Summary
- The commission recommends more proportionate, lifecycle-based regulation rather than concentrating assurance around initial market entry.
- Staged authorisation could allow controlled deployment while manufacturers gather evidence from real clinical environments.
- Responsibility would be distributed across developers, healthcare providers, clinicians, regulators, and policymakers.
Britain’s medical regulator is being urged to treat approval as one stage in the life of healthcare AI rather than the point at which regulatory scrutiny largely gives way to ordinary post-market surveillance, reflecting the difficulty of governing software whose performance can change after deployment.
The National Commission into the Regulation of AI in Healthcare, established to advise government and the Medicines and Healthcare products Regulatory Agency, published its recommendations on 10 September following consultation with patients, clinicians, companies, researchers, and health organisations.
Its central conclusion is that oversight should become more proportionate, lifecycle-based, and system-wide. Recommendations include staged authorisation for some products, stronger monitoring after deployment, greater transparency for patients, and clearer allocation of responsibility across the organisations building, buying, and using AI.
The approach responds to a basic difference between software and many conventional medical devices. A physical product can remain materially unchanged after approval, while an AI system may receive updates, encounter different clinical populations, be connected to other software, or produce weaker results when local workflows differ from the conditions under which it was tested.
Staged authorisation moves evidence into clinics
Under the commission’s proposals, selected AI-enabled medical devices could receive temporary or staged authorisation allowing carefully controlled clinical use while additional evidence is gathered. Greater deployment could follow if real-world performance supports it.
That could give developers an earlier route into the NHS without forcing regulators to make one final judgement before substantial clinical evidence exists. It also places greater responsibility on the organisations hosting the early deployment because controlled use requires monitoring, governance, technical support, and staff able to recognise when the system behaves unexpectedly.
Not every product would require the same regime. The commission argues for oversight proportionate to risk, clinical benefit, technical maturity, and the evidence already available, avoiding an assumption that an administrative AI tool and an autonomous clinical decision system should pass through identical processes.
Such differentiation is necessary because “healthcare AI” covers an extremely wide range of functions. Systems can transcribe notes, prioritise scans, recommend diagnoses, manage administration, predict deterioration, or eventually take actions through connected clinical software.
Performance can change without the model changing
Lifecycle regulation is not needed only because developers update software. A fixed model can perform differently when it encounters a patient population unlike its development data, when clinicians use it in another workflow, or when changes elsewhere in a hospital system alter the information supplied to it.
That makes post-market evidence part of the safety case rather than merely an incident log maintained after approval. Hospitals need comparable ways to record unusual behaviour and outcomes, while manufacturers and regulators need enough visibility to distinguish a local implementation problem from broader performance drift.
The commission recommends improving reporting and information sharing, building on existing safety mechanisms such as the MHRA’s Yellow Card system. Yet meaningful monitoring will require more than a channel through which somebody can file a report.
NHS organisations vary considerably in technical staffing, data quality, procurement, and digital maturity. A national requirement for continuous oversight produces weak evidence if each hospital measures different indicators or lacks the capability to investigate unexpected model behaviour.
Accountability extends beyond the developer
The report therefore treats responsibility as system-wide. Manufacturers retain obligations for the products they create, but healthcare organisations decide how systems are configured and deployed, clinicians determine how outputs interact with care, and policymakers establish the environment in which procurement and regulation occur.
That is particularly important as AI becomes more autonomous. A model presenting information for a clinician to consider creates a different accountability chain from an agent able to update records, initiate tasks, or influence treatment without an equivalent human decision at each step.
Patient transparency will also need to account for that range. The commission recommends proportionate communication about AI use rather than requiring a separate warning for every embedded algorithm, while recognising that patients may need more explicit information where AI materially influences care.
The report discusses approaches such as dynamic information and model documentation capable of changing as systems change, which could help avoid a static disclosure becoming obsolete after an update.
The commercial route could change with the regulatory one
For technology suppliers, staged authorisation may create a faster route into controlled NHS environments, but it also increases the amount of evidence that has to be produced after the first approval. Product teams would need systems for version control, monitoring, incident handling, and continuing performance assessment.
Procurement could also become more dependent on whether a supplier can support lifecycle assurance across multiple sites rather than merely presenting a successful validation study. Smaller companies may find that demanding, although a clearer framework could reduce uncertainty about what evidence regulators expect.
The recommendations are not themselves new law. Government and the MHRA still have to decide which proposals to implement, and some changes may require legislation or further regulatory work. The regulator has already indicated that implementation of an updated framework will extend into 2027.
The outcome will depend on whether the NHS can build the monitoring capability around the rules. A lifecycle regime without reliable data and clearly accountable owners merely extends the period during which oversight is supposed to happen.
Yet the commission’s diagnosis is difficult to avoid. Healthcare AI can change after approval, and the environment around an unchanged model can change as well. A regulatory framework centred mainly on the moment before market entry cannot fully observe either process, which is why Britain is now considering whether medical-AI approval should become the beginning of supervision rather than its main event.












