From Pre-Market to Lifecycle: The National Commission’s 44 Recommendations on AI Regulation in Healthcare
Key contacts
On 10 September 2026, the National Commission into the Regulation of AI in Healthcare published its final report;119 pages and 44 recommendations to reshape how AI-enabled health technologies are regulated in the United Kingdom.
The Commission was established by the Medicines and Healthcare products Regulatory Agency (MHRA) in September 2025 as an independent advisory body, chaired by Professor Alastair Denniston (University of Birmingham; University Hospitals Birmingham NHS Foundation Trust) and Professor Henrietta Hughes OBE (Patient Safety Commissioner for England). It brought together expertise from healthcare, technology, law, patient groups, government, the NHS, and international partners across all four nations.
It conducted one of the most extensive programmes of engagement on AI in healthcare ever undertaken in the UK: a Call for Evidence generating 761 responses, public deliberation sessions with the Health Foundation, engagement with seldom-heard groups through National Voices, professional and industry roundtables, specialist working groups, and structured engagement across England, Scotland, Wales and Northern Ireland.
The Commission’s preliminary findings had already signalled clear themes: support for AI in healthcare is conditional, not automatic. 77% of public respondents considered the current regulatory framework “somewhat loose” or “too loose”, while 65% of industry respondents considered it “somewhat restrictive” or “too restrictive”. 77% of healthcare professionals called for a complete overhaul or significant reform. The final report delivers on these themes with concrete recommendations organised around three principles: proportionate lifecycle regulation, system-wide responsibility, and trust, transparency and predictability.
The Headline Shift: From Pre-Market to Lifecycle
The Commission’s central conclusion is unequivocal: the current UK medical device regulatory framework was designed for static products assessed at a single point in time. AI-enabled products iterate rapidly, perform differently in different settings, and depend on the data, workflows and people around them. A framework that relies too heavily on one-off pre-market assessment is not sufficient.
The future framework must be lifecycle-based with proportionate oversight from development through deployment, monitoring, updating and learning from real-world use. This is the single most important message in the report.
Trust as the Enabler
Trust is not an abstract concept in this report. The Commission's Call for Evidence found that respondents were concerned that inappropriate access to healthcare data 'could affect patient confidence in the use of AI in healthcare and reduce their willingness to engage with AI-enabled healthcare settings’; this lack of confidence could undermine the clinical effectiveness of the very technology being deployed: if patients are uncomfortable with AI being used in the delivery of care, they could withhold important health information, which could directly affect the quality of care.
Public trust depends on transparency, accountability, the ability to challenge AI-supported decisions, and evidence of real-world benefit. The Commission recommends a system-level approach to patient transparency (Recommendation 35), including informing patients when AI is used in their care and enabling opt-out where appropriate, alongside a periodic “AI sentiment census” (Recommendation 38) to track evolving trust levels.
A Flexible Framework
The UK is deliberately not following the EU AI Act’s horizontal, prescriptive, risk-classification approach. Instead, the Commission proposes a sector-specific, lifecycle-based framework built on flexibility and proportionality. Key features include:
- Function-based regulation (Recommendation 4): where an AI product has both medical and non-medical functions, only the medical device function should be regulated.
- Staged authorisation (Recommendation 14): a novel mechanism allowing devices to deploy within a controlled scope and expand as real-world evidence accrues.
- Expanded PCCPs (Recommendation 6): moving from specific pre-defined changes to defined boundaries and guardrails within which AI can adapt, including regulated AI agents.
- Enforcement discretion for low-risk devices (Recommendation 3): provided such decisions are signalled clearly and applied consistently.
Importantly, the Commission also recommends a systematic review and update of the UK Medical Devices Regulations 2002 (Recommendation 1), including the definition of a medical device, the classification system (addressing the known limitations of self-declared Class I), and the definition of intended purpose. Given that the pre-market Statutory Instrument under the Medical Devices (Amendment) Regulations 2026 is at an advanced stage and expected through Parliament this autumn, these broader definitional reforms are likely to come as a subsequent layer of legislative modification rather than through the current SI. The Commission itself acknowledges that legislative change takes time and recommends that the MHRA provide guidance within the current framework in parallel.
The Liability Gap: Acknowledged, but Unresolved
The Commission confronts the liability question head on. Under the current negligence framework, claims are disproportionately likely to be brought against healthcare professionals and providers - creating “liability sinks” where frontline staff absorb responsibility for AI failures despite having limited control over product design.
The Commission calls for clear allocation of responsibility at each stage of the AI product lifecycle (Recommendation 24) and, critically, requires contractual allocation of all risk controls between manufacturer and healthcare provider, with no unaccounted-for responsibilities (Recommendation 28). For in-house lawyers, this is perhaps the most immediately actionable recommendation.
However, the report explicitly acknowledges that broader legal reform on liability will be needed and will take time. It references the UK Jurisdiction Taskforce’s Legal Statement on Liability for AI Harms (2026) as relevant context, but does not propose a comprehensive liability solution.
The Foundation Model Supply Chain
Two recommendations create genuinely novel transparency obligations. The Commission proposes an opt-in “Master File” for general-purpose AI models (Recommendation 7) which enables upstream developers of foundation models to confidentially share technical specifications with the MHRA to support downstream device applications. Separately, manufacturers must transparently report any dependency on general-purpose models, including related risks and continuity plans (Recommendation 8). The report also flags a systemic sovereignty risk: a large and growing number of healthcare AI products depend on a small number of foundation models owned outside the UK.
What Should In-House Counsel Do Now?
Don’t wait for the final legislative framework. The Commission’s recommendations signal a clear direction of travel:
- Map your AI systems and their regulatory classification - including third-party and foundation model dependencies.
- Review commercial contracts in light of Recommendation 28 - expect explicit allocation of all risk controls between manufacturer and provider.
- Build lifecycle governance and post-market monitoring infrastructure now - the shift to lifecycle oversight means companies need drift detection, performance reporting and escalation processes from day one.
- Engage with the MHRA - through consultations, sandboxes and the AI and Digital Regulations Service.
- Watch for the cross-government response - this will set out how the recommendations are taken forward.
CMS will continue to monitor and comment on developments.
References: