Can veterinary practices use AI on clinical records?
Yes, and it is a clean example of sovereignty as good practice rather than a compliance requirement.
Yes, veterinary practices can use AI on clinical records, and the sector offers an honest twist on the usual regulated-data story: the animal's own clinical data is not personal data under UK GDPR, because the definition applies to identifiable living individuals, not animals. But everything around that clinical data is personal or commercially sensitive: client names, addresses, payment details, insurance claim information, and sometimes safeguarding-adjacent context such as an aggression history or a welfare complaint. On the farm and breeder side, herd data can be competitively sensitive commercial information in its own right.
The question matters because veterinary practices sit at an interesting point in the sovereignty conversation: no sector statute specifically compels it here, unlike healthcare or financial services, which makes the case for sovereign AI a genuinely practical one rather than a box-ticking exercise, and that is worth demonstrating clearly.
Why is the animal's own clinical data not personal data?
Because UK GDPR's definition of personal data applies to information relating to an identified or identifiable living individual, and an animal is not a person under that definition. A record of a dog's vaccination history or a cat's blood test result, considered purely as clinical content about the animal, sits outside data protection law's core scope in a way a human patient's equivalent record never would.
So what data around the clinical record does UK GDPR actually reach?
The client-side information attached to almost every record: the owner's name, address and contact details, payment and insurance information, and any notes that touch a person rather than the animal, such as a recorded concern about how an animal has been treated at home. A veterinary practice handling AI on clinical records needs to treat the human-facing layer with the same UK GDPR discipline as any other business handling customer data, even though the animal's clinical content itself sits outside the definition.
What confidentiality duty applies beyond data protection law?
RCVS professional conduct expectations include client confidentiality as a core professional standard; this article characterises that expectation rather than quoting specific code numbers, and practices should confirm current wording directly with RCVS guidance. That duty applies regardless of whether the underlying content is technically personal data, because it protects the client relationship, not merely a data protection category.
Why is farm and herd data especially sensitive?
Because it can be commercially competitive information in its own right. A farm's herd health records, productivity data and treatment history are not just clinical notes, they are business-sensitive material a competitor, a buyer, or an insurer could use to the farm's disadvantage if it leaked. Corporate consolidation across the sector, with many practices now sitting inside groups, adds complexity to where that data actually flows once a practice is no longer independently owned.
What can AI genuinely help a veterinary practice with?
Consultation note drafting from a vet's spoken dictation, discharge instructions for owners, insurance claim narratives that need to be accurate and consistent, lab result summaries, and reminder or triage communications for routine client contact. As with every regulated sector in this series, the output is a draft the clinician reviews; clinical judgement stays with the vet.
Why call this sovereignty as good practice rather than compliance?
Because no sector statute forces the architecture here the way sector-specific rules do elsewhere. The drivers are UK GDPR on the client side, commercial confidentiality on the farm and breeder side, client trust generally, and the same verify-before-it-becomes-the-record discipline that applies in human medicine even without an equivalent statutory push. A practice that adopts practice-owned AI here is doing so because it is the sound choice, which is a cleaner proof point than a sector where the law leaves no alternative.
What does a right-sized setup look like for a veterinary practice?
CPU-selectable inference on modest hardware physically inside the practice, client data that never leaves that boundary, and a sealed record of what the AI touched and what the clinician approved. This scales to the size of the practice rather than assuming enterprise infrastructure, which is exactly why veterinary work is a useful example that the pattern generalises well beyond regulated giants.
“No statute forces this here, which is exactly what makes it the clearest proof that sovereignty is simply good practice.”
How CPU-selectable inference on modest hardware, with client data that never leaves the practice, is set out at /sovereign-ai, and the film at /film shows the interface in operation.
Frequently asked questions
Is an animal's medical record covered by UK GDPR?
The clinical content itself, considered purely as information about the animal, is not personal data because UK GDPR applies to identifiable living individuals, not animals. The client information attached to the record, names, contact details, payment data, is personal data and is fully covered.
Does RCVS require veterinary practices to use sovereign AI?
No specific requirement of that kind is asserted here. RCVS professional conduct expectations include client confidentiality as a general standard, and practices should confirm current specific guidance directly with RCVS rather than rely on a secondary characterisation for compliance purposes.
Is farm herd data more sensitive than an individual pet's record?
In a different way, yes: herd data can carry commercial competitive value for the farm business, whereas an individual pet's clinical data mainly carries client confidentiality and trust considerations. Both deserve careful handling, for different underlying reasons.
Can a small independent veterinary practice realistically run AI on its own hardware?
Yes. Sovereignty scales down to modest hardware running locally with CPU-selectable inference, which does not require the infrastructure scale of a large hospital group, making it accessible to a small independent practice.
Who is responsible if AI-drafted discharge instructions contain an error?
The vet who reviews and issues the instructions remains clinically responsible, exactly as with instructions drafted by a veterinary nurse. AI produces a draft; clinical review is what makes it reliable enough for the owner to rely on.
Does a corporate-owned practice group change how AI on clinical records should be handled?
The same confidentiality and data protection principles apply, though a group structure adds complexity around where data flows between practices under common ownership, which is worth mapping explicitly rather than assuming group membership automatically simplifies or complicates the picture.