AI in social care: what the ICO, CQC and Ofsted actually expect
Published 18 September 2026 · 10 minute read · General information, not legal advice
Nobody regulating care in England has banned AI. Every one of them has said, in their own way, that the provider stays responsible for what it does with people’s data and what it does with the output. This guide collects what they have said, quoted from the documents, so you can put it in front of your board, your DPO or your registered manager.
Regulator names below are England’s. Data protection law is UK-wide, and the same principles apply to providers regulated by Care Inspectorate Wales, the Care Inspectorate in Scotland and RQIA in Northern Ireland.
The ICO: data protection applies to AI like anything else
The Information Commissioner’s Office regulates data protection across every sector. Its AI guidance does not create special rules for care; it applies the ordinary ones. Three points matter most for a provider.
“the use of AI will involve a type of processing likely to result in a high risk to individuals’ rights and freedoms, and will therefore trigger the legal requirement for you to undertake a DPIA.”
Second, you remain accountable when you buy AI in. The guidance expects organisations procuring external AI to evaluate the trade-offs themselves and specify their requirements up front. Third, data minimisation still applies: use the least personal data that does the job. The cleanest way to minimise personal data sent to an AI is to send none, which is what anonymisation achieves.
“Data protection law does not apply to anonymous information”
CQC: no approval of tools, clear expectations of providers
In May 2026 the Care Quality Commission published its role, expectations and plans on AI in health and social care. The first thing to understand is what it will not do:
“We do not assess or approve specific technologies”
Instead it sets out what it expects to see from a provider that uses AI. The statement’s principles include:
- "A DPIA assesses and documents risks to privacy and data subject rights to understand and minimise interference."
- "Those using AI are sufficiently trained and confident in using the technology, and they assess whether it can be integrated."
- "AI outputs and processes are continuously monitored and evaluated."
- "People who use services have appropriate information to make informed decisions about their care, including the role of AI in care pathways."
- "There are effective mechanisms such as risk assessments to ensure AI contributes to high-quality, equitable care."
CQC has also said that the presence or absence of AI does not predict a rating. What it assesses is whether the care is safe, effective and well-led, with AI treated as one more thing the provider is accountable for.
Ofsted: impact on children, and questions for leaders
Ofsted’s approach, published in June 2025 and updated in October 2025, covers every setting it inspects, including children’s homes and fostering agencies. It does not evaluate AI tools directly.
“inspectors can consider the impact that the use of AI has on the outcomes and experiences of children and learners.”
It flags two things a children’s provider should expect questions about. Data: "many applications of AI use large amounts of data, which can include personal data". And safeguarding: "AI can pose new and unique safeguarding risks". Leaders may be asked how they make sure any use of AI supports the best interests of children and learners. A provider that can show what its staff use, what data goes into it, and who checks the output has an answer.
The Department for Education: AI in case recording
The DfE’s National Workload Action Group reviewed AI in children’s social care case recording in September 2025. It is optimistic about reducing unnecessary workload and specific about the conditions:
“Where AI is adopted, human oversight is crucial to ensure accuracy and maintain ethical standards.”
It lists the sector’s live concerns as "bias, privacy and data protection, consent, deskilling and overreliance", warns that "fragmented approaches and lack of oversight and support pose risks", and calls for national guidance. Until that arrives, the practical reading is that a provider needs its own governance rather than waiting.
Professional bodies: BASW and Social Work England
BASW published the first practice guidance on generative AI in social work in March 2025. Community Care’s report of it captured the operative lines: practitioners should "avoid entering sensitive personal information into generic tools without the explicit and informed consent of the person concerned", "accountability ultimately sat with the social worker using the tool", and "data protection assessments should also be undertaken before introducing AI products within services".
Social Work England, the regulator for social workers in England, announced research in February 2025 into how AI affects professional standards and data protection in practice. Its professional standards apply to AI-assisted work as they apply to everything else: a registered social worker remains accountable for records they sign.
The sector: the Oxford statement
In February 2024 the Oxford Institute for Ethics in AI, with Digital Care Hub and partners, published a statement on the responsible use of generative AI in adult social care, endorsed by organisations including Care England, the National Care Forum, Skills for Care, ADASS and SCIE. It frames responsible use around human rights and trusting relationships, and names the obvious risk in one line: irresponsible use "for example by inputting personal data".
What a defensible setup looks like
Read together, the documents above describe the same checklist. A provider that can tick each line has an answer for the ICO, its inspector and its DPO.
- A DPIA for the AI tool you approve, done before staff use it. Start from our DPIA template for AI in social care.
- A named, approved route, so the policy is not only a prohibition that pushes use out of sight. Our AI policy template does this.
- Data minimisation in practice: personal data removed before text reaches the AI, so the transfer carries none.
- A written Data Processing Agreement with the vendor, and clarity on where processing happens.
- A human review step, with staff trained to check outputs for accuracy and bias.
- An audit trail of what was sent, by whom and when.
- Transparency: people who use the service can be told, in plain terms, how AI is used in their care.
Caredact was built to satisfy that list for the writing tasks care teams actually use AI for: it removes personal data before the AI sees the text, puts a review step in front of every send, logs every action, runs in the UK and comes with a Data Processing Agreement. It is not a substitute for the policy, the DPIA or the training; it is the control that makes them workable.
Questions
Will CQC or Ofsted approve a specific AI tool?
No. CQC says explicitly that it does not assess or approve specific technologies, and Ofsted does not evaluate AI tools directly. Both assess the provider’s governance and the effect on the people it cares for.
Do we need a DPIA if the tool anonymises the data first?
Do one anyway. The ICO’s position is that AI processing is likely to be high risk, and the DPIA is where you record that the anonymisation step, the contract and the review process address that risk. It is a short document when the controls are good.
We are in Wales or Scotland. Does any of this apply?
The ICO and the UK GDPR apply UK-wide. CQC and Ofsted are England’s regulators; Care Inspectorate Wales, the Care Inspectorate in Scotland and RQIA in Northern Ireland have their own frameworks, and the governance checklist above holds under all of them.
Sources
- [1]ICO, Guidance on AI and data protection: accountability and governance implications
- [2]ICO, Introduction to anonymisation
- [3]CQC, Artificial intelligence in health and social care: CQC’s role, expectations and plans (21 May 2026)
- [4]Ofsted, How Ofsted looks at AI during inspection and regulation (27 June 2025, updated 21 October 2025)
- [5]Department for Education / Research in Practice, Artificial Intelligence (AI) in case recording: National Workload Action Group supplementary report (September 2025)
- [6]Community Care, First practice guidance for AI in social work warns of bias and data privacy risks (11 April 2025)
- [7]Social Work England, Artificial intelligence in social work (February 2025)
- [8]Oxford Institute for Ethics in AI, Oxford Statement on the responsible use of generative AI in adult social care (1 February 2024)