UK healthcare AI regulation: MHRA, CQC, NHS, NICE
A working guide to the UK’s healthcare AI regulatory landscape, updated for August 2026: MHRA device classification, the completed AI Airlock phase 2, phase 3 design, the National Commission into the Regulation of AI in Healthcare, and the NHS AI & Digital Regulations Service.
- AI Airlock phase 2 is complete. It ran from April 2025 to May 2026. The program report, updated 27 July 2026, is explicitly not formal MHRA guidance.
- Phase 3 is being designed. MHRA says further information will be announced; the official Airlock collection is the current source for program status.
- NHS AI & Digital Regulations Service (digitalregulations.innovation.nhs.uk) brings together guidance from MHRA, NICE, NHS England and CQC. Those bodies retain distinct roles and evidence expectations.
- Joint MHRA, FDA and Health Canada principles on predetermined change control plans (PCCPs) and ML-enabled device transparency remain the international anchor. They are useful pre-positioning for the new UK framework.
- DUAA automated-decision provisions in force from 5 February 2026. For significant solely automated decisions involving non-special-category data, the reforms potentially allow any lawful basis except the new recognized-legitimate-interests basis, subject to safeguards. Special-category health data remains more restricted. The relevant ADM safeguards sit in section 80’s new UK GDPR Articles 22A to 22D; section 103 is a separate complaints provision.
The UK’s healthcare AI framework operates through multiple specialised bodies. MHRA regulates AI as medical devices under UK MDR 2002. Classification drives the obligations. CQC oversees AI use within healthcare providers through its fundamental standards. NICE sets evidence standards for digital health technology adoption. The new NHS AI & Digital Regulations Service consolidates guidance for buyers and developers; the older NHS AI Lab brand sits behind it.
The AI Airlock regulatory sandbox, launched by MHRA in 2024, completed its second phase in May 2026. Its published findings and case studies inform future guidance, policy and phase 3 design; they are not formal guidance, market authorization or proof that a participating product is safe or effective.
The practical path is product- and deployment-specific: (1) determine whether the AI qualifies as a medical device; (2) follow the applicable MHRA classification, registration and conformity route; (3) establish the evidence needed for NHS or NICE evaluation; (4) address provider duties and CQC oversight; and (5) maintain appropriate post-market monitoring. Operational records can support that work, but do not replace clinical validation, legal analysis or regulator decisions.
UK healthcare AI regulatory landscape
Unlike the EU’s horizontal AI Act, the UK regulates healthcare AI through existing sectoral frameworks: primarily medical device regulation for AI products and healthcare provider oversight for deployment settings. This approach sits inside the UK’s broader pro-innovation AI regulatory strategy.
MHRA
Medicines and Healthcare products Regulatory Agency
Regulates medical devices under UK MDR 2002, including registration and market surveillance, and operates the AI Airlock sandbox. Conformity assessment and market-access steps depend on device class and route.
CQC
Care Quality Commission
Inspects and rates healthcare providers in England. Assesses AI use through fundamental standards framework covering safe care, governance, and staffing. Evaluates whether providers properly govern and monitor AI tools.
NICE
National Institute for Health and Care Excellence
Sets evidence standards through the Evidence Standards Framework for Digital Health Technologies. Evaluates clinical and economic evidence for NHS adoption. Guidance informs commissioning decisions.
NHS AI & Digital Regulations Service
Consolidated entry point, formerly NHS AI Lab
Consolidated guidance for AI and digital tech in health and social care, bringing together MHRA, NICE, NHS England and CQC. Replaces the older NHS AI Lab single-source view and runs alongside the NHS AI strategic roadmap (2025 to 2028) and the AI in Health and Care Award.
Additional Oversight Bodies
ICO
Data protection and UK GDPR compliance for health data processing. Automated decision-making requirements under Article 22.
HRA
Health Research Authority oversees AI research involving NHS patients. Ethics approval for clinical studies.
AI Security Institute
Evaluates frontier AI safety, though healthcare-specific guidance remains with MHRA and NHS bodies.
MHRA medical device classification for AI
Under UK MDR 2002, software qualifies as a medical device if it has a medical intended purpose. AI used for diagnosis, monitoring, prediction or treatment recommendation is typically classified as Software as a Medical Device (SaMD). Classification determines regulatory requirements, from self-declaration for Class I to full conformity assessment for Class III.
Is the AI a medical device?
