Artificially Confident

Artificially Confident

Practical AI, properly examined

UK Health AI Commission Proposes Staged Authorisation and Contracted Risk Controls

Written by

in

A staged AI authorisation pathway linking a supplier, healthcare provider and review process to monitored clinical deployment and a continuing evidence loop.

Evidence note: Last checked 11 September 2026 at 06:06 BST (Europe/London). The National Commission’s recommendations are advisory and a cross-government response is still due. The immediate legal effect is therefore limited. The governance lesson is material because the report sets out how staged authorisation, supplier evidence, NHS procurement, local monitoring and clinical responsibility fit together as one system.

The UK’s National Commission into the Regulation of AI in Healthcare published 44 recommendations on 10 September for a new approach to software and AI-enabled medical devices. The proposals would move assurance away from a single assessment before market entry and towards controlled deployment, continuing evidence collection and clearer division of responsibility.

The Commission’s report is not government policy. It was produced by an independent advisory body established by the Medicines and Healthcare products Regulatory Agency, and the government has said it will respond separately. Its operational detail still gives healthcare providers and suppliers a useful view of the evidence they may be expected to produce.

The recommendations include staged authorisation for selected devices, more regular post-market performance reporting, an optional regulatory file for general-purpose models, disclosure of model dependencies and contracts that assign responsibility for each deployment control. Taken together, they treat safety as a chain of duties shared by the manufacturer, healthcare provider, professional and regulator.

Staged authorisation requires defined operating conditions

Recommendation 14 asks the MHRA to enable staged authorisations where a device can enter a tightly controlled setting using initial safety evidence, agreed risk controls and additional reporting. The route would have to state how a product moves from staged to full authorisation and keep patients informed about the arrangement.

This is not a conventional approval with lighter paperwork. The authorisation would depend on the provider’s ability to run the device inside the agreed limits and collect evidence from real care settings. A trust unable to deliver the required monitoring, training or escalation route would not meet the operating conditions that support the staged decision.

Pulse Today described the proposal as an L-plate system and reported the Commission’s linked concern about clinicians becoming liability sinks when responsibility for errors is unclear. That pairing matters. Earlier access transfers part of the assurance work into deployment, so the organisation using the device needs both capacity and a written mandate to perform that work.

Foundation-model dependencies enter the regulatory record

Many healthcare applications rely on a general-purpose model that is built and updated by another company. The downstream device manufacturer may not hold enough technical information to explain a change in the underlying model or assess its effect on a clinical function.

Recommendation 7 proposes an optional Master File through which an upstream model provider could give the MHRA confidential technical information. The report suggests benchmarks, model cards, internal guardrails and protected routes for further disclosure. A device manufacturer could then refer to that material during authorisation without receiving every commercially sensitive detail.

Recommendation 8 addresses the buyer’s side. It says manufacturers should report a product’s dependency on an underlying general-purpose model, the related risks, planned mitigations and continuity arrangements. That information should appear in regulatory submissions for medical devices and in procurement and contract terms for AI-enabled products.

The report also identifies cumulative exposure when many products depend on a small number of foundation-model providers. An NHS inventory that records only the application vendor will miss that concentration. Providers need to know the underlying model and hosting service, which changes require notice, how performance will be retested after an update, and what happens if access is withdrawn.

Deployment controls become contract terms

Recommendation 26 would require manufacturers to specify the operating conditions needed for safe use. The report names cybersecurity, user training, performance monitoring, drift detection, response routes and institutional AI readiness. These conditions would sit in pre-market submissions and risk-management files.

Recommendation 28 then moves those conditions into the commercial relationship. The contract between a manufacturer and healthcare provider should state which party will deliver each required control and regulatory commitment. The Commission’s text says no risk control should remain unaccounted for.

That would make the procurement record part of the safety case. A clause stating that the customer is responsible for monitoring is incomplete unless it also defines the data supplied by the vendor, the measure used to detect degradation, the review frequency, the trigger for escalation and the action available to the provider. The same applies to staff training, security updates, incident reporting and patient communication.

This is the healthcare version of the governance handover from pilot to production. The contract should preserve the conditions that made deployment acceptable, rather than leaving the operational team to reconstruct them after the system is live.

Clinical oversight depends on training and authority

The Commission recommends a coordinated training approach across health departments, professional regulators, royal colleges and education providers. It also says healthcare providers must give staff training matched to the technology they use. Baseline AI literacy would be supplemented by product-specific preparation for people expected to interpret or oversee outputs.

Training alone does not settle responsibility. A clinician needs enough information to recognise a poor output, enough time to examine it and a route to challenge or stop its use. Our article on human oversight as a workflow describes the same control in practical terms: evidence, authority, intervention and a record of the decision.

The public evidence published with the Commission’s report supports that design. Health Foundation research found that support for healthcare AI was conditional on accuracy, effective human oversight, regulation matched to risk and protection against worse care for any group. Staged deployment will need to show those conditions in practice, not only in product documentation.

Preparation before the government response

Healthcare providers do not need to treat the recommendations as current law to test whether their existing controls would satisfy the proposed model. For each AI-enabled product, they can record the clinical purpose, regulatory status, underlying model dependencies, supplier evidence, required local controls and named owners. The record should also state how performance is monitored, how patients are informed, where concerns are reported and which events suspend use.

Suppliers can prepare the same evidence from the other direction. They should identify which risk controls depend on the care setting, what data the provider must return for post-market surveillance, which model changes trigger reassessment and how continuity works if an upstream service changes.

The next decision belongs to government and the MHRA: which recommendations become regulation, guidance or procurement requirements, and how the regulator will be resourced to receive continuing evidence. The report’s useful contribution is already concrete. Approval, purchasing and clinical operation cannot remain separate files when the safety claim depends on all three.

How we work: articles are source-led, AI-assisted and editorially reviewed. Read our editorial method.

Reader response

Questions, corrections or a story lead?

Send us a message with enough context to make it useful. Your note will reach the Artificially Confident editorial inbox.