No rule stops a GP practice putting an AI receptionist on its phone line. What the AI is for decides how much follows. An AI receptionist for a GP practice that only books, takes requests and routes calls is, in the MHRA's words, "unlikely to be considered a medical device". One that sorts callers by urgency is on the other side of that line, and so is the practice's paperwork.
The phone is still where most of the pressure lands. In the 2026 GP Patient Survey, 56.9% of patients said it was easy to contact their practice by phone, up from 52.9% in 2025 (Ipsos, 9 July 2026, 654,714 responses). Better, but more than four in ten still did not find it easy. That gap is why practice managers are being pitched AI. This post covers what to check before signing.
- Intended purpose decides device status. MHRA guidance says software that books appointments or requests prescriptions is unlikely to be a medical device "if it only has an administrative function". Software that filters by red flag or severity is likely to be one.
- The practice has its own duty, whatever the vendor holds. DCB0160 applies to the organisation deploying a health IT system, and it requires the practice to name a Clinical Safety Officer.
- DTAC is applied by the buyer. NHS England replaced the DTAC form on 24 February 2026, and the old form should not be used from 6 April 2026. Ask who assessed the product, and on which form.
- Expect to write a DPIA. The ICO says AI use will "in the vast majority of cases" trigger the legal requirement for one.
- The 2026/27 contract bans asking patients to call back another day. An AI that tells a caller to ring tomorrow breaks the contract on the practice's behalf.
Where the line sits on a single call
| What the AI does on the call | Likely MHRA position | What follows for the practice |
|---|---|---|
| AdministrativeAnswers, takes name, date of birth and the reason in the caller's own words, books a routine slot | Administrative. "Unlikely to be considered a medical device" | DCB0160 hazard log, DPIA, data processing agreement |
| AdministrativeTakes a repeat prescription request for the practice to process | Administrative. MHRA names "request a prescription" in its example | As above |
| GreyReads a fixed, practice-written instruction (for example, to call 999) when a caller uses listed words | Grey. MHRA says software that "only signposts" to care is unlikely to be a device, but has not ruled on phone agents | Record the reasoning in the hazard log; Clinical Safety Officer signs off the wording |
| Likely deviceScores or ranks callers by urgency, or filters by red flag or severity | Likely a medical device | MHRA registration by the manufacturer, plus everything above |
| Device, higher classSuggests what condition the caller might have | Medical device; possibly Class IIa if it "allow[s] direct diagnosis" | As above, at a higher class |
Is an AI receptionist a medical device?
An AI receptionist is a medical device only if its intended purpose is medical. The MHRA's software guidance puts it plainly: "A medical purpose is determined by what the manufacturer states in the device's labelling, instructions for use and any promotional materials."
Read the last three words again. A vendor's website, sales deck and case studies are evidence of intended purpose. If the marketing says the product "triages", that word matters. The MHRA's appendix on symptom checkers lists "Triage" among the terms that indicate a product may be a device.
The same guidance draws the administrative boundary: "Software that is used to book an appointment, request a prescription or have a virtual consultation is also unlikely to be considered a medical device if it only has an administrative function." On the other side, the appendix says software that "offers filters by red flag/severity/probability of a match" is likely to be a device. Symptom-checker software of this kind is typically Class I, and moves to Class IIa where it would "allow direct diagnosis".
There is a catch in the dates. The software guidance the practice is applying is version 1.10f, last revised in July 2023. It was written for apps. Nothing the MHRA has published so far addresses AI phone agents by name.
Two things published this summer point the same way:
- 29 July 2026. The MHRA clarified the status of ambient voice technology. Products "intended solely for transcription, summarising of clinical conversations, drafting letters, or suggesting clinical codes for a clinician to review are not regulated as medical devices". Products that "support diagnosis, treatment or prevention, or that take automated action such as placing orders without clinician review, are regulated as medical devices". Swap "ambient scribe" for "phone agent" and the test carries over: capture and hand to a human is one thing, acting on its own clinical judgement is another.
- September 2026. The National Commission into the Regulation of AI in Healthcare said products for "administrative purposes" are among those "likely not medical devices within the existing definition", and recommended the MHRA clarify "which types of software and AI-enabled products are, and are not, medical devices". That is a recommendation. It is not yet guidance.
Where does booking end and triage begin?
