www.cqc.org.uk/about-us/how-we-involve-you/consultations/improving-how-we-assess-and-rate-providers
- Caring Times, Majority of homecare providers have adopted AI, says report (reporting Birdie's Moving Faster than the Rules: AI, Care Quality and the Homecare Sector in 2026, published 2 July 2026; survey of 122 UK homecare providers) — 70% currently use AI rising to a projected 85% within a year; ~50% use AI to shape care including care plans and risk assessments; 76% report improved care quality; 59% of those re-inspected saw ratings improve; 66% have a formal AI policy; ChatGPT 63%, Microsoft Copilot 47%, Google Gemini 38%, Grammarly 35%; "These are the least governed tools in use, typically adopted informally and without the audit trail a purpose-built care system would carry". Note: vendor-published survey, cited as sector signal not official statistics — https://caring-times.co.uk/majority-of-homecare-providers-have-adopted-ai-says-report/
- MHRA, National Commission into the Regulation of AI in Healthcare: research, engagement and call for evidence findings (published 11 June 2026, GOV.UK) — evidence gathered from patients and the public, healthcare professionals, industry, academics and wider health system stakeholders, including an open call for evidence and insights from the MHRA's AI Airlock programme — https://www.gov.uk/government/publications/national-commission-into-the-regulation-of-ai-in-healthcare-research-engagement-and-call-for-evidence-findings
Frequently asked
Does the CQC approve AI tools for care providers?
No. The CQC’s position statement on artificial intelligence in health and social care, last updated 21 May 2026, states: "We do not assess or approve specific technologies but have a role in ensuring that technology including AI contributes to safe, effective and equitable care across all settings and services." There is no approved-tool list, no certification and no registration category for AI. The regulator assesses whether your care meets the fundamental standards, and it says its role applies "regardless of technology".
Which CQC regulations apply to a care provider using AI?
The CQC names five in its position statement: Regulation 9, person-centred care (giving people the right information to make choices); Regulation 10, dignity and respect (protecting privacy and treating everyone fairly); Regulation 11, consent (making sure staff who obtain consent have the necessary knowledge of the care or treatment they are asking people to consent to); Regulation 12, safe care and treatment (ensuring equipment, for example AI, is safe); and Regulation 17, good governance (adhering to regulation, effective risk management systems, and monitoring outputs). None of these are new. They are the regulations you are already assessed against, read through an AI lens.
What are the CQC’s principles for good use of AI?
Eleven, set out in the 21 May 2026 statement: AI to support, not to replace; human oversight; transparency and choice; safety and reliability; security; fairness and impartiality; AI readiness and training; effective governance; a Data Protection Impact Assessment; accountability; and procurement in line with relevant regulatory standards. The CQC says it aligned these with principles published by the British Medical Association (2024) and the World Health Organization (2024) and linked them back to the regulations it enforces.
Will using AI improve our CQC rating?
The CQC says no such link exists. Under "Rate" in its statement it says: "the absence or presence of AI does not predict a specific rating." A July 2026 homecare survey found that 59% of providers re-inspected since adopting AI saw their rating improve, but that is an association reported in a vendor-published survey, not a causal finding and not a regulatory position. Treat AI as something you must govern well, not as something that earns credit by itself.
Can we use AI to write our CQC registration application?
Be careful. The CQC lists among the risks of AI that "when used inappropriately, for example when applying for CQC registration, AI can lead to wrong decisions". An application that misdescribes your service because a model filled in the gaps is your responsibility, not the tool’s. The same logic applies to care plans, risk assessments and notifications: the accountable person is the registered manager, and the CQC’s first principle is that AI "can enhance, but not replace human decision making".
Is the CQC writing separate AI guidance?
Possibly, but not yet. The statement says new assessment frameworks "will be rolled out alongside supporting guidance for providers" and that as technology evolves the CQC will "keep requirements for AI-specific guidance and training under review", adding that it "may develop AI guidance tailored to providers across different sectors and settings". In the meantime the operative documents are the existing regulations and the 11 principles. Waiting for AI-specific guidance is not a governance strategy.
Related insights
Want this sorted, properly?
Our 90-minute audit leaves you with a one-page action list: three things AI should be doing, what it will cost and what it will save. Keep the report either way.
Put what you read into practice.
Book a free 30-minute call. We map your business, find the few things AI should be doing, and send a one-page action list. No obligation.
Book a free call0330 043 7414 hello@nerdster.ai Mon–Fri 9–5:30