Likely yes, if it:
- Diagnoses, prevents, monitors, predicts or treats disease
- Provides clinical decision support that influences treatment
- Analyses medical images, pathology slides or clinical data for diagnosis
- Monitors physiological parameters with clinical implications
Probably not, if it:
- Provides general health and wellness information only
- Performs purely administrative functions (scheduling, billing)
- Acts as a simple data repository without clinical analysis
- Supports research without direct clinical application
SaMD classification under UK MDR 2002
| Class | Risk Level | AI Examples | Requirements |
|---|---|---|---|
| Class I | Low | Wellness apps, symptom checkers providing general info only | Self-declaration, UKCA marking, register with MHRA |
| Class IIa | Medium-Low | Clinical decision support, triage tools, non-critical monitoring | Approved Body audit, QMS, clinical evidence |
| Class IIb | Medium-High | Diagnostic imaging AI, cancer detection, treatment planning | Full Approved Body review, clinical trials may be required |
| Class III | High | AI driving life-sustaining decisions, autonomous treatment | Stringent Approved Body review, prospective clinical studies |
Clinical Evidence Requirements
- Analytical validation: Accuracy, sensitivity, specificity on representative data
- Clinical validation: Performance in intended clinical setting with UK population
- Real-world performance: Post-market surveillance and monitoring
- Algorithm change protocol: Re-validation requirements for model updates
Technical Documentation
- Intended purpose: Clear statement of clinical use and user population
- Training data: Description of data sources, quality, and representativeness
- Risk analysis: FMEA or equivalent covering AI-specific failure modes
- Cybersecurity: Threat model and security controls for connected devices
AI Airlock: phase 2 complete, phase 3 in design
The AI Airlock is MHRA’s regulatory sandbox for AI as a Medical Device, launched in 2024. Phase 2 ran from April 2025 to May 2026 and is complete. Its reports describe seven case studies and program lessons, but do not constitute formal MHRA guidance. MHRA says phase 3 design is in progress.
How the AI Airlock works
What the completed second phase did, and what it did not do
Application and assessment
MHRA selected seven technologies to explore three defined regulatory challenges. That cohort is complete; future phase 3 participation details have not yet been announced.
Controlled testing
The program used case-study work and simulation workshops with regulator, clinical, industry and technical participants.
Evidence generation
Published reports record technical and regulatory insights. They are program findings, not clinical validation or formal guidance.
Regulatory pathway
Participation did not itself grant market authorization or an expedited approval pathway. MHRA says the work will inform future guidance, policy and Airlock phases.
What phase 2 offered
- Direct engagement with MHRA on regulatory requirements
- Structured case-study and simulation work
- Regulatory learning without market authorization
- Published lessons for future guidance and policy
What the program informs
- Understanding of novel AIaMD regulatory challenges
- Recommendations for future regulatory support
- Design of the next Airlock phase
- National Commission advice, guidance and policy work
Future participation
Current status:
- Phase 2 completed in May 2026
- Programme report published in June 2026
- Report updated 27 July 2026
- Phase 3 design is in progress
What to do now:
- Follow MHRA’s official collection for phase 3 announcements
- Use current medical-device requirements for live market-access decisions
- Treat Airlock reports as program evidence, not formal guidance
- Do not infer approval from past participation
NHS adoption pathway
Meeting applicable medical-device requirements is necessary but not sufficient for NHS adoption. Vendors may also need to address NICE evidence standards, NHS data and security requirements, procurement needs and local clinical assurance. The NHS AI & Digital Regulations Service brings together guidance, while each body and buyer retains its own role.
NICE evidence standards framework for digital health technologies
Functional evidence
The technology works as intended. Technical performance, usability, accessibility, and integration capabilities.
Clinical evidence
Clinical outcomes improve. Comparative effectiveness, safety profile, and benefits across patient populations.
Economic evidence
Cost-effectiveness demonstrated. Resource impact, value for money, and budget impact analysis.
