AI Ethics and Governance in Adult Social Care
AI is being deployed across health and social care at pace, but the UK does not currently have a single, AI-specific regulatory framework, and the existing frameworks were not designed specifically with these tools in mind. In this session from the Connected Health & Care Summit 2026, Stewart Duffy, health technology and regulatory advisor at Weightmans, maps the full legal and governance landscape that organisations must navigate before, during and after deploying AI, covering data protection, medical device regulation, CQC requirements, cybersecurity, professional accountability and the critical question of where liability sits when things go wrong.
Watch Stewart Duffy of Weightmans explain the full legal landscape for AI in health and social care, from automated decision-making rules through to medical device law, CQC requirements and the cybersecurity risks that LLMs and agentic AI introduce.
What the session covers and the key principles
This session provides a detailed overview of the regulatory and governance considerations for organisations deploying AI in health and social care. The key principles were:
- You cannot delegate accountability to the tools. Professional and organisational accountability remains with the humans who deploy and oversee them
- Solely automated decision-making using health data is prohibited under data protection law unless very narrow conditions are met
- "Meaningful human involvement” requires someone with the skills, knowledge and organisational authority to intervene in the decision and provide appropriate oversight of the process
- Software can be a medical device, and deploying an uncertified medical device is a criminal offence
- The UK has no AI-specific regulation, but existing frameworks covering professional conduct, CQC requirements, data protection and medical device law all apply directly
- Function creep is a foreseeable risk. AI scribes may be reviewed by clinicians on day one but not six months later


