AI工具Score B (47)
National Commission into the Regulation of AI in Healthcare: Recommendations for a future ...
3 小时前3 viewsSource: gov.uk
Medicines & Healthcare products Regulatory Agency Print this page © Crown copyright 2026 This publication is licensed under the terms of the Open Government Licence v3.0 except where otherwise stated. To view this licence, visit nationalarchives.gov.uk/doc/open-government-licence/version/3 or write to the Information Policy Team, The National Archives, Kew, London TW9 4DU, or email: psi@nationalarchives.gov.uk . Where we have identified any third party copyright information you will need to obtain permission from the copyright holders concerned. This publication is available at https://www.gov.uk/government/publications/national-commission-into-the-regulation-of-ai-in-healthcare-recommendations-for-a-future-regulatory-framework/national-commission-into-the-regulation-of-ai-in-healthcare-recommendations-for-a-future-regulatory-framework Foreword Healthcare is about people. In healthcare we are interested in technology not for technology’s sake, but because of its potential benefits to people. We want to see more accurate diagnostics, more effective treatments, and better access to sustainable, high-quality services. Any technology – including artificial intelligence (AI) – has to prove its worth. As with any technology we need to consider the opportunities and the risks. We require evidence of the benefits, the safety profile and downstream consequences. We need to ensure that our systems can be trusted to bring safe and effective technologies to patients and the health system, whilst keeping out those that are unsafe, ineffective or not yet ready. The National Commission into the Regulation of AI in Healthcare is people-centred rather than tech-centred. It is about defining what we want our future AI-enabled healthcare system to look like, and how we use regulation to shape that future. In chairing this Commission, we have brought our experience as a hospital doctor and a general practitioner, to keep the discussions, however technical, grounded in the reality of healthcare, and focused on people. We have been supported in this endeavour by a huge number of patients, the public, healthcare professionals, innovators, regulators, policymakers, healthcare leaders and others, who have generously shared their perspectives on the opportunities and challenges presented by AI in healthcare. Contributing through individual conversations, formal public dialogues, large-scale surveys, ‘Call for Evidence’ submissions, expert working groups, and international engagements, all these insights have influenced the Commission and its recommendations. What we heard was not a debate about whether AI should be used in healthcare, but rather how it should be used. People are simultaneously enthusiastic about its potential benefits, and worried about the risks. They want to see healthcare ‘catch up’ with other sectors where this would lead to faster, more personalised services; but they also want reassurance that any AI is introduced responsibly and equitably, that accountability remains clear, that concerns are heard and acted upon, and that the benefits of innovation are felt by patients and healthcare staff. Trust, in other words, cannot be assumed. It must be earned. People want to know that any move towards greater use of AI in healthcare has been considered in terms of its impact not only on some people, or on the majority, but on everyone. We have viewed every discussion, and every recommendation through that lens. The changes described here are designed to improve safety for everyone, to accelerate beneficial innovation for everyone, and to do whatever we can to ensure that AI in healthcare reduces inequality gaps rather than worsens them. Every single one of our recommendations should be viewed through this lens. In being people-centred, we have considered not only what AI means for all who use healthcare, but also what it means for all those who provide healthcare. Patients, carers and the wider public have consistently stressed the importance of human connection, and of human oversight. As healthcare professionals, our roles may change, but it is clear that we still have a role and that role is valued. The challenge from the public is to find a path for ‘AI to do what AI is good at, and humans to do what they are good at’. Indeed, there is an important opportunity here for AI to improve the working lives of healthcare staff and reduce the risk of burn-out. Healthcare professionals recognise many routine and frustrating tasks that simply get in the way of us delivering high-quality care, and we would welcome the opportunity for AI assistance on those tasks to allow us to spend more time on those parts of our role where we can make the most difference. This report represents the culmination of one of the most extensive programmes of research and engagement undertaken on AI in healthcare. Our recommendations have been shaped by evidence gathered from across the four nations, alongside the expertise of Commission members, working groups and partner organisations. Most importantly, they have been informed by the people who will ultimately be affected by the decisions that follow. We would like to express our sincere thanks to everyone who contributed to this work. To those who responded to the Call for Evidence, participated in public engagement activities, joined roundtables and working groups, challenged our assumptions and shared their expertise and experience: this report is stronger because of your contribution. Publication of this report is not the end of a conversation. It is the beginning of the next phase. The recommendations set out here will require continued collaboration between government, regulators, healthcare providers, professionals, industry, patients and the public. Success will depend not on the actions of any single organisation, but on a shared commitment to delivering this together. The regulatory framework set out in this report addresses both the opportunities and the risks of AI in healthcare. We aim to ensure that patients can benefit earlier from AI technologies that are safe, effective, and equitable; to