Ask a GP where the working day goes and they will talk about consultations. Ask a practice manager and you will get a very different answer: documents, rotas, recalls, complaints, payroll, policies, and an inbox that refills faster than anyone can empty it. This module is about that second answer.
Modules 3 and 4 focused on AI in the consultation room — ambient scribes, note review, implementation. That is where most of the attention goes, because that is where the clinical risk sits.
But consultations are only part of what a practice does. Behind every surgery list there is an operational engine: incoming correspondence to process, results to file, recalls to run, letters to write, staff to rota, policies to update, and quality work to evidence. Much of it is repetitive. Much of it is text. And work that is repetitive and text-shaped is exactly the work that AI handles well.
This module is about applying what you already know — the safety rules from Module 2, the evaluation framework from Module 3, the implementation discipline from Module 4 — to the operational side of your practice.
Two very different kinds of AI
Before we go further, we need a distinction that will run through this whole module. There are two kinds of AI in practice operations, and they carry completely different levels of risk.
Embedded tools. AI built into systems your practice has procured — document management that suggests coding, triage platforms, analytics dashboards, features appearing inside EMIS or SystmOne. These tools process patient data. That is only acceptable because they sit inside a contract: a data processing agreement, a completed DPIA, a supplier with legal obligations. They are adopted through the Decide, Prepare, Pilot, Embed process from Module 4.
General-purpose AI. Tools like ChatGPT, Claude, or Copilot in NHSmail, used by you or your staff for drafting, summarising, and thinking work. These tools must never see patient-identifiable data — the rule from Module 2 has not changed. But used on the right tasks, they are free or nearly free, available today, and need no procurement at all.
Most of this module is about the second kind, because that is where any practice can start this week. But we will be clear, every time, about which kind of AI we are discussing — because mixing them up is how patient data ends up somewhere it should never be.
If a task involves patient-identifiable information, it belongs either in an embedded tool with proper governance or with a human. The convenience of a general-purpose chatbot is never a reason to make an exception. If you are unsure which side of the line a task sits on, treat it as identifiable and keep it out.
Why operations is the sensible place to start
There is a strong argument that operational work, not clinical documentation, is where a practice should first build its AI confidence.
The risk is lower. A protocol draft, a job advert, or a website update contains no patient data and passes through human review before anything happens. The worst case for most operational AI tasks is a mediocre draft that you rewrite — not a clinical error in a patient record.
The volume is high. Practices produce an enormous amount of routine text: letters, policies, minutes, adverts, newsletters, reports. Shaving thirty minutes off each of these adds up quickly, and the time saved goes to the people who are often forgotten in AI conversations — practice managers, administrators, and reception teams.
The whole team benefits. Clinical AI helps clinicians. Operational AI helps everyone. In my experience, a practice where the administrative team has learned to draft with AI becomes a practice where AI conversations stop being about fear and start being about workload.
None of this makes operational AI risk-free. It makes it the right training ground.
What the operational workload looks like
It is worth naming the categories, because each one gets a lesson in this module.
Documents and correspondence. Every day a practice receives discharge summaries, clinic letters, and reports that need reading, coding, actioning, and filing. This is patient data territory — embedded tools only — and Lesson 2 covers it.
Outbound writing. Referral templates, patient information, website content, newsletters, responses to complaints. Lesson 3 shows how general-purpose AI transforms this work when it is done safely.
Population health and recall. Searches, QOF work, recall campaigns, health promotion. Lesson 4 separates what general AI can help with from what needs governed systems.
The engine room. Rotas, policies, meeting minutes, recruitment, training materials — the practice manager’s world. Lesson 5.
Quality improvement. Audits, significant event analysis, PDSA cycles, and the write-ups that follow. Lesson 6.
Lesson 7 pulls it together into a practical starting plan for your practice.
The rule that carries through
Everything in this module rests on the foundation laid in Module 2. It is worth restating plainly.
General-purpose AI tools — ChatGPT, Claude, Gemini, Copilot Chat — must never be given patient-identifiable data. Not a name, not an NHS number, not a date of birth, not a combination of details that could identify someone. Removing the name is not enough. If the task needs patient data, it needs an approved, contracted, governed tool — or a human.
With that line firmly drawn, there is a great deal of genuinely useful work on the safe side of it. That is what the rest of this module is about.
Key Takeaway
Practice operations — documents, writing, recalls, management, and quality work — is high-volume, text-heavy, and mostly lower-risk than clinical AI. Keep two categories distinct: embedded tools with proper governance may process patient data; general-purpose AI never does. Operational work is the best training ground for a practice building AI confidence.