Skip to content
AI employeesPublished 10 min readBy 7 Minds Systems

Last updated

Does an AI receptionist meet CQC expectations in a GP practice?

The CQC has published guidance on AI in GP services, and answering the telephone is not in it. What GP mythbuster 109 actually says, the ten areas assessors look at, and where the guidance genuinely stops.

Key takeaways

  • CQC GP mythbuster 109, published 14 July 2025, is the guidance on AI in GP services. It covers scribes, online questionnaire triage, results processing, documentation, chatbots and predictive modelling, and says nothing about a system answering the practice telephone.
  • The CQC assesses systems and processes across ten named areas, from procurement and governance through to managing bias, and looks for the evidence in audits, the significant incident log and quality improvement activity.
  • An AI tool that influences clinical decision-making is likely to qualify as a medical device under MHRA regulations, classified from Class I to Class III by intended use.
  • DCB0160 requires the adopting practice to nominate a clinical safety officer who is a senior clinician with current professional registration and practitioner-level digital clinical safety training.
  • On consent, the CQC's position is transparency: tell people AI is being used and allow them to object, which is a lower bar than explicit consent but a firm one.
  • The guidance calls it essential that practices offer a non-digital route to access care, so an automated line cannot be the only way in.

The honest answer is that the CQC has not addressed this specific thing. Its guidance on artificial intelligence in GP services exists, it is detailed, and answering the practice telephone is absent from it. What the guidance does give a practice is a clear framework of systems and processes that any AI tool has to sit inside, and that framework is what an assessment will test. A practice can meet it. It cannot cite a CQC blessing for an AI receptionist, because none has been written.

GP mythbuster 109 on the use of artificial intelligence in GP services, published 14 July 2025, is the document, and this post stays inside what it actually says.

Has the CQC published guidance on AI receptionists in GP practices?

Not on answering the telephone. GP mythbuster 109, published 14 July 2025, is the CQC guidance on artificial intelligence in GP services, and the uses it describes are ambient voice scribes, triage through a structured online questionnaire, results processing, clinical documentation, diagnosis and treatment planning support, chatbots, and predictive modelling for missed appointments and staffing. A conversational system answering the practice phone appears nowhere in it. The expectations still reach such a system, because they are written about a practice's systems and processes and those cover any AI tool it adopts. This is general information about published CQC guidance and not legal or clinical advice.

Two details in the guidance matter more than they first appear. The CQC defines AI as technologies that simulate human intelligence to perform complex tasks by learning from data, and it separates that from rules-based automation, which follows fixed logic and produces the same outcome for a given input every time. A scripted telephone menu is the second thing. A system that interprets what a caller says is the first, and the guidance follows it.

The other detail is that the CQC already lists administrative AI in general practice without treating it as exotic. Under predictive modelling it names predicting missed appointments and helping to schedule them, and forecasting staffing levels. Administrative AI in a GP practice is, on the regulator's own account, ordinary.

What does the CQC look at when a GP practice uses AI?

The practice's systems and processes. GP mythbuster 109 names ten areas an assessment covers, running from how the tool was procured through to whether it works fairly across the practice population, and taking in risk assessment, named responsibilities, human oversight, learning from errors, data protection, consent and staff training on the way. The CQC states it will check that AI is being used as a support tool, and that it will look for the evidence in a practice's audits, significant incident log or other quality improvement activity. The practice that cannot produce that evidence is the one with the problem.

The ten areas are set out below in the order the guidance uses. This is the list to walk into an assessment with, and the practice that has an answer for each one is in a strong position whatever the tool happens to be.

Procurement and governance
What the practice has to be able to show
The tool was procured in line with DCB0160, DTAC and MHRA registration where applicable, and is used within its intended purpose
Risk assessment
What the practice has to be able to show
A hazard log and completed risk assessments covering the AI tool
Responsibilities
What the practice has to be able to show
A named clinical safety officer and digital lead, both with relevant training completed
Human oversight
What the practice has to be able to show
Monitoring and evaluation of AI outputs, evidenced through audits, a significant incident log or quality improvement work
Learning from errors
What the practice has to be able to show
Systems to report and investigate, including to the developer and through the MHRA Yellow Card scheme, with lessons shared internally and externally
Data protection
What the practice has to be able to show
UK GDPR compliance including a record of processing activities, data protection impact assessments, cybersecurity arrangements and the NHS Data Security and Protection Toolkit
Consent
What the practice has to be able to show
That patients have been told AI is in use, with the type of consent matched to the technology and its purpose
Staff training
What the practice has to be able to show
Staff are competent to use the tool
Equity in access
What the practice has to be able to show
A non-digital route to care remains available, with practical steps taken on digital skills, connectivity and accessibility
Managing bias
What the practice has to be able to show
Assurance sought on the risk of bias against particular population groups

The ten areas CQC GP mythbuster 109 says an assessment will look at, in the order the guidance lists them. Summarised from the published guidance and not a substitute for reading it.

Does an AI phone system need to be registered as a medical device?

That turns on whether it influences clinical decision making. The CQC states that an AI tool used in a practice which influences clinical decision-making is likely to qualify as a medical device under MHRA regulations, with classification driven by intended use and running from Class I at the lowest risk to Class III at the highest. A system that books appointments and takes messages sits outside that. A system that assesses symptoms or assigns urgency is doing the thing that pulls it in, and a practice should then ask the supplier for MHRA registration, UKCA or CE marking, and the classification documents.

