Abstract

I began this research after a dental voice AI booked me with the wrong specialist. The visible failure was small. What interested me was what happened next: the mistake was dismissed with the words, "The AI screwed up," and I could see no obvious route by which that experience would make the system better.

NHS England has spent more than twenty-five years building mechanisms intended to prevent valuable evidence disappearing in that way. It records millions of patient-safety events, asks organisations to respond proportionately, supports staff to speak up, involves patients and families, commissions independent investigations, and tries to turn patterns into safer practice. It is not a perfect learning organisation. Its own reports identify fragmented data, weak feedback, variable implementation, under-reporting and recommendations that are difficult to track. That tension makes it useful.

This paper examines what NHS England has built and translates the underlying principles into an Agentic Learning Contract. The central argument is simple: an agentic organisation does not learn merely because it stores more conversations or lets a model update its memory. It learns when evidence is captured safely, reviewed proportionately, converted into a tested change, assigned to an owner, monitored in practice, and returned to the people who raised the issue.

Reader Guide

Core question: What would it mean for an agentic organisation to learn as an organisation, rather than merely produce more output?

NHS answer: create routes for events, near misses, good care, staff voice and patient experience to become proportionate investigation, improvement and monitored action.

Agentic answer: separate observations from interpretation, proposed learning from approved change, and system memory from permission to act.

A Note On Scope

This paper focuses on NHS England. The National Health Service is not one legal employer or one uniform operating system, and Scotland, Wales and Northern Ireland have their own structures. The frameworks examined here - including PSIRF, LFPSE and HSSIB - apply specifically to England.

1. The Question Behind A Wrong Appointment

I had been rather pleased with the dental practice's voice AI.

It answered the phone. It understood that I needed to move an appointment. It found another time. Then I arrived and discovered that it had booked me with an implant dentist. I do not need an implant.

The explanation was: "The AI screwed up."

That sentence can be the end of a story, or it can be the start of a learning system.

In The AI Screwed Up. Then What?, I explored the immediate operating questions. What did the system hear? What intent did it select? Which routing rule did it use? Could the event be reproduced? Who owned the correction?

This paper asks the larger question.

What would it take for an agentic organisation to remember the right things, learn the right lesson, and prove that something became better?

Healthcare is a useful place to look because it cannot treat every failure as a clever anecdote. It has to create ways for people to report, investigate, challenge, apologise, improve and monitor. It has to do that across extraordinary scale, professional boundaries, local organisations, national bodies and situations where the consequences are human.

That does not mean the NHS always gets learning right. Quite the opposite. Its continuing difficulties tell us as much as its frameworks do.

2. A Very Large Human Learning System

Official workforce statistics recorded 1,545,872 people working in NHS trusts and other core organisations in England in March 2026. That figure excludes primary care staff. It is safer to describe the NHS as one of the world's largest workforces than to repeat a precise global ranking, because the NHS is made up of many employing organisations and international comparisons count organisations differently.

The scale still matters.

Every day, people make decisions across hospitals, ambulance services, mental-health services, community care, general practice, dentistry, pharmacy and commissioning. Much of the knowledge required to do that work is not neatly written down. It lives in clinical judgement, handovers, workarounds, patient stories, professional communities, local routines and the quiet recognition that something does not feel right.

This is tacit knowledge: knowledge carried by people and practice. Policies, standards, reports, classifications and training materials are explicit knowledge: knowledge that has been made visible enough to share, test and govern.

A learning organisation needs both. If it captures only structured data, it loses context. If it relies only on experience held in people's heads, the knowledge disappears when people move, retire, become exhausted or stop speaking.

3. Twenty-Five Years Of Building Organisational Memory

The present NHS patient-safety architecture did not appear in one policy. It accumulated through reports, failures, reforms, new institutions and repeated attempts to make learning more systematic.

Timeline of NHS England patient-safety learning from the National Patient Safety Agency in 2001 to the 2026 Quality Strategy.
The system has moved from collecting incidents towards proportionate systems-based response, independent investigation, wider staff and patient voice, and faster detection of emerging risks.

In 2001, the National Patient Safety Agency was established to make patient safety a national priority. In 2004, the National Reporting and Learning System began collecting patient-safety reports across England and Wales. NHS England describes NRLS as having held approximately 30 million records during its life.

This was a profound move. Local mistakes and near misses could become national evidence.

But collection is not the same as improvement. Over time, the system added more routes and more obligations. The Serious Incident Framework formalised investigation of the most serious events. The Mid Staffordshire inquiries exposed what happens when targets, hierarchy and defensive culture overpower patient voice. The statutory Duty of Candour required regulated providers to be open when notifiable safety incidents occurred. Freedom to Speak Up created guardians and routes for workers who felt unable to raise concerns through ordinary management.

