AI in Healthcare: a blueprint for lifecycle regulation and public trust

read time: 4 mins read time: 4 mins
28.09.26 28.09.26

AI has the potential to transform healthcare. It could support earlier diagnosis, enable more personalised care, improve patient outcomes, and enhance the experience of clinicians, while helping the NHS and wider health system respond to growing demand.

However, AI-enabled technologies present regulatory challenges that differ from those associated with traditional medical devices. Unlike many conventional products, AI systems may evolve over time, and their performance can be influenced by the context in which they are deployed and used.

Against this backdrop, the National Commission into the Regulation of AI in Healthcare was established to advise the Government on a future regulatory framework. Its recently published report sets out 44 recommendations aimed at ensuring regulation keeps pace with software and AI-enabled health technologies.

Healthcare is exposing the gap between traditional regulation and adaptive AI

Existing regulatory models were designed for products that remain largely unchanged after approval. AI systems do not fit neatly within this current approach due to their ability to evolve beyond deployment. The Commission therefore advocates a lifecycle-based approach to regulation, under which oversight continues throughout a product's lifecycle rather than ending at market entry. The recommended adoption of ongoing reporting and escalation processes for AI systems seems proportional, recognising that some uncertainties about AI performance can only be addressed through ongoing monitoring in real-world environments. Adopting a lifecycle-based regulatory framework will also help to address a key finding from the research that where AI is being used to improve care, people want the AI to be safe and overseen by humans.

Perhaps unsurprisingly given the importance of data protection frameworks within AI governance, the report contains similar emphasis to core principles echoed in the UK GDPR: transparency, ongoing management, accountability and oversight but addresses a much wider set of risks and governance issues around safe development, deployment, monitoring and governance of AI systems used in healthcare.

The report is likely to be considered welcome guidance, offering more detail than ever before on AI regulation within the healthcare sector. However, the report is just the starting point; to achieve effective monitoring as advised, consideration will need to be given to the development of fast, affordable, standardised and easily reproducible monitoring methods.

Trust to become a key legal and commercial issue

The report places considerable emphasis on transparency as a means of building public confidence in AI-enabled healthcare. Recommendation 35 proposes a proportionate, system-level approach to transparency around the use of AI-enabled products in patient care, including recognising patients’ reasonable expectation of being informed when such technologies are used in their care and, where appropriate, being able to opt out. Recommendations 36 and 37 build on this by encouraging greater patient and public involvement in the regulatory process and the development of accessible safety information about AI-enabled medical devices. The lived experiences of patients should not be underestimated, as they may provide valuable insights into AI-enabled health technologies and help identify emerging risks at an early stage.

The report also recognises the importance of making AI systems understandable to users. Recommendation 9 encourages the use of model cards, dynamic labelling, and other forms of user-facing information to support safe use of AI-enabled devices.

Alongside this, the Commission also highlights the importance of accountability and governance. Recommendations 24 to 28 seek to clarify roles and responsibilities across the healthcare system, while Recommendation 28 specifically proposes that contracts between manufacturers and healthcare providers contain explicit allocations of responsibility for operational risk controls and regulatory commitments.

However, it remains to be seen whether the transparency measures proposed by the Commission go far enough. Transparency has long been a cornerstone of data protection law, which requires organisations to provide individuals with clear information about how their personal data is used, why it is processed and the implications of that processing. By comparison, the Commission's recommendations appear to take a more principles-based approach to transparency, focusing on awareness, engagement, and access to information rather than setting out detailed disclosure requirements regarding AI-enabled systems. As the use of AI in healthcare expands, questions around what level of transparency is necessary to secure public confidence are likely to become increasingly significant.

A possible indication of where UK AI regulation is heading

The challenge of AI regulation is being tackled worldwide. While many countries including the UK, EU, US, and China share similar core values for the adoption of AI in healthcare, there is variation when it comes to enforcement mechanisms and resources. Contrary to the EU, the Government has generally favoured sector-specific regulation rather than introducing a single comprehensive AI Act.

From a wider regulatory perspective, the report may provide an early indication of how UK AI governance could evolve. While the recommendations are specific to healthcare, they reflect a growing focus on governance, accountability and transparency throughout an AI system's lifecycle, themes that are increasingly emerging across wider discussions on AI regulation in the UK.

The Commission’s report places a considered focus on governance design but it remains to be seen how the recommendations will be progressed as we await a cross-government response. If the recommendations can be implemented effectively, this will be great progress towards patients receiving safe access to the latest technology. The UK may also position itself as a global leader in responsible AI healthcare regulation which would encourage further technology companies to bring their innovations to the UK.

Sign up for legal insights

We produce a range of insights and publications to help keep our clients up-to-date with legal and sector developments.  

Sign up