AI Dent
026 Choosing and Integrating Tools 2,002 words · 9 min

Open APIs in UK Dental Software: Who Actually Lets You Connect

A practice in Leeds bought an AI radiograph tool in January 2025. Good product. The caries detection was genuinely better than the associate’s eye on bitewings, and the demo made everyone in the room lean forward. Eighteen months later it gets opened maybe twice a week, by one dentist, who happens to enjoy fiddling with software.

The tool didn’t fail. The connection did. The practice runs SOE Exact, the sensor writes into Exact’s imaging module, and the AI tool needed the image pushed to it separately. So every reading meant: finish the radiograph, minimise Exact, open the browser tab, find the patient by name (not by their Exact patient number, because the two systems don’t share one), drag the exported JPEG across, wait, read the overlay, then type the findings back into the clinical notes by hand. Ninety seconds per image, on a good day, when the export folder behaved.

Ninety seconds doesn’t sound like much until you multiply it. Eight bitewings a day, four days a week, forty-four weeks: that’s roughly 35 hours a year of pure clicking for one dentist. Nobody made a decision to stop using it. It just lost, quietly, to the fact that the notes had to be typed anyway.

The feature list is not the product

When you’re comparing AI tools for a UK practice, the sales material invites a comparison on capability. Sensitivity and specificity on caries. Number of pathologies detected. CE mark or UKCA status, class of device, whether it’s cleared for bone level measurement as well as caries. All of this matters, and all of it is table stakes among the serious vendors now.

What it doesn’t tell you is whether the thing will still be running in your surgery in a year. That’s decided by something much more boring: whether your practice management system will let the AI tool in, and on what terms. An 89% sensitivity tool that appears automatically over the image you just took beats a 94% tool that needs six clicks. Every time. It isn’t close.

So the question to ask a vendor is not “what can it detect.” It’s “show me what a nurse does, on my PMS, between taking the radiograph and the finding landing in the patient record.” Make them demo it on your system, not their demo rig. If the answer involves the word “export,” you have found the problem.

What integration depth actually means

There’s a hierarchy here, and vendors use the word “integration” for all four levels of it.

Level 1: shared login. Single sign-on, and nothing else. Your staff use one password. The data still moves by hand. This is not integration, and you should say so when a salesperson calls it that.

Level 2: file watching. The AI tool watches a folder. Your PMS or sensor software is configured to drop a copy of each new image into that folder, the AI picks it up, processes it, and shows results in its own window. Patient matching is done by filename or by whatever metadata survives the export. This works, sort of. It breaks when someone renames a folder, when Windows updates, or when two patients share a surname. Findings still get retyped.

Level 3: embedded viewer. The AI runs inside your imaging window, or in a panel docked next to it, and knows which patient is open. The radiograph goes straight in. You read the overlay in place. Findings still usually need a copy-paste into notes, but the patient-matching problem is gone and the click count drops to one or two.

Level 4: read and write via API. The AI pulls the image and the patient context automatically, and writes structured findings back into the clinical record as a note, a chart entry or a treatment plan proposal. Nobody retypes anything. The dentist reviews, edits, accepts.

Level 4 is where daily use becomes the default rather than an act of discipline. Almost nothing in UK dentistry is there yet, and that gap is the real story.

Where the main UK systems currently sit

SystemPublic API?How third parties actually connectPractical ceiling
SOE Exact (Carestream/Envista)No open public APIPartner programme, SDK under NDA, negotiated per vendorLevel 3 for approved partners, Level 2 for everyone else
Dentally (Henry Schein One)Yes, documented REST + OAuth 2.0Self-serve developer registration, public docsLevel 4 for admin and patient data
Carestream R4No open public APIPartner integrations, some direct database workLevel 2–3
Kodak/Carestream imaging modulesTWAIN and DICOM in varying statesImage-level onlyLevel 2–3
iSmile / Systems for DentistsLimited, partner-ledBespoke arrangementsLevel 2–3
Dentr, Dentally-adjacent newer entrantsGenerally yes, RESTPublic or near-publicLevel 3–4

Take that table as a shape rather than a spec sheet. Vendor partner programmes change, and the honest answer for any specific pairing is “ask both sides, in writing, before you sign.”

The pattern underneath it is worth naming. The older, larger, more entrenched systems (Exact and R4 between them run a very large share of UK practices) treat integration as a commercial relationship, not a technical capability. There’s an API. You just can’t have it unless you’re in the partner programme, and the partner programme has a queue, a fee and a review. The newer cloud-native systems treat integration as a product feature, publish the docs, and let anyone build.

Neither approach is wrong in the abstract. Gatekeeping has a real clinical argument behind it: uncontrolled write access to a patient record is a genuine safety and information-governance problem, and a partner review is one way to manage it. But the effect on you, buying an AI tool in 2026, is concrete. If you’re on Exact, your realistic universe of deeply-integrated AI tools is whoever has made it through Carestream’s partner process. If you’re on Dentally, it’s much wider, because a vendor can build against the public API without asking permission first.