AI-specific NICE considerations
- Algorithmic transparency and explainability
- Training data quality and representativeness
- Ongoing performance monitoring plans
- Generalizability across settings and populations
NHS data security requirements
- DSPT Compliance: Data Security and Protection Toolkit assessment required
- DCB0129/DCB0160: Clinical risk management standards for health IT
- Cyber Essentials / Plus: May be required by a particular NHS procurement, contract, or data-access route; verify the applicable buyer requirement
- UK GDPR: Lawful basis for health data processing
NHS AI & Digital Regulations Service resources
- Buyer’s Guide: Procurement guidance for AI in health and care
- Algorithm Assurance: Framework for AI governance in NHS
- AI Ethics Initiative: Ethical guidance for health AI development
- AI Award: Funding for promising AI health innovations
CQC oversight of healthcare AI
CQC assesses AI use through its fundamental standards, evaluating whether providers have appropriate governance, staff training, and monitoring in place. Key inspection focus areas:
- AI governance structure and accountability
- Staff training and competency assessment
- Clinical validation and ongoing monitoring
- Human oversight of AI-informed decisions
- Incident reporting and response procedures
- Patient information and consent processes
- Integration with clinical workflows
- Performance monitoring and audit trails
UK vs EU healthcare AI requirements
| Aspect | UK Approach | EU Approach |
|---|---|---|
| Regulatory framework | Sectoral (medical devices, data protection) | Horizontal AI Act + MDR / IVDR |
| High-risk classification | Based on medical device class | AI Act Annex III + MDR class |
| Conformity marking | UK MDR route; applicable conformity marking and transitional recognition depend on device and certificate | CE + AI Act compliance |
| Regulatory sandbox | AI Airlock (MHRA): phase 2 completed May 2026; phase 3 design under way | AI Act regulatory sandboxes (member states) |
| Fundamental rights | UK GDPR, DUAA 2025, Human Rights Act | AI Act FRIA, EU Charter, GDPR |
| High-risk timing | No single horizontal UK AI Act date; current medical-device and sector requirements continue to apply | AI Omnibus in force: relevant Annex III duties from 2 Dec 2027; relevant Annex I product-embedded duties from 2 Aug 2028 |
| Market access | Transition arrangements vary by device and certificate; verify current MHRA registration and conformity requirements | Single market access |
Dual-market strategy: organizations seeking access to both UK and EU markets should map each applicable regime separately. The EU AI Omnibus is in force, with relevant Annex III duties applying from 2 December 2027 and relevant Annex I product-embedded duties from 2 August 2028. UK medical-device and sector rules continue on their own path; an Airlock report is not a substitute for current MHRA guidance. See our detailed UK vs EU AI Act comparison →
Key takeaways
For AI developers
- 1 Determine early whether your AI qualifies as a medical device and its likely classification
- 2 Monitor the official AI Airlock collection for phase 3 eligibility and program announcements
- 3 Build NICE evidence requirements into development from the start
- 4 Ensure robust documentation of training data, validation, and performance monitoring
For healthcare providers
- 1 Verify the applicable conformity marking, MHRA registration and intended-purpose claims before procurement
- 2 Address the CQC fundamental standards and governance duties relevant to the deployment
- 3 Ensure clinical validation in your specific patient population
- 4 Implement ongoing performance monitoring and incident reporting
How GLACIS can support evidence preparation
MHRA, CQC, NHS and NICE have different roles, processes and evidence expectations. For an instrumented workflow, GLACIS can connect an intended rule to selected control events and preserve independently verifiable records of what the configured path reported. Teams may reuse those records when preparing different review, monitoring or procurement artefacts; execution, source truth, timing, and coverage require surrounding evidence, and GLACIS is not integrated with these bodies or claiming regulator acceptance, clinical validity, or legal sufficiency.
Post-market surveillance
For a deliberately instrumented workflow, GLACIS can preserve timestamped records of selected events and control decisions. Those records may support internal monitoring, incident review and preparation of vigilance or trend-analysis material; they do not satisfy reporting or clinical-safety requirements by themselves.
CQC inspection evidence
A scoped evidence pack can help a provider explain which configured controls were active and when they triggered. It does not establish safe integration, clinical outcomes or compliance, and no CQC acceptance is implied.
NICE evidence requirements
GLACIS can bind supplied measurements and test results to the relevant model, policy and control context. It does not generate clinical or economic evidence on its own; teams still need the studies and analyses required for their NICE pathway.
Algorithm assurance
Where teams configure cohort tests, model-version tracking or drift alerts, GLACIS can preserve the resulting control-execution records. Those records do not demonstrate fairness, stability or clinical validity without the underlying methodology and results.
Mapping GLACIS to UK healthcare regulatory requirements
| Regulatory Requirement | Potential evidence contribution |
|---|---|
| MHRA Post-Market Surveillance | Timestamped records of selected events and control decisions can support incident correlation and report preparation. |
| CQC Safe Care & Treatment | Records of recommendations, overrides and review events where the workflow is configured to capture them; no compliance conclusion is implied. |
| NICE Performance Monitoring | Supplied measurements can be bound to model, policy and control context for review; GLACIS does not create clinical evidence. |
| NHS algorithm assurance | Configured cohort tests, version changes and drift alerts can be preserved as operational records. |
| ICO ADM and DUAA rights | Retrieval of captured decision and review events may support investigation and response preparation; rights analysis remains context-specific. |
Prepare the evidence boundary before review
Requirements depend on the product, intended purpose, deployment and pathway. Bring us the action that matters and we’ll map the intended rule, the control events that can be captured, and what the resulting evidence can and cannot establish.