What NHS England says about AI receptionists (2026)

Can a GP practice put an AI on the phone? The medical-device line, DCB0129, DCB0160 and DTAC explained for practice managers, and what to ask a vendor.

"Can we put an AI on the phones?" is now a common question in general practice, and the answers online are almost entirely written by people selling one.

This is the version without a product attached: what the rules actually are, which duty is yours and which is the supplier's, and the questions that separate a serious vendor from a confident one.

The short answer

There is no rule against an AI answering a practice phone. There are conditions, and they turn almost entirely on what the AI does, not on what it is called.

NHS England's guidance on improving telephone journeys in general practice asks practices to map out any third-party products sitting on top of their core telephony system, and to understand the contracts behind them, before making changes. That is the starting point: know what is on your line.

The line that decides everything: booking or triage

This is the single most important distinction on this page, and most vendor material skates over it.

  • A tool that calculates, interprets, triages, or otherwise informs a clinical decision about an individual is likely a medical device under the UK Medical Devices Regulations 2002. That means MHRA registration and UKCA or CE marking, a substantial regulatory undertaking.
  • A tool used purely for scheduling administration is likely outside that.

The guidance is explicit that admin and operations tools must be designed and documented so their stated intended purpose does not meet the medical-device threshold.

Two practical consequences.

First, "AI receptionist" and "AI triage" are different products, however similar the marketing looks. If a tool decides that a caller describing chest pain should be seen today rather than next week, it is grading clinical urgency. That is triage, whatever the website calls it.

Second, documentation is not a shield. A product's intended purpose is what it is designed and stated to do, but if it demonstrably grades urgency in practice, a stated purpose will not undo that. Ask a vendor what happens when a caller volunteers a symptom. The answer tells you which product you are looking at.

DCB0129 is the supplier's duty. DCB0160 is yours.

These get used interchangeably and they are not the same obligation.

DCB0129 applies to the manufacturer. It is an NHS England information standard for clinical risk management, published under section 250 of the Health and Social Care Act 2012. It requires the supplier to hold:

  • a Clinical Safety Officer: a senior clinician with current professional registration (doctor, nurse or pharmacist) and clinical safety training
  • a hazard log
  • a Clinical Safety Case Report: a structured, evidenced argument that the product is safe

DCB0160 applies to you, the deploying organisation. It is your assessment of whether the product is safe in the way you intend to use it, which is a different question from whether it was safely built.

The practical link between them: you cannot discharge DCB0160 without the supplier's safety case. That is the reason to ask for it before signing, not after.

One honest nuance that vendors rarely mention: not every digital solution is in scope. NHS England states plainly that formal clinical safety assurance is mandated in some cases and advised in others, and provides guidance for working out which. A supplier telling you the standard definitely does not apply to them should be able to explain why.

DTAC is the gate you will actually meet

The Digital Technology Assessment Criteria is the framework a practice or ICB typically puts in front of a supplier. It covers five areas:

  1. Clinical safety
  2. Data protection
  3. Technical security
  4. Interoperability
  5. Usability and accessibility

It was refreshed in 2026: roughly 25% fewer questions, elements overlapping with the Medical Device Regulations removed, and the requirement for Clinical Safety Officers to complete NHS Digital's own specific training dropped. Full transition to the updated form was due by 6 April 2026, so if a supplier hands you the old form, they are working from stale paperwork.

The non-negotiable: a patient must be able to reach a person

Across the guidance in this area, one requirement is consistent. There must be a clear, immediate route to a human, triggered by the patient asking, by the AI being unable to resolve the query, or by the AI identifying signals of clinical urgency.

This is worth testing rather than accepting. Ring the number during any trial and simply ask for a person. What happens next is the most informative ninety seconds you will spend on the decision.

What to ask any vendor

Copy this list into the procurement conversation.

  1. Does your product triage, or only book? What happens when a caller describes a symptom?
  2. Do you hold a current DCB0129 clinical safety case? May we see it?
  3. Who is your Clinical Safety Officer, and are they currently registered?
  4. Are you MHRA-registered / UKCA marked? If not, on what basis do you sit outside the medical-device definition?
  5. Can you complete the current (2026) DTAC form?
  6. How does a patient reach a human, and how quickly?
  7. Where is call data processed and stored, and what does your DPIA say?

