AI has genuine potential to transform healthcare delivery. Whether that potential is realised depends on the infrastructure underneath it: connectivity to the right networks, security that travels with the data, and governance that holds up to scrutiny.
The application of artificial intelligence to healthcare data is no longer a future prospect. Clinical AI tools are in active use across NHS trusts and private providers, helping clinicians navigate patient records, identify diagnoses from imaging, triage referrals, and flag deteriorating patients earlier than manual review would allow. The technology has moved from pilot to production in a meaningful number of settings.
What has not always kept pace is the infrastructure underneath it. The connectivity, security, and governance layer that determines whether an AI application can reach the data it needs, handle that data compliantly, and produce evidence of how it did so.
That infrastructure is where most healthcare AI deployments encounter their real constraints.
AI in healthcare depends on data. Not generic data, but specific clinical data: patient records, prescribing information, diagnostic results, referral histories, and the outputs of systems like EMIS and SystmOne that carry the information clinicians act on. Most of that data sits behind the Health and Social Care Network (HSCN), the private network that connects NHS organisations, social care providers, and the technology companies that serve them.
An AI application that cannot reach HSCN cannot reach the data it was built to work with. For healthtech companies deploying cloud-hosted AI products to NHS customers, this is not a secondary consideration. It is the prerequisite for the product to function.
Dyad AI is a useful illustration. Their platform uses AI-driven automation to extract and categorise clinical information from patient correspondence, identifying diagnoses, medications, results, and actionable items, and routing patients towards appropriate care pathways faster than manual triage allows. The intelligence in the system depends entirely on access to the clinical systems that hold the data. Without a compliant HSCN connection from their cloud environment to those systems, the product does not work.
This is the position most healthtech companies building AI into clinical workflows find themselves in. The product is ready. The infrastructure to connect it compliantly is where the work is.
Healthcare AI creates data flows that the existing infrastructure was not always designed for. Training and inference workloads move large volumes of sensitive clinical data between cloud environments and on-premise systems. The volume can be significantly higher than the application traffic the same infrastructure was originally provisioned to carry.
That creates two practical problems. Performance: infrastructure that was adequate for standard application traffic may not be adequate for the volumes AI workloads generate, producing latency and throughput issues that affect the AI application’s reliability. Governance: the path that data takes between cloud and on-premise systems, and what happens to it on the way, is subject to the same scrutiny as the data itself. An ungoverned path between a cloud AI environment and NHS clinical systems is not a defensible position at a DSPT assessment.
Private connectivity, with telemetry on the path and controls at the cloud boundary, addresses both. It provides the performance headroom that AI data volumes require and produces the evidence trail that governance teams need to see.
Healthcare AI sits in a particularly demanding compliance environment. NHS organisations must evidence their controls against CAF-aligned DSPT. Technology suppliers into the NHS are assessed as part of their customer’s DSPT obligations. The AI application itself may be subject to DTAC assessment. And the infrastructure that carries the data – the connectivity, the cloud boundary controls, the access management – all needs to be evidenced as part of the same picture.
For a healthtech company delivering an AI product to NHS customers, the compliance question is not just about the product. It is about the full chain from clinical data source to AI application and back. Every connection in that chain needs to be governed, and the evidence of that governance needs to be available when the customer’s governance team asks for it.
Building that evidence as a by-product of the operating model, rather than assembling it ad hoc before each assessment cycle, is the difference between a sustainable compliance posture and one that creates ongoing overhead.
For a healthtech company deploying AI into healthcare settings, the infrastructure underneath the product needs to cover several things reliably.
Compliant connectivity to HSCN, delivered through an accredited CN-SP, so the application can reach the clinical systems and data sources it depends on. Private connectivity between the cloud environment and those systems, sized for the data volumes the AI workloads generate. Security at the cloud boundary, applied consistently and producing the change records, access logs, and policy enforcement evidence that NHS governance teams expect from technology suppliers. And visibility across the full path, so performance and security posture can be demonstrated rather than asserted.
For NHS organisations deploying AI tools from healthtech suppliers, the same requirements apply from the other side: confidence that the supplier’s infrastructure is governed, evidenced, and aligned to the assurance standards the organisation is accountable for.
The AI applications being deployed into healthcare today are delivering real value. Earlier diagnosis, faster triage, reduced administrative burden on clinical staff, and better use of the data that healthcare systems generate. That value is only realisable when the infrastructure underneath it is built for the environment.
Cloud Gateway works with NHS organisations and healthtech companies on the connectivity, security, and operational assurance layer that healthcare AI depends on. For more on how we work in healthcare, see our Healthcare sector page and our Healthtech and Medtech sector page.