The NHS Patient Safety Strategy, published in 2019, organised the next phase around safer culture and safer systems. It introduced or strengthened patient-safety specialists, patient-safety partners, a national syllabus, modern event recording and a new incident-response framework.

The Learn from Patient Safety Events service replaced NRLS as the primary national event-recording service. NRLS was decommissioned in June 2024. LFPSE is designed to record harm, near misses, future risks and examples of good care, while making information easier to analyse and return to local organisations.

The Patient Safety Incident Response Framework, or PSIRF, replaced the 2015 Serious Incident Framework. It moved away from a single threshold and fixed investigation process towards proportionate responses, compassionate involvement, systems-based learning and oversight focused on improvement.

In 2023, the Health Services Safety Investigations Body became a fully independent arm's-length body. HSSIB investigates safety concerns without assigning blame or liability and can protect information supplied to its investigations.

The July 2026 Quality Strategy for NHS-funded care in England brings the next direction into view: quality-management systems, stronger tracking of recommendations, earlier warning signals, improved transparency and the development and evaluation of AI models to analyse LFPSE data for discrepancies, unusual patterns and emerging risks. Those are plans and developing capabilities, not proof that the learning problem has been solved.

4. What The NHS Learning System Is Trying To Do

The NHS does not have one learning loop. It has overlapping systems for incident response, clinical audit, regulation, professional standards, complaints, claims, research, staff voice, patient experience and independent investigation.

The underlying moves are remarkably consistent.

A learning loop from patient-safety event through recording, proportionate response, systems analysis, improvement, sharing, and monitoring.
The event is not the lesson. The lesson emerges through a proportionate response, a tested improvement and evidence from practice.

Capture more than disasters

LFPSE can receive incidents that caused harm, incidents that could have caused harm, risks that may affect future safety, and examples of good care. This matters because a system that learns only after catastrophe learns too late. Near misses, weak signals and ordinary success can reveal how the work really operates.

Involve the people who experienced the system

PSIRF begins with compassionate engagement and involvement. Patients, families and staff are not simply sources of data. They hold different parts of the event. A clinical record may show what was entered. A patient may know what was said. A receptionist may know which workaround was necessary. A technical supplier may know which mapping failed.

Respond proportionately

Not every event needs a large investigation. A wrong administrative booking may need a five-minute review and a routing correction. A death or widespread risk may need an independent investigation. Proportionality protects attention. It allows the organisation to preserve serious inquiry for serious or systemic risks without throwing away smaller learning.

Look for system conditions, not a convenient culprit

Systems-based investigation asks how the environment made an outcome possible. That includes workload, equipment, software, interfaces, staffing, training, incentives, handovers, competing goals and organisational boundaries. Accountability remains, but blame is not used as a substitute for understanding.

Convert findings into stronger action

A report is not a correction. The useful output is a change that can be implemented and tested: a redesigned process, a safer interface, an altered staffing arrangement, new training, an escalation route, a clearer standard or a national alert.

Share and monitor

Local evidence may reveal a national pattern. National guidance must return to local practice. The final question is not whether an investigation was closed. It is whether the risk reduced, the work changed, and the affected people heard what happened next.

Learning surface What it contributes Agentic lesson
LFPSE A shared record of incidents, near misses, risks and good care. Create one visible route for operational evidence, with structured meaning and protected context.
PSIRF Proportionate, systems-based learning responses with compassionate involvement. Match review effort to consequence, recurrence and uncertainty rather than investigating everything equally.
Duty of Candour Openness, apology and communication with people affected by qualifying incidents. Do not hide automated failure behind technical language. Notify, explain and provide correction routes.
Freedom to Speak Up An independent route when ordinary hierarchy does not feel safe. Give humans a route around the agent, workflow owner and management chain.
HSSIB Independent, systems-focused investigation of risks with wider learning value. Consequential systems need review independent from the team whose success is being judged.
Audit, standards and research Comparison between expected and observed practice, plus evidence for improvement. Logs are not enough. Compare outcomes with standards, baselines and affected-user experience.

5. Reporting Is Not Learning

This is where the paper needs to be honest.

The existence of thirty million records does not prove that thirty million lessons reached practice.

A systematic review of incident-reporting systems found evidence that reports sometimes produced changes to clinical settings or processes, but little strong evidence that they improved final outcomes or produced deeper cultural change. The authors argued that reporting works better when definitions are clear, clinical teams own the process, and reporting is embedded in a wider safety programme.

