As artificial intelligence (AI) transforms healthcare and life sciences, how can regulation keep pace with innovation while maintaining high standards of safety, accountability and transparency? From diagnostics and clinical decision-making to drug discovery and operational efficiency, AI technologies are advancing rapidly, creating both significant opportunities and new regulatory challenges.

Two recent initiatives from the Medicines and Healthcare products Regulatory Agency (MHRA) provide important insight into how the UK is seeking to address these challenges: its Call for Evidence on the future regulation of healthcare AI and AI sandbox to accelerate medicines development and improve safety, which allows innovative technologies to be tested in real-world settings. Together, they offer an early view of the UK's emerging regulatory framework for healthcare AI.

Here, we take a look at the key themes emerging from both initiatives and what they mean for those involved in developing, deploying or investing in AI-enabled technologies. Focusing on what matters most as businesses strive to gain early mover advantage in this market, we highlight the regulatory trends organisations should be preparing for now as the UK evolves its approach to AI in healthcare.

What should the future regulatory framework for healthcare AI look like?

When the MHRA issued its 'Call for Evidence' last December on the regulation of AI in healthcare it provided a window of opportunity for both the public and all interested stakeholders to contribute views. Key areas it sought perspectives on to inform the recommendations of the National Commission into the regulation of AI in healthcare were:

  • whether current rules are sufficient;
  • how safety should be assessed once AI is in real‑world use;
  • how responsibility and liability should be allocated across developers, users and providers; and
  • what principles should guide a modernised regulatory regime.

It received a strong response with 761 individuals and organisations sharing their views and expertise to help. The resulting report, published in June, identifies ten key findings to inform the MHRA's final recommendations to the National Commission into the Regulation of AI in healthcare.

The overarching message is that healthcare AI requires a regulatory framework that differs from those designed for areas such as traditional medical devices. Stakeholders consistently highlighted that existing frameworks are not well suited to adaptive, AI systems that can evolve after deployment. The regulatory framework for AI in healthcare needs to be safe, fast and trusted – one that keeps pace with the speed of developments in this space, while maintaining safety, accountability and public confidence.

The ten key findings:

  1. Regulation must be proportionate and lifecycle based

    The regulatory approach should be lifecycle-based, risk-proportionate and balance innovation with patient-safety. The consensus was that it should be flexible enough for iterative and adaptive AI systems, providing clear guidance and with oversight extending throughout the product lifecycle.
  2. A consensus for significant regulatory reform

    While a 'complete overhaul' isn't needed, findings highlight the current framework requires substantial changes to better accommodate AI and digital technologies – particularly given the adaptive nature and potential for ongoing change after deployment.
  3. Strengthen continuous post-market surveillance and monitoring

    An ongoing and continuous approach is important to track performance, monitor safety and manage compliance. AI systems should also be monitored throughout their use in real-world settings to identify performance drift, emerging risks and safety concerns over time.
  4. Clarify and share responsibility across the AI ecosystem

    A comprehensive approach to accountability is needed to address current gaps and to ensure accountability is distributed across the lifecycle and is proportionate. Views highlighted the importance of having clarity over roles and liability.
  5. Retain human oversight and clinical judgment

    AI should support the work of healthcare professionals and not be fully responsible for clinical decision making. Human involvement in care and the checking and validation of decisions involving AI by a human clinician is crucial.
  6. Improve trust, transparency and explainability

    Users, providers and patients need clearer information about how AI systems work, their limitations, and how decisions or recommendations are generated – integral to helping build trust, enabling deployment and ensuring the safe use of these systems. AI systems should not operate in a 'black box'.
  7. Address data access, governance and public concerns

    Respondents recognised that healthcare data is both an enabler of AI and a barrier to the development and use of AI systems in healthcare. Areas for improvement included stronger governance, clearer standards, and safeguards around consent, privacy and the commercial use of NHS data.
  8. Build AI literacy and workforce capability

    Ongoing training is needed for clinicians, managers and governance teams to ensure AI is deployed and monitored safely and effectively. It was noted that a lack of AI-specific training can bring increased risk of automation bias.
  9. Improve incident reporting and organisational learning

    There is a need for standardised mechanisms to report AI-related errors, adverse events and performance issues, enabling faster identification of systemic risks. Clearer guidance on how incident reporting works and even a national reporting system for AI incidents is also proposed.
  10. Prioritise patient engagement, trust and communication

    Public trust was identified as a critical enabler of AI adoption. Respondents emphasised transparency (see finding 6 above), clear communication, informed consent and meaningful patient involvement in decisions about AI use.

What is the MHRA AI sandbox and why does it matter?

Alongside policy development, the MHRA has launched a new AI sandbox, designed to help accelerate medicines development and improve safety – giving companies and researchers a controlled testing ground to work with regulators and explore how AI tools might support this goal.

Announced in June, the initiative allows innovators to explore AI models that predict how medicines behave in the body and assess how clinical data can support safety and regulatory decision-making. It will also generate insights to inform future regulation.

The sandbox's value extends beyond supporting innovation. It allows regulators, developers and healthcare organisations to work together to better understand how AI technologies perform in real-world settings and where existing regulatory frameworks need to adapt. It also shows the UK is at the forefront of tackling these tough questions, and will give companies the confidence to invest in innovation here.

This is one of several AI-focused sandboxes that the MHRA is currently involved in. There is also, for example, the AI Airlock, which is the MHRA's regulatory sandbox for AI as a medical device (with a phase three of the programme currently being designed) and the London Region I sandbox. The latter is a collaboration between the MHRA, NHS England and the London Health Innovation Networks to accelerate innovations that will address key challenges facing London's health and care system. It is designed to safely test AI-enabled devices in a real-world environment, so that patients can benefit more quickly.