Medical device regulation was built around relatively stable products: a device is evaluated, its safety and performance are certified, and then it is monitored. Artificial intelligence makes this sequence less linear, as performance and risks can depend on data, clinical context, and updates. The British National Commission into the Regulation of AI in Healthcare has proposed a model that attempts to adapt oversight to this reality.
The recommendations published on September 10, following a consultation process that the government describes as extensive, outline more flexible pathways to enable the adoption of promising tools alongside proportionate safeguards. Among the ideas discussed is a form of conditional initial authorization, likened to a provisional driving license, paired with subsequent monitoring and greater transparency regarding incidents.
The problem of performance drift
A system may perform well on the validation dataset and behave differently when encountering different populations, hospitals, or procedures. This is why post-market surveillance becomes central: it is not enough to ask whether the model was safe at the time of authorization; one must be able to verify whether it remains so.
The British model thus attempts to avoid two extremes: demanding an impossible upfront certainty or letting innovation proceed without public tools to intervene when issues arise. It is an issue that extends far beyond healthcare, as many AI systems are dynamic products.