That distinction is useful well beyond healthcare. Organisations often measure the easiest visible object: reports filed, actions opened, training completed, recommendations accepted. The real outcome - whether the system became safer - is harder.

Where organisational learning leaks away: silence, burden, fragmentation, blame, weak ownership, recommendation overload, and absent feedback.
Learning can disappear before reporting, during investigation, between organisations, inside a recommendation backlog, or after a change nobody monitors.

Silence and psychological safety

People do not report everything they see. They may fear blame, doubt that anything will change, lack time, feel uncertain about what counts as an incident, or believe senior people do not want to know. Research links psychological safety with greater willingness to speak and report, but the measurement is tricky: a high number of reports can indicate an unsafe service, a healthy reporting culture, or both.

Reporting burden

A form that takes too long competes with care. A taxonomy that people cannot understand produces weak data. A system that asks for the same story several times trains people to stop using it. LFPSE is intended to improve the usability and relevance of event data, but that work continues.

Fragmented systems and boundaries

Patients move between organisations. Risks do too. HSSIB has found that system-level risks may not be visible to integrated care boards because of practical limitations in LFPSE data and that informal relationships sometimes carry information which formal governance fails to preserve.

Recommendation overload

Healthcare can produce more recommendations than the system can absorb. The 2026 Quality Strategy proposes work on a repository and methods for tracking, costing and prioritising recommendations. That is an acknowledgement of a general problem: a recommendation with no owner, resources, implementation route or outcome measure is a document, not learning.

Weak feedback

If the person who speaks up never hears what happened, reporting becomes an extraction process. The organisation takes their effort but gives no evidence that it mattered. The next signal is less likely to arrive.

6. From Tacit Knowledge To Governable Agentic Knowledge

Agentic systems make this problem more urgent because they can create, repeat and scale changes quickly.

They also tempt us to misuse the word "learning". An agent remembering a conversation is not the same as an organisation learning. A model changing its answer is not proof that the system improved. Adding an anecdote to a prompt can spread the wrong lesson just as efficiently as the right one.

The first discipline is to preserve distinct states:

  1. Observed fact: what was seen, heard or recorded.
  2. Interpretation: what somebody thinks the event means.
  3. Proposed learning: the change that might prevent recurrence or preserve success.
  4. Approved operating change: a reviewed change to policy, prompt, skill, workflow, data, model, interface or authority.
  5. Evaluated outcome: evidence about whether the approved change worked and what else it affected.

That sequence converts tacit knowledge without pretending it becomes truth the moment it is written down.

7. The Agentic Learning Contract

NIST's AI Risk Management Framework expects post-deployment monitoring to include user feedback, appeal and override, incident response, recovery, change management and communication about incidents. The NHS experience helps make that operational.

The Agentic Learning Contract linking an event receipt, evidence, affected people, systems review, named owner, tested correction, monitored release, and closed-loop feedback.
The Agentic Learning Contract keeps the affected human, named owner and evidence visible from the first signal through monitored change.

Minimum Agentic Learning Contract

  • Event receipt: intended outcome, actual outcome, time, route and relevant system state.
  • Evidence: observations, logs, source material and what could not be recovered.
  • Uncertainty: assumptions, missing context and plausible alternative explanations.
  • Affected people: whose experience, dignity, rights or work may be changed.
  • System factors: model, prompt, data, tool, interface, integration, workload, policy, training and incentives.
  • Named owner: the human accountable for proportionate review and closure.
  • Correction: the proposed change, its authority and its possible side effects.
  • Evaluation: failed case, neighbouring cases, normal journeys and success measure.
  • Monitored release: bounded rollout, stop-lines, rollback and recurrence monitoring.
  • Feedback: what changed, who was told, what remains unresolved and when to review again.

The contract does not mean every minor error becomes a committee. It means every deployed system has a proportionate route from signal to decision. High-consequence, repeated, discriminatory or cross-system failures receive greater scrutiny. Low-consequence isolated errors may receive a quick review. Silence is never mistaken for proof that the system works.

8. Six Prompts For Building A Learning Organisation

These prompts are designed to make the learning route visible. They are not downloadable skills and they grant no operational authority. Read them before using them.

Prompt 1: Map Our Learning Loop

Help me map how this organisation learns from mistakes, near misses, risks, complaints, staff concerns and examples of good work. For each input, identify who can report, where it is recorded, who reviews it, how urgency is decided, who owns action, how changes are tested, how results are monitored and how feedback returns to the person who raised it. Separate confirmed facts from assumptions and unanswered questions. End with the three places where learning is most likely to disappear.

