The most common dental practice AI mistakes are recording appointments with an AI scribe without telling patients, pasting patient details into consumer chatbots, using tools with no data processing agreement, and automating recalls, reviews or phones so far that clinical judgement and a human route disappear. Each one is fixable with a short policy and a few settings.
Dental practices are especially exposed for two reasons. Everything a practice holds about a patient is health data, which data-protection law such as the GDPR treats as a special category needing extra protection. And "consent" already means something specific in dentistry, so staff can assume a signed treatment consent form covers the new tool too. It doesn't. The ten mistakes below are grouped under the three headings in the title, with how each one tends to show up and what to change.
Consent mistakes: when patients don't know AI is involved
1. Switching on an AI scribe and relying on the treatment consent form
An AI scribe records the conversation in the surgery and drafts the clinical note. The patient agreed to a check-up, not to a recording being processed by a third-party supplier. The first you hear of the problem is a patient who spots a phone or microphone and asks, reasonably, "are you recording me?"
The fix is to tell patients before the appointment, give them a genuine choice, and note their answer. A short line in the appointment confirmation works: "Some of our dentists use an AI note-taking assistant during appointments. It records the conversation to help write your notes, and the recording is deleted after [period]. Tell us or your dentist if you'd prefer we didn't use it." The detailed wording options, including what to say chairside, are in consent wording for AI note-taking.
2. Treating an AI-written explanation as the consent conversation
AI is useful for turning a treatment plan into plain English. The mistake is letting the leaflet stand in for the discussion. Valid consent to treatment rests on the clinician explaining the options, risks, costs and what happens if the patient does nothing, and checking they've understood.
How it shows up: an illustrative AI draft for an implant explanation lists healing time, cost and aftercare, and says nothing about the risk of nerve injury or implant failure, because the prompt didn't ask for risks. A patient who later has a complication points to the leaflet. Every AI-drafted patient explanation needs a clinician's read for omissions, not only errors, and should say "your dentist will talk you through the risks for your case". The prompt can do some of that work. Asking for "a plain-English explanation of a single implant, with sections for what happens, healing time, the main risks including nerve injury and implant failure, alternatives including doing nothing, and questions to ask your dentist" gets a leaflet with every heading the conversation needs. The clinician still checks each section against the patient in the chair, because the general risks of implants aren't the same as this patient's risks. Explaining dental treatment plans with AI covers how to prompt for this properly.
3. Letting a chatbot pass as a receptionist
A web chat widget with a human first name and a smiling photo, answering booking questions in the first person, feels friendly until a patient discovers the "receptionist" is software. If you sell to customers in the EU, the EU AI Act's transparency rules have required since 2 August 2026 that people are told when they're dealing with a chatbot. Even where that law doesn't reach, patients who feel misled stop trusting what the practice tells them. Say it plainly in the first message: "I'm the practice's automated assistant. I can help with bookings and opening hours, or pass you to the team."
Data mistakes: where patient information ends up
4. Pasting patient details into a consumer chat tool
This is the most common one, and it's usually well-meant. A dentist asks a free chatbot to tidy a referral letter and pastes in the patient's name, date of birth, medical history and radiograph findings. On consumer plans, chats may be used to improve the model unless someone has switched that off, and the practice has no contract covering the data.
The fix has two parts. First, give staff a proper tool: business plans such as ChatGPT Business, Claude Team, Microsoft 365 Copilot and Gemini in Workspace don't train on business content by default and come with contract terms. Second, teach the habit of stripping identifiers even there. An illustrative before and after:
Before: "Tidy this referral: [patient's title and full name], DOB [date of birth], [home address], on warfarin, LL6 periapical radiolucency..."
After: "Tidy this referral letter for an endodontist. Patient: female, 60s, on an anticoagulant. Finding: lower left first molar, periapical radiolucency, symptomatic..." Names and dates of birth are added back in your practice software, not in the chat.
5. Signing up without a data processing agreement or retention answer
Plenty of dental AI tools are sold on a free trial with a click-through licence. Nobody asks where the audio from the scribe is stored, how long it's kept, whether the supplier's staff can listen to it, or which sub-processors (the supplier's own suppliers, often an AI model provider) see it. Then a patient makes a subject access request and the practice can't say.
Before anything processes patient data, get written answers to: what's stored, where, for how long, who can access it, whether it's used to train models, and how you delete it. What to check in an AI vendor's data processing agreement lists the clauses to look for.