provide greater confidence to health professionals in their delivery of healthcare in an AI-enabled world; and to give greater clarity to innovators as they develop these technologies. This is about creating a future healthcare system that is increasingly tech-enabled and always people-centred. Professor Alastair Denniston Chair, National Commission into the Regulation of AI in Healthcare Professor of Regulatory Science and Innovation at the University of Birmingham Honorary Consultant Ophthalmologist, University Hospitals Birmingham NHS Foundation Trust Executive Director, Centre of Excellence for Regulatory Science in AI & Digital Health (CERSI-AI) Professor Henrietta Hughes Deputy Chair, National Commission into the Regulation of AI in Healthcare Patient Safety Commissioner for England General Practitioner and Visiting Professor, Institute of Medicine, University of Greater Manchester Executive summary Artificial Intelligence (AI) has the potential to transform healthcare. It can support earlier diagnosis, more personalised care, improved patient outcomes and better experiences for clinicians, while helping the NHS and wider health system meet rising demand. AI should augment, rather than replace healthcare professionals. Used responsibly, AI can automate routine and administrative tasks, streamline patient care and enable professionals to focus on communication, compassion and shared decision-making. However, software and AI products also present regulatory challenges that differ from those associated with traditional medical devices. Unlike many conventional devices, AI products may evolve over time, with their performance being context-dependent and sensitive to real-world deployment environments. The National Commission into the Regulation of AI in Healthcare was established to advise government on a future regulatory framework for AI in healthcare. In doing so, it is considering not only the regulation of safe and effective software and AI-enabled medical devices but also wider issues such as accountability, transparency, clinical practice, organisational governance and system-wide level assurance. Its mission is to help ensure that patients can benefit from safe and effective AI technologies, support the government’s ambition to make the NHS the most AI-enabled healthcare system in the world, and establish a globally competitive regulatory environment that attracts investment and supports innovation. The Commission’s recommendations are grounded in a research and engagement programme , including the Call for Evidence, public deliberation events, engagement with groups who are seldom-heard, professional and industry roundtables, specialist working groups and further engagement across government and the health system. What the evidence showed The evidence showed strong support for the use of AI in healthcare, but this support is conditional, rather than automatic. People are not asking simply whether AI should be used in healthcare. They are asking how it can be used safely, fairly and transparently, with clear evidence of benefit, meaningful human oversight, accountability and continued public trust. What needs to change The Commission’s central conclusion is that the regulation and assurance of AI in healthcare must become more proportionate, lifecycle-based and system-wide. Current approaches were largely designed for products that are more static and easier to reliably assess at a single point in time. AI-enabled products may iterate rapidly, perform differently in different settings and depend on the data, workflows, people and organisations around them. A framework that relies too heavily on one-off pre-market assessment will not be enough. Regulation must support safe, effective and trusted use throughout the lifecycle of a device, from development and deployment through to monitoring, updating and learning from real-world use. More continuous monitoring of these products, once deployed, will be needed to provide ongoing assurance across the lifecycle. The United Kingdom (UK) needs a framework that is safe, fast and trusted: safe in protecting patients and managing risk; fast in enabling responsible innovation and timely access to beneficial technologies; and trusted in giving confidence to patients, professionals, providers, developers, manufacturers, regulators and government. Delivering the vision The Commission’s recommendations are organised around three connected areas of change. 1. Proportionate lifecycle regulation AI-enabled devices require regulatory approaches that reflect their distinctive characteristics. The future framework should support proportionate and tailored oversight across the product lifecycle, including clear routes to market, flexible mechanisms to support rapid device iteration and stronger use of real-world evidence to support ongoing assurance. Key themes include: proportionate regulation focused on risk and benefit health equity as an ethical imperative and a critical aspect of safety and performance improved device qualification and classification pathways flexible mechanisms for safe device iteration and updating staged routes to market that support innovation while generating real-world evidence greater use of regulatory sandboxes enhanced enforcement mechanisms international leadership, harmonisation and recognition. 