UK Accepts All 44 NHS AI Commission Recommendations, Sets December 2026 Deadline
Source
Government backs recommendations of NHS doctors-led AI CommissionMedicines and Healthcare products Regulatory Agency (MHRA) / UK Government
What happened
The UK government accepted all 44 recommendations from the National Commission into the Regulation of AI in Healthcare. Its response is detailed in Government backs recommendations of NHS doctors-led AI Commission. The commitment moves the Medicines and Healthcare products Regulatory Agency (MHRA) away from single point-in-time approvals toward a staged, lifecycle-based framework for AI-enabled medical devices. Specific deliverables include draft MHRA guidance on AI device change management by December 2026 and a full implementation roadmap due by Spring 2027. Alongside this, the MHRA opened applications for AI Airlock Phase 3, a regulatory sandbox focused specifically on post-market surveillance and continuous monitoring of AI medical devices. The Airlock program gives medtech companies an opportunity to work directly with the regulator to shape the practical standards that will underpin the new framework.
Why it matters
- ·Compliance programs built around one-time device approval will not satisfy the new framework. Organizations selling AI-enabled medical devices into the UK market should begin mapping how their change management and post-market surveillance processes align with the December 2026 MHRA draft guidance.
- ·The MHRA AI Airlock Phase 3 sandbox creates a concrete opportunity for early regulatory engagement. Companies that participate can help shape practical standards and demonstrate proactive compliance, which is increasingly a factor in both procurement decisions and regulatory goodwill.
- ·Health sector procurement teams face a vendor due diligence gap: AI medical devices approved under current rules may not meet lifecycle governance requirements as new standards take effect. Contracts signed now should include provisions for ongoing conformance assessment and change notification obligations.
Governance controls affected
What to do now
- ☐Identify every AI-enabled medical device in your product portfolio or procurement pipeline that is sold or used in the UK, and flag each for review against the incoming lifecycle-based framework.
- ☐Review current change management documentation for AI medical devices to determine whether it captures the type of continuous monitoring and post-market evidence the MHRA December 2026 draft guidance is likely to require.
- ☐Ask your regulatory affairs and procurement teams whether supplier contracts for AI medical devices include obligations for vendors to notify you of material updates or retraining events that could affect device behavior.
- ☐Assess whether your organization should apply for AI Airlock Phase 3 to engage directly with MHRA on post-market surveillance standards before they are finalized.
- ☐Set a calendar trigger for December 2026 to review the draft MHRA guidance on AI device change management and assess any gap between current practices and the new requirements.
What to watch next
Compliance teams should monitor the MHRA's publication of draft AI device change management guidance, expected by December 2026, and the full implementation roadmap due Spring 2027. The AI Airlock Phase 3 application window is open now, and companies that miss it will have less influence over the practical standards that emerge. More broadly, this development is part of a wider pattern of regulators moving from static approvals to continuous oversight of AI systems in regulated sectors. Teams should watch for the EU AI Act to develop analogous requirements for high-risk medical AI under its own conformity assessment and post-market monitoring obligations.
Stay ahead of stories like this
Get every UK AI governance development like this one, plus the rest of the week's developments. Every Thursday.
Recent issues
- AI agents this week destroyed backups at machine speed, leaked sensitive data without developer approval, and drew federal scrutiny that may extend liability to every enterprise deploying them.1 Oct
- A vulnerability that bypasses approved-plugin controls, new criminal liability for executives, and a landmark safety-disclosure framework all point to one conclusion: AI systems are outpacing the controls organizations have built around them.23 Sept
Free every Thursday. Unsubscribe anytime.
