
Established by the Medicines and Healthcare Products Regulatory Agency (MHRA) last year, the independent commission asserts that existing regulations are inadequate, as they primarily address medical products that remain static post-market.
In contrast, AI systems can evolve rapidly and perform variably based on data, workflows, users, and healthcare organizations, the report notes. The recommendations are structured around three key areas: proportional lifecycle regulation, system-wide accountability and safety management, and trust, transparency, and predictability.
Regulatory Framework
“AI-enabled devices demand regulatory strategies that align with their unique features. The proposed framework should enable tailored oversight throughout the product lifecycle, including clear market entry pathways, adaptable mechanisms for rapid updates, and enhanced use of real-world evidence for ongoing assurance,” the report states.
“Intended purpose should encompass device design and functionality, in addition to manufacturer claims and promotional materials,” the report emphasizes.
Implementation and Safety
The commission suggests allowing certain AI products to enter the market incrementally, enabling their use under specific conditions while developers gather safety and efficacy data. The report calls for increased reliance on real-world data to monitor AI performance post-deployment and for regulatory testing environments where developers and regulators can assess new technologies before widespread adoption.
Regulators, the commission notes, should evaluate whether AI operates safely and effectively across diverse patient groups. The framework should also incorporate “international regulatory harmonization.”
Training and Liability
Healthcare professionals should receive training to safely use AI technologies, including understanding their limitations and risks, the commission advises. It recommends integrating AI education into initial, postgraduate, and continuing professional development programs.
Healthcare providers would be responsible for ensuring staff receive technology-specific training. The commission stresses that AI safety accountability should be shared among manufacturers, healthcare providers, clinicians, regulators, and policymakers.
Patients should have access to information about how AI influenced their care and avenues for redress if issues arise. “Liability for AI in healthcare is complex and evolving.
Public Involvement and Cybersecurity
Patient involvement is key in AI regulation decisions, and patients and healthcare professionals should be regularly surveyed about their views on healthcare AI. The report calls for stronger cybersecurity requirements and clearer guidelines for consumer health apps and wearables.
The 44 recommendations are advisory and do not introduce new regulatory mandates.