2. System-wide responsibility and safe management Safe and effective use of AI in healthcare depends on more than regulation alone. Regulation cannot be the only enabler of change; the safe and effective use of AI will require a collaborative, system-wide effort. Manufacturers, healthcare providers, healthcare professionals, regulators and policymakers all have a role to play. The future framework should support clear responsibilities, organisational readiness, workforce capability and effective governance across the healthcare system. Key themes include: fostering a culture of safety for everyone in relation to AI AI readiness toolkit to support healthcare organisations clear responsibilities throughout the product lifecycle, including liability arrangements strong governance arrangements for implementation and monitoring workforce capability and AI literacy best practices for procurement, deployment and risk controls 3. Trust, transparency and predictability Public confidence is essential to realising the benefits of AI in healthcare. The future framework should strengthen transparency, accountability and patient involvement, while providing clearer and more predictable pathways for innovators. Key themes include: system approach to improved transparency of AI used in care pathways enhanced, inclusive patient and public engagement in policymaking processes stronger user-centred design and transparency for device users improved communication about safety concerns for patients and healthcare professionals educational resources and tools to demystify the regulatory journey predictable mechanisms for early engagement with regulators to support innovation. What this means in practice Together, these three areas of change support the Commission’s vision for a regulatory and assurance framework that is safe, proportionate, trusted, flexible and works for everyone. The recommendations are designed not only to address today’s challenges, but also to create a framework that can evolve as technologies, evidence and patterns of use change over time. In doing so, they support the UK’s ambition to become a global leader in AI-enabled healthcare innovation and regulation. The Commission is therefore not proposing a single new process or a narrow set of technical fixes. It is recommending a modern framework that recognises the distinctive characteristics of AI-enabled products and supports safe innovation throughout the product lifecycle. The framework is intended to protect patients, support healthcare professionals, provide confidence for healthcare providers and create a predictable environment for innovators. In practice, this means: For patients and the public, greater confidence that AI technologies used in healthcare are safe, effective, inclusive and properly governed, alongside greater transparency about when and how AI is used in their care and clearer routes to raise concerns when things go wrong. For healthcare professionals, clearer expectations regarding the safe use of AI, better access to training and support, stronger mechanisms for reporting concerns, and greater clarity regarding accountability and responsibilities. For healthcare providers, practical tools to assess organisational readiness, deploy technologies safely, monitor performance over time and demonstrate effective governance of AI-enabled products. For developers and manufacturers, a pragmatic, proportionate and innovation-friendly regulatory framework that provides clearer expectations, more predictable pathways and greater regulatory clarity throughout product development, deployment and improvement. Regulation should not operate as a barrier, but as a framework that helps innovators, regulators and healthcare systems work together to ensure new technologies are safe, effective and ready for real-world use. For regulators and government, a more joined-up system that can learn from real-world evidence, respond to emerging risks, adapt as technologies evolve, maintain public confidence and support the UK’s long-term global leadership in AI-enabled healthcare innovation. Next steps AI presents one of the most significant opportunities to improve healthcare in a generation. Realising that opportunity will require a regulatory and assurance framework that evolves alongside the technology itself: protecting patients, enabling responsible innovation and maintaining public trust. The Commission’s recommendations aim to provide a foundation for the Medicines and Healthcare products Regulatory Agency (MHRA), government and wider system partners to achieve that ambition. A cross-government response will follow separately, setting out how government and system partners will consider and take forward the recommendations. Introduction Background Through the 10 Year Health Plan for England and the Life Sciences Sector Plan , the UK Government has set out an ambition for the NHS to become one of the most AI-enabled healthcare systems in the world. AI has the potential to improve health outcomes, support healthcare professionals, increase productivity and contribute to growth in the UK’s life sciences sector. At the same time, AI is creating new questions about regulation, governance, accountability and public confidence [footnote 1] . These questions extend beyond any single regulatory framework or organisation and affect how technologies are developed, deployed, monitored and used across the health system. AI used in healthcare may fall within different regulatory and governance regimes depending on its intended purpose, functionality and context of use. Some AI-enabled products will qualify as medical devices and be regulated under the UK Medical Devices Regulations 2002 (as amended) and associated MHRA requirements. Others may be governed primarily through data protection law, professional standards, organisational governance, consumer protection law or other sector-specific frameworks. AI is used across a wide range of healthcare applications, from administrative tools to decision support for healthcare professionals and direct-to-consumer products, and not all applications are regulated in the same way. As adoption increases, questions have emerged around qualification and classification of software and AI-enabled medical devices, visibility of use across the health system, post-market monitoring in real-world settings, accountability and the suitability of existing regulatory approaches for technologies that may be frequently updated over time. These developments have prompted consideration of whether regulatory and assurance approaches should evolve to better reflect how AI technologies are developed, deployed and used in practice. Scope of the National Commission The National Commission considered the wider regulatory ecosystem for AI in healthcare. This includes product regulation, professional regulation, organisational governance, patient safety and redress, public confidence, and the wider systems and institutions that support the safe adoption and oversight of AI in healthcare. While many of the Commission’s recommendations relate to software and AI-enabled medical devices, the