The UK Commission Wants L-Plates for AI and an End to One-Time Approval
The National Commission into the Regulation of AI in Healthcare published its recommendations on 10 September. Coverage is treating them as new rules for AI. Read together, they propose something narrower and more consequential: replacing the single approval decision with a supervised entry and a permanent monitoring obligation.
The Commission is an independent, non-statutory advisory group established by the MHRA in September 2025 and chaired by Professor Alastair Denniston, an NHS consultant. Its report runs to 119 pages and draws on engagement with more than 12,000 stakeholders, alongside public deliberation, industry roundtables and international contributors including from the US and Singapore.
Four recommendations carry the framework. Staged authorisation, described as L-plates for new AI models, deploying them under close supervision and tight guardrails to demonstrate real-world safety before fuller authorisation. Continuous real-world monitoring across a device’s working life in place of a single point-in-time approval. A publicly searchable record of safety information and adverse incidents for named AI-enabled devices, modelled on the MHRA’s interactive Drug Analysis Profiles. And stronger MHRA enforcement powers.
The UK currently regulates these products under medical device regulation as software as a medical device or AI as a medical device. In the MHRA’s June 2026 consultation, 50% of respondents said the framework needed substantial revision and a further 21% called for complete overhaul.
None of this is policy. A cross-government response will follow separately.
Staged authorisation is conditional marketing authorisation, applied to devices
The L-plate framing is doing a lot of work and it is worth unpacking. Under the proposal a new model enters clinical use before it holds full authorisation, operating under supervision and constrained guardrails, and earns fuller approval by generating real-world safety and performance data in use.
Devices do not currently work that way. Medicines sometimes do. Conditional marketing authorisation in the EU and accelerated approval in the US both permit market entry on incomplete evidence against an obligation to complete it. The Commission is proposing to import that logic into device regulation for one technology class.
That has a specific commercial consequence. The point at which a developer can begin generating revenue moves earlier, and the point at which regulatory obligation ends moves later, possibly never. Cash flow improves at the front and compliance cost extends indefinitely at the back.
Continuous monitoring is aimed at a documented failure
The second recommendation replaces single-point approval with monitoring across the working life of the device. Framed as patient safety, it also answers an evidence problem that has been quantified.
An evidence census published in PLOS Digital Health in August examined all 1,357 AI and machine-learning enabled devices cleared by the FDA through December 2025. It found 34 linked to registered prospective trials, 12 with published results, and 3 evaluating patient-centred outcomes. The mechanism it identified was the predicate chain: a 510(k) demonstrates equivalence to an existing device rather than independent effectiveness, so a device cleared against an unvalidated predicate inherits and passes on that gap.
Continuous monitoring does not fix that by raising the entry bar. It removes the assumption that entry settles the question at all. Evidence generation becomes a condition of continued marketing rather than a hurdle cleared once.
The commercial angleFor anyone building AI-enabled devices for the UK market, the proposals change the shape of the cost curve rather than its size. Entry gets cheaper and faster under staged authorisation, which favours smaller developers who cannot fund a full evidence package before revenue. Post-market obligation gets heavier and permanent, which favours companies with the infrastructure to run continuous surveillance, and that is not the same set of companies. A developer optimising for the current regime builds toward a submission and then stops. A developer optimising for this one builds a data pipeline it will operate for the life of the product. The second is a different engineering and staffing decision, and it has to be made before the first product ships rather than after.
The public incident database is the recommendation with teeth
The third recommendation attracts least attention and would change behaviour most. It proposes public, searchable safety information on specific named AI-enabled devices, including adverse incidents, built on the model of the MHRA’s Drug Analysis Profiles.
No equivalent transparency exists for AI devices in any major market. Adverse incident reporting generally flows to the regulator and stays there, surfacing in aggregate or through enforcement.
A named, searchable incident record changes two things at once. Procurement acquires a due diligence tool, so an NHS trust could examine a device’s incident history before purchase rather than relying on vendor claims. And vendors acquire a reputational exposure that operates continuously rather than at the point of a recall.
That combination tends to move behaviour faster than enforcement does, because it works through the buyer rather than through the regulator.
What to watch
The cross-government response, which is where recommendations either become a workplan or a filed report. The Commission is non-statutory and advisory, and several of these proposals require legislation rather than guidance.
Whether staged authorisation survives contact with liability. A model deployed under supervision before full authorisation raises the question of who carries responsibility when it errs, and the report’s remit covered accountability and clinical practice alongside device regulation.
And whether the MHRA gets the enforcement powers it has been recommended. A regulator being handed a more permissive entry route and a continuous oversight duty needs the second to make the first defensible, and asking for enforcement powers alongside staged authorisation is not coincidental.
The framing to resist is that this is a set of AI rules. What the Commission has described is a different regulatory shape for a technology that changes after approval, where the one-time decision was always a poor fit. Whether the UK adopts it is a separate question, and the answer arrives with the government response rather than with this report.
