Info Gov

The National Commission into the Regulation of AI in Healthcare has published recommendations calling for patients to be told when AI is used in their care, for a public searchable database of adverse incidents involving AI-enabled medical devices, and for staged authorisations that would let new AI models into NHS use under close supervision before full approval.

The independent commission, which was established by the Medicines and Healthcare products Regulatory Agency (MHRA) in September 2025, published its report on 10 September following what it describes as the largest engagement exercise ever undertaken in the UK on the regulation of healthcare technology.

The commission - chaired by Professor Alastair Denniston, an NHS consultant ophthalmologist, with Professor Henrietta Hughes, Patient Safety Commissioner for England, as deputy chair - heard from more than 12,000 patients, members of the public, clinicians, healthcare leaders and technology developers over the course of a year.

Its overarching recommendation is that the regulation of AI in healthcare must become proportionate, lifecycle-based and system-wide, replacing a framework designed for static products assessed at a single point in time. The main recommendations were:

1. A staged authorisation pathway, likened to "L-plates" for learner drivers, under which new AI models would be deployed within tight guardrails and reporting requirements before being granted fuller authorisation, with the deployment clearly communicated to patients and health system partners.
2. Continuous real-world monitoring of AI-enabled medical devices throughout their working life, including regular performance reporting, escalation processes where performance degrades even if no reportable incident has occurred, and logging to detect drift.
3. A public database or tool, building on the MHRA's interactive Drug Analysis Profiles, allowing members of the public to search adverse incident reports by manufacturer, device name and timeframe.
4. MHRA guidance requiring developers to provide clear information to users and the public through model cards, user-centred interface design and dynamic labelling, setting out where a device is used, its risks and benefits, how it was developed and tested, and its level of autonomy.
5. A requirement for manufacturers to report transparently where a product depends on an underlying general-purpose AI model, including related risks, mitigations and continuity plans, both in regulatory submissions and through procurement and contract terms.
6. Cybersecurity guidance across the device lifecycle, with the report singling out data poisoning, where training data is deliberately corrupted to compromise outputs, as a specific threat to patient safety.
7. Stronger enforcement powers for the MHRA where AI systems fall short of expected standards.

Existing data protection obligations already apply to the use of AI in healthcare. Where AI-enabled tools process patient data, controllers are subject to the transparency requirements of Articles 13 and 14 UK GDPR, the security obligations of Article 32, and the provisions on automated decision-making apply tighter restrictions where special category data, including health data, is involved.

The commission noted that many AI products used in healthcare will not qualify as medical devices at all and will instead be governed primarily through data protection law, professional standards and organisational governance.

Denniston said the message from the engagement programme was that people are open to AI improving their care, but only if it is safe, overseen by humans, and they know when it is being used. He said the recommendations were designed to make that trust possible.

Hughes said patients had told the commission that to trust AI they wanted to know when it was used, that it supported rather than replaced clinicians, and that there was clear accountability if things went wrong.

Research conducted for the commission by the Health Foundation with Ipsos, involving 78 members of the public in workshops in Cardiff, Milton Keynes and York between March and April 2026, found accuracy was the public's top priority, human oversight was a critical condition for the use of AI, and there was a firm red line that AI should never lead to worse outcomes for any population group.

The commission's call for evidence separately found 65% of respondents disagreed that current post-market surveillance arrangements were sufficient, and that fragmented data infrastructure and siloed reporting made it harder to take a lifecycle view of device safety.

Professor Neil Lawrence, chair of the commission's technology working group and DeepMind Professor of Machine Learning at the University of Cambridge, said generative AI could behave differently in different circumstances and evolve after deployment, so regulators could not rely on a single point of approval. He said the recommendations meant being honest about uncertainties in these systems so that patients and clinicians could judge when outputs should be questioned.

Jennifer Dixon, chief executive of the Health Foundation, said the real test would be whether the NHS had the capacity, skills and systems to implement and monitor AI applications safely at scale.

Lawrence Tallon, chief executive of the MHRA, said the agency would only realise the opportunities of AI with a modern regulatory framework that accelerated safe adoption, protected patients and commanded public and professional confidence. The government and the MHRA will now consider the recommendations, with a cross-government response to follow.

A copy of the report can be downloaded from: https://www.gov.uk/government/publications/national-commission-into-the-regulation-of-ai-in-healthcare-recommendations-for-a-future-regulatory-framework

Also in this section

Sep 11, 2026

Government rejects Lords "last-resort" power to shut down AI systems and data centres

The government has rejected a cross-party amendment to the Cyber Security and Resilience (Network and Information Systems) Bill that would have given the Secretary of State statutory "last-resort" powers to direct the shutdown of data centres and AI systems deployed at scale in the UK in the event of an AI security or operational emergency.
Sep 03, 2026

What is AI Governance – and Why Does it Matter?

[data-gutter="2%"][data-nb="2"]:not(.ckadvancedlayout) [data-width="50"] [data-gutter="2%"][data-nb="2"].ckadvancedlayout [data-width="50"] [data-gutter="2%"][data-nb="2"]:not(.ckadvancedlayout) [data-width="50"] [data-gutter="2%"][data-nb="2"].ckadvancedlayout [data-width="50"] #block_ID1788458782633 { } #block_ID1788458782633 a.pbck-link-wrap { } #block_ID1788458782633…
Aug 03, 2026

NHS England to revise Palantir platform metrics after FOI request reveals internal doubts

NHS England is to change the methodology behind two of its most widely cited claims about the Palantir-built Federated Data Platform, after internal emails disclosed under a freedom of information request showed the health service's own analysts had questioned the validity of the baseline used to measure the system's success, the Financial Times has reported.

InfoGov Masthead Newsletter 800