A worked comparison

Two practices, same AI triage tool for incoming patient enquiries. The tool’s job: read inbound web-form and email enquiries, classify urgency, and either book routine cases straight into a free slot or flag the urgent ones for a human call-back.

Practice A runs Dentally. The vendor authenticated once via OAuth, and the integration calls the appointments endpoint directly:

GET  /api/v1/appointments?practitioner_id=4412&from=2026-10-01&to=2026-10-07
→ 200 OK, 63 slots, 11 free

POST /api/v1/appointments
     { "patient_id": 88214, "start": "2026-10-03T14:20:00Z",
       "duration": 20, "reason": "AI triage: routine exam, non-urgent" }
→ 201 Created, appointment_id 771902

Twelve seconds from enquiry to confirmed booking. Nobody touched it. The practice manager sees a daily digest of what was booked automatically and what was flagged.

Practice B runs Exact, and the same vendor is not an Exact partner. The tool classifies the enquiry, then emails the practice a summary. A receptionist reads the summary, opens Exact, searches for the patient, checks the book, makes the booking, and emails the patient back. Call it four minutes per enquiry, plus the latency of whenever somebody gets round to the inbox.

At 30 enquiries a week, Practice B spends about 2 hours a week on work that Practice A has automated. Over a year that’s roughly 88 hours, which is somewhere around £1,300–£1,800 of receptionist time depending on what you pay. The AI tool costs both practices the same subscription. One of them is getting maybe a quarter of the value.

This is the argument in a single comparison: identical software, identical clinical capability, wildly different return, and the only variable is what the PMS lets through.

Questions that separate real integration from brochure integration

Ask these before money changes hands. The answers are short and diagnostic.

  1. Are you an approved partner of my PMS vendor, today, in writing? Not “we’re in discussions.”
  2. Does the integration read patient context automatically, or does someone select the patient in two places?
  3. Can it write back to the clinical record? If yes, as what: a free-text note, a structured finding, a proposed treatment plan?
  4. If my PMS vendor pulls partner access, what happens to my installation? Get this in the contract.
  5. Where does the image go? On-premise processing, UK cloud, EU cloud, or somewhere that turns your DPIA into a research project?
  6. What’s the click count from “radiograph captured” to “finding in notes”? Make them count out loud, on your system.
  7. Is the connection version-locked? Some partner integrations break on PMS upgrades and stay broken for weeks.

Question 4 catches people out more than you’d expect. A partner relationship is a commercial arrangement between two companies you don’t control, and it can end. When it does, the tool you bought becomes a tool you export files into, and you’re back to ninety seconds an image.

What to do if you’re on a closed system

You’re not stuck, but you should adjust what you’re buying for. If your PMS is Exact or R4 and the AI vendor you want isn’t a partner, three options are realistic.

Pick a tool that is a partner, even if it scores slightly worse on paper. A Level 3 tool at 89% sensitivity used on every bitewing finds more disease in your practice than a Level 1 tool at 94% used on the interesting ones.

Alternatively, buy AI for the workflows that sit outside the PMS entirely. Front-desk triage, call answering, recall messaging and patient comms often touch the phone system and the website rather than the clinical record, so the PMS integration question barely applies. That’s where a lot of practices on closed systems are getting their easiest wins this year.

Or take the PMS migration seriously as part of the AI decision. Moving from Exact to a cloud system is a real project with real disruption, and nobody should do it lightly. But if you’re already weighing it for other reasons, the integration ceiling on your current system is a legitimate item on the list, and it’s worth putting a number against it the way Practice B’s 88 hours does. Our guide to choosing and integrating tools works through how to sequence that decision alongside procurement, so you’re not buying an AI tool and a PMS in the same panicked month.

Deep integration cuts both ways, and it’s worth being straight about it. A tool that writes to the clinical record is a tool that can write the wrong thing to the clinical record. If your AI radiograph reader pushes “distal caries, LR6” into notes and the dentist accepts it without looking, that’s a clinical record you’ll be defending later.

Insist on three things at Level 4. Findings arrive as proposals requiring explicit acceptance, never as committed entries. Every AI-originated entry is labelled as such in the record, permanently and visibly. And the audit trail shows who accepted what, when. Any vendor building serious integration has thought about this already; a vendor who looks blank when you ask is telling you something useful about how much of the product exists.

Your DPIA needs to cover the connection itself, not just the AI. Where the data flows, who processes it, under what lawful basis, and what happens on termination. If the vendor can’t hand you a data flow diagram and a UK GDPR position on day one, that’s a procurement red flag regardless of how good the model is.

The practice in Leeds switched to a partner-integrated reader in March. Same clinical claim, roughly. It now runs on every bitewing taken in the building, because it appears on its own and nobody has to decide to use it, and the associate who used to enjoy fiddling with software has gone back to being a dentist.