<?xml version="1.0" encoding="UTF-8"?><!DOCTYPE article PUBLIC "-//NLM//DTD Journal Publishing DTD v2.0 20040830//EN" "journalpublishing.dtd"><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" dtd-version="2.0" xml:lang="en" article-type="news"><front><journal-meta><journal-id journal-id-type="nlm-ta">J Med Internet Res</journal-id><journal-id journal-id-type="publisher-id">jmir</journal-id><journal-id journal-id-type="index">1</journal-id><journal-title>Journal of Medical Internet Research</journal-title><abbrev-journal-title>J Med Internet Res</abbrev-journal-title><issn pub-type="epub">1438-8871</issn><publisher><publisher-name>JMIR Publications</publisher-name><publisher-loc>Toronto, Canada</publisher-loc></publisher></journal-meta><article-meta><article-id pub-id-type="publisher-id">v28i1e112992</article-id><article-id pub-id-type="doi">10.2196/112992</article-id><article-categories><subj-group subj-group-type="heading"><subject>News and Perspectives</subject></subj-group></article-categories><title-group><article-title>The United Kingdom&#x2019;s New Blueprint for Regulating AI in Health Care</article-title></title-group><contrib-group><contrib contrib-type="author"><name name-style="western"><surname>Athni</surname><given-names>Tejas S</given-names></name><role>JMIR Correspondent</role></contrib></contrib-group><contrib-group><contrib contrib-type="editor"><name name-style="western"><surname>Clegg</surname><given-names>Kayleigh-Ann</given-names></name></contrib></contrib-group><pub-date pub-type="collection"><year>2026</year></pub-date><pub-date pub-type="epub"><day>5</day><month>10</month><year>2026</year></pub-date><volume>28</volume><elocation-id>e112992</elocation-id><history><date date-type="received"><day>25</day><month>09</month><year>2026</year></date><date date-type="accepted"><day>25</day><month>09</month><year>2026</year></date></history><copyright-statement>&#x00A9; JMIR Publications. Originally published in the Journal of Medical Internet Research (<ext-link ext-link-type="uri" xlink:href="https://www.jmir.org">https://www.jmir.org</ext-link>), 5.10.2026. </copyright-statement><copyright-year>2026</copyright-year><self-uri xlink:type="simple" xlink:href="https://www.jmir.org/2026/1/e112992"/><abstract><p>Current medical device regulation is insufficient for addressing the unique features and evolving nature of AI technology, leaving gaps that regulators across the world are working to close. In this <italic>News and Perspectives</italic> article, JMIR Correspondent Tejas S Athni reports on a recently released report outlining 44 recommendations that, if implemented, could provide a more comprehensive, life cycle&#x2013;based regulatory framework for health care AI in the United Kingdom.</p></abstract><kwd-group><kwd>artificial intelligence</kwd><kwd>AI</kwd><kwd>health care AI</kwd><kwd>United Kingdom</kwd><kwd>UK</kwd><kwd>National Health Service</kwd><kwd>NHS</kwd><kwd>AI regulation</kwd><kwd>medical devices</kwd><kwd>Medicines and Healthcare Products Regulatory Agency</kwd><kwd>MHRA</kwd><kwd>AI governance</kwd><kwd>regulatory sandbox</kwd></kwd-group></article-meta></front><body><boxed-text id="box1"><p><bold>Key Takeaways</bold></p><list list-type="bullet"><list-item><p>The United Kingdom&#x2019;s National Commission into the Regulation of AI in Healthcare set out 44 recommendations that propose life cycle&#x2013;based regulation, calling for continuous postmarket monitoring of AI technologies.</p></list-item><list-item><p>The recommendations provide a blueprint for a future regulatory framework that clarifies when AI counts as a regulated medical device; strengthen the existing AI Airlock sandbox; introduce regulatory tools like Master Files, unique device identifiers, and adverse event reporting; and build up medical workforce preparedness.</p></list-item></list></boxed-text><p>The United Kingdom&#x2019;s National Commission into the Regulation of AI in Healthcare set out 44 recommendations for new ways to regulate AI in health care, as per a <ext-link ext-link-type="uri" xlink:href="https://www.gov.uk/government/publications/national-commission-into-the-regulation-of-ai-in-healthcare-recommendations-for-a-future-regulatory-framework">report</ext-link> published in September 2026. The commission was established by the Medicines and Healthcare Products Regulatory Agency (MHRA) 1 year prior to advise the government on how AI in health care should be overseen, with a stated <ext-link ext-link-type="uri" xlink:href="https://www.gov.uk/government/groups/national-commission-into-the-regulation-of-ai-in-healthcare#purpose-of-the-national-ai-commission">mission</ext-link> to &#x201C;help ensure that patients can benefit from safe and effective AI technologies, support the government&#x2019;s ambition to make the NHS the most AI-enabled healthcare system in the world, and establish a globally competitive regulatory environment that attracts investment and supports innovation.&#x201D;</p><p>This marks one of the most ambitious regulatory rethinks of AI in health care by any national health system to date.