Digital, AI and Cyber Risk Are Now Core Clinical Delivery Risks

29 Jul 2026

Share with

Blogs - June 10

NHS England’s June 2026 Board papers show that digital, artificial intelligence and cyber risk are no longer peripheral technology issues. They are now core clinical delivery risks.

This is one of the strongest future-facing signals in the Board pack. The Research, Innovation and Growth Board discussed the future regulation of AI in healthcare, Ambient Voice Technologies, HealthTech adoption and innovation priorities. The Risk Management paper identified cyber, data breach, digital workforce capacity, technology transformation and AI medical device regulation as material risks. The Operational Risk Register linked digital service disruption directly to patient harm, poor outcomes and service continuity.

For NHS leaders, the message is clear: digital maturity is now part of clinical resilience. Cyber security is part of patient safety. AI governance is part of clinical governance. Digital workforce capacity is part of operational delivery.

The NHS cannot deliver the 10 Year Health Plan, productivity improvement, elective recovery, neighbourhood health or more personalised care without reliable digital infrastructure. But the same technologies that enable transformation also introduce new risks if governance, regulation, workforce and resilience do not keep pace.

System Incentive Lens

The system pressure driving digital and AI adoption is the need to improve access, productivity, prevention, patient communication, diagnostics and service efficiency. The financial and operational constraint is that the NHS must modernise within limited resources, while managing legacy systems, cyber threats and workforce shortages. The behavioural incentive is to accelerate innovation that supports clinical need and reduces unwarranted variation. The operational trade-off is that faster adoption increases dependency on digital systems, data quality, supplier assurance and regulatory readiness.

Cyber risk is now a clinical continuity risk

The Risk Management paper states that cyber risk remains above appetite in the medium term. It notes persistent external threat levels, variable sector maturity and reliance on capabilities such as supplier assurance and recovery planning, which require sustained investment and time to embed.

This matters because cyber risk is no longer only about data loss or organisational disruption. The Operational Risk Register describes cyber and digital resilience failure as a risk that can compromise data, create unavailability, reduce productivity, and lead to patient harm and poor outcomes.

That is a clinical risk.

If digital systems are unavailable, clinical teams may lose access to records, referrals, prescribing, diagnostics, imaging, scheduling or communication tools. Patient flow can slow. Decisions may be delayed. Manual workarounds may increase documentation risk. Providers may struggle to maintain routine and urgent services safely.

NHS England’s planned July cyber simulation exercise is therefore significant. Its focus on maintaining critical services and coordinating a national response during prolonged disruption reflects the reality that cyber resilience must be tested as part of emergency preparedness, not treated as a back-office control.

Provider boards should therefore ask a simple question: if a major cyber incident occurred, which clinical services would be most exposed, and how long could they operate safely?

Data breach risk is becoming more complex

The Board papers show progress on data breach risk, including strengthened information governance, enhanced third-party assurance, data protection health checks and improved incident response arrangements.

This is positive. But the risk environment is becoming more complex.

Data is now central to clinical delivery, productivity, performance oversight, research, screening, digital triage, patient communication and population health management. As data use expands, so do the points of vulnerability. These include cyber incidents, non-cyber data handling failures, supplier access, third-party platforms, AI tools, internal records management and organisational transition.

For patients, trust in data use is essential. The NHS cannot expand digital and AI-enabled services unless patients and staff have confidence that data is handled lawfully, safely and transparently.

For providers, data governance must now sit closer to clinical governance. Decisions about data use, digital tools or AI deployment are not only technical or legal decisions. They affect patient safety, consent, equity, accountability and public trust.

The future NHS will need to use data more effectively. But it must also be able to explain why data is being used, how it is protected, and how risks are managed.

AI adoption is moving faster than governance maturity

The Research, Innovation and Growth Board discussed the future regulation of AI in healthcare and noted that full recommendations from the National Commission into the Regulation of AI in Healthcare were due in September 2026. It also discussed Ambient Voice Technologies, with DHSC and NHS England considering joint guidance and potential regulation.

This is an important signal. AI is moving from experimental interest into practical clinical and operational use. Ambient Voice Technologies, AI-enabled triage and AI-supported diagnostics all have potential to reduce administrative burden, support decision-making and improve access.

But AI adoption creates new governance questions.

Who is accountable when an AI tool influences a clinical decision? How is bias tested? How are outputs validated? How are staff trained? How is patient consent managed? How are errors detected? How do providers distinguish between decision support and clinical automation? How are suppliers assured?

The Board papers do not suggest rejecting AI. They suggest the opposite: AI and HealthTech are becoming central to future delivery. But the same papers also show that governance and regulation must keep pace with adoption.

The system should welcome clinically useful AI, but not treat innovation as automatically safe or effective. In healthcare, speed must be balanced with assurance.

AI medical device regulation creates a delivery risk

The Operational Risk Register identifies a new risk relating to new and updated software and AI medical devices going live from spring 2027. It states that NHS England may be unable to place new and updated software and AI medical devices into clinical use lawfully, creating a potential “innovation freeze” that could affect delivery of 10 Year Health Plan commitments such as intelligent triage on the NHS App.

This is a highly significant governance signal.

