The UK’s National Commission into the Regulation of AI in Healthcare has issued 44 recommendations for a future framework governing healthcare AI, addressing how technologies should be assessed, deployed and monitored across their lifecycle.
Established by the Medicines and Healthcare products Regulatory Agency (MHRA), the independent commission said existing approaches are largely designed around medical products that remain relatively stable after entering the market. AI systems can instead change rapidly and perform differently depending on data, workflows, users and healthcare settings.
The recommendations cover three broad areas: proportionate lifecycle regulation; system-wide responsibility and safe management; and trust, transparency and predictability.
“AI-enabled devices require regulatory approaches that reflect their distinctive characteristics. The future framework should support proportionate and tailored oversight across the product lifecycle, including clear routes to market, flexible mechanisms to support rapid device iteration and stronger use of real-world evidence to support ongoing assurance,” the report states.
The commission has proposed clearer criteria for determining when AI should be regulated as a medical device, with oversight reflecting intended purpose and potential patient risk. It also recommends staged market entry for some products, allowing deployment under defined conditions while developers continue collecting safety and effectiveness evidence.
Real-world data would play a larger role in post-deployment monitoring, alongside regulatory testing environments where developers and authorities could evaluate emerging technologies before wider adoption. Regulators should also assess performance across different patient populations and pursue appropriate international regulatory harmonization.
The framework additionally addresses agentic AI systems capable of pursuing goals and coordinating tasks with limited human oversight.
Workforce preparedness forms another central component. The commission recommends AI education during initial professional training, postgraduate education and continuing professional development, supplemented by technology-specific training from healthcare providers.
Responsibility for AI safety would be shared across manufacturers, providers, clinicians, regulators and policymakers, with clearer agreements covering cybersecurity, training and safeguards. The commission also calls for greater clarity around liability and mechanisms enabling patients to understand AI’s role in their care and seek redress following harmful outcomes.
The recommendations remain advisory and do not establish new regulatory obligations. A separate cross-government response is expected to outline how government and healthcare system partners will consider and potentially advance the proposals.
Click here for the original news story.