6. AI review replies that confirm someone is a patient
A patient leaves a one-star review about a crown. The practice manager asks an AI tool for a reply, and gets something like this (illustrative):
"We're sorry to hear about your experience with your crown, [patient's name]. Our records show your fitting on 12 June went as planned, and [dentist's name] offered you a follow-up appointment."
Polite, and a confidentiality breach: it confirms he's a patient, names the treatment, the date and the clinician. A safe reply acknowledges the concern without confirming anything: "Thank you for your feedback. We take every concern seriously and would welcome the chance to talk this through. Please contact our practice manager directly." Put that rule in your reply prompt permanently. Patient reviews and AI replies has more safe templates.
7. Saving AI-drafted notes without reading them
Accuracy is a data-protection principle as well as a clinical one. Scribes are good at structure and occasionally wrong in the details that matter most: "no known allergies" when the patient said they'd had a reaction once and weren't sure; the wrong tooth notation; a medication the patient mentioned stopping recorded as current. The note gets signed in a hurry at the end of a long list, and the error sits in the record.
Build the check into the workflow: the clinician reads every AI-drafted note before saving, with particular attention to allergies, medications, tooth numbers and anything the patient declined. If your list doesn't leave time for that, the scribe isn't saving time; it's moving risk.
Over-automation mistakes: when the human route disappears
8. Recall messages that ignore the clinical record
Automated recalls are a good use of AI, until they go to the wrong people. An illustrative set of misfires: a recall reminder sent to a patient who died last month, addressed to them by name, arriving at the family home; a patient on a three-month gum health recall getting the generic "it's been six months" message; a patient who asked not to be contacted receiving a cheerful "we miss you".
These aren't AI errors; they're data errors that automation sends faster. Before switching on AI-personalised recalls, check your practice software's flags for deceased, moved away, do-not-contact and clinician-set recall intervals, and make the automation respect every one of them. Then prove it with test records before the first real batch. In an illustrative practice, the manager created three dummy patients (one flagged deceased, one do-not-contact, one on a three-month gum health recall) with her own mobile number, and ran the recall in preview. The first two were correctly skipped. The third still got "it's been six months since your last visit", because the hygienist had recorded the three-month interval in the clinical notes rather than the recall field the automation reads. Moving 60 or so such intervals into the proper field took an afternoon; finding it through patients would have taken much longer. How dental practices use AI for recalls and reminders goes through the setup.
9. An AI phone line with no way to reach a person
AI receptionists answer calls, book appointments and handle routine questions well. The mistake is routing everything through them. A caller who says "my face has swollen up since yesterday and I'm finding it hard to swallow" needs a person, immediately, not a booking slot next Thursday. Older or anxious patients who struggle with automated systems will simply stop calling.
Every AI phone or chat setup in a practice needs: a list of phrases that transfer straight to a person (swelling, bleeding that won't stop, trauma, difficulty breathing or swallowing, severe pain), a "press 0 or say 'reception'" option at any point, and a weekly review of call transcripts for anything that should have been escalated. Test it yourself by calling with each emergency phrase. The weekly review is where the phrase list grows. In one illustrative week of 212 calls, the review turned up three that should have gone to a person. One was a parent saying their child's front tooth had been "knocked clean out" at school that morning, which the AI booked for the next day because "knocked out" wasn't on the list. A knocked-out permanent tooth is a same-hour problem. The practice added "knocked out", "broken tooth" and "fell" to the transfer phrases the same afternoon and retested with each one. Which dental front desk tasks AI can take over sets out where the line usually sits.
10. Treating AI radiograph findings as the diagnosis
AI radiograph analysis tools highlight possible caries, bone loss or periapical changes on an image. They're decision support. The mistake is letting the highlight become the diagnosis, or showing patients a screen full of coloured boxes as a sales tool. Patients shown an AI "finding" can feel pressured into treatment, and a clinician who defers to the software on a borderline lesion is still the one accountable.
The rule: the dentist examines, interprets and decides; the AI is a second look. If you show AI annotations to patients, explain them as "the software flags areas for me to check", and record your own clinical reasoning, not the tool's label.
How three tools can produce five mistakes in one month
The mistakes rarely arrive one at a time. Picture an illustrative three-surgery practice, two dentists and a hygienist, about 4,500 active patients, that adopts three tools in the same month: an AI scribe, a website chatbot and AI-personalised recalls.
- The scribe goes live on about 140 appointments a week. Patients aren't told in advance (mistake 1), the supplier's retention setting is left at its default, which nobody has checked (mistake 5), and one dentist signs notes at the end of each session without reading them (mistake 7).