Urgency is where it gets difficult. A purely administrative AI still has to do something when a caller says their child is struggling to breathe. The 2025/26 GP contract made the same point about online tools, which must stay open during core hours "subject to necessary safeguards in place to avoid urgent clinical requests erroneously submitted online" (NHS England). The phone needs an equivalent.
UK vendors have landed in three different places on this, going by their own public pages in September 2026:
Offers to submit triage requests into the practice's total triage system.
Describes the agent as built to "recognise urgent situations and hand the call to your team or direct the patient to 999 or 111 where appropriate, rather than attempting to triage emergencies itself".
States that it "does not provide clinical advice or triage".
None of these is automatically wrong. The difference between them is a regulatory decision, and the practice should see the reasoning behind it before any demo, because the same MHRA test will be applied to what the product actually does on a live call.
For a practice, the workable position is this. The practice writes the escalation wording. The agent reads it word for word and puts the call through to a person. No score, no ranking, no suggestion of what might be wrong. The Clinical Safety Officer reviews that wording and records it in the hazard log. Whether that design keeps a product outside MHRA scope has not been tested by the MHRA for phone agents, so write down why you think it does, and revisit it when the guidance changes.
Not yet tested by the MHRA for phone agents. Write down why you think this design stays outside MHRA scope, and revisit it when the guidance changes.
Does an AI receptionist for a GP practice need DCB0129 and DCB0160?
Yes, in NHS general practice, and the second one falls on the practice. Both standards are "published under section 250 of the Health and Social Care Act 2012":
- DCB0129 applies to "organisations that are responsible for the development and maintenance of Health IT Systems". That is the vendor.
- DCB0160 applies to "health organisations that are responsible for the deployment, use, maintenance or decommissioning of Health IT Systems". That is the practice.
- Clinical safety case
- Vendor hazard log
- Names its own Clinical Safety Officer
- Practice hazard log
- Names a Clinical Safety Officer: a senior clinician with current GMC or NMC registration
- In most practices, a GP partner or a registered nurse, not the practice manager
If the vendor has no DCB0129 safety case, the CSO does more of the work, and may reasonably decide not to.
The definition of a Health IT System is wide: a "Product used to provide electronic information for health or social care purposes" (NHS England Digital). It does not carve out administrative systems. An AI that writes patient requests into the practice's records is squarely in it, device or not.
Two practical consequences. First, NHS England's guidance says both standards "require you nominate an individual to be the Clinical Safety Officer (CSO)", and "The CSO must be a senior clinician and have a current registration with a professional body such as the General Medical Council (GMC) or Nursing and Midwifery Council (NMC)" (NHS England). In most practices that means a GP partner or a registered nurse, not the practice manager. Second, the practice's hazard log leans on the vendor's. If the vendor has no DCB0129 safety case, the CSO does more of the work, and may reasonably decide not to.
These standards are also moving. NHS England's review ran a consultation from 29 June to 11 September 2026 (NHS England engagement hub). Its supporting paper says AI, machine learning and ambient voice technologies "present novel risk profiles requiring specific governance frameworks that current standards do not adequately address", and that "A risk-based, tiered approach, similar to medical device classification, was widely supported" (NHS England). Expect the rules for AI tools to get more specific, not less.
What DTAC does and does not tell you
DTAC, the Digital Technology Assessment Criteria, is something the buyer applies. NHS England's wording: "Care commissioners and providers of health and social care services should apply DTAC to any DHT products they are considering to use." It covers "clinical safety, data protection, technical security, interoperability, usability and accessibility" (NHS England Transformation Directorate).
So when a vendor page says a product is DTAC "certified" or "compliant", three questions sort out what that means:
- Who carried out the assessment: an NHS organisation, a consultant, or the vendor itself?
- When?
- On which form? NHS England introduced an updated form on 24 February 2026 and says "The previous version of the DTAC form should not be used from 6 April 2026 onwards."
DTAC does not replace the practice's own DCB0160 work.
DTAC also does not replace the practice's own DCB0160 work. It asks whether the manufacturer has done its clinical safety homework. It does not do the practice's.
Data: the DPIA, the DSPT and special category data
Anything a patient says about their health on a call is special category data under UK GDPR Article 9, and an AI receptionist records, transcribes and stores it. The ICO's guidance on AI says: "In the vast majority of cases, the use of AI will involve a type of processing likely to result in a high risk to individuals' rights and freedoms, and will therefore trigger the legal requirement for you to undertake a DPIA" (ICO). The same page notes the guidance is under review following the Data (Use and Access) Act, so check it again before you sign off.