</p><p>The commission argues that the United Kingdom&#x2019;s existing medical device rules were built for products that do not change after they are approved (eg, surgical tools and diagnostic kits), whereas AI technology can be updated frequently and can perform differently depending on the hospital, patient population, or workflow in which it is deployed, necessitating ongoing oversight throughout the life cycle. The commission&#x2019;s conclusions draw on evidence gathered from more than 12,000 people, including patients, clinicians, AI researchers, innovators, and international regulatory experts.</p><sec id="s1"><title>The Current Landscape</title><p>AI-enabled software in the United Kingdom is currently regulated as a medical device under the <ext-link ext-link-type="uri" xlink:href="https://www.legislation.gov.uk/uksi/2002/618/contents/made">UK Medical Devices Regulations 2002</ext-link>, which was written long before AI-driven tools existed. Most AI devices are self-declared as low-risk and undergo a single assessment before launch, with limited follow-up after launch. The commission found that 65% of the 761 respondents in its public Call For Evidence felt that this kind of postmarket monitoring was substandard.</p><p>By comparison, the European Union treats AI systems that are also medical devices as automatically high-risk under its <ext-link ext-link-type="uri" xlink:href="https://artificialintelligenceact.eu/">AI Act</ext-link>&#x2014;the first legal framework on AI globally&#x2014;with extra requirements layered on top of existing EU device rules. In the United States, the Food and Drug Administration (FDA) lets manufacturers preapprove certain planned updates to their AI models through a <ext-link ext-link-type="uri" xlink:href="https://www.fda.gov/regulatory-information/search-fda-guidance-documents/marketing-submission-recommendations-predetermined-change-control-plan-artificial-intelligence">predetermined change control plan</ext-link>. The agency also maintains their public <ext-link ext-link-type="uri" xlink:href="https://www.fda.gov/medical-devices/software-medical-device-samd/artificial-intelligence-enabled-medical-devices">AI-Enabled Medical Device List</ext-link>, so clinicians and patients can see which products on the market use AI. The UK commission&#x2019;s recommendations borrow pieces from both approaches while simultaneously adding more continuous, real-world monitoring than either currently requires.</p></sec><sec id="s2"><title>Expanding the AI Airlock</title><p>A key part of the commission&#x2019;s recommendations centers around expanding the MHRA&#x2019;s existing <ext-link ext-link-type="uri" xlink:href="https://www.gov.uk/government/collections/ai-airlock-the-regulatory-sandbox-for-aiamd">AI Airlock</ext-link> program, which was established in 2024 as a regulatory sandbox where manufacturers and regulators can test new AI tools together before full authorization.</p><p>In its first pilot, the AI Airlock worked with four companies: <ext-link ext-link-type="uri" xlink:href="https://www.philips.com/a-w/about/artificial-intelligence">Philips</ext-link> (product: a generative AI tool to help radiologists draft final report impressions), <ext-link ext-link-type="uri" xlink:href="https://oncoflow.ai/">OncoFlow</ext-link> (product: AI-assisted personalized cancer treatment planning), <ext-link ext-link-type="uri" xlink:href="https://www.automedica.ai/">AutoMedica</ext-link> (product: a health care&#x2013;focused retrieval augmented generation tool built on large language models with verified knowledge bases), and <ext-link ext-link-type="uri" xlink:href="https://www.newtonstree.ai/">Newton&#x2019;s Tree</ext-link> (product: a federated AI monitoring service [<ext-link ext-link-type="uri" xlink:href="https://www.gov.uk/ai-assurance-techniques/newtons-trees-federated-ai-monitoring-service-famos?">FAMOS</ext-link>] to detect performance and safety issues in health care AI products in clinical settings).</p><p>Beyond the original AI Airlock, real-world regional test beds are already launching in London and Manchester, in partnership with NHS (National Health Service) England and local health innovation networks. For instance, the <ext-link ext-link-type="uri" xlink:href="https://www.gov.uk/government/publications/london-region-i-mhra-regulatory-sandbox-call-for-expressions-of-interest/london-region-i-mhra-regulatory-sandbox-call-for-expressions-of-interest">London</ext-link> site alone is poised to support up to 10 AI-enabled devices in gathering evidence in real clinical settings. The commission also flags the <ext-link ext-link-type="uri" xlink:href="https://www.nice.org.uk/news/articles/faster-fairer-access-to-healthtech-under-new-national-programme">National HealthTech Access Programme</ext-link> (NHAP)&#x2014;a joint initiative spearheaded by the <ext-link ext-link-type="uri" xlink:href="https://www.nice.org.uk/news/articles/faster-fairer-access-to-healthtech-under-new-national-programme">National Institute for Health and Care Excellence</ext-link> (NICE) that is fast-tracking a small number of promising AI tools, including devices for detecting prostate and breast cancer&#x2014;as a complementary effort. However, the UK commission recommends that the MHRA coordinate with the NICE and other NHAP partners to avoid confusion between the two pathways for developers.