Safety boundary: use only public, synthetic or specifically approved information. This prompt grants no permission to access health or personal data, contact people, alter systems, deploy changes or override organisational policy.

Prompt 2: Create A Privacy-Safe Learning Record

Turn the following approved incident or near miss into a privacy-safe learning record. Capture the intended outcome, actual outcome, time and route, observed facts, available evidence, missing evidence, uncertainty, possible system factors, affected groups, consequence, recurrence risk, immediate containment and named review owner. Do not diagnose the cause. Mark interpretations and proposals separately from facts. Recommend a proportionate next review step.

Safety boundary: minimise data and remove unnecessary personal details. Do not request or infer health data. This prompt grants no authority to contact people, change systems, publish, deploy or override policy.

Prompt 3: Make Tacit Knowledge Explicit

Interview me about one workflow I know well. Ask one question at a time about normal work, exceptions, warning signs, workarounds, handoffs, difficult judgements, people affected and what experienced practitioners notice that a written procedure misses. Then produce: observed practice, explicit rules, judgement that must remain human, unresolved disagreements, proposed examples for testing and knowledge that should not be stored. Do not turn my account into policy without review.

Safety boundary: use no confidential, health, client or personal information unless the organisation has explicitly approved the tool and purpose. This prompt grants no permission to act or publish.

Prompt 4: Review The System Without Defaulting To Blame

Using only the approved evidence supplied, conduct a systems-based review of this event. Consider task design, workload, environment, interface, model behaviour, prompts, data, tools, integrations, handoffs, staffing, training, incentives, authority and organisational boundaries. Distinguish individual choices from the conditions shaping those choices. List competing explanations and the evidence needed to test each one. Identify any immediate stop-line risk. Do not assign blame, liability or clinical conclusions.

Safety boundary: this is a draft analysis for qualified human review. It grants no permission to access data, contact affected people, discipline staff, change systems or deploy corrections.

Prompt 5: Design And Evaluate A Correction

Turn this approved learning proposal into a bounded correction and evaluation plan. State the problem, evidence, intended improvement, proposed change, owner, authority required, affected users, possible unintended consequences, test cases, baseline, success measure, stop-lines, rollback route, monitoring period and review decision. Include the failed case, neighbouring edge cases and normal journeys that must continue to work. Leave implementation pending human approval.

Safety boundary: do not deploy, edit production systems, use live personal data or contact people. This prompt prepares a plan only and cannot override organisational change control.

Prompt 6: Close The Loop And Promote A Pattern

Review the approved incident record, correction evidence and monitoring results. Draft a closure receipt showing what happened, what changed, what testing found, whether the success condition was met, what remains uncertain, who was informed and when the issue will be reviewed again. Then assess whether this is an isolated event or a repeated pattern. If it may be reusable, propose - but do not perform - promotion into guidance, policy, memory, a skill, an eval or training. Name the evidence and approval required for promotion.

Safety boundary: keep affected people anonymous unless disclosure is explicitly approved. This prompt grants no permission to publish, contact people, change agent memory, alter policy or deploy anything.

9. What Has The NHS Ever Done For Us?

It has given us more than a healthcare service.

It has given us decades of hard-earned work on how large human systems notice harm, listen to quiet signals, investigate complexity, protect candour, share learning and try to improve without pretending that every failure belongs to one bad person.

That work was not produced by a single strategy team. It was built by patients and families who kept asking questions, staff who spoke up, clinicians who reported incidents, investigators who resisted easy blame, safety specialists who developed better methods, analysts who worked through millions of records, and volunteers and communities who continued to care.

Some of it arose because the NHS failed people. Acknowledging the infrastructure also means acknowledging the people whose harm forced the system to learn.

Agentic organisations should not copy NHS forms or bureaucracy. They should copy the serious intent underneath them:

  • make it safe and easy to raise a signal;
  • preserve facts and human context;
  • respond in proportion to risk;
  • understand systems before assigning blame;
  • name the owner and the authority;
  • test the correction;
  • tell people what changed;
  • and verify that the outcome improved.

The NHS has not finished this work. No learning organisation ever does.

That may be the most useful lesson of all.

10. Supporting The People And The System

If this research leaves you wanting to support the NHS, use a real, accountable route.

NHS England's volunteering service explains the range of local opportunities. Volunteers work alongside skilled staff; they are not substitutes for paid professionals. Roles can include patient support, administration, fundraising, participation groups and community services.

NHS Charities Together is the national charity supporting a network of local and specialist NHS charities. You can also find and support the charity attached to your local trust.

Time, money, voice and gratitude all help. So does recognising the difficult, often invisible work required to make a huge public system capable of learning.

Sources And Notes