Can GP practices use AI scribes for consultations?
Yes, provided the practice acts as the data controller it is: DPIA first, patients told, and every note verified by the GP.
Yes, GP practices can use AI scribes for consultations, and the duties that come with them land on the practice itself. A GP practice is an independent contractor and a data controller in its own right, so the data protection impact assessment, the lawful basis analysis, the patient notice and the vendor contract are the practice's responsibility, not an integrated care board's or a trust's. The scribe may draft the note; only the clinician can make the record.
The question matters in 2026 because ambient scribes are the fastest-spreading AI in primary care. Documentation burden is the sharpest pain point general practice has, and a scribe that listens to the consultation and drafts the note attacks it directly. In many practices adoption is running ahead of governance, and that gap is where the risk lives.
Who is responsible when a practice adopts an AI scribe?
The practice. Hospital deployments of ambient voice technology sit inside trust governance structures, and medical device classification for these products is a separate question covered elsewhere; the duties described here apply whatever the classification. As controller, the practice must complete a DPIA before deployment, identify its lawful basis and its special category condition for processing health data, tell patients what is happening, and hold a contract with the vendor that states exactly where the data goes. None of it can be delegated upwards, and none of it transfers to the vendor.
What does national guidance expect?
National guidance on ambient voice technologies exists and has been evolving as adoption grows. Characterised broadly, it sets expectations around information governance, clinical safety and data protection: know what the product does with audio, assess it before deployment, keep the clinician responsible for the record, and be able to show the work. Practices should check the current version before deploying, because expectations have tightened rather than loosened, and a deployment assessed against last year's guidance may not meet this year's.
Does the patient have to be told, and can they decline?
Yes and yes. Recording a consultation processes special category health data of the patient, and of the clinician, whose speech is captured too. The patient should be told before recording starts, in terms a person under stress can absorb, and given a genuine chance to decline. Declining must not degrade the consultation: the fallback is the clinician taking notes, exactly as before. A poster in the waiting room is not consent, and a privacy notice on a website nobody reads is not notice. The practical standard is a short spoken explanation and an easy no.
Where do the audio and the transcript go?
With a cloud scribe, out of the building. Before signing anything, a practice should hold written answers to five questions:
- Where are the audio and the transcript processed, and in which jurisdiction?
- How long does the vendor retain them, and can the practice set retention to zero?
- Are recordings or transcripts used to train the vendor's models?
- Which sub-processors touch the data?
- What is deleted when the contract ends, and how is deletion evidenced?
A vendor that cannot answer these in writing is telling the practice something important.
What should enter the GP record?
Only what the clinician has verified. A scribe's draft is a draft: it can mishear a negative, compress a nuance, or insert a plausible phrase the patient never said. The GP must read the note before it becomes the record, because errors in a medical record persist, propagate into referrals and repeat prescribing, and surface years later in complaints and claims. Verification is not a formality to click through; it is the control the entire deployment rests on.
What about third parties in the room?
Consultations are not always two people. A parent answers for a child, a carer speaks for a patient, an interpreter renders both sides. A scribe captures all of it, so the notice and the processing analysis must cover people who are not the patient. Some moments justify not recording at all: safeguarding conversations, disclosures of domestic abuse, or a patient asking to speak off the record. The clinician needs a way to pause capture instantly, and the whole team needs to know it exists.
What changes when the scribe runs inside the practice?
The hardest questions dissolve. Transcription and summarisation running on hardware inside the practice boundary answer the question of where the audio goes with nowhere: nothing leaves, so there is no vendor retention, no training reuse and no jurisdiction analysis. On Mickai, a Sovereign Intelligence Operating System that runs offline on operator-owned hardware, every action is sealed to a post-quantum signed audit ledger, so the practice can evidence exactly what was captured and exactly what the clinician approved into the notes. Inference is selectable between CPU and GPU, which matters where the hardware is a workstation rather than a server room. Clinical responsibility stays precisely where it always was: with the GP who signs the record.
“The scribe drafts the note; the GP makes the record.”
How the architecture behind a practice-owned deployment fits together is set out at /sovereign-ai, and the film at /film shows the interface in operation.
Frequently asked questions
Do I need a DPIA before using an AI scribe in my GP practice?
Yes. Recording consultations processes special category health data with novel technology, which is exactly the territory where a data protection impact assessment is expected before deployment. The DPIA should be completed and its mitigations in place before the first consultation is recorded, not retrofitted afterwards.
Can a patient refuse to be recorded, and what happens then?
Yes, and refusal must cost the patient nothing. The consultation proceeds with the clinician taking notes manually, as before. Practices should log the preference so the patient is not asked to object again at every appointment, and staff should offer the choice neutrally rather than presenting recording as a default to be argued against.
Is the audio recording part of the medical record?
That is a decision the practice must take and document. The verified note is the record; whether audio and transcripts are retained at all, for how long and for what purpose belongs in the DPIA and the privacy notice. A defensible default is deletion once the clinician has approved the note, because retained audio is a growing store of special category data with no clinical purpose.
What if the scribe gets a drug name or dose wrong?
This is why verification is the load-bearing control. The clinician must read the draft against what actually happened before approving it, and dosages, allergies and negative findings deserve particular attention because transcription errors there carry clinical consequences. A deployment with a sealed record can show what the scribe captured and what the clinician approved, which protects the GP as much as the patient.
Can we run an AI scribe without sending audio to the cloud?
Yes. Speech recognition and summarisation at consultation quality run on hardware a practice can own, inside its own walls. That removes vendor retention, training reuse and offshore processing from the analysis entirely, and it is the deployment model we build Mickai around: the audio never leaves the building, and the record of what happened is sealed and verifiable.