Commission’s remit was broader than UK medical device regulation alone. The report addresses AI products regulated as medical devices and considers wider uses of AI in healthcare where issues such as safety, accountability, governance, transparency and public confidence are relevant. Throughout this report, the term ‘product’ is used deliberately to encompass both AI-enabled medical devices and other AI-enabled products used in healthcare that are not subject to UK medical device regulation. The Commission considered how different forms of regulation, assurance, governance and oversight should work together to support the safe, effective and responsible use of AI in healthcare. This includes the roles of government, regulators, healthcare providers, professionals, developers, manufacturers, patients and the public. The Commission recognises that successful implementation of its recommendations will require regulatory bodies to be appropriately resourced and equipped with the necessary capability and capacity. The National Commission and its approach The National Commission into the Regulation of AI in Healthcare was established by the MHRA in September 2025 as an independent expert advisory body. It was asked to consider how the UK’s regulatory and assurance framework should evolve to support the safe, effective and responsible use of AI in healthcare. Chaired by Professor Alastair Denniston and Deputy Chair Professor Henrietta Hughes, the Commission brought together expertise from healthcare, technology, law, patient groups, the public, government, the NHS, and partners across England, Scotland, Wales and Northern Ireland. The Commission also sought international expertise, inviting stakeholders from partners in the United States (US), Europe and Singapore to support its work. Its work was supported by a core group of experts, providing strategic oversight and challenge, and four specialist working groups: Cross Whitehall Working Group Devolved Authorities Working Group Brought together government departments and public bodies to consider policy alignment and wider regulatory and system implications. Brought together partners from across England, Scotland, Wales and Northern Ireland to reflect different health systems, delivery contexts and responsibilities. Health Systems Working Group Technology Working Group Considered how AI-enabled technologies operate within healthcare pathways, including governance, adoption, operational readiness and safe management. Provided technical insight on AI capabilities and their regulatory implications, helping ensure recommendations were grounded in how technologies are developed and deployed. Together, these groups helped ensure that the recommendations were informed by practical delivery considerations as well as regulatory principle. What we heard The Commission’s recommendations were informed by a UK-wide research and engagement programme coordinated on behalf of the Commission by the MHRA [footnote 2] . This included an open Call for Evidence, targeted engagement with patients, healthcare professionals and industry, public deliberation sessions delivered with The Health Foundation, engagement with seldom-heard groups supported by National Voices, and structured clinical engagement with healthcare leaders. Taken together, this represented one of the most extensive programmes of engagement undertaken on AI in healthcare in the UK. The evidence highlighted both the opportunities presented by AI and the expectations that accompany its adoption. Stakeholders consistently emphasised the importance of maintaining patient safety, public confidence, transparency and accountability while enabling innovation and beneficial technologies to reach all patients, so that the benefits of AI are felt by everyone. The recommendations that follow seek to respond to those expectations through a framework that is proportionate, lifecycle-based, flexible and focused on supporting equitable access to safe and effective technologies. Purpose of this report This report sets out the Commission’s recommendations for the future regulation and assurance of AI in healthcare. The recommendations are intended to: support timely and inclusive access to safe and effective AI-enabled technologies strengthen patient safety and public confidence support healthcare providers and professionals in the safe adoption of AI provide greater clarity and predictability for developers and manufacturers help ensure that regulation and governance remain effective as technologies evolve. The report is directed at government, regulators, healthcare providers, professional bodies, developers, manufacturers and others with a role in shaping the future use of AI in healthcare. Structure of this report The report is organised around three connected themes. Chapter 1: Proportionate lifecycle regulation This chapter considers how regulatory approaches should evolve to reflect the characteristics of AI-enabled technologies. It explores how regulation can be proportionate to risk and benefit, informed by evidence generated across the product lifecycle, and designed to support timely and equitable access to safe and effective technologies. Chapter 2: System-wide responsibility and safe management This chapter examines how the safe adoption, management and oversight of AI-enabled technologies should be supported across the healthcare system. It considers how responsibilities should be shared across manufacturers, healthcare providers, professionals, regulators and other system partners, and how accountability, organisational readiness, workforce capability and governance can support their safe and effective use. Chapter 3: Trust, transparency and predictability This chapter explores how trust, transparency and predictability can be strengthened across the healthcare ecosystem. It considers how greater transparency, clearer accountability, meaningful stakeholder involvement and more navigable pathways can support the responsible development, adoption and use of safe and effective AI technologies. Together, these chapters set out the Commission’s recommendations for a regulatory and assurance framework that is safe, proportionate, trusted and flexible, supporting both