UK · Healthcare · GLACIS guides · Checked 26 August 2026

UK healthcare AI regulation: MHRA, CQC, NHS, NICE

A working guide to the UK’s healthcare AI regulatory landscape, updated for August 2026: MHRA device classification, the completed AI Airlock phase 2, phase 3 design, the National Commission into the Regulation of AI in Healthcare, and the NHS AI & Digital Regulations Service.

By Joe Braidwood 15 min read EU timeline checked 26 August 2026
Apr 2025 to May 2026
AI Airlock phase 2 ran and is now complete
27 Jul 2026
MHRA updated the phase 2 program report
Now
Phase 3 sandbox design is in progress
Current
Existing medical-device and sector rules still govern
What changed since January 2026
  • AI Airlock phase 2 is complete. It ran from April 2025 to May 2026. The program report, updated 27 July 2026, is explicitly not formal MHRA guidance.
  • Phase 3 is being designed. MHRA says further information will be announced; the official Airlock collection is the current source for program status.
  • NHS AI & Digital Regulations Service (digitalregulations.innovation.nhs.uk) brings together guidance from MHRA, NICE, NHS England and CQC. Those bodies retain distinct roles and evidence expectations.
  • Joint MHRA, FDA and Health Canada principles on predetermined change control plans (PCCPs) and ML-enabled device transparency remain the international anchor. They are useful pre-positioning for the new UK framework.
  • DUAA automated-decision provisions in force from 5 February 2026. For significant solely automated decisions involving non-special-category data, the reforms potentially allow any lawful basis except the new recognized-legitimate-interests basis, subject to safeguards. Special-category health data remains more restricted. The relevant ADM safeguards sit in section 80’s new UK GDPR Articles 22A to 22D; section 103 is a separate complaints provision.
Executive summary

The UK’s healthcare AI framework operates through multiple specialised bodies. MHRA regulates AI as medical devices under UK MDR 2002. Classification drives the obligations. CQC oversees AI use within healthcare providers through its fundamental standards. NICE sets evidence standards for digital health technology adoption. The new NHS AI & Digital Regulations Service consolidates guidance for buyers and developers; the older NHS AI Lab brand sits behind it.

The AI Airlock regulatory sandbox, launched by MHRA in 2024, completed its second phase in May 2026. Its published findings and case studies inform future guidance, policy and phase 3 design; they are not formal guidance, market authorization or proof that a participating product is safe or effective.

The practical path is product- and deployment-specific: (1) determine whether the AI qualifies as a medical device; (2) follow the applicable MHRA classification, registration and conformity route; (3) establish the evidence needed for NHS or NICE evaluation; (4) address provider duties and CQC oversight; and (5) maintain appropriate post-market monitoring. Operational records can support that work, but do not replace clinical validation, legal analysis or regulator decisions.

UK healthcare AI regulatory landscape

Unlike the EU’s horizontal AI Act, the UK regulates healthcare AI through existing sectoral frameworks: primarily medical device regulation for AI products and healthcare provider oversight for deployment settings. This approach sits inside the UK’s broader pro-innovation AI regulatory strategy.

MHRA

Medicines and Healthcare products Regulatory Agency

Regulates medical devices under UK MDR 2002, including registration and market surveillance, and operates the AI Airlock sandbox. Conformity assessment and market-access steps depend on device class and route.

Medical Devices UKCA Marking AI Airlock

CQC

Care Quality Commission

Inspects and rates healthcare providers in England. Assesses AI use through fundamental standards framework covering safe care, governance, and staffing. Evaluates whether providers properly govern and monitor AI tools.

Provider Oversight Governance England Only

NICE

National Institute for Health and Care Excellence

Sets evidence standards through the Evidence Standards Framework for Digital Health Technologies. Evaluates clinical and economic evidence for NHS adoption. Guidance informs commissioning decisions.

Evidence Standards HTA NHS Adoption

NHS AI & Digital Regulations Service

Consolidated entry point, formerly NHS AI Lab

Consolidated guidance for AI and digital tech in health and social care, bringing together MHRA, NICE, NHS England and CQC. Replaces the older NHS AI Lab single-source view and runs alongside the NHS AI strategic roadmap (2025 to 2028) and the AI in Health and Care Award.

NHS guidance Procurement Cross-regulator

Additional Oversight Bodies

ICO

Data protection and UK GDPR compliance for health data processing. Automated decision-making requirements under Article 22.

HRA

Health Research Authority oversees AI research involving NHS patients. Ethics approval for clinical studies.

AI Security Institute

Evaluates frontier AI safety, though healthcare-specific guidance remains with MHRA and NHS bodies.

MHRA medical device classification for AI

Under UK MDR 2002, software qualifies as a medical device if it has a medical intended purpose. AI used for diagnosis, monitoring, prediction or treatment recommendation is typically classified as Software as a Medical Device (SaMD). Classification determines regulatory requirements, from self-declaration for Class I to full conformity assessment for Class III.