- The chatbot introduces itself with a first name and never mentions it's automated (mistake 3).
- The recalls go to roughly 2,300 patients in the first batch. The do-not-contact flag lives in a notes field the automation doesn't read, so a handful of patients who'd asked not to be contacted hear from the practice again (mistake 8).
None of this is dramatic on its own, and each fix is small: a line in the confirmation text, a retention setting changed to the shortest period that suits your workflow, a five-minute note check per session, one sentence in the chatbot greeting, and a flag moved into a field the automation respects. Together that's perhaps six hours of work. The expensive version is finding out through a complaint instead of an audit.
A 30-minute AI audit for a dental practice
Run this with the practice manager and one clinician. Each row takes two or three minutes.
| Question | Where to look | Red flag |
|---|---|---|
| Which AI tools does anyone here use? | Ask every team member, including associates and nurses | Someone uses a free chatbot "just for letters" |
| Do patients know about the scribe? | Confirmation messages, website, chairside script | Only mentioned in a privacy notice nobody reads |
| Is there a signed data processing agreement for each tool? | Supplier contracts folder | Click-through terms only |
| How long are recordings and transcripts kept? | Supplier's settings page and DPA | Nobody knows |
| Does the chatbot say it's automated? | Open your own website chat | It has a human name and photo |
| Can a caller reach a person at any point? | Call the AI line and say "swelling" | It offers a routine appointment |
| Do recalls respect deceased and do-not-contact flags? | Automation settings and one test patient | Flags exist but the automation ignores them |
| Are AI review replies checked for confidentiality? | Last ten review replies | Any reply names treatment, dates or staff |
| Are AI-drafted notes read before saving? | Ask clinicians directly | "Mostly" |
Anything in the red-flag column is your to-do list, roughly in that order: data leaving the practice first, then patient-facing consent, then automation routing. Most practices clear the list in a couple of weeks. Where you're unsure whether a setup meets your regulator's guidance or your data-protection duties, ask your indemnity provider or a data-protection adviser; they deal with exactly these questions.
Dental AI risks: questions practice managers ask
Do we need a DPIA before using an AI scribe in the surgery?
Very likely. A data protection impact assessment is expected when new technology processes health data at scale, and an AI scribe records and processes exactly that. It needn't be long: describe the data, the supplier, retention, the risks and your safeguards. Your data-protection adviser or indemnity provider can tell you whether your version is sufficient.
Can the front desk use ChatGPT for practice social media posts?
Yes, as long as posts contain no patient information and no before-and-after photos without written permission for that specific use. Marketing posts are among the safest AI uses in a practice. Check any clinical claims yourself, because AI tools sometimes overstate what a treatment achieves.
Who is responsible if an AI scribe gets the clinical notes wrong?
The clinician who signs the record. The notes are yours, whatever tool drafted them, so each entry should be read and corrected before it's saved. Treat the scribe's output as a draft from a new nurse: usually helpful, occasionally wrong in ways that matter, and never filed unread.
Further reads
- Patient Data and AI: A Confidentiality Checklist for Small Practices — A full confidentiality checklist for any AI tool in a practice.
- How to Roll Out an AI Scribe Without Losing Patient Trust — Introduce an AI scribe without unsettling patients.
- What Does an AI Receptionist Cost a Dental Practice in 2026? — What an AI receptionist really costs a dental practice.
- Winning Back Lapsed Dental Patients With AI Messages — Reactivation messages that respect patients' wishes.
- Shadow AI: How to Stop Staff Pasting Client Data Into Free Tools — Stop staff pasting patient details into free tools.
- Do You Need a DPIA Before Using AI Tools? — When an impact assessment is needed and what goes in it.
- How to Run a Pre-Mortem Before You Launch an AI Project — A facilitator script, a 75-minute agenda and AI-specific failure prompts for finding what will sink your AI project before it goes live.
- AI Literacy Requirements: What Your Staff Need to Know — A role-by-role checklist of what staff should know about AI, what Article 4 of the EU AI Act asks since the 2026 changes, and how to record it.
- AI Receptionist vs Front Desk Hire: A Dental Practice Comparison — What a dental front desk really does, where an AI receptionist beats a hire and where it can't, and a worked decision for a practice replacing a leaver.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: EU AI Act Article 50 transparency obligations; general data-protection principles on special category (health) data and accuracy; vendor documentation on AI scribes and chat assistants' business plans (checked September 2026).