innovation and public confidence in AI-enabled healthcare. A key consideration for the Commission was to define its scope, in terms of both breadth and depth. In terms of breadth, the Commission centred on those AI-enabled technologies which are involved in direct patient care. Particular attention is given to technologies that qualify as medical devices, given their risks and regulatory requirements. In terms of depth, the Commission operated at four tiers, and the recommendations are aligned accordingly. Tier 1 describes the overall intent in terms of what the new regulatory framework should be characterised to be: person-centred, safe, fast and trusted. This is the ‘why’. Tier 2 describes the three key regulatory principles that emerged during the Commission and starts to provide some degree of specificity to the key elements of the proposed new framework. Each chapter reflects one of these three principles. This is the ‘what’. Tier 3 describes the specific regulatory innovations and changes that are necessary in order to achieve the desired new framework. This has a much higher degree of specificity and is contained within the individual recommendations. This is the ‘how’. Tier 4 would be the detail of the policy change itself, and needs to sit with the relevant regulator, government department or other body responsible for those actions. The Commission sought to balance its remit to set direction and shape the new regulatory framework, without stepping into the remit of the policymakers themselves; in responding to these recommendations, it will be important that policymakers have the flexibility to respond in line with a fast-moving technology field and a fast-moving policy landscape. Testing the recommendations across the UK system Healthcare is a devolved policy area in the UK. Responsibility for healthcare policy sits with the Department of Health and Social Care (DHSC) in England and the devolved health departments in Scotland, Wales and Northern Ireland, while healthcare is delivered through the respective national health systems. These health systems are further supported by an ecosystem of national and devolved bodies, including sector regulators, professional regulators, representative bodies, and national guidance organisations (see Glossary of terms and acronyms ). Unless otherwise stated, references to the relevant healthcare organisations should be understood to include all organisations that may have a role in implementing, supporting or overseeing recommendations, as appropriate within England and each of the devolved authorities. The following terms are used to distinguish between different groups of organisations involved in implementing recommendations: ‘DHSC and the devolved health departments’ refers to the health policy functions of the UK Government and the devolved governments (see Glossary of terms and acronyms ). ‘Relevant healthcare organisations from England and the devolved authorities’ is used where recommendations may affect organisations beyond the health departments themselves, including national health system bodies, sector regulators and professional regulators (see Glossary of terms and acronyms ). The Commission Chairs undertook further engagement with groups across government and the health system, taking a four-nation approach, to test the practical implications of the recommendations prior to publication. This engagement helped ensure that the recommendations took account of different health system arrangements, governance structures and implementation environments across England, Scotland, Wales and Northern Ireland. The Commission believes it is important to maintain a four-nations approach to UK medical device regulation wherever feasible and appropriate. At the same time, implementation will need to reflect differences in governance, digital maturity, workforce capacity and service delivery across the four nations. This includes the distinct position of Northern Ireland under the Windsor Framework and the need to consider national requirements such as Welsh language standards. Continued engagement with devolved authorities and wider health system partners will be important as the recommendations are taken forward. Looking ahead These recommendations support the creation of a regulatory framework that aims to address the needs of today, while introducing sufficient flexibility to engage with the needs of tomorrow. The acceleration of AI innovation will bring further potential opportunities for patients and the health system, but also new regulatory challenges that will need to be addressed. Despite the flexibility we have provided here, we anticipate that updates will be needed over time to address new specific challenges and opportunities. We anticipate that the core principles underlying our recommendations will remain true, even if the mechanisms to achieve them may need to be updated to match advances in the technologies being considered. The Commission has highlighted the extent to which the regulation and assurance of AI in healthcare is something that affects all of us, and that there is an enthusiasm across all groups to work together to shape what that AI-enabled future looks like. There is a need to ensure that as the Commission finishes, the collaboration and dialogue continue. There needs to be a continuation of the very constructive discussions across the health system, government and wider society, as we seek together to iterate the UK’s regulatory framework and wider system assurance, to responsibly engage with the emerging benefits of AI in healthcare. Members of the National Commission into the Regulation of AI in Healthcare Chair - Professor Alastair Denniston, Professor of Regulatory Science and Innovation at the University of Birmingham; Honorary Consultant Ophthalmologist at University Hospitals Birmingham NHS Foundation Trust, and Executive Director of the UK Centre of Excellence for Regulatory Science in AI & Digital Health Tech (CERSI-AI). Deputy Chair - Professor Henrietta Hughes OBE, Patient Safety Commissioner for England; practising GP and Visiting Professor at the Institute of Medicine, University of Greater Manchester. Professor Neil Lawrence , DeepMind Professor of Machine Learning