Is the AI a medical device?

Likely yes, if it:

  • Diagnoses, prevents, monitors, predicts or treats disease
  • Provides clinical decision support that influences treatment
  • Analyses medical images, pathology slides or clinical data for diagnosis
  • Monitors physiological parameters with clinical implications

Probably not, if it:

  • Provides general health and wellness information only
  • Performs purely administrative functions (scheduling, billing)
  • Acts as a simple data repository without clinical analysis
  • Supports research without direct clinical application

SaMD classification under UK MDR 2002

Class Risk Level AI Examples Requirements
Class I Low Wellness apps, symptom checkers providing general info only Self-declaration, UKCA marking, register with MHRA
Class IIa Medium-Low Clinical decision support, triage tools, non-critical monitoring Approved Body audit, QMS, clinical evidence
Class IIb Medium-High Diagnostic imaging AI, cancer detection, treatment planning Full Approved Body review, clinical trials may be required
Class III High AI driving life-sustaining decisions, autonomous treatment Stringent Approved Body review, prospective clinical studies

Clinical Evidence Requirements

  • Analytical validation: Accuracy, sensitivity, specificity on representative data
  • Clinical validation: Performance in intended clinical setting with UK population
  • Real-world performance: Post-market surveillance and monitoring
  • Algorithm change protocol: Re-validation requirements for model updates

Technical Documentation

  • Intended purpose: Clear statement of clinical use and user population
  • Training data: Description of data sources, quality, and representativeness
  • Risk analysis: FMEA or equivalent covering AI-specific failure modes
  • Cybersecurity: Threat model and security controls for connected devices

AI Airlock: phase 2 complete, phase 3 in design

The AI Airlock is MHRA’s regulatory sandbox for AI as a Medical Device, launched in 2024. Phase 2 ran from April 2025 to May 2026 and is complete. Its reports describe seven case studies and program lessons, but do not constitute formal MHRA guidance. MHRA says phase 3 design is in progress.

How the AI Airlock works

What the completed second phase did, and what it did not do

1

Application and assessment

MHRA selected seven technologies to explore three defined regulatory challenges. That cohort is complete; future phase 3 participation details have not yet been announced.

2

Controlled testing

The program used case-study work and simulation workshops with regulator, clinical, industry and technical participants.

3

Evidence generation

Published reports record technical and regulatory insights. They are program findings, not clinical validation or formal guidance.

4

Regulatory pathway

Participation did not itself grant market authorization or an expedited approval pathway. MHRA says the work will inform future guidance, policy and Airlock phases.

What phase 2 offered

  • Direct engagement with MHRA on regulatory requirements
  • Structured case-study and simulation work
  • Regulatory learning without market authorization
  • Published lessons for future guidance and policy

What the program informs

  • Understanding of novel AIaMD regulatory challenges
  • Recommendations for future regulatory support
  • Design of the next Airlock phase
  • National Commission advice, guidance and policy work

Future participation

Current status:

  • Phase 2 completed in May 2026
  • Programme report published in June 2026
  • Report updated 27 July 2026
  • Phase 3 design is in progress

What to do now:

  • Follow MHRA’s official collection for phase 3 announcements
  • Use current medical-device requirements for live market-access decisions
  • Treat Airlock reports as program evidence, not formal guidance
  • Do not infer approval from past participation

NHS adoption pathway

Meeting applicable medical-device requirements is necessary but not sufficient for NHS adoption. Vendors may also need to address NICE evidence standards, NHS data and security requirements, procurement needs and local clinical assurance. The NHS AI & Digital Regulations Service brings together guidance, while each body and buyer retains its own role.

NICE evidence standards framework for digital health technologies

1

Functional evidence

The technology works as intended. Technical performance, usability, accessibility, and integration capabilities.

2

Clinical evidence

Clinical outcomes improve. Comparative effectiveness, safety profile, and benefits across patient populations.

3

Economic evidence

Cost-effectiveness demonstrated. Resource impact, value for money, and budget impact analysis.

AI-specific NICE considerations

  • Algorithmic transparency and explainability
  • Training data quality and representativeness
  • Ongoing performance monitoring plans
  • Generalizability across settings and populations

NHS data security requirements

  • DSPT Compliance: Data Security and Protection Toolkit assessment required
  • DCB0129/DCB0160: Clinical risk management standards for health IT
  • Cyber Essentials / Plus: May be required by a particular NHS procurement, contract, or data-access route; verify the applicable buyer requirement
  • UK GDPR: Lawful basis for health data processing

NHS AI & Digital Regulations Service resources

  • Buyer’s Guide: Procurement guidance for AI in health and care
  • Algorithm Assurance: Framework for AI governance in NHS
  • AI Ethics Initiative: Ethical guidance for health AI development
  • AI Award: Funding for promising AI health innovations

