Yes. Data collected to run a clinical AI tool could also be used to monitor staff activity or infer performance, depending on the product and deployment. That possibility does not establish misconduct by any supplier. It does require a clear distinction between supporting care, evaluating a service and judging an individual employee from information that may not validly measure their work.
The same event can serve different purposes
A log showing that a clinician opened an answer may help diagnose a technical problem. The same event could be used to count engagement or infer how often the clinician needs assistance. Those interpretations have different purposes and evidential requirements.
Similarly, time spent reviewing a draft might reflect careful checking, a difficult case, an interruption or an awkward interface. A dashboard cannot establish which explanation applies merely because it can display a duration.
Before introducing monitoring, define the question the organisation wants to answer. "Understand whether this workflow works" is different from "rank clinicians by productivity". The data needed for the first may be less intrusive and less individualised than the data proposed for the second.
The UK data-protection context needs explicit assessment
The ICO's worker-monitoring guidance, checked on 10 October 2026, requires a lawful, fair and transparent approach, a defined purpose and proportionate collection. It also explains that employee consent is often unsuitable because of the power imbalance, and that high-risk processing requires a data protection impact assessment.
The ICO marks this guidance as under review following the Data (Use and Access) Act. Organisations should obtain current information-governance and employment advice for the proposed arrangement rather than treat this article as a complete statement of every applicable rule.
The practical implication is straightforward: adding analytics because the software makes them available is not the same as establishing a justified purpose for using them.
A fictional productivity dashboard
Imagine a fictional organisation ranking clinicians by how quickly they approve AI-generated notes. The dashboard labels slower approval as lower productivity and greater use of the reference function as lower confidence.
Neither inference follows automatically from the recorded activity. A clinician may be reviewing more complex encounters, correcting more errors or using the reference tool to check an unusual but important detail. Another may appear efficient because they approve outputs without sufficient scrutiny.
The organisation could investigate workflow differences, but it should not treat the ranking as a validated measure of clinical quality. The first question is what the metric actually captures and which alternative explanations remain.
This example is a proposed risk scenario, not a claim that a particular employer or platform uses such a dashboard.
Learning data are especially easy to misread
An error during a practice question can be evidence of a learning need, not an error made in patient care. Repeated attempts may show persistence and improvement. Choosing a difficult topic may reflect appropriate self-awareness rather than poorer competence than a colleague who avoids it.
A learning system should therefore not be evaluated as though every activity were a workplace performance test. Moving information from private practice into employment assessment changes its meaning as well as its audience.
The GMC's Outcomes for graduates, checked on 10 October 2026, concerns demonstrated knowledge, skills and behaviours. The existence of a platform activity log does not establish that it is a valid assessment of those outcomes or of an experienced clinician's wider practice.
Separate safety investigation from continuous ranking
An organisation may need to investigate a specific incident using relevant records. That does not automatically justify continuous, broad monitoring of every conversation and learning activity for unspecified future purposes.
A proposed policy should distinguish service evaluation, security monitoring, clinical incident investigation and individual performance management. For each, specify the information used, the people who can access it and the process for interpreting and challenging the result.
The aim is not to make legitimate accountability impossible. It is to prevent a dataset collected for one purpose becoming an unexamined source of judgement for another. A proportionate investigation can be more defensible than maintaining a permanent reservoir of potentially misleading inferences.
Give staff a meaningful opportunity to shape the design
The ICO guidance recommends seeking and documenting workers' or representatives' views when introducing monitoring, unless there is a good reason not to. Consultation can reveal practical problems that a technical specification misses, including work performed outside the measured system and differing accessibility needs.
A useful discussion should show staff the proposed outputs, not merely tell them that analytics exist. Can they see what a manager would see? Can they explain a discrepancy? Does the system distinguish a draft from approved work and an educational attempt from a clinical decision?
These questions should be resolved before the first performance discussion relies on the dashboard. Retrospective reassurance is less useful once the metric has already shaped a judgement about someone.
Design a narrower evaluation where possible
To assess whether a tool reduces duplication, a service may need aggregate workflow observations rather than a named ranking of every clinician. To investigate a specific failure, it may need a bounded set of records rather than unrestricted access to all historical prompts.
A proposed design review should ask what information can be omitted without undermining the legitimate purpose. It should also ask how long identifiable detail remains useful and whether the outcome can be measured through a less intrusive method.
These are practical design questions, not a promise that aggregation automatically makes information anonymous or removes every legal obligation. The arrangement still requires assessment in its actual context.
Apply the same scrutiny to iatroX
As described in October 2026, iatroX's CPD page centres on a learner reviewing and personalising a record before confirmation and export. That supports a distinction between the learner's activity and the professional evidence they choose to articulate. It should not be turned into an assumption that every click measures competence.
Its privacy policy, checked on the same date, should be examined for the relevant processing rather than assuming that a learning product has no logs. This article does not claim that iatroX provides employer-surveillance features; it applies the same questions to any learning or clinical platform proposed for organisational use.
Judge the monitoring by what it can legitimately establish
A good analytics system can reveal bottlenecks and help improve a service. A poor interpretation can reward superficial approval, discourage appropriate reference checking or penalise people whose work is not fully visible in the tool.
The decision is therefore not analytics versus no accountability. It is whether the information is necessary, the interpretation is valid and the people affected can understand and challenge how it is used.
Frequently asked questions
Does using clinical AI automatically mean an employer can see every conversation?
No. Access depends on the product, account arrangements, contracts and deployment, which should be checked rather than assumed.
Can AI usage statistics measure clinical competence?
Not by themselves. Activity can reflect many factors, and a metric needs relevant validation and contextual interpretation before supporting a judgement about professional performance.
Should learning-platform data be reused for staff assessment without a fresh review?
No automatic assumption of suitability should be made. The organisation needs to assess the new purpose, lawful processing, validity of the measure and appropriate safeguards.
Create a reviewed record of learning you actually undertook →