The practice is the controller. The vendor is a processor. For the DPIA you need the vendor to tell you, in writing:
- where call audio and transcripts are stored, and in which country;
- which sub-processors handle the data (the speech-to-text provider, the language model provider, the telephony carrier);
- how long recordings and transcripts are kept, and whether you can change that;
- whether any of it is used to train models.
Then there is the Data Security and Protection Toolkit. "All organisations that have access to NHS patient data and systems must use this toolkit" (DSPT), so ask whether the vendor has its own submission, and make sure the new supplier is reflected in yours. A vendor that cannot answer the list above in a page is not ready for a GP practice.
What the 2026/27 GP contract means for an AI on the phone line
Three changes in the 2026/27 contract bear directly on an AI receptionist.
No "call back tomorrow". Practices "must not ask patients to call back another day". If the diary is full, the AI has to capture the request and hand it to the practice's own process. Ask to see the exact words the agent uses when there are no appointments left. If that script sends callers away, it breaks the contract in the practice's name.
Parity between phone and online. Online consultation systems "must not cap the number of requests that can be submitted during core hours". The direction is plain: a request should be accepted whichever route the patient takes.
Measured waiting times. The access data includes "call waiting time between 8am and 10am" and during core hours. Ask the vendor how calls answered by the AI appear in your cloud-based telephony data, before those numbers start appearing in reports about your practice.
What will CQC ask?
CQC has published a GP mythbuster on AI. The operative line: "Any AI tools must have been procured in line with relevant evidence and regulatory standards (DCB0160, DTAC, MHRA registration (if applicable)." It also says AI should be used as "a support tool", and is not "a replacement for human oversight".
Inspectors say their assessments "will focus on your systems and processes to ensure the safe and compliant use of AI": procurement and governance, risk assessment, human oversight, learning from errors, data protection, staff training, equity of access and bias. In practice that means a folder: the DCB0160 hazard log, the DPIA, the DTAC assessment, the vendor's intended purpose statement, and a record of who reviews the agent's calls and how often.
- The DCB0160 hazard log
- The DPIA
- The DTAC assessment
- The vendor's intended purpose statement
- A record of who reviews the agent's calls and how often
Does any of this apply to private clinics?
Some of it applies to every clinic, and some depends on NHS funding.
| Requirement | NHS GP practice | Private clinic (no NHS contract) |
|---|---|---|
| MHRA medical device rules | Yes | Yes. Device status depends on what the product does, not who pays |
| UK GDPR, Article 9, DPIA | Yes | Yes |
| DCB0160 and a Clinical Safety Officer | Yes | Less clear. Section 250, as amended, allows information standards to apply to CQC-registered providers, but the standards are written for "health organisations". Treat DCB0160 as the baseline either way |
| DTAC | Expected by CQC for GP services | Not required, but a sensible buying checklist |
| DSPT | Yes | Only if the clinic has access to NHS patient data and systems |
| GP contract access rules | Yes | No |
For a private clinic the short version is: MHRA and UK GDPR always, clinical safety documentation as good practice, and the NHS-specific toolkits where NHS work or NHS data is involved.
How to read the claims on vendor pages
A few phrases carry more weight than they should:
Where Magixis sits
Magixis is built on the administrative side of this line. The agent asks no clinical question, offers no assessment, says nothing about medication, and does not tell a caller where to seek treatment on its own judgement. It captures the request in the caller's own words, books where the practice allows it, and writes the call into the practice's records. When a caller uses words the practice has listed, it reads the practice's own wording and puts the call through to the person the practice has chosen.
We hold no MHRA registration and no clinical safety or healthcare regulatory certification today. For an NHS practice, that means your Clinical Safety Officer would carry the DCB0160 assessment without a manufacturer's DCB0129 safety case to lean on. Some practices will reasonably decide that is too much work. We would rather you knew that before a demo than after one. The data side (UK and EU storage only, named sub-processors, retention periods) is set out on our trust page, and how it works for practices is on the AI receptionist for medical practices page.
Seven questions to put to any vendor, in writing
- What is your intended purpose statement, word for word? Does any of your marketing use "triage", "prioritise" or "urgency"?