A vendor who answers all seven plainly is one you can assess. A vendor who answers "we're fully NHS compliant" has answered none of them.

Where Remi fits: briefly, and honestly

Remi is a booking and messaging receptionist. It answers calls and WhatsApp, books into the diary you already use, sends reminders, takes deposits and chases unpaid invoices. It does not assess clinical urgency, and it hands over to a person when a caller asks or when it cannot help.

To be straight about the rest: Remi is not currently DCB0129 assured, not DTAC assessed, and not an approved NHS supplier. We serve private clinics (physiotherapy, dental, private GP) where those frameworks do not apply. We would rather say that plainly than let a page like this imply otherwise, because in healthcare a vague compliance claim is worse than no claim at all.

If you are an NHS practice, the list above is the right conversation to have with whoever you are considering, us included.

Related reading: what a GP surgery needs from its phone system, AI receptionist for UK physio clinics, and what an AI receptionist costs in the UK.

See it on your own line.

Leave your details and we'll set up a live demo on your own number, with no obligation.

Prefer WhatsApp? Message us here →

Booking, not triage.

Remi answers calls and WhatsApp, books into your diary, sends reminders and chases invoices. It does not assess clinical urgency, and it hands over to a person on request. £149 a month ex VAT, 1-week free trial.

See what Remi does

Common questions

Is a practice allowed to use an AI receptionist?

There is no rule against it, but there are conditions. NHS England's guidance on improving telephone journeys in general practice asks practices to map any third-party products sitting on top of their core telephony and understand the contracts behind them. Beyond that, the obligations depend on what the AI actually does: a tool that only books appointments sits in a very different place from one that assesses how urgently a patient needs to be seen. The distinction matters more than the label the vendor uses.

Is an AI receptionist a medical device?

It depends entirely on intended purpose. If a tool calculates, interprets, triages or otherwise informs a clinical decision about an individual, it is likely a medical device under the UK Medical Devices Regulations 2002, which means MHRA registration and UKCA or CE marking. A tool used purely for scheduling administration is likely outside that. The guidance is explicit that admin tools must be designed and documented so their stated intended purpose does not cross the threshold, and in practice the product also has to behave that way, not just say so on paper.

What is DCB0129 and does it apply to my supplier?

DCB0129 is an NHS England information standard for clinical risk management, published under section 250 of the Health and Social Care Act 2012, and it applies to the manufacturer of a health IT system. It requires a Clinical Safety Officer (a senior clinician with current professional registration and clinical safety training) plus a hazard log and a Clinical Safety Case Report. Not every digital solution is in scope; NHS England says compliance is mandated in some cases and advised in others, and provides guidance for determining which. Ask a supplier directly whether they hold a current safety case, and ask to see it.

What is the difference between DCB0129 and DCB0160?

DCB0129 is the supplier's duty and DCB0160 is yours. The supplier evidences that the product is safe to build and sell; the deploying organisation assesses whether it is safe in the specific way you intend to use it. They are not interchangeable, and you cannot discharge DCB0160 without the supplier's safety case, which is the practical reason to ask for it before you sign anything rather than afterwards.

What is DTAC and what does it cover?

The Digital Technology Assessment Criteria is NHS England's assessment framework for digital health technologies, and it is usually what a practice or ICB puts in front of a supplier during procurement. It covers five areas: clinical safety, data protection, technical security, interoperability, and usability and accessibility. It was refreshed in 2026 with roughly 25% fewer questions, overlap with the Medical Device Regulations removed, and the requirement for Clinical Safety Officers to complete NHS Digital's own specific training dropped. Full transition to the updated form was due by 6 April 2026.

The AI receptionist question nobody asks: will it actually write into my diary?

Most AI receptionists read your calendar. Far fewer write a booking back with the right practitioner, duration and service. Which ones do, and what to check.

The no-show policy that actually works for UK restaurants

A copy-paste no-show policy for UK restaurants, plus what makes it stick: card holds, per-cover deposits, and the window to resell a cancelled table.