at the University of Cambridge; Chief Scientist at Trent AI. Professor Catherine Sudlow OBE , Head of School of Population Health Sciences, University of Edinburgh; Director of UKRI Adolescent Health Study. Dr Brian Anderson , CEO of the Coalition for Health AI (CHAI). Dr Ricardo Baptista Leite , CEO of HealthAI. Adjunct Professor Raymond Chua , CEO of Health Sciences Authority; Deputy Director-General of Health (Health Regulation) for Ministry of Health, Singapore. Dame Jennifer Dixon , Chief Executive of the Health Foundation. Dr Paul Goldsmith , Non-Executive Director of the MHRA; Chair of the MHRA’s Regulatory and Safety Committee; visiting Professor at the Institute of Global Health Innovation, Imperial College London; Consultant Neurologist and Clinical Senate. Professor Vish Ratnasuriya MBE , Practising GP; Chair of Our Health Partnership; co-founder of Primary Care Accelerator; Honorary Professor at the University of Birmingham. Dr Gabriella Spinelli , Head of Brunel Design School, College of Engineering, Design and Physical Science, Brunel University of London. Dr Barry Stein , Chief Clinical Innovation Officer and Chief Medical Informatics Officer for Hartford HealthCare. Richard Stubbs , Chief Executive of Health Innovation Yorkshire & Humber. Professor Richard Susskind CBE KC , President of the Society for Computers and Law. Chapter 1. Proportionate lifecycle regulation Key principle: Ensure regulatory requirements are proportionate to a device’s risks and benefits, tailored to the evidentiary needs across the product lifecycle and support equitable access to safe and effective software and AI-enabled technologies. Chapter summary This chapter sets out recommendations to support a more proportionate, risk-based and lifecycle-focused approach to regulating software and AI-enabled medical devices, from understanding when a product is a regulated medical device through to pre-market evidence needs, efficient routes to market, post-market surveillance and taking action when something goes wrong. As software and AI-enabled medical devices continue to develop, it is critical to have a proportionate and tailored regulatory approach to support their safe and effective use. This tailored approach needs to recognise that there are many types of software and AI-enabled devices, such that it should enable a right-sized approach to a given device’s intended purpose, risks, and benefits. To face the needs of the rapidly evolving technological landscape, regulation and evidence generation for these devices must become more continuous across the product lifecycle, including for safety and performance. The current regulatory framework for medical devices was not designed for software and AI-enabled medical devices, particularly devices whose design and performance can change over time. The current framework generally relies on performance and safety data at the pre-deployment stage and gathers insight on adverse outcomes through reactive post-market surveillance. The current framework is not fit-for-purpose for these technologies, as it lacks the necessary balanced lifecycle oversight mechanisms for software and AI-enabled medical devices. Specifically, the current approach is heavily weighted on pre-market assurance, which does not work well for these devices as they may show significant differences in performance between pre-market and real-world deployment. These devices also may experience performance drift over time, including as a result of context-dependent differences between sites and environments of use. Further, the current framework was not designed to practically accommodate the frequent updates or changes these devices may be subject to over their lifecycle. Patients, healthcare professionals [footnote 3] , industry and policymakers who took part in the National Commission’s research and engagement programme also highlighted that current regulatory frameworks are not well matched to AI [footnote 4] . Additionally, the emphasis on lifecycle oversight is consistent with public expectations, with a recent report from The Health Foundation highlighting strong support for continuous monitoring and real-world evaluation of AI-enabled technologies after deployment, rather than relying on initial regulatory approval alone [footnote 5] . Moving forward, a more tailored, flexible and proportionate approach to regulation is required. This can not only enhance safety but can foster an ecosystem that enables innovation through ensuring that the regulatory requirements are proportionate, and that they do not impose unnecessary regulatory burden that could hinder patient access to beneficial devices. This approach should enable MHRA to focus its time and resources on devices that benefit from closer scrutiny and oversight. In a lifecycle-based regulatory framework that has sufficient flexibility, levels of regulation for device types may need to be reviewed and updated over time, based on understanding of safety, performance and ongoing controls such as post-market surveillance taking place as a more integrated, real-time activity. For medium and high-risk medical devices, the current Great Britain regulatory framework relies on conformity assessment by MHRA-designated Approved Bodies [footnote 6] . Following a successful assessment against the requirements set out in the UK Medical Device Regulations 2002 [footnote 7] (SI 2002 No 618, as amended) (UK MDR 2002), an Approved Body issues a certification enabling a manufacturer to affix a UK Conformity Assessed (UKCA) marking and place the device on the market in Great Britain. The MHRA itself does not assess medical devices for conformity with the regulations. During the course of the National Commission process, the MHRA informed the Commission of the government’s intention to address certain limitations with this model, including by exploring the ability to directly license medical devices. This reflects MHRA’s wider ambition to develop a more flexible and responsive regulatory system that can better support emerging technologies, including AI-enabled medical devices, while maintaining high standards of patient safety and strengthening the long-term resilience of the UK’s regulatory framework. This has been considered and taken into account by the National Commission as it developed this report. The recommendations included in this section are designed to support a regulatory framework that is proportionate and can support manufacturers to manage performance and safety of devices across the entire lifecycle. In particular, it supports a clear and predictable framework for device qualification, device classification, generation of necessary evidence, management of changes, and more continuous understanding of device performance across the product lifecycle. 