There is a category of risk in care settings that most registered managers are aware of but rarely name directly. It sits in the gap between what the organisation has approved and what staff are actually doing — and it is growing quietly, shift by shift, on the phones and personal devices of care workers across the country.
Shadow AI is the use of artificial intelligence tools by staff without organisational knowledge, approval, or governance. It is not a new phenomenon — shadow IT, the use of unapproved software generally, has been a feature of workplace technology for decades. What is new is the scale, the accessibility, and the consequences specific to AI tools in care settings where documentation carries regulatory weight and confidentiality obligations are absolute.
What Shadow AI Looks Like in Practice
A care worker finishing a long shift needs to write up a care note but is tired and short of time. They type a brief summary of what happened into ChatGPT or a similar tool and ask it to produce a care note they can paste into the electronic care record. They do not tell anyone. The note is filed.
A team leader wants to draft a response to a complaint but is uncertain how to phrase it. They describe the situation to an AI chatbot and use the suggested text, lightly edited, as the basis for the formal response. No manager is aware this happened.
A registered manager, under pressure to update a policy before an upcoming inspection, asks a general-purpose AI tool to draft a safeguarding policy. They review it briefly, make a few changes, and file it as the service's own policy. It has never been assessed against CQC's specific requirements for the service type or the regulated activities being delivered.
None of these individuals are acting with malicious intent. Each is using a tool that is genuinely available, genuinely capable, and genuinely faster than the alternative. Each is making a judgment, implicitly, that the tool is good enough for the purpose. And in each case, the organisation has no record that AI was involved, no ability to assess whether the output was accurate, and no governance framework that would allow it to demonstrate human oversight of the process to a CQC inspector.
Why Care Settings Are Particularly Vulnerable
Shadow AI is a workplace phenomenon that affects every sector, but care settings face specific vulnerabilities that make its consequences more serious than in most other environments.
The first is the sensitivity of the information being processed. Care records contain detailed personal and clinical information about vulnerable adults and children — diagnoses, medication regimes, safeguarding histories, financial circumstances, family relationships. When a care worker pastes this information into a general-purpose AI tool, they are transmitting it to a third-party system whose data handling, storage, and use policies they have almost certainly never read. Most major AI tools use inputs for model training unless users specifically opt out — a process that requires deliberate action and is not the default. The ICO's enforcement action under the Better Records Together campaign and the broader UK GDPR framework make clear that care providers bear responsibility for how personal data about service users is processed, including when that processing is carried out by individual staff members using unapproved tools.
The second vulnerability is the evidential status of care documentation. Care records are not simply administrative artefacts. They are evidence — of the care delivered, the decisions made, the risks identified and managed, the observations that led to escalation or to continuation of existing care. When care records are generated by an AI tool rather than by the professional who delivered the care, the record no longer accurately represents what the professional observed, decided, and did. It represents what the AI produced from a brief description. A CQC inspector who asks a care worker about a specific entry in a care record and receives an answer inconsistent with what is documented has found an evidentiary gap. If that gap exists because the entry was AI-generated from a summary rather than written by the person who delivered the care, the governance implications extend well beyond that individual entry.
The third vulnerability is the absence of organisational knowledge. Shadow AI, by definition, operates outside the organisation's awareness. A registered manager who does not know that staff are using AI tools cannot assess the risk, cannot establish governance, and cannot demonstrate human oversight. At inspection, the inability to demonstrate that AI outputs are reviewed and verified before entering care records is a governance failure regardless of whether the outputs themselves are accurate. The Kevin Humphreys case, shared at the South East Social Care Alliance conference and examined in our article on AI governance in care settings, made this concrete: a care provider received an Inadequate rating partly because AI tools were being used without governance, not because the care itself was poor.
The Tools Most Commonly in Use
Understanding which tools are most likely to be in shadow use helps registered managers have more specific conversations with their teams.
General-purpose large language models — ChatGPT, Google Gemini, Microsoft Copilot accessed through personal Microsoft accounts, and similar tools — are the most accessible and most widely used. They are free or low-cost, available on any device with internet access, capable of producing plausible care-related text from brief prompts, and used by millions of people in their personal lives. The barrier to using them for work purposes is essentially zero.
