Skip to main content
Lavanya Rangarajan
Lavanya Rangarajan
Policy Manager

The Medicines and Healthcare products Regulatory Agency’s (MHRA) National Commission into the Regulation of artificial intelligence (AI) in Healthcare, published their recommendations to Government on 10 September. It is the product of a year-long consultation with over 12,000 patients, clinicians and stakeholders, the largest exercise of its kind the UK has run on regulating healthcare technology, and it sets out 44 recommendations for how AI should be governed once it reaches patients. 

The Commission’s core argument is that the current regulatory regime was built for physical devices that do not change once they are approved, such as hip replacements and stethoscopes. However, the key challenge to address is that AI software does change. It learns from data, it can drift in performance, it will definitely behave differently in three years than it did at launch time, and as the Commission says, a framework built around a single point-in-time sign-off cannot cope with the constant change. 

The Report and Its Recommendations 

There are 44 important recommendations made in the report, but three in particular are worth addressing here. The first recommendation concerns staged authorisation. This is described as an L-plate model, where new AI tools are deployed under close supervision and tighter guardrails before receiving final approval. This step is important to include, because real-world evidence should be built gradually rather than hedging all bets on a single pre-market assessment that might not account for all harms or risks. 

The second recommends continuous, lifecycle-based monitoring. If this were to be adopted, authorisation would have to be sought continuously, and importantly could be withdrawn if a model’s performance degrades after deployment. This comes with the recommendation to give the MHRA stronger enforcement powers over developers, which is important as this has been one of the weakest parts of the regime in practice. 

The final key recommendation is for patients to have the right to know when AI is being used in their care, and that this should be backed by a system level approach to transparency and traceability across a device’s lifecycle. About 40% of GPs are already noted to be using AI scribes, and patient safety and privacy are an important consideration that needs to be addressed. 

Unresolved Challenges 

The recommendations are currently framed generically across ‘AI-enabled devices’, but there are varying levels of risk within that. A device with a fixed diagnostic algorithm reading a scan does not introduce the same level of risk as a large language model (LLM) powering a clinical assistant. The former has bounded and predictable failure modes. However, the latter by design does not. The Commission’s recommendation of proportionate, function-based regulation is the right instinct but there is still some missing detail on how that proportionality actually flexes between narrow and general-purpose systems. 

There is also a noticeable gap in the transparency recommendation itself. Research published alongside the report found that some patients are less willing to disclose sensitive information, such as substance use, if they know an AI system is processing the conversation. Transparency is the right principle, but it can work against the honesty it’s meant to protect, and the Commission needs to offer more details on how both can be held at once.  

The bigger challenges lie upstream of what’s covered currently; the recommendations sit at the adoption side of the AI lifecycle. This is the other side of the problem, where it touches on how an already-built device gets authorised, monitored and used safely. There is not enough, if any, focus given to earlier concerns of innovation, particularly to how models get built and validated on NHS data in the first place. There is currently no national guideline for sharing NHS data with AI developers for training purposes, no standard agreements between trusts, or between trusts and universities, and the data quality and coding problems the Goldacre Review flagged years ago remain largely the same. It is possible to have the very best of deployment regimes in the world and still end up with models that were poorly trained because the data governance underneath them was never properly established. 

The next important step is to see how the Government responds to these recommendations, and what timeline it proposes for implementation. AI is continuously evolving, with recent developments pointing to its immense potential to do both good and bad. The government needs to respond swiftly. 

Conclusion 

This is a serious and well-evidenced step towards workable AI regulation, and it answers a question the UK urgently needed answered: how do we govern AI once it is already embedded in the system? What it does not answer, and what has yet to be fully addressed, is how we make ensure the right AI gets built in the first place. That is the harder problem, and the one that determines whether any of this regulation ends up governing AI that is worth deploying at all. 

The All-Party Parliamentary Group for Health (APHG) and the All-Party Parliamentary Group for Data and Emerging Technologies (APGDET) are jointly hosting an inquiry into AI and Healthcare. Further details on how to contribute, and on upcoming evidence sessions, will be announced shortly.  

If you are interested in learning more about this programme of work and understanding ways to get involved, please write to Lavanya.rangarajan@policyconnect.org.uk 

Cross-party forum

All-Party Parliamentary Group on Data and Emerging Technologies
See more from this group

Cross-party forum

All-Party Parliamentary Health Group
See more from this group

More from Policy Connect

  • News

    Trusting data to give the health sector a boost with digital solutions

    13 December 2022
  • Event

    Health, Data and Public Trust

    Event date: 7 December 2022
  • Event

    What next for health data partnerships?

    Event date: 29 October 2020