If you are choosing an AI scribe for therapy or psychology work in the UK, the twelve questions below are the ones worth asking before you put a client's material anywhere near it. They cover where the data goes, whether it is used for training, whether the vendor will sign a data processing agreement with you as the controller, what happens to the audio, whether identifiers are removed before the AI sees them, who counts as the author of the record, and how you get everything back out again. A vendor that answers all twelve clearly and in writing is one you can defend using. A vendor that answers in marketing language on more than one or two of them is telling you something.
I write this as someone with an obvious interest, since I built one of these tools. So I have written the list so that it works whichever product you end up with, including one I had nothing to do with. Every question here is one I have had to answer myself, and a few of them are ones I got wrong at first and had to go back and fix.
Before the checklist, the thing that decides most of it
You are the data controller for your clients' information. The tool is your processor. That single relationship sets almost everything else: it is why you need a written contract with the vendor, why you need to know every company in the chain behind them, why the record stays yours and stays your responsibility, and why a breach at their end becomes your notification duty. Any vendor who seems unclear about which of you is the controller has not thought about clinical work carefully enough to be trusted with it.
The second thing worth holding onto is that a good answer is specific and a bad answer is reassuring. Secure, encrypted, private and GDPR-compliant are not answers. Country names, clause numbers, retention periods and named sub-processors are answers.
The twelve questions
-
Where is my client data processed and stored?
Ask for named countries rather than marketing words. A tool can be sold by a UK company, hosted in the United States, and route your text through a third region for the AI itself, and all three answers matter separately. You want the hosting region, the storage region, the region the AI inference runs in, and the region any speech-to-text runs in, each named. If any of it leaves the UK, ask which transfer mechanism covers it, which for most UK arrangements means the UK Addendum to the EU standard contractual clauses.
Watch forA single line saying data is secure, encrypted, or cloud-hosted without naming a country.
-
Is my content used to train models?
The answer needs to be no, in the contract rather than in the FAQ, and it needs to cover the AI provider sitting behind the tool as well as the tool itself. Most clinical AI products sit on top of a large model from one of a handful of providers, so the question is whether that provider is contractually barred from training on what passes through. Ask to see the clause.
Watch forWe do not sell your data, which answers a different question, or an opt-out you have to find and switch on yourself.
-
Will you sign a data processing agreement with me as controller?
You are the controller for your clients' information and the tool is your processor, so UK GDPR Article 28 requires a written contract between you. A vendor built for clinicians will have a DPA ready to sign, available to read before you sign up, and will not need you to be an institution to get one. Read the sub-processor list attached to it, because that is the actual data chain.
Watch forA DPA available only on enterprise plans, or terms that describe the vendor as a controller of clinical content.
-
Is it registered as a medical device, and does it need to be?
Software that only records, transcribes and formats what you said is generally documentation rather than a device. Software that interprets, scores, flags risk, or suggests a diagnosis is doing something else, and in Great Britain that pushes it towards registration under the UK MDR 2002 and, for anything decision-supporting, a higher class than most vendors want to talk about. Ask what the intended purpose is in writing, and whether the MHRA registration matches the features being sold to you.
Watch forRisk flagging, diagnostic suggestion or triage features alongside a claim that the product is not a medical device.
-
What happens to the session audio?
Audio is the most sensitive thing in the chain because it cannot be de-identified before it is transcribed. Ask whether audio is stored or discarded after transcription, how long any recording is retained, which company receives the stream, and in which country it is processed. Ask whether the audio passes through the vendor's own servers or goes from your browser to the transcription provider directly, since that changes who holds what.
Watch forIndefinite audio retention for quality improvement, or no clear answer about who the transcription provider is.
-
Are identifiers removed before the AI sees them?
There is a real difference between a tool that sends your client's name to the model and relies on contracts to keep it safe, and one that replaces identifiers with placeholders before the text leaves your device. Neither is dishonest, but only one limits the blast radius if something goes wrong upstream. If a vendor claims de-identification, ask what it detects, whether it is reversible, and what happens to the mapping between placeholder and real name.
Watch forAnonymised used loosely. If the tool can put the names back, it is pseudonymisation, and it is still personal data.
