Governance, structured workflows and education: The three pillars for successful AI adoption in NHS environments

Governance, structured workflows and education: The three pillars for successful AI adoption in NHS environments

As NHS trusts accelerate AI adoption, many are attempting to layer new technologies onto fragmented systems and disconnected data. The result? AI that is difficult to scale, hard to govern and unlikely to deliver on its promise. Joanne Atkinson, Blue Light Business Development Manager at Node4, argues that the NHS is asking the wrong questions about AI. Before trusts focus on what AI can do, they must first ensure their data, governance and people are ready to support it. She explores why AI readiness – not AI capability – will ultimately determine whether NHS AI projects succeed or fail.

Most discussions about AI in healthcare focus on chatbots, Copilots and user interfaces rather than the systems and data structures behind them. That’s not unique to this sector. Node4’s last Mid-Market Report found that AI-powered assistants and Copilots were the joint most popular AI deployment among IT leaders. Yet two out of every five respondents identified data quality and availability as one of the biggest barriers to AI adoption.

The research demonstrates the same underlying tension that will be familiar across much of the NHS: enthusiasm for AI adoption must be matched by a financial and cultural commitment to improve data quality, connect the systems that underpin it, define how AI can use approved information within existing processes and control who or what has access to the responses. Without this vital preparatory work, AI tools and systems risk being installed in environments that are not ready to support them. 

That focus is understandable. For many organisations – including NHS Trusts – chatbots, Copilots and user interfaces are the first AI use case because they’re the most visible. But the interface is only the visible layer of a much larger operational system.

So, as Agentic AI moves towards mainstream adoption, there’s a conversation to be had about how to use the technology to connect disparate data sources, automate manual information retrieval processes and surface answers. Users may still interact with the technology via a prompt but the potential productivity gains come from the work happening behind the scenes.

AI projects can stall without strong foundations

Striking the right balance

Despite Agentic AI’s potential advantages, some healthcare-sector adopters remain understandably wary. There’s concern, for example, that trusts may accidentally unleash an AI system they can’t control. Recent disclosures from OpenAI, Anthropic and Meta show that this is not merely a theoretical risk. During cybersecurity evaluations, their AI agents reached real external systems and took actions outside the intended boundaries of the tests that resulted in unauthorised access to third-party services.

These incidents exposed weaknesses in network isolation and oversight, underlining why containment, permissions and configuration controls are core governance requirements, not merely technical details. With these measures in place, an agent’s access to systems and data can be tightly controlled so it focuses only on information relevant to its intended task and does not expose sensitive data to unauthorised staff.

Strict controls and solid foundations

Agentic AI systems can trigger workflows, connect multiple data sources or automate operational tasks – all of which can help reduce administrative burden. However, NHS Trusts need to define where an agent enters a process, which data it can access and what it may automate. It’s also important to define when a human needs to provide oversight or take over completely.

Those decisions need to be supported by strong governance and reliable data. Information should be consolidated so the system and its users can work from a dependable source of truth. For NHS trusts, these controls are also essential to maintaining confidentiality and meeting their legal and ethical obligations to protect sensitive information. Without those foundations, trusts risk scaling inefficiencies and operational problems rather than resolving them.

Learning starts when the agent goes live

Employees intending to use new AI systems will need formal training and education but that learning shouldn’t stop once the agent is up and running. Users are more likely to engage with AI if they understand how it fits into their work, where its boundaries lie and how to question or challenge its outputs. After all, AI adoption has the capacity to change how NHS trusts surface and respond to data – while also restructuring workflows and, sometimes, even cultures. It’s therefore far more than a routine IT system upgrade.

As users learn how the technology works and evolves, continuing support can reinforce governance and stress the importance of retaining human oversight. Onboarding also plays an important part in helping users incorporate AI into established ways of working. A system that has technically gone live will not deliver its full value if users remain uncertain about when to use it, how to interpret its outputs or when to escalate a concern.

Users also need clear guidance on what to do when an answer appears incomplete, inaccurate or potentially biased. That includes manually checking it against approved source material, challenging the output and escalating the query where necessary. This makes human oversight part of everyday work rather than an abstract principle of governance policy.

Using Copilot data to improve skills and training

AI deployments could also help surface knowledge and training gaps. For example, Copilot’s back-end query log can create an evidence base of the questions employees are actually asking – rather than leaving the trust to rely on assumptions about what they understand. This could enable the trust to identify recurring questions and knowledge gaps, showing where additional training or guidance may be needed.

Access to this usage data offers the trust an opportunity to respond by changing onboarding processes, using additional workshops and internal communications and improving the information at source. When handled with appropriate privacy and access controls, the data creates a feedback loop through which training, support and the underlying information can evolve alongside actual usage.

Conclusion

AI adoption shouldn’t be measured in terms of whether a chatbot, Copilot or agent has gone live. The more meaningful test is whether a trust has connected the right data, established dependable workflows and controls and equipped its people to use, question and improve the technology. That means putting the operational, technical and cultural foundations in place in the right sequence, with retained human oversight as the capability develops. The prompt interface may be where many users first encounter AI. But it is the data, governance and organisational capability behind it that will determine whether AI systems deliver lasting value and the positive organisational changes that IT leaders within NHS Trusts are looking for.

Browse our latest issue

Intelligent Health.tech

View Magazine Archive