- Are you registered with the MHRA as a medical device? If so, which class, and what does the registration cover? If not, why not, given what the agent does with urgent callers?
- Can we see your DCB0129 clinical safety case and hazard log, and who is your Clinical Safety Officer?
- Who assessed you against DTAC, when, and on which version of the form?
- What exactly does the agent say when there are no appointments left?
- How do AI-answered calls appear in our cloud-based telephony data, including waiting time between 8am and 10am?
- Where are audio and transcripts stored, which sub-processors touch them, for how long, and will you sign a data processing agreement and support our DPIA and DSPT submission?
Get the answers on paper before you look at a demo. A demo shows the best call. The answers show what happens on the worst one.
Dates that will date this post
MHRA software and apps guidance, v1.10f. Still the current version
Online consultation tools open throughout core hours, with urgent-request safeguards
New DTAC form; old form not to be used from 6 April 2026
No "call back another day"; no capping of online requests; waiting-time metrics
2026 GP Patient Survey: 56.9% found phone contact easy
MHRA clarifies ambient voice technology status
DCB0129/DCB0160 review consultation closes
WatchNational Commission into the Regulation of AI in Healthcare reports
WatchMarked "watch": the DCB review and the MHRA's response to the National Commission are the two most likely to change this post.
Every source in this post was checked on 25 September 2026. The DCB review and the MHRA's response to the National Commission are the two most likely to change it, and we will update this page when they land.
FAQ
Is it legal for a GP practice to use an AI receptionist?
Yes. No rule prohibits it. The practice must meet its existing duties: DCB0160 clinical risk management with a named Clinical Safety Officer, a DPIA under UK GDPR, the GP contract's access rules, and MHRA rules if the product has a medical purpose. CQC expects AI tools to be procured in line with DCB0160, DTAC and MHRA registration where applicable.
Is an AI receptionist a medical device?
It depends on its intended purpose. MHRA guidance says software used to book appointments or request prescriptions is unlikely to be a medical device if it only has an administrative function. An AI receptionist that filters callers by red flag, severity or urgency, or suggests a likely condition, is likely to be a medical device.
Does a GP practice need a Clinical Safety Officer to use an AI receptionist?
In NHS general practice, yes. DCB0160 applies to the organisation deploying a health IT system, and NHS England says the standard requires a named Clinical Safety Officer who is a senior clinician with current GMC or NMC registration.
Can an AI receptionist triage patients?
Only a product regulated for that purpose should. Triage and urgency prioritisation are medical purposes under the MHRA's software guidance, which lists "triage" among the terms that indicate a medical device. An administrative AI receptionist should pass urgent callers to a person using wording the practice has approved.
Is DTAC a certificate?
NHS England describes DTAC as criteria that care commissioners and providers "should apply" to digital health products they are considering. Ask any vendor claiming DTAC who carried out the assessment, when, and on which version of the form. The form changed on 24 February 2026.
Do private clinics need DCB0160?
The position is less explicit than for NHS practices. Section 250 of the Health and Social Care Act 2012 allows information standards to apply to CQC-registered providers, but DCB0160 is written for "health organisations". MHRA and UK GDPR duties apply to private clinics in full, and DCB0160 is a sensible baseline for any clinic.
- MHRA, Medical device stand-alone software including apps (including IVDMDs), v1.10f
- MHRA, Appendix 1: symptom checkers
- MHRA, MHRA clarifies regulatory status of ambient voice technologies used in the NHS, 29 July 2026
- National Commission into the Regulation of AI in Healthcare, Full report, September 2026
- NHS England Digital, DCB0160 standard
- NHS England Digital, DCB0129/DCB0160 terms and definitions
- NHS England, Digital clinical safety assurance
- NHS England, National review of DCB0129 and DCB0160: supporting information
- NHS England, Consultation: national review of DCB0129 and DCB0160
- NHS England Transformation Directorate, Digital Technology Assessment Criteria (DTAC)
- ICO, Accountability and governance implications of AI
- NHS England, Changes to the GP contract in 2025/26
- NHS England, Changes to the GP contract in 2026/27
- CQC, GP mythbuster 109: Artificial intelligence in GP services
- Ipsos, 2026 GP Patient Survey results released, 9 July 2026
- UK Government, Health and Social Care Act 2012, section 250