TL;DR

The Medicines and Healthcare products Regulatory Agency has published Information on how AI is used in Health and the Current Regulatory Frameworks, drawing ten findings from a call for evidence held late last year. The headline one is that there is strong consensus for significant regulatory reform — a regulator reporting that the sector wants it to act, rather than the sector resisting.

The ten findings cluster into four demands. First, proportionate and lifecycle-based regulation, rather than approval at a single point in time. Second, continuous post-market surveillance and monitoring, with responsibility shared across the system and each institution clear on its own role. Third, governance and liability: healthcare providers want clear organisational responsibility, and the report finds that clarity and consistency in liability are lacking. Fourth, capability — robust training and improved AI literacy, plus better incident reporting and learning mechanisms.

Two principles run underneath all of it. Human oversight and responsibility for clinical judgment should be retained. And transparency and explainability are treated as prerequisites for continued deployment, not desirable extras.

“The increasing AI in healthcare will affect all of us,” said Alastair Denniston, who chairs the National Commission into the Regulation of AI in Healthcare. He described the evidence as consistently pointing to benefits in quality, speed, convenience and safety, while stressing this is “a change that the regulators and wider health system need to actively engage with, including ensuring that our regulations and governance systems match the risks and benefits of these new technologies.”

Looking Forward

This is a call for evidence, not a rulebook, and the gap between the two is where the practical consequences sit. But the direction it points is consistent with what other UK regulators have concluded independently this month, and with the shift underway in the EU: away from one-off approval towards continuous, demonstrable monitoring. For medtech vendors selling into the NHS, the finding on shared responsibility and post-market surveillance is the one to plan against — it implies obligations that persist for the life of a deployed system rather than ending at procurement. For NHS trusts, the liability finding is the awkward one. The report says clarity is needed precisely because it does not currently exist, which means the question of who answers for a bad AI-assisted decision remains open while adoption continues.