Approval would no longer be the final regulatory test for some healthcare AI under a blueprint published in the UK on 10 September. An expert commission wants performance checked in real use, software versions traceable in patient records and problems escalated before they become reportable incidents.
That is the proposed direction, not the law. The National Commission into the Regulation of AI in Healthcare is an independent, non-statutory advisory body established by the Medicines and Healthcare products Regulatory Agency. Its 44 recommendations, published on 10 September, do not bind ministers, the MHRA, the NHS or manufacturers. The report leaves implementation to a separate cross-government response.
The distinction matters because the report describes a different regulatory bargain. Some promising systems could reach patients through temporary, closely controlled authorisations. Under the proposal, manufacturers and healthcare providers would have to keep producing evidence after deployment. Faster access would come with a longer regulatory shadow.
Approval becomes a checkpoint
The commission’s starting point is that AI software can change or perform differently after it enters a new hospital, workflow or patient population. A one-off assessment before sale may therefore say less about later performance than it would for a static device.
Recommendation 17 asks the MHRA to use a menu of proportionate post-market requirements. These include real-world data plans assessed when a device is authorised, post-market studies where needed, more regular performance reporting and escalation when performance deteriorates even if no reportable incident has occurred. Recommendation 20 would add device identification and version control, potentially recording a unique device identifier in the patient record.
This is not a proposal to watch every algorithm continuously in real time. The report repeatedly says oversight should vary with risk, benefit and uncertainty. The material change is that evidence after approval would become part of the planned assurance case, rather than relying mainly on reactive incident reports.
Britain already has post-market law. Requirements that took effect on 16 June 2025 oblige manufacturers to maintain surveillance plans and periodic reports, analyse benefit and risk, and record corrective action. The commission explicitly presents its proposals as a further AI-specific layer on those reforms. It wants more frequent performance evidence, better links between deployment sites and the regulator, and action on degradation before harm crosses an incident threshold.
Earlier access would carry conditions
Recommendation 14 proposes staged authorisations. A system could enter a controlled deployment with extra risk controls and evidence gathering, then progress towards full authorisation if real-world results justify it. The commission says the pathway should be temporary, transparent to patients and paired with a clear route to full market access.
The MHRA’s announcement compared the model with learner-driver plates. The useful detail is not the analogy. It is that a provider would need enough staff, governance and monitoring capacity to host the controlled deployment. A shortage of prepared NHS sites could become the practical limit on faster access.
The enforcement recommendation would add teeth only if implemented. Recommendation 22 calls for earlier public sharing of safety signals and financial penalties for manufacturers that breach legal requirements and put patients at risk. The MHRA already has enforcement powers against breaches of current medical-device law, including notices, recalls and prosecution routes. The advisory blueprint creates no new breach or penalty by itself. Ministers would first need to turn the relevant recommendation into a binding duty and specify how it is enforced.
Responsibility moves into the contract
The report also rejects the idea that safety belongs to the vendor alone. Manufacturers would specify the operational conditions required for safe use, including cyber security, training, local monitoring and institutional readiness. Contracts between a manufacturer and healthcare provider would allocate each risk control, so a duty such as supplying performance data could not quietly fall between them.
DHSC and the devolved health administrations would be asked to clarify responsibility across vendors, providers, professionals and regulators. That four-nation work matters because health delivery is devolved, while medical device rules also differ at the border: Northern Ireland continues to apply EU medical device law under the Windsor Framework.
This allocation is not a settlement of liability. The commission says wider legal reform may be needed and could take time. Its immediate answer is operational: make clear who can prevent a risk, who has the information and how patients obtain evidence and redress when care falls below the expected standard.
The implementation clock has started, not finished
There is a route beyond the report, but not yet a completed policy. The MHRA’s published economic-growth goals committed it to respond to the commission by September, begin operationalising an updated framework and aim for full implementation in 2027, subject to any legislation required.
Some work can start through guidance, sandboxes, reporting systems and coordination under existing responsibilities. Other elements need Parliament. Draft pre-market regulations published in May would make unique device identifiers compulsory. Separately, Health Bill amendments tabled on 1 September would create enabling powers for a future MHRA licensing regime, but the government says they make no immediate regulatory change and any new system would still require policy work, consultation, impact assessment and scrutiny.
The commission does not map every recommendation to a power or a Bill. It also states that it made no decisions about public funding, grants or MHRA allocations. The report therefore leaves two questions for the government’s response: which obligations can be introduced through guidance or existing regulations, and who pays for the regulatory and NHS capability needed to monitor AI after approval.
The report is a serious design for lifecycle regulation, not a new compliance duty. Its test will be whether ministers turn continuous assurance from a principle into funded requirements that manufacturers and hospitals can actually operate.
Discussion
Sign in to join the discussion.
No comments yet. Be the first to share your thoughts.