The government has accepted all 44 recommendations from the National Commission into the Regulation of AI in Healthcare. That sounds like a sentence designed to clear a room, but it could determine whether software that reads scans, drafts notes or recommends treatment is watched after it enters an NHS hospital—or merely admired at the door.
The decision was announced on 6 October by the Medicines and Healthcare products Regulatory Agency. The commission, an independent advisory body led by clinicians, published its recommendations on 10 September. Its central argument is simple: an AI medical device cannot be treated like a conventional machine that passes a test once and then remains essentially the same.
Software can be updated. Its performance can shift when it meets a different population, hospital or workflow. Staff can use it in ways its designers did not expect. A model can look impressive in a controlled trial and disappoint in a crowded ward. The commission therefore wants regulation that follows products throughout their working lives, with proportionate controls based on risk.
The government says it accepts that blueprint in full. A detailed implementation roadmap is promised by spring 2027. The MHRA is also opening a third phase of its “AI Airlock”, a regulatory sandbox in which developers, healthcare organisations and regulators test real products and learn how they should be monitored.
That is the reported position. It does not mean 44 statutory rules appeared overnight, or that every AI tool already used in healthcare has received a fresh seal of approval. Acceptance is a policy commitment; delivery will depend on guidance, regulations, funding, technical standards and enforcement.
What patients are actually being promised
The commission’s model moves away from relying too heavily on a single pre-market assessment. It calls for continuous evidence about safety and effectiveness, clearer responsibility across the system and better information for patients when AI is involved in their care.
The recommendations include clearer classification of AI-enabled devices, conditional routes to market in appropriate cases, monitoring after deployment and more accessible reporting of incidents. They also address the human part of the system: training, usability, procurement and who is accountable when a tool influences a clinical decision.
That last question is where the cheerful launch language meets a corridor full of locked doors. If an algorithm misses a tumour, was the developer responsible, the hospital that bought it, the clinician who relied on it, or the regulator that allowed it? A sensible framework cannot answer every case in advance, but it can stop each participant arriving later with a professionally drafted version of “not my department”.
The public-facing guidance says patients should receive clearer information about AI use and have routes for questions and concerns. That matters because consent becomes theatrical if a patient is simply told that “technology” helped with a decision without being told what it did, how much weight it carried or whether a person checked the result.

The policy is not an instruction for doctors to surrender judgement to a dashboard. The commission explicitly treats AI as part of a wider healthcare system. Safe performance depends on data quality, staff competence, clinical context and the ability to challenge or override a recommendation.
Why a one-off safety test is not enough
Traditional medical devices may change slowly and predictably. AI systems can be more complicated. Some are fixed after approval, while others may be updated regularly. Even a fixed model can produce different outcomes when the people, scanners or record systems around it change.
Imagine a diagnostic tool trained largely on images from large teaching hospitals. It may not work identically in a smaller hospital with older equipment. A transcription system might save clinicians time but introduce plausible errors into notes. A risk-scoring tool might perform unevenly for demographic groups poorly represented in its training data.
None of those examples proves that medical AI is unsafe. They explain why real-world monitoring matters. The correct comparison is not “fallible machine versus perfect doctor”; clinicians and existing systems also make mistakes. The relevant question is whether the new tool improves care, for whom, under what conditions and with what route for detecting harm.
The MHRA says the next Airlock phase will select its first participants in November. Applications close that month, with a webinar for prospective applicants on 22 October. The programme should produce evidence for future guidance, but a sandbox is not the same thing as national oversight. It tests approaches on selected products. The NHS still needs consistent procurement standards and enough technical expertise to recognise an impressive sales demonstration wearing a stethoscope.
The implementation gap
The government’s acceptance of all 44 recommendations is significant because it avoids the familiar Whitehall manoeuvre of welcoming a report and quietly selecting only the inexpensive nouns. But the hardest commitments are the ones not completed by the announcement.
Hospitals will need people able to monitor performance and investigate incidents. Clinicians will need training that fits inside an already strained service. Developers will need predictable rules, while patients need transparency that is meaningful rather than a 4,000-word privacy notice. Regulators will need access to data and the authority to intervene when performance changes.
There is also a national consistency problem. A safe tool in one trust should not become a mystery box in another because procurement teams received different promises or recorded different outcomes. The commission calls for system-wide responsibility because the risk does not live entirely inside the code.
The timetable deserves attention. A full roadmap by spring 2027 is not unreasonable for a complex regulatory system, but AI adoption is not politely waiting outside. Hospitals and suppliers are already experimenting with diagnostic tools, ambient scribes and workflow automation. Interim guidance and visible incident reporting will matter while the permanent framework is built.
Readers interested in the wider workplace risks can also see our explainer on British workers buying their own AI tools. Healthcare raises the stakes: a mistaken email summary is irritating; a mistaken clinical conclusion can change a life.
The OutOut verdict
Accepting the commission’s recommendations is the correct direction. Medical AI needs more than a launch event, a benchmark score and a founder saying the word “transformative” until the procurement form signs itself.
The promising part is the shift towards lifetime supervision. The test is whether the government builds the unglamorous machinery: reporting, audits, training, responsibility and the power to pause a product. Innovation and safety are not rival teams. Unsafe innovation is simply a faster route to public distrust.
Patients should not have to choose between useful technology and understandable accountability. If AI helps a clinician find disease earlier, reduce paperwork or target treatment better, it deserves a route into the NHS. If it fails, somebody must notice quickly, explain honestly and act. Forty-four accepted recommendations are a beginning. The bedside is where they acquire meaning.