The Medicines and Healthcare products Regulatory Agency has published the recommendations of its independent National Commission into the Regulation of AI in Healthcare, setting out how the UK could update oversight of artificial intelligence used in clinical care. Released on 10 September 2026, the report, led by Professors Alastair Denniston and Henrietta Hughes, both practising NHS doctors, is presented as a blueprint for a regulatory system that is safe, more responsive and capable of keeping pace with software that can change after deployment. The recommendations are not yet government policy. The MHRA and ministers have said they will consider the package and issue a formal response. That leaves the report in an important but interim position: detailed enough to shape market expectations now, but still dependent on future regulatory and legislative action before its main proposals take effect.
According to the MHRA, AI is already being used across the NHS to support earlier detection of strokes and skin cancers and to reduce administrative pressure through voice-enabled tools. The commission argues that the next phase of adoption will require a framework designed for systems that may behave differently across settings and, in some cases, continue to evolve after initial approval. That is a marked shift from the conventional model used for many medical devices, where scrutiny is concentrated at the point of authorisation. The report says AI-enabled tools, particularly newer generative systems, raise a different regulatory problem: safety cannot be judged once and then left untouched if performance may change in live clinical use.
The evidence base is one of the report's strongest claims to authority. The commission, established by the MHRA in September 2025 as an independent non-statutory advisory body, says it gathered evidence from more than 12,000 people over the course of a year, including patients, carers, clinicians, managers, developers and industry groups. The agency describes this as the largest UK engagement exercise of its kind on the regulation of healthcare technology. Additional public research commissioned through the Health Foundation and carried out with Ipsos added a more detailed picture of what confidence looks like in practice. Workshops held between March and April 2026 in Cardiff, Milton Keynes and York found broad support for AI in healthcare, but only where accuracy, human oversight, proportionate regulation and protection against unequal outcomes are clearly built in.
One of the commission's central proposals is a staged authorisation model for new AI systems. In practical terms, that would allow a product to enter limited real-world use under tighter supervision, narrower conditions and clearer guardrails before it receives fuller approval. The MHRA presents this as a way to shorten the route from development to patient benefit without removing regulatory control. For developers and NHS organisations, that model would change the sequence of evidence generation. Instead of treating market entry as the end-point of testing, early deployment would become part of the evidence base itself. For patients, the trade-off is direct: earlier access to promising tools, but with a stronger expectation that their use is bounded, monitored and reversible if risks begin to emerge.
The report's second major recommendation is continuous lifecycle monitoring for AI-enabled medical devices. Rather than relying on a single approval decision, the commission says regulators should be able to track safety and performance throughout a product's working life, using real-world evidence once systems are embedded in care pathways. This is especially relevant for tools that learn from new data, are updated regularly or produce outputs that may vary by context. A lifecycle approach would place more weight on incident reporting, post-market surveillance and the ability to revisit authorisations when performance drifts. It would also demand better data collection from manufacturers and clearer governance inside NHS providers using the technology.
Transparency is treated as a regulatory requirement rather than a communications extra. The commission recommends that members of the public should be able to search for safety information on specific AI-enabled medical devices, including adverse incidents. The proposal builds on existing MHRA transparency tools, including its Drug Analysis Profiles, and would move AI devices closer to a model where safety information is easier for patients, clinicians and managers to inspect. The report also responds directly to a consistent public message: people want to know when AI is being used in their care and want it to support, not substitute for, professional judgement. The commission stops short of suggesting a single uniform disclosure rule for every use case, but it does set out a proportionate expectation that patients are informed when AI plays a material part in decision-making or service delivery.
A further strand of the blueprint concerns enforcement. The commission recommends stronger powers for the MHRA so that the regulator can intervene more decisively where AI systems do not meet required standards. That matters because a more open route to early deployment is only credible if it is matched by clear powers to restrict, suspend or remove unsafe products. External responses published alongside the report point to a second challenge: implementation capacity. The Health Foundation said the main test will be whether the NHS has the skills, systems and operational headroom to monitor AI safely at scale. Professional and industry bodies made similar points, linking successful adoption to clinician training, defined accountability and clearer pathways from regulatory clearance to routine use.
As a policy document, the report sits within a wider government programme rather than in isolation. The notes accompanying the publication say the commission's work was intended to support commitments in the 10-Year Health Plan for England and the Life Sciences Sector Plan, while keeping patient safety and public confidence central to adoption. If ministers accept the main direction of travel, the likely result would be a more active form of regulation: earlier but narrower access for new AI tools, more reporting once products are live, greater public visibility over safety, and a stronger role for the MHRA after approval rather than only before it. The immediate next step is simpler. Government and regulator will now decide how much of the commission's blueprint moves from advisory report into the UK's formal rules for AI in healthcare.