The risk is not opposition to innovation. It is that regulatory readiness may determine whether innovation can be deployed at all. If digital and AI-enabled products cannot meet required standards, they may be delayed, restricted or withdrawn from clinical use.

The mitigations referenced include developing a Quality Management System aligned to ISO 13485, preparing for external certification and up-classification of legacy products, internal audits, root cause analysis and transition to external notified body approval where required.

For provider leaders, this points to a wider lesson. AI and software used in clinical pathways must be treated with the same seriousness as other clinical technologies. Procurement, clinical safety, information governance, supplier assurance, post-deployment monitoring and regulatory compliance must be built in from the start.

Innovation that cannot be governed will not be sustainable.

Digital workforce capacity is a limiting factor

The Risk Management paper identifies digital workforce capacity as one of the most significant operational risks, with recruitment and retention of digital and data specialists described as a critical dependency for digital transformation and service continuity.

This is central to the future operating model.

The NHS can set digital ambitions, procure new platforms and identify AI opportunities. But implementation depends on people: digital architects, analysts, engineers, cyber specialists, clinical safety officers, informatics leads, data governance experts, transformation teams and operational managers who can translate digital tools into service change.

Digital workforce shortages create delivery risk in several ways. Projects may slow. Legacy systems may remain in use for longer. Cyber resilience may be harder to improve. Data quality may remain inconsistent. Providers may lack the internal capability to evaluate supplier claims or implement tools safely.

This is why digital workforce resilience should be treated as part of wider workforce strategy. The NHS does not only need more clinical capacity. It also needs the specialist digital capability required to make modern clinical services safe, efficient and resilient.

HealthTech adoption must align with clinical priorities

The Research, Innovation and Growth Board discussed the need for a more integrated HealthTech delivery approach. It identified priority areas for testing innovative procurement approaches, including AI-enabled dermatology triage, digital therapeutics for insomnia, robotic assisted surgery and wearables to support digital cardiac rehabilitation.

This is a positive direction. Each of these areas has potential relevance to access, productivity, prevention or patient experience.

But the Board also highlighted the importance of aligning HealthTech priority areas with strategic priorities, Modern Service Frameworks, commissioning and procurement approaches. That alignment is essential.

Digital tools should not be adopted because they are novel. They should be adopted where they meet defined NHS needs, support clinical pathways, improve outcomes, reduce variation, release capacity or strengthen patient experience.

For providers, the practical test is whether technology solves a real operational problem. A tool that does not integrate into workflow may add burden. A tool that lacks evidence may create risk. A tool that cannot be scaled may consume effort without meaningful system benefit.

The strongest HealthTech adoption will be clinically led, evidence-informed and linked to measurable delivery priorities.

Digital risk is also an equality and access issue

Digital transformation can improve access, but it can also widen gaps if not designed carefully.

The Board papers include digital-first correspondence in screening programmes, NHS App development, digital cardiac rehabilitation, AI-enabled triage and digital therapeutics. These tools may improve reach, speed and convenience. But they also depend on digital inclusion, accessibility, language, health literacy, trust and patient choice.

If digital transformation is not designed around patient diversity, some groups may benefit less than others. This is especially important in screening, prevention, long-term condition management and mental health, where inequalities are already visible.

Digital delivery therefore needs an equality lens. The question is not only whether a tool works technically. It is whether it works for the populations most at risk of being left behind.

What this means now

Digital, AI and cyber risk are now core clinical delivery risks.

The June 2026 Board papers show a system that is increasingly dependent on digital infrastructure, data, AI and HealthTech to deliver access recovery, productivity, prevention, research and future care models. That direction is necessary. Modern healthcare cannot operate effectively without strong digital capability.

But the risks are equally clear. Cyber threats can disrupt clinical services. Data breaches can damage trust. AI tools can create governance and accountability challenges. Regulatory readiness may affect whether products can be lawfully deployed. Digital workforce shortages can slow transformation and weaken resilience.

For patients, the opportunity is better access, faster communication, more personalised care and earlier intervention. The risk is disruption, exclusion, unsafe deployment or loss of confidence if digital tools are not governed well.

For healthcare workers, digital transformation should reduce burden, not add complexity. Ambient voice, decision support, triage tools and improved data should support clinical work. They should not replace clinical judgement or create hidden administrative and safety risks.

For provider leaders, the message is clear: digital risk now belongs on the main board agenda. It should be considered alongside finance, workforce, quality and operational performance. Boards should understand their cyber resilience, AI governance, supplier assurance, digital workforce capacity and clinical safety processes.

The forward outlook is one of opportunity with increasing dependency. Digital and AI will shape the next phase of NHS delivery. The providers and systems that benefit most will be those that combine innovation with discipline: clinically led adoption, strong governance, resilient infrastructure and clear accountability for patient safety.

References

  • NHS England, Board Committee Updates – Research, Innovation and Growth Board, 4 June 2026.
  • NHS England, Risk Management, 4 June 2026.
  • NHS England, NHS England Operational Risk Register, Annex 2, 4 June 2026.
  • NHS England, Integrated Performance Report, June 2026.
  • NHS England, Digitrials Recruitment Service Directions 2026, 4 June 2026.
  • NHS England, Vaccination and Screening Directions 2026, 4 June 2026.

29 Jul 2026 | Leave a comment

Share with socials

Leave a Comment

You must be logged in to post a comment.