CQC oversight of healthcare AI

CQC assesses AI use through its fundamental standards, evaluating whether providers have appropriate governance, staff training, and monitoring in place. Key inspection focus areas:

  • AI governance structure and accountability
  • Staff training and competency assessment
  • Clinical validation and ongoing monitoring
  • Human oversight of AI-informed decisions
  • Incident reporting and response procedures
  • Patient information and consent processes
  • Integration with clinical workflows
  • Performance monitoring and audit trails

UK vs EU healthcare AI requirements

Aspect UK Approach EU Approach
Regulatory framework Sectoral (medical devices, data protection) Horizontal AI Act + MDR / IVDR
High-risk classification Based on medical device class AI Act Annex III + MDR class
Conformity marking UK MDR route; applicable conformity marking and transitional recognition depend on device and certificate CE + AI Act compliance
Regulatory sandbox AI Airlock (MHRA): phase 2 completed May 2026; phase 3 design under way AI Act regulatory sandboxes (member states)
Fundamental rights UK GDPR, DUAA 2025, Human Rights Act AI Act FRIA, EU Charter, GDPR
High-risk timing No single horizontal UK AI Act date; current medical-device and sector requirements continue to apply AI Omnibus in force: relevant Annex III duties from 2 Dec 2027; relevant Annex I product-embedded duties from 2 Aug 2028
Market access Transition arrangements vary by device and certificate; verify current MHRA registration and conformity requirements Single market access

Dual-market strategy: organizations seeking access to both UK and EU markets should map each applicable regime separately. The EU AI Omnibus is in force, with relevant Annex III duties applying from 2 December 2027 and relevant Annex I product-embedded duties from 2 August 2028. UK medical-device and sector rules continue on their own path; an Airlock report is not a substitute for current MHRA guidance. See our detailed UK vs EU AI Act comparison →

Key takeaways

For AI developers

  • 1 Determine early whether your AI qualifies as a medical device and its likely classification
  • 2 Monitor the official AI Airlock collection for phase 3 eligibility and program announcements
  • 3 Build NICE evidence requirements into development from the start
  • 4 Ensure robust documentation of training data, validation, and performance monitoring

For healthcare providers

  • 1 Verify the applicable conformity marking, MHRA registration and intended-purpose claims before procurement
  • 2 Address the CQC fundamental standards and governance duties relevant to the deployment
  • 3 Ensure clinical validation in your specific patient population
  • 4 Implement ongoing performance monitoring and incident reporting

How GLACIS can support evidence preparation

MHRA, CQC, NHS and NICE have different roles, processes and evidence expectations. For an instrumented workflow, GLACIS can connect an intended rule to selected control events and preserve independently verifiable records of what the configured path reported. Teams may reuse those records when preparing different review, monitoring or procurement artefacts; execution, source truth, timing, and coverage require surrounding evidence, and GLACIS is not integrated with these bodies or claiming regulator acceptance, clinical validity, or legal sufficiency.

Post-market surveillance

For a deliberately instrumented workflow, GLACIS can preserve timestamped records of selected events and control decisions. Those records may support internal monitoring, incident review and preparation of vigilance or trend-analysis material; they do not satisfy reporting or clinical-safety requirements by themselves.

CQC inspection evidence

A scoped evidence pack can help a provider explain which configured controls were active and when they triggered. It does not establish safe integration, clinical outcomes or compliance, and no CQC acceptance is implied.

NICE evidence requirements

GLACIS can bind supplied measurements and test results to the relevant model, policy and control context. It does not generate clinical or economic evidence on its own; teams still need the studies and analyses required for their NICE pathway.

Algorithm assurance

Where teams configure cohort tests, model-version tracking or drift alerts, GLACIS can preserve the resulting control-execution records. Those records do not demonstrate fairness, stability or clinical validity without the underlying methodology and results.

Mapping GLACIS to UK healthcare regulatory requirements

Regulatory Requirement Potential evidence contribution
MHRA Post-Market Surveillance Timestamped records of selected events and control decisions can support incident correlation and report preparation.
CQC Safe Care & Treatment Records of recommendations, overrides and review events where the workflow is configured to capture them; no compliance conclusion is implied.
NICE Performance Monitoring Supplied measurements can be bound to model, policy and control context for review; GLACIS does not create clinical evidence.
NHS algorithm assurance Configured cohort tests, version changes and drift alerts can be preserved as operational records.
ICO ADM and DUAA rights Retrieval of captured decision and review events may support investigation and response preparation; rights analysis remains context-specific.

Prepare the evidence boundary before review

Requirements depend on the product, intended purpose, deployment and pathway. Bring us the action that matters and we’ll map the intended rule, the control events that can be captured, and what the resulting evidence can and cannot establish.

Talk to us