AI will transform the NHS. But only after invasive surgery on its data and systems
"If AI is layered onto fragmented systems, controls and complex cloud environments, it risks adding another layer of difficulty."
The NHS is entering one of the most ambitious periods of digital change in its history.
The government’s 10 Year Health Plan sets out a clear direction of travel: Care should become more digital, preventative and connected. Plans include a single patient record, a transformed NHS app, wider use of AI scribes and a goal to make the NHS the most AI-enabled health system in the world.
This modernisation is exactly what many have been calling for. Digital tools can help reduce pressure on overstretched staff, remove repetitive admin, improve patient access and support more joined-up care.
And, in a system facing rising demand, workforce pressure and long waiting lists, AI has an important role to play. But it cannot deliver those benefits in isolation, it needs strong digital foundations.
If AI is layered onto fragmented systems, inconsistent access controls and complex cloud environments, it risks adding another layer of difficulty rather than reducing pressure. For the NHS, the priority should be to build a digital environment where AI can be adopted safely, securely and in a way that genuinely supports care delivery.
AI in hospitals
AI already plays a large part in healthcare workflows, from scribes and automated documentation to tools that support knowledge work and routine admin. In fact, in terms of generative-AI tools alone, 68% of healthcare organisations are using ChatGPT, while Microsoft Copilot is used by 63% and Google Gemini by 57%. However, while the benefits are considerable, the risks are too.
As of 2025, regulated data accounts for 89% of data policy violations tied to generative AI in the healthcare sector, far higher than the global average of 31%. And, the same pattern extends beyond AI, with regulated data making up 82% of policy violations in personal applications.
Not only is this concerning from a legal standpoint, but sensitive healthcare information can include diagnoses, treatments, prescriptions, test results and deeply personal details about a patient’s life. Public trust depends completely on whether patients and staff believe that information is being handled responsibly.
Protecting that data is not straightforward. The NHS is made up of national systems, local trusts, public/private partnerships, integrated care systems, suppliers, cloud services, legacy technologies and modern applications. As such, NHS data is not staying in one neat, controlled environment.
It is constantly moving between clinical systems, productivity tools, cloud applications, suppliers and, increasingly, AI services. Even a small gap in access control, policy enforcement or data protection can have huge consequences for patient care.
The solution is not simple; the NHS cannot simply pause, simplify everything and then restart. Care has to continue while transformation happens around it, so security needs to work across that complexity rather than around it.
Strong foundations
For NHS leaders, the priority should be to create the conditions for AI to work safely at scale, and this starts with understanding AI use across the organisation. For example, which applications are being used, whether they are approved, what data is being shared, which users are interacting with them and whether activity is taking place in managed or unmanaged services.
It’s also important to reframe access through zero trust thinking. In a modern healthcare environment, staff need to work across hospitals, GP practices, community care settings and remote locations. Access should be based on identity, context and risk, rather than outdated assumptions about whether someone is inside or outside the network. The right person should be able to reach the right data at the right time, without creating unnecessary exposure.
In practical terms, this means bringing together signals such as user identity, device posture, location, application risk, data sensitivity and behaviour. A clinician accessing an approved clinical system from a managed device is very different from the same account trying to move patient information into an unmanaged AI tool. Controls should adapt to that context, allowing trusted work to continue smoothly while risky activity is coached, restricted or blocked.
Secure adoption
Just as importantly, security needs to follow the data. This means protecting sensitive information wherever it moves, rather than only defending the network, device or application it started in. As the NHS becomes more cloud-based and AI-enabled, information will move across more applications, devices and services. Traditional approaches that rely on fixed perimeters are not enough.
NHS organisations need real-time visibility into how data is accessed and used, alongside data protection and policy enforcement that work consistently across users, applications and traffic. This becomes harder with AI because the risk is not only whether someone has opened an approved or unapproved application. It is what they are asking the tool to do, what information is being shared in prompts, what data the tool can reach and whether the output creates new risk.
A staff member might paste patient information into a public AI tool, use an embedded AI assistant inside a productivity app or interact with an AI agent that connects to other systems. Security teams therefore need insight into the AI interaction itself, not just the application name.
READ MORE: NHS warns of “significant” robotics dependency risk as it sets new tech buying rules
The answer is to make the secure route the easiest route. Guide staff towards approved AI services, apply proportionate controls in the background and stop sensitive data from moving where it should not.
This is also where simplification matters. Many NHS organisations are already managing a complex mix of systems and suppliers. Adding more point solutions can make that harder, not easier. A stronger foundation is one that reduces complexity through unified platforms, shared signals and common policy across web, cloud, SaaS, private applications and AI. This way, teams are not creating another layer of tools and resource requirements that becomes harder to manage as adoption grows.
Speed also matters. AI adoption will only succeed if approved tools are easier to use than unsafe workarounds. The NHS cannot afford to trade speed for security. Secure access needs to be fast enough for healthcare environments, where delays can directly affect staff experience and patient care. This means optimising access to approved AI, cloud and clinical applications while keeping data protection, threat protection and policy controls in place.
Security is now part of patient trust
The NHS’s digital future will depend on public confidence. Patients need to trust that their information is being protected. Staff need to trust that the tools they are given will help them do their jobs safely. And leaders need confidence that innovation is not introducing risks they cannot see.
This makes security a central part of transformation, not a technical side issue. If AI is going to support clinical and operational work across the NHS, it needs foundations that allow secure access, clear data controls, simple user experiences and continuous risk management to work together. Those foundations should make safe AI easier to adopt, not harder to use.
This is the balance the NHS now has to strike. It needs to move quickly enough to unlock the benefits of AI, but carefully enough to protect the data, systems and trust that healthcare depends on. Stronger digital foundations make it easier to scale safely, reduce friction for staff and build confidence in new services.
Colette Kitterhing is Vice President UK & Ireland at Netskope