Safe AI in social care means AI that never makes a clinical call on someone's behalf, that keeps every decision traceable back to evidence, that keeps data under UK control, and that fits into services already built to run safely. Anything less isn't safe, no matter what a provider’s marketing might say.
We hear the same question from every provider looking at AI tools: is this safe for my service, my staff and the people I support? It's the right question. Here's how we answer it, in the same amount of detail we'd want from any supplier before we trusted them with our own data.
We hold ourselves to four pillars:
Our AI runs entirely within the AWS environment that already hosts your data, protected by the same encryption in transit and at rest, individual access controls, and full audit logging as the rest of Log my Care. Turning on AI doesn't introduce a new supplier, sub-processor, or international transfer for you to assess. There's no data processing agreement to sign, because there's no third party added to the chain. You remain the data controller. We remain your processor, exactly as we already are.
Care records hold health information, which counts as special category data under UK GDPR, and it's treated with the highest level of protection whether AI touches it or not. The AI features themselves run on AWS Bedrock, which doesn't store your prompts or outputs and doesn't share them with model providers. Your data is never used to train AI models.
Compare that to typing information into a general-purpose AI tool, or using a care platform that hasn't been through the same NHS assessment and assurance we have. With these tools, a document you paste in can end up training the model behind it. That's a fundamentally different arrangement to what happens inside Log my Care, where your data stays inside the same ring-fenced, protected environment it's always lived in.
Our AI is built to stay out of clinical decision making on purpose. It surfaces what's already in your records, patterns your team created and could easily miss under time pressure, and turns that into an insight. What it never does is tell you what to do about it.
Keeping humans in the loop is critical to safe AI. A tool that says "this person's fluid intake has dropped over the past week" is doing something useful: showing you something that would otherwise take time and manual review to spot, or that you might not catch at all. An AI tool that says "you should now increase their fluid intake to X" has crossed into clinical decision making, and that's a judgement for your care experts to make, not a model.
Every AI feature we build is designed around a boundary where a human always makes the final call. AI does the noticing; your team does the deciding.
We're hearing the same story from providers across the sector: services running into trouble at inspection because staff were using general AI tools without any policy or oversight in place, asking a chatbot what to do about a resident and treating the answer as guidance. Without governance, nobody can say who approved that, what it was based on, or why.
Compliance safe means the opposite of a black box. Whether an insight came from a member of your team or from AI, you need to be able to show your working: what happened, why, and on what evidence. That's what an inspector is actually asking for when they ask how you reached a conclusion.
This is where our AI-powered Care Plan Audits does the heavy lifting. It reviews every care plan against the depth, risk and consistency an inspector would expect to see, not a sample, and shows exactly which findings need attention and why. Nothing about how it reached a finding is hidden, so when you're asked to evidence quality, you can.
Operationally safe is about where and how AI is allowed to run. Used inside your DSCR, AI sits within a platform that's already been assessed and assured, including by the NHS. Used outside it, on general tools with no oversight, you're relying on individual judgement alone with no policy behind it.
That's the reality of the choice that providers are faced with when deciding where AI enters their service: inside a system built and assured for care, or bolted onto tools that were never designed with CQC, safeguarding or data protection requirements in mind. Few generic AI tools on the market today can back up that level of assurance, and that's a problem.
Every provider should be asking their tech partners some hard questions: where does your data live, is a human always in the loop, and can you evidence every AI-driven decision if a regulator asks? Don't just take a supplier's word for the answers.
That's why we're a signatory to the Digital Care Hub's pledge on the responsible use of generative AI in social care, a public commitment that sits outside our own marketing. It's also why we're watching CQC's own position on AI in health and social care closely as it develops, and building to meet it rather than catch up to it later.
Safe AI isn't a feature you switch on. It's a set of boundaries you hold to on every release, and a set of questions you should be comfortable answering in public. These are ours.
You can read our full manifesto on how we’re approaching AI development at Log my Care, or discover how our AI-powered Care Plan Audits can help you get a complete view of your care planning in minutes.