The guidance is specific about the evidence to request. A practice should ask an AI supplier for MHRA registration, UKCA or CE marking, and device classification with the clinical safety and regulatory documentation, and the CQC notes that by law a manufacturer must know and disclose this where the product is regulated. Registered devices can be checked on the MHRA public access registration database. The classification depends on intended use, which is why the boundary a system is built to matters so much: booking an appointment and taking a message keeps a tool clear of clinical decision-making, and assessing symptoms does not.

The guidance adds a caution worth carrying: software should only be used within the constraints described in its instructions for use, and adopters who go beyond them take on significantly more risk. A tool sold for scheduling and quietly used for triage is exactly that scenario.

Does a GP practice need a clinical safety officer for an AI tool?

Where DCB0160 applies, yes, and the CQC states the scope. Its wording is that when adopting an eligible digital technology on behalf of the NHS, providers need to first meet the safety standards set by NHS Digital, so a tool that is neither eligible nor adopted on behalf of the NHS is not caught by the standard on the face of the guidance. Most general practice delivers NHS-commissioned services, eligibility is a question for the ICB, and the ten assessment areas apply either way. Where DCB0160 does apply, the clinical safety officer must be a senior clinician, hold current registration with aprofessional body such as the General Medical Council or the Nursing and Midwifery Council, and have training in digital clinical safety and clinical risk management to practitioner level. The CQC notes that a practice without that expertise in house may seek it from the commissioning organisation, the primary care network or a third party provider.

The clinical safety officer owns the process defined in the standard, which the guidance describes as evaluating the evidence that clinical risks are mitigated or accepted, keeping the risk management documentation in order, maintaining the clinical safety case report, hazard log and clinical risk management plan, and organising hazard workshops. The CQC also distinguishes the two NHS standards cleanly: DCB0129 applies to the developer of the technology and DCB0160 to the adopter, so a supplier's compliance never discharges the practice's own.

The eligibility wording is worth reading before concluding it lets a practice off. Most general practice delivers NHS-commissioned services, the question of what counts as eligible is one for the ICB rather than the supplier, and the ten assessment areas set out above apply to the practice's use of AI whatever the answer on DCB0160 turns out to be. Procurement, governance and human oversight are assessed either way.

Telling them is the requirement, and explicit consent is a separate question. The CQC states that the type of consent needed depends on the technology and its intended use, and that because AI technologies are new a practice does need to tell people it is using them. Its wording is that this is about being transparent and allowing people to object, rather than asking for explicit consent. The same guidance calls it essential that practices offer a non-digital route to access care, so a patient who declines the automated route still has to be able to reach the practice.

The worked example in the guidance concerns AI scribes, where the CQC says a practice does not need explicit consent to use one for tasks delivering individual care, and may rely on implied consent under the common law duty of confidentiality, while still needing to tell patients they are in use. Transparency carries the obligation. On human oversight the guidance is direct in requiring a practice to demonstrate that AI is being used as a support tool, with the CQC adding that this is never a replacement for human oversight.

What a practice can honestly claim

A practice can say its AI tool was procured against DCB0160 and DTAC, that a named clinical safety officer owns the hazard log, that oversight is evidenced in audit, that patients are told, and that a non-digital route remains open. That set of claims is checkable and it maps onto what the CQC says it will look for. A claim that the CQC approves of AI receptionists is not available to anyone, and a supplier offering it is describing a document that does not exist.

Where that leaves the telephone is a matter of scope. A system that answers, identifies itself, takes a name and a number, books into the appointment book against rules the practice set, and moves anything clinical to a person, is doing administrative work the guidance already recognises in other forms. The rules on regulated AI intake draws the same boundary across four markets, and how an AI employee is scoped and governed on our side is on how we work.

Where this leads

The branch as we build it for private GP clinics, with health-screen and results-review recalls tracked and booked.

Or run your own figures and see what the enquiries you miss are worth.

Written and published by

7 Minds Systems

The architecture is not improvised. It comes from KOVA Intelligence, the private institutional trading-intelligence platform our founder built, where eight cooperating engines work as specialist parts under a governance layer that holds final authority. 7 Minds Systems applies the same principle to your business: a department of cooperating AI agents that hand work between each other and to your people, with a named person in command, not a single bot bolted to a page.

We run this system inside our own group of operating companies. 7 Minds Systems holds no certificate, report or badge under Cyber Essentials, ISO 27001 or SOC 2 Type II, and the security page sets out what we do and do not hold.

Before you go

See the enquiries your field tends to lose.

Tell us the work you do and we will send the estimate written against it, including the hours where enquiries in your field usually go unanswered. One email, no sequence.

We use your address to send that one estimate, never share it, and delete it on request. Read the privacy policy.

See what this is worth to your business.

We scope the role, the questions it asks, and the point it hands a person the work.

Thirty minutes, no pitch. You leave knowing which enquiries the role would answer and where it would hand your team the work.

Book a strategy call

Thirty minutes. A clear plan.

Thirty minutes on the enquiries you are losing after hours, what catching them is worth, and what the role would cost to run.

Book a thirty-minute call

Pick a time straight from the diary. If you would rather write first, email us and a person replies, usually the same working day.