44 Recommendations, 12,000 Voices: The UK Just Published Its Blueprint for Regulating AI in Healthcare
The National Commission into the Regulation of AI in Healthcare proposes AI 'L-plates', lifelong monitoring, and patient transparency rights for the NHS — the most detailed framework of its kind.
The Medicines and Healthcare products Regulatory Agency (MHRA) has published the final report of the National Commission into the Regulation of AI in Healthcare — 44 recommendations that amount to the most detailed attempt yet by any country to answer a question every health system now faces: how do you let AI into the clinic without losing control of it?
The report, published on 10 September 2026, was led by two practising NHS doctors — Professor Alastair Denniston, a consultant ophthalmologist who chaired the Commission, and Professor Henrietta Hughes, a GP who served as Deputy Chair and is Patient Safety Commissioner for England. It was established by the MHRA in September 2025 and took a full year of evidence-gathering, drawing on input from more than 12,000 people: patients, carers, clinicians, healthcare leaders, industry and technology developers. The MHRA describes it as the largest engagement exercise ever undertaken in the UK on the regulation of healthcare technology.
Why the current rulebook doesn’t fit
At the heart of the report is a blunt diagnosis: the UK’s medical device regulatory framework was built for a different era of technology. MHRA Chief Executive Lawrence Tallon put it plainly to the BBC — the framework “predominantly dates from a period where we were thinking about things like hip replacements and knee replacements, or smaller things like stethoscopes and plasters.”
That rulebook works tolerably well for a static AI product trained to spot known symptoms on a scan. It breaks down for the systems now arriving: generative models and adaptive algorithms that keep changing after approval. “Unlike most of the medical products we’re used to regulating, these products continue to change after the point of authorization,” Tallon said. “As new data gets fed in, they learn, they adapt, they drift.”
Professor Neil Lawrence, Chair of the Commission’s Technology Working Group and the DeepMind Professor of Machine Learning at Cambridge, made the same point from the research side: generative AI “can behave differently in different circumstances, and it can evolve after its initial deployment. That means we can’t rely on a single point of approval and assume the job is done.”
The four pillars of the blueprint
AI ‘L-plates’ — staged authorisation. The Commission’s flagship proposal borrows from learner-driver licensing. New AI models would be deployed in the NHS under close supervision and tight guardrails, and would have to demonstrate real-world safety and performance before earning fuller authorisation. The intent is explicitly dual: give UK patients “world-first access” to promising models while keeping risk controlled at every step.
Lifelong monitoring, not point-in-time approval. AI-enabled medical devices should be watched continuously throughout their working lives, not just vetted once at launch. Because deployed systems learn and drift, the regulator needs standing visibility so it can act quickly when performance degrades — including the power to pull products from approval when they malfunction or become less effective over time.
Patient transparency rights. The public should be able to easily search for safety information about specific AI medical devices, including adverse incident reports, building on the MHRA’s existing interactive Drug Analysis Profiles. Patients also told the Commission they want to know when AI is involved in their care, and the recommendations set out a proportionate way to keep them informed as AI becomes embedded in NHS services.
Tougher enforcement. The MHRA would get enhanced enforcement powers, including the ability to penalise developers whose products fail to meet required standards — closing a gap where an approved-but-drifting system currently has few consequences attached to it.
The evidence behind it: trust, on conditions
The scale of public engagement is what makes this report unusual. Beyond the 12,000-person evidence base, the Health Foundation ran in-depth deliberative research with the UK public, published alongside the report. The finding was consistent: broad support for AI in healthcare, with three strings attached — strong safety standards, meaningful human oversight, and transparency about when and how AI is used in someone’s care.
That maps closely onto what AI already does in the NHS today: spotting strokes and skin cancers earlier, and freeing clinician time through voice-enabled tools. AI scribes powered by large language models are reportedly used by around 40% of UK GPs to record consultations and draft notes. But adoption is outpacing comfort. A recent University of Edinburgh study found patients can be less willing to share sensitive information — such as substance abuse history — when they know an AI is processing the conversation. Hughes noted that some of her patients opt out entirely: “Some say, ‘I don’t want to talk to a robot’, and that is also fine.”
Analysis: regulation as competitive strategy
The most interesting thing about the report is its framing. This is not a brake-pumping exercise. Denniston describes AI as “an exceptional opportunity” for healthcare, “likely to rank alongside step-changes such as antibiotics and MRI,” and the report’s stated ambition is to make the UK “the best place for innovators to build and safely test AI, the best place for healthcare professionals to use it and, most importantly, the best place for patients to engage with it in their care.”
In other words, the UK is betting that credible regulation is what unlocks adoption, not what slows it. The L-plate mechanism is the clearest expression of that bet: it lowers the barrier to early real-world trials — precisely what AI developers complain is hardest in healthcare — while keeping a supervisory lid on risk. If it works, UK pilots become faster than those in less structured markets, and the evidence generated during supervised deployment feeds directly into fuller authorisation.
The risks are equally clear. Jennifer Dixon, Chief Executive of the Health Foundation, flagged the implementation gap: the real test is “whether the NHS has the capacity, skills and systems in place to implement and monitor AI applications safely and effectively at the scale now needed.” Continuous monitoring of every deployed AI device is a serious operational undertaking for a regulator currently funded for periodic assessments — and for hospitals that would need to feed real-world performance data back to the MHRA.
There is also the global dimension. Tallon acknowledged that no country has “absolutely cracked it” when it comes to AI regulation. The EU’s approach under the AI Act treats medical AI primarily through risk classes defined largely at launch; the US FDA has wrestled for years with its own predetermined change control plans for adaptive algorithms. The UK’s lifecycle-plus-L-plates model, built on an unusually deep public evidence base, is a genuinely different entry in that field — and one other regulators will read closely.
What happens next
The government and the MHRA will now consider the recommendations, with a formal response to follow. Legislation would be required for some elements, notably the enhanced enforcement powers. Until then, the report stands as both a policy document and a statement of direction: AI in the NHS is coming at scale, and the UK intends to be the country that shows it can be governed — not merely adopted — with public trust intact.
As Denniston put it: “These technologies need to show that they are safe, effective and bring benefits to patients, staff and the wider NHS, without leaving people behind. These recommendations are designed to make that trust possible, so that the UK can lead the world not just in developing AI for healthcare, but in showing how it can be regulated and used responsibly.”