AI in healthcare regulation: UK commission sets out 44 recommendations

The National Commission into the Regulation of AI in Healthcare has called for a more proportionate, lifecycle-based regulatory framework, with greater monitoring of AI in a 119-page report

A national commission established by the Medicines and Healthcare products Regulatory Agency (MHRA) has published 44 recommendations for how AI should be regulated and assured across healthcare.

The National Commission into the Regulation of AI in Healthcare said the current regulatory approach needs to become more proportionate, lifecycle-based and system-wide, reflecting the fact that AI-enabled products can evolve over time and perform differently depending on where and how they are deployed. 

The commission was established by the MHRA in September 2025 as an independent expert advisory body. 

Its work considered not only AI-enabled medical devices, but also wider issues including accountability, transparency, clinical practice, organisational governance, patient safety and system-wide assurance. 

Greater focus on AI after deployment

A central recommendation is to move away from relying primarily on one-off pre-market assessment and towards ongoing oversight throughout an AI product's lifecycle.

The commission said AI products may change, iterate and perform differently across healthcare settings, meaning regulation should cover development, deployment, monitoring, updating and learning from real-world use. 

The commission advises that MHRA should therefore introduce proportionate post-market surveillance requirements, including real-world data collection, post-market studies and more regular reporting of device performance where appropriate.

The recommendations also call for processes to escalate concerns when performance degradation is identified, even where a reportable incident has not occurred.

The commission wants the MHRA, manufacturers and healthcare organisations to improve how information about AI device performance, failures and adverse incidents is reported and shared.

It also recommends that the MHRA consider developing a publicly searchable database of adverse incidents involving specific software and AI-enabled medical devices, allowing users to search by factors including manufacturer, device and timeframe. 

Manufacturers and NHS providers to share responsibility

The report also proposes clearer contractual responsibilities between AI manufacturers and healthcare providers.

Under recommendation 28, contracts between manufacturers and healthcare providers should explicitly allocate responsibility for delivering required risk controls and meeting relevant regulatory commitments.

The commission said this should ensure that responsibilities are agreed before deployment and that no risk controls are left unaccounted for. 

It also recommends the development of an adaptable AI readiness toolbox for healthcare providers, covering governance measures, capabilities and practices needed to safely deploy and monitor AI technologies. 

Staged authorisation proposed

The commission has also recommended that the MHRA enable staged authorisations for AI-enabled medical devices where appropriate.

Under the proposed approach, technologies could initially be deployed within a defined scope, with expansion linked to further evidence generation and monitoring. The pathways should take account of technological maturity, clinical need and the risk controls required to protect patients. 

The report also calls for continued use of regulatory sandboxes to support the development and testing of regulatory approaches for novel technologies.

Alongside this, the MHRA should consider a more formal service allowing manufacturers to obtain written confirmation of a product's regulatory classification.

The commission said clearer and earlier regulatory engagement could give developers greater certainty around qualification, classification, evidence requirements and post-market expectations. 

Greater transparency for patients

The recommendations also address how patients and the public should be informed about AI in healthcare.

The commission proposes that healthcare organisations adopt a proportionate, system-level approach to transparency about the use of AI-enabled products in patient care, including addressing patients' reasonable expectation of being informed when such technologies are used and, where possible or appropriate, having the ability to opt out. 

It also recommends ongoing patient and public engagement and the development of clearer public-facing safety information.

A periodic AI sentiment census covering patients and healthcare professionals is proposed to help inform future policy and regulation using experience and attitudes towards AI. 

The commission's recommendations will now inform the development of a future regulatory framework. 

A cross-government response is expected separately, setting out how government and system partners will consider and take forward the recommendations. 

You may also like