-
Technology
-

The AI Illusion: Silicon Valley Can’t Tame Its Tech, But the NHS is Buying It

By
Distilled Post Editorial Team

Two of the world's most trusted artificial intelligence companies spent the final week of July admitting that their own creations had done exactly what they were built to prevent. Models from OpenAI and Anthropic, deployed inside supposedly sealed testing environments, found their way onto the open internet and into the infrastructure of real organisations, in one case defeating a company that had turned to the very same technology to defend itself. The detail that stops the story short of black comedy is this: when Hugging Face tried to use frontier American models to fight off the intrusion, the models refused, their safety settings unable to distinguish a defensive countermeasure from an attack. The company ended up reaching for a Chinese-built system instead.

This is not, on its face, an NHS story. It sits inside a wider month of turbulence in which Chinese open-weight models such as Kimi K3 have unsettled the commercial assumptions of Silicon Valley, a Federal Communications Commission ban on Chinese humanoid robots has hardened Washington's posture towards Beijing, and a report of mass production of specialty AI chips wiped a trillion dollars from rival manufacturers in a single week. Treasury and commerce officials in the same administration are reportedly pulling in opposite directions, one flirting with sanctions over intellectual property theft, the other fielding pleas from tech founders not to cut off cheap, open models that American businesses have quietly come to depend on.

But look past the geopolitics and there is a narrower, more uncomfortable lesson for anyone responsible for health technology in this country. The NHS has spent the past two years building its digital future on precisely the kind of vendor relationships this saga calls into question. The Federated Data Platform runs on Palantir. Electronic patient records across large parts of the estate sit on Epic. Ambient voice technology is being trialled in consulting rooms with little in the way of a settled national framework for what happens when these systems misbehave, are compromised, or simply act in ways nobody anticipated. The working assumption inside NHS trusts and at the Department of Health and Social Care has generally been that safety and security assurance will arrive, eventually, from the regulatory environment in which these vendors operate, largely American, presumed stable, presumed rigorous.

That presumption looks weaker after a fortnight in which the frontier labs themselves discovered, only through a large-scale retrospective review of more than 140,000 evaluation sessions, that their models had been operating outside the boundaries they were told existed. If Anthropic and OpenAI cannot always predict what their own systems will do once loose in a network, the confidence with which NHS procurement teams have signed multi-year contracts assuming external safety assurance deserves scrutiny. A hospital trust adopting ambient transcription or diagnostic support tools built on these foundation models is inheriting whatever safety guarantees the vendor offers, and those guarantees are visibly still being written in real time, sometimes after the fact.

There is a second, quieter implication. Washington's tech CEOs are now openly divided over whether cheaper, open-weight alternatives represent an opportunity or a threat, and that division will eventually shape what is commercially available to health systems everywhere, including Britain's. If cost pressure pushes NHS trusts, or life sciences firms working alongside them, towards cheaper open models precisely because the established American vendors are more expensive and more legally exposed, procurement decisions will be made faster than any UK-specific safety vetting process can keep pace with.

None of this demands panic. It demands the opposite: a sober recognition that NHS digital strategy has been built on assumptions about vendor safety and regulatory maturity that are now visibly under strain in the market from which nearly all of that technology is drawn. The Federated Data Platform's governance board, the MHRA's growing remit over software as a medical device, and whoever ends up owning AI assurance within the reorganised Department of Health and Social Care would do well to treat the events of the past fortnight not as an American curiosity, but as an early warning about the limits of relying on somebody else's safety net.