</p></sec><sec id="s3"><title>Three Main Areas of Recommendations</title><sec id="s3-1"><title>Life Cycle Regulation</title><p>The commission calls for clearer rules on when an AI product counts as a medical device and how much oversight it requires, based on potential risk to patients. A device&#x2019;s design and functionality&#x2014;not just a manufacturer&#x2019;s claims and promotional materials&#x2014;must factor into this decision. The MHRA would be able to add or relax safety requirements as new evidence emerges. For AI tools with multiple functions, the commission recommends regulating only the specific function that meets the medical device definition.</p><p>The commission also proposes a &#x201C;Master File&#x201D; system, whereby developers of general-purpose AI models share technical details confidentially with regulators. This system would be built upon similar work undertaken by the <ext-link ext-link-type="uri" xlink:href="https://www.fda.gov/medical-devices/premarket-submissions-selecting-and-preparing-correct-submission/device-master-files">US FDA</ext-link>, <ext-link ext-link-type="uri" xlink:href="https://www.canada.ca/en/health-canada/services/drugs-health-products/drug-products/applications-submissions/guidance-documents/master-files-procedures-administrative-requirements.html">Health Canada</ext-link>, and <ext-link ext-link-type="uri" xlink:href="https://www.pmda.go.jp/english/review-services/reviews/mf/0001.html">Japan&#x2019;s Pharmaceuticals and Medical Devices Agency</ext-link>. This would prevent downstream device-makers from getting blocked by a lack of access to a model&#x2019;s inner workings. In conjunction, the commission recommends unique device identifiers, which could act as digital barcodes to better track and follow devices throughout their life cycle.</p></sec><sec id="s3-2"><title>Shared Responsibility</title><p>Responsibility for AI safety should be shared among multiple stakeholders, the commission recommends, including manufacturers, health care providers, regulators, and policymakers, with clear agreements spelling out who is responsible for areas like cybersecurity and staff training. Though legal reform will take time, the commission emphasizes that increased clarity must be provided for legal liability when AI contributes to patient harm.</p></sec><sec id="s3-3"><title>Trust and Transparency</title><p>With no universal requirement for routine disclosure under current law, the commission recommends that patients receive access to information on how AI is involved in their clinical care, in conjunction with clearer pathways for patients to raise concerns. They also propose a public, searchable database of adverse incidents tied to specific AI devices, modeled on the US FDA&#x2019;s Manufacturer and User Facility Device Experience (MAUDE) <ext-link ext-link-type="uri" xlink:href="https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfmaude/search.cfm">database</ext-link> and the MHRA&#x2019;s own <ext-link ext-link-type="uri" xlink:href="https://www.gov.uk/drug-analysis-prints">Drug Analysis Profiles</ext-link> tool. Improvements to the United Kingdom&#x2019;s existing <ext-link ext-link-type="uri" xlink:href="https://yellowcard.mhra.gov.uk/">Yellow Card</ext-link> reporting scheme&#x2014;the MHRA&#x2019;s running system for reporting suspected drug and device safety issues&#x2014;are recommended to better equip it for AI and software adverse event reporting. The commission further recommends regularly surveying both patients and providers about their attitudes toward AI.</p></sec></sec><sec id="s4"><title>Cybersecurity and Workforce Training</title><p>The commission regards cybersecurity as a critical part of patient safety and not just an IT issue, warning that AI tools are increasingly connected to hospital data systems in ways that create openings for malware disruptions and corrupted training data. Their recommendations call for the MHRA to issue clear cybersecurity guidance&#x2014;built into AI devices from the design stage&#x2014;and tailored rules for consumer health apps and wearables. The commission points to warnings from senior NHS leaders that cyberattacks now pose a larger threat to the health service than another <ext-link ext-link-type="uri" xlink:href="https://www.hsj.co.uk/technology-and-innovation/mackey-cyber-attack-risk-dramatically-accelerating/7041858.article">pandemic</ext-link>. They also recommend that AI training becomes a part of medical education from the early stages of medical school and that health care providers train staff specifically on the AI tools that they use.</p><fig position="float" id="figureWL1"><graphic alt-version="no" mimetype="image" position="float" xlink:type="simple" xlink:href="jmir_v28i1e112992_fig01.png"/></fig></sec><sec id="s5"><title>The Next Steps</title><p>While the commission&#x2019;s recommendations are advisory and do not create new legal precedent on their own, the goal&#x2014;and perhaps the outcome, if the recommendations are successfully implemented&#x2014;is to help the UK health system adopt AI safely while maintaining public trust.</p></sec></body><back/></article>