UK Commission Proposes New Healthcare AI Regulations
The recommendations are grouped into three areas: proportionate lifecycle regulation; system-wide responsibility and safe management; and trust, transparency and predictability.
The UK's National Commission into the Regulation of AI in Healthcare has proposed 44 recommendations for regulating artificial intelligence across the healthcare sector, including lifecycle monitoring, AI safety incident reporting, stronger cybersecurity requirements and mandatory training for healthcare professionals.
The independent commission, established by the Medicines and Healthcare products Regulatory Agency (MHRA) last year, said existing regulations may not adequately address AI systems because they can be updated frequently and may perform differently depending on data, workflows, users and healthcare settings.
The recommendations are grouped into three areas: proportionate lifecycle regulation; system-wide responsibility and safe management; and trust, transparency and predictability.
The commission called for clearer rules to determine when an AI product should be regulated as a medical device and what level of oversight should apply, based on its intended purpose and potential patient risk. It also recommended staged market entry for certain AI products, allowing deployment under defined conditions while developers continue collecting evidence on safety and effectiveness.
The proposed framework would increase the use of real-world data to monitor AI after deployment and establish regulatory testing environments where developers and regulators can assess emerging technologies before wider adoption. Regulators would also be expected to assess whether AI systems work safely across different patient populations.
The recommendations extend to agentic AI, which the commission describes as systems capable of autonomously pursuing goals and coordinating tasks with limited direct human oversight. The commission also called for international regulatory recognition pathways for selected software and AI-enabled medical devices, subject to review mechanisms.
Healthcare providers would be responsible for ensuring professionals and other staff receive appropriate AI training, including technology-specific education and training on automated decision-making systems, limitations and potential risks. The commission recommended incorporating AI into initial professional education, postgraduate training and continuing professional development.
The framework also proposes shared responsibility for AI safety among manufacturers, healthcare providers, clinicians, regulators and policymakers. It calls for clearer agreements covering safeguards such as cybersecurity and staff training, alongside greater clarity over liability when AI contributes to patient harm.
Patients should receive information about how AI influenced their care and have access to mechanisms for seeking redress, according to the recommendations. The commission also proposed stronger cybersecurity requirements and clearer guidance for consumer health apps and wearable devices.
The 44 recommendations are advisory and do not create new regulatory requirements. The commission said a separate cross-government response will outline how the government and system partners will consider and take forward the recommendations.
Stay tuned for more such updates on Digital Health News