1. Clear and consistent device qualification and classification There is a wide spectrum of software and AI-enabled products for use in healthcare, and not all of these products are regulated as medical devices. It is important that manufacturers and the health system have the clarity needed to understand when a product qualifies as a regulated medical device. This clarity is generally provided through the combination of legislation and guidance that outlines the interpretation of the legislation. The existing framework as set out in the UK MDR 2002 outlines that products with an intended purpose that meets the definition of a medical device are regulated medical devices. This foundational concept of device regulation should be maintained but refined moving forward. For many software and AI-enabled products, decisions on qualification and classification in the current framework can be complex and subjective. It can be challenging to characterise a product’s intended purpose while considering potential changes in capability, design and risk across the product lifecycle. For example, manufacturers may position AI-enabled medical devices for a wider range of applications or functions, which results in less specific intended-purpose statements and increased uncertainty around the necessary supporting evidence to validate such broad purposes. The National Commission recognises that the MHRA has already taken steps to help explore and address this challenge. Through the AI Airlock regulatory sandbox programme [footnote 8] , the MHRA worked with innovators to understand how to define, maintain and enforce the intended purpose of an AI product that can evolve in functionality and clinical influence over time. This work identified the need for updated guidance to address the changing device landscape and considerations across the product lifecycle [footnote 9] . As manufacturers continue to develop such devices with different functions and broader uses that may change over the course of product lifecycle, it will therefore be even more important to consider and define intended purpose clearly. Intended purpose should explicitly include device design and functionality in addition to a manufacturer’s claims and promotional materials. It is important to understand how and when the specifics of how a device has been designed to function is factored into understanding its intended use, especially if that design is inconsistent with specific claims or promotional materials. Clear guidance and resources are needed to support more consistent and ongoing evaluation and understanding of a device’s intended purpose. To achieve a proportionate regulatory framework, several categories of products warrant careful consideration by MHRA as to how and when the UK medical device regulations should apply (‘qualification’). Three categories of software and AI-enabled products which deserve specific consideration in this regard are those for: (1) administrative purposes, (2) general wellbeing purposes and (3) low risk clinical decision support purposes. Some of these products, including many of those belonging to the first two categories, are likely not medical devices within the existing definition. Some of these products, such as those that are intended to provide certain clinical decision support, may currently meet the definition of a device but are sufficiently low risk such that regulatory oversight may not add value. The MHRA should consider this issue, including the potential role of legislative change and new guidance to provide clarity on when such products should be subject to UK medical device regulation. The current classification scheme also carries significant limitations for software and AI-enabled devices, as it was not designed for modern technologies of this kind. Most of these devices today are self-declared as Class I and this can result in limited understanding of the risks and benefits to patients. Further, this may lead to regulatory requirements that are not right-sized for a given device. Some of these products are very low risk and may not even qualify as medical devices, while others warrant more tailored oversight beyond self-registration prior to deployment, such as regulatory authorisation and ongoing surveillance. Further, approaches to classification can create challenges for manufacturers and the health system in Northern Ireland, who comply with the EU’s medical device regulations through the Windsor Framework. For example, if a software and AI-enabled product is not classed as a medical device in Great Britain but is in the EU, the manufacturer may not pursue Conformité Européenne (CE) marking, which could impact on access in Northern Ireland. Any changes to Great Britain’s qualification and classification rules should include careful consideration of Northern Ireland impact. Where divergence occurs, the MHRA should consider other possible routes for innovative products, to ensure Northern Ireland can still access emerging technologies. The following recommendations focus on updating existing UK medical device regulations and guidance documents to support clear, consistent, and proportionate qualification and classification processes for software and AI-enabled medical devices. These changes are recommended to provide the necessary clarity, oversight and predictability to help the ecosystem determine when software and AI products need to be classed as medical devices. Legislative change can take time, so it is important that MHRA consider what guidance and clarity can be provided in the near-term within the current framework in parallel to broader reform efforts. Recommendation 1. Modernising the