UK commission proposes 44 recommendations for regulating healthcare AI across its lifecycle

A UK commission issued 44 recommendations to overhaul healthcare AI governance, warning that rules for static devices can't handle software that learns after deployment.

Categorized in: AI News Healthcare
Published on: Sep 15, 2026
UK commission proposes 44 recommendations for regulating healthcare AI across its lifecycle

A UK regulatory commission has released 44 recommendations for overhauling how healthcare AI is governed, warning that current rules designed for static medical products cannot handle software that learns and changes after deployment. The independent commission, set up by the Medicines and Healthcare products Regulatory Agency (MHRA), delivered its report after a year-long review of what it calls a regulatory gap between fast-moving AI development and existing approval frameworks.

The recommendations target three areas: proportionate lifecycle regulation, system-wide responsibility for safety, and trust through transparency. The commission said AI-enabled devices need oversight that reflects their distinctive characteristics - unlike traditional medical devices that remain relatively unchanged after market entry, AI systems can be updated rapidly and perform differently depending on the data, workflows, and organizations using them.

Rethinking what counts as a medical device

The commission wants clearer rules on when an AI product should be regulated as a medical device and how much oversight it should receive, based on potential risk to patients and its intended purpose. It said a product's design and functionality should explicitly factor into its intended purpose, not just a manufacturer's claims and promotional materials.

"Intended purpose should explicitly include device design and functionality in addition to a manufacturer's claims and promotional materials," the report reads. "It is important to understand how and when the specifics of how a device has been designed to function is factored into understanding its intended use, especially if that design is inconsistent with specific claims or promotional materials."

Staged market entry and real-world monitoring

The commission recommended allowing some AI products to enter the market in stages, operating under specific conditions while developers continue gathering evidence about safety and effectiveness. It also called for greater use of real-world data to monitor AI performance after deployment and for regulatory testing environments - sometimes called sandboxes - where developers and regulators can evaluate technologies before wider introduction.

Regulators should assess whether AI works safely across different patient populations, the report said, and the framework should account for international regulatory harmonization. The commission urged the MHRA to develop recognition pathways with selected international regulators, including review points and break clauses so pathways "remain responsive to emerging capabilities and risks, while supporting investment and market growth and ensuring patient safety."

The guidance should also address technologies such as agentic AI, which the commission defines as systems that can autonomously pursue goals and coordinate tasks with limited direct human oversight.

Shared responsibility and liability clarity

The commission said responsibility for AI safety should be distributed among manufacturers, healthcare providers, clinicians, regulators, and policymakers. It called for agreements outlining who handles safeguards, including cybersecurity and staff training, and pushed for greater clarity around liability when AI contributes to patient harm.

"Liability for AI in healthcare is complex and evolving. Wider legal reform may be needed, is likely to take time, and will require cooperation beyond the National Commission," the report reads. "Any future legal reform should create the conditions that encourage the responsible innovation of AI-enabled healthcare technologies, while providing appropriate and fair routes to redress so affected parties can challenge harmful AI-enabled outcomes."

Healthcare professionals should receive training on AI's limitations and potential risks, the commission said, spanning initial education, postgraduate training, and continuing professional development. Providers would be responsible for ensuring staff receive technology-specific training aligned with the AI systems used in their practice.

The commission also recommended that patients have access to information about how AI influenced their care and ways to seek redress when something goes wrong. It said patients and the public should have an ongoing role in regulatory decisions, with periodic surveys tracking attitudes toward healthcare AI. Stronger cybersecurity requirements and clearer guidance for consumer health apps and wearables rounded out the recommendations.

Why this matters for healthcare professionals

The 44 recommendations are advisory and do not create new regulatory requirements yet - the commission said a cross-government response will follow separately. But the direction is clear: healthcare providers will likely face new obligations around staff training, AI performance monitoring, and liability arrangements. Professionals who understand how these systems are regulated and where responsibility falls will be better positioned as organizations prepare for formal framework changes. For those building that understanding now, courses on AI for Healthcare and AI for Executives & Strategy offer structured grounding in the technology and governance questions the commission's report raises.


Get Daily AI News

Your membership also unlocks:

700+ AI Courses
700+ Certifications
Personalized AI Learning Plan
6500+ AI Tools (no Ads)
Daily AI News by job industry (no Ads)