Key Takeaways #
- On 6 October 2026 the government accepted all 44 recommendations of the National Commission into the Regulation of AI in Healthcare. Almost every response ends with "further details to be shared by Spring 2027".
- The firmest next steps are draft MHRA guidance on managing AI updates by December 2026 and a consultation on software and AI device classification by spring 2027. Device identifiers, version traceability and civil sanctions need separate implementation; the response does not put them all into force.
- The response imposes no new statutory duty on NHS providers. Existing clinical risk management requirements, including DCB0160 where applicable, still apply. A new working group on responsibility "will not determine or redistribute responsibilities".
- For procurement, the Commission recommends allocating risk controls in contracts and reporting general-purpose model dependencies, including continuity plans. The government will review contract allocation and develop disclosure expectations; neither is a new blanket duty today.
- Developers can apply now for MHRA AI Airlock Phase 3, which focuses on post-market surveillance. The applicant webinar is on 22 October and the first wave is selected in November.
Sources, checked 7 October 2026: the government response to the National Commission's recommendations (6 October 2026); the DHSC and MHRA announcement Government backs recommendations of NHS doctors-led AI Commission; the Commission's report, Recommendations for a future regulatory framework (10 September 2026); the MHRA's medical device reform timetable; and NHS England's explanation of DCB0129 and DCB0160.
On 6 October 2026 the government accepted, in full, the 44 recommendations of the National Commission into the Regulation of AI in Healthcare. The Commission, chaired by Professor Alastair Denniston with the Patient Safety Commissioner, Professor Henrietta Hughes, as deputy chair, published its report on 10 September after hearing from more than 12,000 patients, clinicians and members of the public.
Its central conclusion is that AI-enabled medical devices should be assessed and monitored throughout their working life, instead of relying on a single approval before launch. The government has now committed to that model. The Health Innovation Minister, James Frith, said innovation "must never come at the expense of patient safety".
Accepting a recommendation is not the same as making it law. Most of the 44 responses commit a body to "explore", "consider" or "review", with details due in an implementation roadmap by spring 2027. The useful question for NHS organisations and their suppliers is which commitments will become binding, on whom, and how soon.
What Was Announced #
- All 44 recommendations accepted. They fall under three principles: proportionate, lifecycle-based regulation (recommendations 1 to 23), system-wide responsibility for safe use (24 to 34), and trust, transparency and predictability (35 to 44).
- AI Airlock Phase 3. The MHRA's regulatory sandbox for AI-enabled medical devices has three more years of funding and opened for applications on 6 October. This phase focuses on post-market surveillance and lifecycle regulation. A webinar for applicants runs on 22 October at 10:00, and the first wave will be selected in November 2026.
- Draft guidance on AI updates by December 2026. The MHRA will propose predetermined change control plans that let manufacturers define the boundaries within which an AI device may change, rather than listing each change in advance.
- A consultation by spring 2027 on how software and AI devices are qualified and classified, followed by secondary legislation that may exclude some administrative, wellbeing and decision support software from regulation as a medical device.
- An implementation roadmap by spring 2027 , with timelines and owners for all 44 recommendations, overseen by a new cross-system Programme Board that meets quarterly.
Accepted in Full, Implementation Still Ahead #
The response commits the government to work in three areas; it does not itself create three new obligations. Existing post-market surveillance requirements for medical devices already apply separately from this announcement.
- Classification. The MHRA intends to consult by spring 2027, then use secondary legislation to update how medical devices, intended purpose and software or AI risk classes are defined (recommendation 1). Those changes are not in force through this response.
- Traceability. The response refers to mandatory unique device identifiers under a pre-market statutory instrument and promises guidance on software version control (recommendation 20). The MHRA'spublished reform timetable describes the UDI requirement as part of planned pre-market regulations; buyers should check the instrument's commencement before treating it as a current duty. Recording versions in patient records is also work to be developed.
- Enforcement. The MHRA says it will implement the civil sanctions regime under the Medicines and Medical Devices Act 2021, allowing financial penalties where appropriate (recommendation 22). The response does not say those new penalties are already being issued.
Other powers still depend on further decisions. The MHRA will explore licensing powers (recommendations 5 and 14), work on statutory sandbox provisions through the Department for Business, Innovation, Science and Trade's proposed Regulating for Growth Bill (recommendation 15), and work toward a public adverse-incident database while considering whether legislation is needed (recommendation 19).
For NHS providers, the response adds no new statutory duty. That does not remove existing duties: DCB0160 already sets clinical risk management requirements for care organisations deploying and using health IT where it applies. On training, the response points to "existing training obligations set out by professional regulators" (recommendation 33). It proposes strengthening guidance under DCB0129 and DCB0160 (recommendation 31). A working group will clarify responsibilities, but "will not determine or redistribute responsibilities" (recommendation 24). Contracts can make the split between supplier and provider risk controls explicit, but they do not replace a trust's existing clinical safety duties. The Commission warned of "liability sinks", where responsibility for errors "may be transferred onto healthcare professionals and providers without sufficiently recognising the influences of AI systems". A trust should assess the deployment under applicable standards and record which party owns each control in the contract.