-
Who is the author of record?
It should be you, on every document, and the tool should be built so that nothing enters the record without you reading and accepting it. This is the professional point rather than a technical one, and your regulator will treat the note as yours regardless of what drafted it. Check that the workflow has an explicit sign-off step and does not file anything automatically.
Watch forAuto-filing into a record system, or copy that describes the tool as writing your notes rather than drafting them.
-
What does it do when information is missing?
This is the question that separates tools that are safe in clinical work from tools that read well. A model that has learned what a session usually contains will happily write the check-in, the grounding exercise and the closing that a protocol implies, whether or not any of it happened. Ask to see what a note looks like when you give it a thin input. You want to see visible gaps rather than smooth prose.
Watch forBeautiful notes from almost no input. That is confabulation, and in medico-legal work it is a serious exposure.
-
Does it understand the way my approach writes?
A note that splits the difference between models fits none of them. EMDR notes need the phase, the cognitions and the SUDS and VOC ratings. CBT needs the agenda and the homework set. IFS needs parts kept in the client's own naming. Ask to see a real example in the approach you actually use, rather than a generic sample, and read it as though you were the supervisor.
Watch forOne template for all therapy, or clinical terms used loosely, such as defusion described as challenging a thought.
-
Can I get everything out, and delete everything?
Ask for a one-click export of all your content in a usable format, and a deletion route that removes it rather than hiding it. Ask what happens to your data if you stop paying, and how long backups keep a copy after you delete. You should also confirm you can meet a client's subject access request using the tool rather than in spite of it.
Watch forExport limited to PDF, deletion only by emailing support, or no answer on backup retention.
-
Is there an audit trail I could show someone?
If a complaint, a claim or a regulator ever asks how a record was produced, you want to be able to show when a draft was generated, from what, and when you accepted it. Ask whether the tool keeps a tamper-evident log and whether you can see it. Most cannot, and it is worth knowing before you need it rather than after.
Watch forActivity logs the vendor can edit, or no record of which drafts were AI-assisted at all.
-
Who actually answers when something goes wrong?
Small practices carry the risk personally, so response time matters more than feature lists. Ask who supports the product, what the response commitment is, and whether there is a published incident and breach notification process, since you have your own 72-hour duty to the ICO that depends on the vendor telling you promptly.
Watch forSupport only through a chatbot, or no published breach notification commitment.
How to actually run this
Send the list. Most vendors have a sales inbox and a support inbox, and a short email asking all twelve questions in one go tells you a great deal before anyone answers, because the speed and the shape of the reply is itself information. Keep the answers. If you ever have to write a DPIA, or explain your reasoning to an indemnity insurer or an information governance lead, the reply email is your evidence that you asked before you started rather than after.
Then test it on your own work. Run the tool on a de-identified session of your own, in the approach you actually practise, and read the output as though a supervisor had handed it to you. Give it a thin input on purpose and see whether it fills the gaps or marks them. Ten minutes of that tells you more than any demonstration.
A note on who these tools are built for
Most AI scribes were designed around medical consultations, where a note is a record of a presenting problem, an examination and a plan. Therapy is not shaped like that. The work builds over time, the formulation is the thread, and the note has to carry the approach used. A tool that writes a competent summary of a conversation can still be the wrong tool, and it is worth being clear with yourself about whether you are buying a transcriber or something that understands the writing.
It is also worth checking who a tool will accept. Some are open to any healthcare professional, some are scoped to particular registers, and the answer affects both your indemnity position and how well the templates will fit what you do.
For completeness, Cogent Clinic is my answer to these questions: hosting, storage and AI drafting in the UK, no training on your content by contract, a DPA any single clinician can sign, identifiers replaced with placeholders in your browser before drafting, MHRA-registered as a Class I device with documentation as its intended purpose, one-click export and deletion, and a hash-chained audit log. Sign-up is currently open to UK HCPC-registered practitioner psychologists. The full answers are in the Trust Centre, which is where I would point anyone running this checklist on us.
Dr Aisha Tariq is a HCPC-registered clinical psychologist in private practice in Glasgow and the founder of Cogent Clinic. This article is general information about choosing software and is not legal advice.