Life Sciences · 7 October 2026

AI medical devices will be regulated for their whole working life

Government has accepted every recommendation of the National Commission on AI in healthcare. The approval stops being the finish line. For anyone who has run a GxP system, this will feel familiar.

By Chris, Ovett & CxO · 6 min read

On 10 September, the National Commission into the Regulation of AI in Healthcare published its report: 44 recommendations, shaped by input from more than 12,000 patients, clinicians and members of the public, and led by two practising NHS doctors, Professors Alastair Denniston and Henrietta Hughes. On 6 October, the government published its response and accepted all 44.

The headline shift is simple to state. An AI-enabled medical device will no longer be judged mainly at the point of approval. It will be watched for as long as it stays in use.

What the Commission asked for

Three recommendations stand out for anyone building, buying or running clinical AI.

Staged authorisation. The Commission proposed that new AI models be authorised in stages, likened to L-plates for learner drivers: limited use first, with wider use earned through evidence gathered in practice.

Transparency for patients. Patients told the Commission they want to know when AI is involved in their care, and the recommendations set out a proportionate way to tell them as AI becomes embedded in NHS services.

Stronger enforcement. The MHRA should get enhanced powers to act decisively when an AI system falls short.

What happens next

The first dates are tight. The MHRA has committed to draft guidance on managing changes to AI-enabled devices by December. Alongside the response, the MHRA opened applications for the third phase of its AI Airlock sandbox, focused on post-market surveillance and lifecycle regulation, with the first wave of innovators selected in November. A consultation on how AI devices are qualified and classified follows in 2027.

It sits alongside guidance the MHRA issued in late July on ambient voice technology, which drew a useful line: an AI scribe used purely to transcribe, summarise or draft letters for a clinician to review is not a medical device, whereas one with a genuine medical purpose is. Intended purpose, not the technology, decides which side you're on.

Why this is a GxP problem in a new costume

I've written before about what life sciences' GxP culture can teach other sectors. Here, the lesson runs the other way: AI developers are about to learn what validated-system owners have known for decades.

A validated system is never “done”. It has a defined intended use, a controlled change process, periodic review, and a documented reason to believe it still performs as it did when it was validated. Every one of those maps onto what lifecycle regulation of AI will demand. The model's intended purpose has to be pinned down tightly enough to judge drift against. Retraining is a change, and needs impact assessment before release, not after. Performance in the field needs monitoring with thresholds that trigger action, and someone with the authority to pull the model if they're breached.

The organisations that will struggle are the ones that treat a model as a project deliverable: built, approved, handed over and left. The ones that will cope already think of models the way a QA function thinks of a validated instrument.

The question nobody owns yet

The hardest part isn't technical. It's ownership after go-live. Continuous monitoring needs real-world performance data, and that data usually sits with the NHS trust or provider using the device, not with the manufacturer. If the manufacturer is accountable for post-market performance but can't see outcomes, the obligation is unworkable.

That makes contracts the first place to act. Suppliers and NHS buyers should be agreeing now who collects performance data, how it flows back, who reviews it, and who decides when a model's behaviour has moved far enough to matter. Getting that into procurement terms before the guidance lands in December is far easier than retrofitting it into live contracts afterwards.

← Back to Insights

Running AI in a regulated clinical setting?

A short conversation on change control, monitoring and who owns your models after go-live.

Book an introductory call