Toward Stronger Monitoring After Approval #
The government plans to build "an enhanced toolkit" of post-market measures that could be required individually or together (recommendation 17). The Commission's proposed menu includes monitoring plans assessed at authorisation, real-world studies where needed, performance reporting made available publicly and/or to regulators as appropriate, and escalation when performance degrades. The response accepts that direction but leaves the toolkit's detailed requirements, and any legislative changes, for later.
Reporting is also under review. The MHRA plans improvements to the Yellow Card scheme, which could include additional ways to report incidents involving software and AI devices (recommendation 18), and will explore automated reporting through electronic patient records and devices (recommendation 21). DHSC will work to strengthen reporting for "relevant non-device AI tools" too (recommendation 34).
A useful local audit asks three questions about each AI tool in clinical use: can the trust identify the version involved in a patient's care, how is performance monitored locally, and who assesses and reports safety concerns? The answers will depend on the tool and applicable requirements. The response names existing work on ambient voice technology as a model for future national guidance on specific AI categories.
What Procurement Teams and Suppliers Can Prepare For #
Two recommendations could shape future NHS contracts. Buyers and suppliers can address them now without treating the recommendations as new legal duties.
Allocate risk controls in contracts
The Commission recommends that contracts between manufacturers and healthcare providers "should include an explicit allocation of responsibilities for delivering required risk controls" (recommendation 28). The government committed to reviewing how to make that allocation clearer, while the MHRA will develop guidance on operational conditions needed for safe deployment (recommendation 26). A responsibility matrix is a practical step buyers and suppliers can take now; the response does not mandate a new contract clause.
Prepare model dependency disclosures
Under recommendation 8, the MHRA plans guidance on information that products built on general-purpose models would provide in regulatory submissions, including "provenance, nature, dependencies, related risks and their controls". DHSC plans to build related expectations "into procurement processes and contract terms". The Commission also recommends continuity plans. For a clinical documentation tool that calls a third-party foundation model, it would be prudent to document the model, how changes are managed and what happens if it is withdrawn; these are not yet a blanket new disclosure requirement.
Assurance at the point of purchase is also part of the planned work. The government says it will build on the AI Readiness Checklist from CERSI AI, overseen by NHS England, alongside the existing Digital Technology Assessment Criteria, which the response describes as "a national assurance gateway for AI and broader digital technologies" (recommendation 29).
For suppliers, these proposals point toward more evidence after the sale. Buyers may ask for a post-market monitoring plan, a change control plan, a model dependency statement and a responsibility matrix before any new MHRA requirement takes effect.
What to Do Before Spring 2027 #
- Build an AI inventory with versions. List every AI tool in clinical and operational use, including tools that are not medical devices, with the supplier, version, intended purpose and the underlying model where one is used.
- Add four clauses to new AI contracts. A responsibility matrix for risk controls, disclosure of general-purpose model dependencies and continuity plans, notice of material model changes, and access to performance data. Renegotiate high-risk tools at renewal.
- Set a local monitoring plan for each high-risk tool. Define the performance measure, the threshold that triggers escalation, who reviews it and how often, and who assesses whether an incident needs reporting through Yellow Card or another applicable route.
- Suppliers: prepare evidence buyers may request. A post-market surveillance plan, a draft change control plan and a model dependency statement. Developers with an eligible device should consider AI Airlock Phase 3 and join the 22 October webinar.
- Respond to the MHRA's consultations. Comment on the draft change control guidance when it is published in December, and on the classification consultation in spring 2027. The resulting classification rules may change whether some decision support tools fall within medical device regulation.
Frequently asked questions #
What did the government agree on AI in healthcare on 6 October 2026?
It accepted all 44 recommendations of the National Commission into the Regulation of AI in Healthcare, chaired by Professor Alastair Denniston. The response commits to developing more lifecycle-based oversight of AI medical devices, with an implementation roadmap due by spring 2027. Acceptance did not itself bring every proposed measure into force.
Do NHS trusts have new legal duties for AI?
The 6 October response does not itself impose a new duty on trusts. Existing clinical risk management requirements still apply where relevant, including DCB0160 for the deployment and use of health IT. The response proposes further guidance and clarification of responsibilities; its working group will not redistribute them.
What will AI suppliers to the NHS have to disclose?
The government plans MHRA guidance on information about general-purpose model dependencies in regulatory submissions and expects these disclosures to be reflected in future procurement processes and contract terms. The Commission also recommended continuity plans. The response does not create a blanket new disclosure duty today.
What is AI Airlock Phase 3?
It is the third phase of the MHRA's regulatory sandbox for AI-enabled medical devices, focused on post-market surveillance and lifecycle regulation. Applications opened on 6 October 2026, a webinar for applicants runs on 22 October and the first wave will be selected in November 2026.
We cover UK AI policy as it develops. Get new posts by email.