regulation The MHRA should systematically review and update, as necessary, the existing UK Medical Devices Regulations to allow for a more tailored approach to software and AI-enabled medical devices. This should include: (a) updates to the definition of a medical device to provide more clarity on when certain software and AI-enabled products are regulated as medical devices. For example, such updates should explicitly clarify when software intended for administrative purposes in a healthcare setting, general wellbeing purposes, and certain decision support purposes are not medical devices. (b) a classification system and approach that considers the clinical risks, patient benefits, device lifecycle, and international harmonisation to provide a clear and resilient approach to classification of software and AI-enabled devices. This classification system should: i. address the known limitations of self-declared Class I devices in the current framework ii. appropriately apply requirements and/or oversight for devices where there is sufficient risk to patients iii. employ a proportionate approach to low-risk devices (c) updates to the definition of intended purpose to ensure that device design and functionality are appropriately considered in addition to a manufacturer’s claims and promotional materials. Recommendation 2. Improving regulatory guidance The MHRA should systematically review and update, as necessary, guidance and other resources to provide clarity and predictability for the ecosystem. The MHRA should develop and implement an ongoing process for reviewing and updating guidance and other resources to ensure supporting policies are updated and available in a timely fashion. This should include: (a) clarification of which types of software and AI-enabled products are, and are not, medical devices (b) clarification of the application of the risk-based classification system to relevant software and AI-enabled devices (c) clarification of how intended purpose is interpreted for software and AI-enabled devices, including practical examples relevant to both understanding device qualification and post-market compliance. 1.2 Tailored and risk-proportionate regulatory approaches Traditionally, UK medical device regulation has lacked the necessary agility to meet the needs of a rapidly evolving field such as AI. It is well-understood that AI-enabled medical devices are challenging this established approach, and a framework is needed that is more clearly tailored to the benefits and risks of a given device across its lifecycle. Regulation will also need to become more flexible and responsive to modern, emerging technologies, with new approaches to better manage device changes while assuring safety and effectiveness over time. Regulators will additionally need to consider how this flexibility works for more increasingly capable AI products, even at some future point addressing the challenges of Artificial General Intelligence (AGI). When new types or risks of software and AI-enabled medical devices emerge, regulators need flexibility to introduce appropriate requirements or controls to manage specific risks. Those requirements should apply to any subsequent devices of that type to ensure fair and consistent regulation. It is also important to have a regulatory framework that accounts for a regulator’s learning over time. It may be necessary and appropriate to change (increase, amend or reduce) the requirements for a given device type, so they remain proportionate as the technology, and its use, mature. For example, various regulatory jurisdictions address this for certain low risk software and AI-enabled devices by applying enforcement discretion or not focusing their regulatory oversight on such products. Although the MHRA can learn from the deployment of these devices and refine its approaches, updating the underlying regulatory requirements across the product lifecycle can be slow. This can make it difficult to adjust controls as evidence develops and as the device becomes better understood. To support innovation while maintaining appropriate safeguards, the MHRA should consider ways to make its regulatory framework more flexible and adaptable, enabling it to respond effectively to the ongoing development of software and AI‑enabled medical devices. This could include clearer mechanisms to amend regulatory requirements and, where justified by evidence, to strengthen or reduce requirements as signals and safety data emerge. These powers should be applicable across all risk classes. Recommendation 3. Proportionate regulatory oversight The MHRA should be empowered to improve the flexibility of its application of the regulatory framework, allowing for tailored approaches over time to allocate its resources and oversight to best assure the public health. For example: (a) adding safety-related requirements for devices where new/available evidence shows a need for this beyond which is covered by existing classification requirements to support patient safety. (b) reducing or limiting requirements and/or oversight for devices where the best available evidence shows that the risk is sufficiently low (for example, applying concepts such as enforcement discretion, where appropriate). Where such actions are proposed, it is essential that this be signalled clearly, applied consistently, and aligned to risk proportionality and patient benefit. As software and AI-enabled medical devices become more complex and capable, they often include multiple functions within a single product. More of these multifunction products are becoming available, and they can have both regulated medical device functions as well as functions that are not regulated as medical devices. For example, an Ambient Voice Technology (AVT) product may include functions such as summarisation and transcription that are not classed as medical devices, alongside functions that provide advanced decision support that may be classed as medical devices [footnote 10] . However, it would be disproportionate and inefficient for regulators like the MHRA to oversee non-medical device functions within the product instead of focusing on the specific functions or purposes th
Read the full original article:
gov.uk#人工智能