Translation and transcription tools are also increasingly in shadow use, particularly in settings with multilingual workforces. A care worker who uses a consumer-grade transcription app to convert voice notes into written records, or a translation tool to communicate with a service user whose first language is not English, may not consider this AI use at all — but the same data transmission and accuracy concerns apply.
Document drafting tools, presentation generators, and summary tools are used by managers and team leaders as much as frontline staff. A deputy manager who uses a general-purpose AI tool to draft a governance report or summarise an incident for a management meeting is engaging in shadow AI use with governance implications that may not be immediately obvious.
How to Find Out Whether Shadow AI Is Already Happening
Most registered managers who ask themselves honestly whether shadow AI is occurring in their service already know the answer is probably yes. What is harder is finding out specifically where, how, and with what consequences.
A brief, non-punitive conversation with staff — framed as the organisation wanting to understand how AI tools are being used so it can support staff appropriately rather than as an investigation into wrongdoing — will typically surface more information than any audit. Framing matters: if staff believe they will be disciplined for admitting AI use, they will not admit it. If they understand that the organisation wants to establish proper governance so they can use these tools safely, they are more likely to be open about current practice.
The questions worth asking in this conversation are simple: Do you ever use AI tools at work? What for? Which tools? What information do you put into them? Do you check the output before using it?
The answers will almost certainly reveal that shadow AI use is more widespread than the organisation realised, that it varies significantly by role and individual, and that most staff have not considered the data protection implications of what they are doing.
Moving From Shadow to Governed AI Use
The discovery that shadow AI is occurring in a service is not, in itself, a crisis. It is an opportunity to establish governance before a CQC inspector makes the same discovery.
The starting point is an AI systems register — a documented inventory of every AI tool in use across the service, approved or otherwise. Creating this register is the first step in the AI Impact Assessment process, and it typically produces findings that registered managers find genuinely surprising. Tools that no manager knew about, use cases that had never been formally considered, data transmission practices that carry real regulatory risk — all of these emerge from the process of simply asking, systematically, what is being used and for what.
The register then forms the basis for a set of governance decisions: which tools to approve for which purposes, under what conditions and with what oversight; which tools to prohibit because the data protection or accuracy risks cannot be managed; and what training staff need to use approved tools safely and within the organisation's governance framework.
An acceptable use standard makes the governance decisions operational — translating policy into the specific, practical guidance staff need to know what they can and cannot do, and under what conditions AI assistance is appropriate in their role.
The governance infrastructure does not need to be elaborate to be effective. A register, an assessment, a standard, and a process for reviewing AI outputs before they enter care records is the minimum viable governance framework. It is also the framework that demonstrates to a CQC inspector that the organisation understands the risk, has assessed it, and has managed it — which is precisely what the Well-led key question is designed to reveal.
Turn shadow AI into governed AI
The complete governance infrastructure in one pack
ReporticaAI's AI Governance Management Pack provides everything needed to manage AI use in CQC-regulated care settings — AI Systems Register, Risk Assessment, Acceptable Use Standard, Supplier Due Diligence, and seven further templates, all editable and aligned to the 2026 Single Assessment Framework.
The Window Before This Becomes a Regulatory Priority
CQC has not yet published specific guidance on AI use in care settings, and inspection findings specifically attributable to shadow AI remain rare in the public domain. The Kevin Humphreys case is documented. The regulatory direction is clearly toward greater scrutiny of AI governance in care settings. But the formal framework has not yet caught up with the operational reality.
This creates a window — not to delay action, but to take action before the pressure is regulatory rather than voluntary. The care providers who establish AI governance now, before it is required, will be in a fundamentally different position at their next inspection from those who are still developing a governance response after an inspector has identified the gap.
Shadow AI is already in care homes. The question is not whether to address it but when — and whether that timing is chosen by the registered manager or by a CQC inspector.
Related articles
- AI Governance in Care Settings: What CQC Is Already Looking For
- The AI Impact Assessment for Care Providers
- AI Governance Management Pack
This article is published in accordance with PAIDS™ (Professional AI Documentation Standards) — well-sourced, thoroughly researched, and defensible with verifiable data.