
Queen Elizabeth Hospital Birmingham, an NHS hospital, in March 2012. Illustrative. Image: Tony Hisgett / Wikimedia Commons, CC BY 2.0, cropped
The UK government has accepted all 44 recommendations of a doctor-led commission on how to regulate AI in healthcare, promising a system where AI tools used in the NHS are checked throughout their working life rather than signed off once and left alone.
The government response, published on Tuesday by the Department of Health and Social Care and the Medicines and Healthcare products Regulatory Agency (MHRA), backs the National Commission into the Regulation of AI in Healthcare, which reported on September 10 after a year of evidence gathering involving more than 12,000 patients, clinicians and members of the public. In its own words, the government says the UK’s medical device rules, written in 2002, are “not fit for purpose” for AI.
What the government has agreed to
Accepting every recommendation is the headline, but most of the response is a list of things the MHRA will “explore”, “consider” or publish guidance on. The firmest dates are:
- December 2026: draft guidance on how AI medical devices can be updated and retrained over time without a fresh approval each time, through what regulators call predetermined change control plans.
- Early 2027: a consultation on how AI software is classed as a medical device in the first place, the commission’s first recommendation.
- Spring 2027: a full roadmap with timelines for all 44 recommendations, overseen by a new programme board.
The government also says it will explore “staged authorisation” routes, letting promising AI tools be used in the NHS earlier under close supervision while real-world evidence is gathered, and will work on clearer routes to redress for patients when AI-assisted care falls below the expected standard.
Medical AI makers will have to say which big model they use
Two of the accepted recommendations reach beyond the NHS to the companies building the underlying models. The MHRA will publish guidance on what medical AI makers must disclose when a product depends on a general-purpose AI model, including where the model comes from, the risks that dependency brings and plans if it changes or disappears. The same expectation will be written into NHS procurement contracts.
The regulator will also look at a voluntary “Master File” system, where the makers of foundation models could file benchmarks, model cards and details of their guardrails once, so that every medical device built on top of them does not have to start from scratch. Details of both are due by spring 2027.
Health innovation minister James Frith called it “a continually-evolving process as the technology itself develops”. The commission’s chair, Professor Alastair Denniston, said the response showed the government had listened to the public as well as the commission:
This response shows that government has listened, not just to the Commission, but to the more than 12,000 patients, clinicians and members of the public who shaped our recommendations.
Professor Alastair Denniston, Chair of the National Commission
A testing ground for AI medical devices reopens
Alongside the response, the MHRA opened applications for the third phase of AI Airlock, its regulatory sandbox for AI medical devices, which has secured three more years of government funding. This round focuses on how AI tools are monitored once they are in real use. A webinar for applicants is on October 22, and the first developers will be picked in November.
The commission’s deputy chair, England’s Patient Safety Commissioner Professor Henrietta Hughes, said patients wanted AI that “improves care without compromising safety, transparency or accountability”, adding:
Patients must remain at the heart of how these technologies are developed, regulated and used across healthcare.
Professor Henrietta Hughes OBE, Patient Safety Commissioner for England
Scotland was more cautious, saying it shares the commission’s ambition and will set out its own response in due course.
The question of who answers for AI in healthcare is already live elsewhere: in the US, insurer Blue Cross has accused hospitals of using AI coding tools to make patients look sicker on paper, while families are using chatbots to chase diagnoses, as one did when ChatGPT named a toddler’s ultra-rare condition.
Why it matters
The NHS wants to be the most AI-enabled health system in the world, and this is the rulebook it intends to build. Accepting everything is easy; the test is whether the December guidance and spring roadmap turn “explore” into firm rules, and whether model makers such as OpenAI, Google and Anthropic play along with the Master File idea.
Sources: UK government and MHRA announcement; Government response to the National Commission; National Commission report; MHRA AI Airlock Phase 3.


