Confirmation is not a mitigation. It is the classification.
The MHRA's guidance of 29 July 2026 leaves ambient scribing tools outside medical device regulation only while their outputs restate what was said and a clinician confirms them. Both conditions are held in place by product decisions, and both can be undone by an ordinary feature release.
The guidance arrives forwarded, with one line written above it: we are out of scope. An ambient scribing tool has been running in clinics for months. It listens, it writes the note, it drafts the letter. The regulator has now said in print that a product doing only that is not a medical device. Nobody reopens the safety case. The next three tickets go into the sprint.
The reading is correct. On 29 July 2026 the MHRA published guidance on ambient voice technology-enabled products, developed in partnership with NHS England, setting out that a product intended solely to transcribe a consultation, summarise it, draft a letter, or suggest clinical codes for a clinician to review does not have a medical purpose and is therefore not regulated as a medical device.
What the guidance does not do is settle the question. It states conditions, and a product sits outside the regime only while they hold: the outputs restate what was said rather than derive something that was not, and a clinician confirms them before they reach the record or cause anything to happen. Both conditions live in a product backlog. Neither of them lives in anything a governance forum currently has scheduled.
Where the line actually falls
The guidance is unusually concrete about the boundary, and the examples are worth reading in the original rather than through a summary of them. A product that turns a transcript into structured data for a clinician to review and confirm stays outside, on the condition that it is “not intended to derive or recommend any new information”. A product suggesting clinical codes stays outside where the codes come from terms that were explicitly mentioned. A product offering “suggested diagnoses or relevant follow-up and treatment options” is inside.
The distinction is derivation, not difficulty. Condensing a long consultation without losing what mattered in it is not an easier engineering problem than listing plausible diagnoses from a symptom list, and yet condensing is the one that stays outside the regime. What moves a product across is the appearance in the output of something nobody said.
- 01 Capture Audio becomes a transcript. Nothing is added.
- 02 Restate Summary, letter, code — all from what was said.
- 03 Derive A diagnosis or a follow-up nobody mentioned.
- 04 Act The order is placed, or the record is written.
There is a second crossing further along the same chain. A product that will “autonomously determine necessary follow-up tests and place the relevant orders without clinician input or confirmation” is regulated, and the reason is the missing confirmation rather than the sophistication of the ordering logic. The MHRA is explicit that responsibility for reviewing and verifying generated transcripts, summaries and other outputs before they are used in patient care sits with clinicians, and that the guidance does not change that.
And there is a third crossing that is not in the code at all. Intended purpose is defined by the claims in the instructions for use, the labelling and the manufacturer’s promotional material. A marketing page saying the product guides diagnosis and treatment planning makes a medical claim whatever the software does. The guidance closes the obvious escape route as well: general disclaimers, it says, “are not acceptable to demonstrate a product is not a medical device if medical claims are made or implied elsewhere in the product labelling”. The website is inside the regulatory perimeter. Most engineering change-control processes do not know that the website exists.
The guidance then says the thing that ought to be pinned above the backlog. A product released without a medical purpose “may be given features and new functions over time”, and “these modifications may result in the product meeting the definition of a medical device”.
Why the confirmation step is not a control
On most risk registers this practice has read, human review appears as a mitigation. It sits in the column next to a residual score, which means it is implicitly tradeable — against latency, against clinician fatigue, against the cost of a workflow step that most of the time changes nothing. That is what a mitigation is for. It buys down a risk, and when the risk falls or the cost rises, it can be revisited.
Under this guidance, in this product category, that framing is wrong. The confirming step is not buying down a residual risk. It is one of the conditions that keeps the product outside a regulatory regime altogether. Removing it does not move a score by a notch. It changes which obligations apply and which party carries them.
Human review that can be traded away for latency was never a control. Here it is the classification.
The harder version of the same problem is confirmation that exists in the interface and not in practice. A screen that pre-selects the suggested codes, a save that fires on a timeout, a bulk accept for a day’s worth of notes — each of those is a design decision about how real the review is, taken for good operational reasons, and none of them looks like a regulatory event when it is written as a ticket. The guidance draws its line at clinician review and confirmation. It does not define how much review is enough, and that is a genuine gap rather than an oversight to be argued away.
What to do about it
Put intended purpose in the definition of done. The question a ticket has to answer is short: does this derive, or does it restate, and can anything now reach the record without a confirming action. Asked at the ticket it costs a sentence. Asked after deployment it costs a regulatory assessment and a conversation with a regulator about a product that has been live for two quarters.
Contract for notification if you are deploying rather than building. A supplier’s roadmap is now part of the deploying organisation’s regulatory position, and the deploying organisation does not see it. The announcement of the guidance puts the duty to identify a change in a product’s functionality that may alter its regulatory status on NHS boards, and that is a duty which cannot be discharged without the supplier’s cooperation. Ask for it in writing before the renewal, not after the release note.
Read the marketing copy as a regulated artefact. The claims that set intended purpose are usually written by people who have never seen the change-control process. A single sentence added to a pricing page can make a medical claim that the engineering team would not recognise as one.
Evaluate the property that matters. Transcript word error rate is the easiest thing to measure and it says nothing about the boundary. The two observables that do are the rate at which a summary asserts something absent from the transcript, and the rate at which a clinician edits what was presented before confirming it. The second is the only evidence that the confirming step is real rather than nominal, and it is collected by the product itself.
The shape recurs outside healthcare. Wherever a regime attaches obligations to whether an output was derived and whether a person confirmed it, the boundary sits inside the build rather than in the annual review. The recalibration here has been welcomed by the sector — techUK’s position statement of 14 August 2026 supports proportionate treatment while noting that any product claiming a medical intended purpose continues to be regulated as a device. Proportionate treatment is the right outcome. It also moves the decision to the people least equipped to notice they are making it.
What this does not tell you
This is guidance on how existing medical device law applies. It is not a change in the law, and it does not decide the status of any particular product. Classifying a specific product is a regulatory question for its manufacturer, and the legal interpretation stays with counsel and the regulatory affairs function. The institute assesses readiness and maps controls against obligations. It does not determine device status for anyone, and no assessment here or anywhere else substitutes for the manufacturer’s own determination.
Nor does the guidance settle what counts as adequate clinician review, or what a deploying organisation must do under NHS England’s separate expectations for these products. Both are open, and a piece that pretended otherwise would be selling certainty that does not exist.
The clinical safety officer reading this has one task that was not on the list yesterday, and it is not a document review. It is to find the ticket — the one that adds a ranked suggestion, or removes a click — because that is where the classification changes, and it changes on the day the ticket ships.