Request a scoping call Contact
← Research

Plan the evaluation route before healthcare AI scales

The Government has accepted all 44 recommendations on artificial intelligence (AI) in healthcare, but much of the implementation detail is still forthcoming. Providers can prepare by deciding how local evaluations will be classified, governed and connected to clinical safety evidence.

Governance / Conceptual study
Trace the evidence.
  1. Sources
  2. Evidence links
  3. Decision record

Keep sources linked to the record used for review. The diagram does not represent automatic approval.

On 6 October 2026, the UK Government accepted all 44 recommendations from the National Commission into the Regulation of AI in Healthcare. That is a substantial policy signal for organisations buying and using health technology. It is not yet a local deployment checklist. The response schedules an implementation plan and roadmap for Spring 2027, while naming several pieces of guidance that still need development.

The decision providers can make now is narrower and more useful: who will own the evidence generated when a product is evaluated in the service where it may later be used? The Commission’s recommendation 31 calls for national best practice across procurement, implementation, monitoring, reporting and end-of-life management, including for emerging technologies such as agentic systems. The Government accepts it and says the Department of Health and Social Care, working with devolved health departments, will explore lifecycle guidance and strengthen guidance under DCB0129 and DCB0160. Further details are due by Spring 2027.

Recommendation 44 addresses a different boundary. The Government says the Health Research Authority will update its guidance on when AI development, deployment, evaluation and monitoring constitute research requiring research governance, including silent local evaluation and in-silico methods. It says classification depends on an activity’s purpose, design and context rather than its label. That guidance is also due by Spring 2027. Until it arrives, teams should plan evaluation as a governed activity, not assume that calling it a pilot, audit or silent test resolves its status. (Government response, recommendations 31 and 44)

observed evidence

A commitment leaves a local evaluation decision

Swipe or scroll for the full diagram →

The evidence stops before the proposed applicationObserved finding connects to an inference. A dashed boundary separates that inference from the untested application.ObservedInferenceUntested application
The evidence stops before the proposed applicationObserved finding and inference appear above a dashed boundary. The untested application remains below it.Observed findingInferenceUntestedapplication

Assign a local owner and review route before evaluating deployed healthcare AI.

Observed
On 6 October the Government accepted recommendations to develop lifecycle guidance and clarify governance for local evaluation. Further detail is due by Spring 2027.
Inference
A short evaluation charter can link the product version, purpose, cohort, data route, clinical safety review and escalation trigger.
Evidence boundary
The response does not classify a particular provider’s activity or replace local decisions about clinical safety, patient information and research governance.

This evidence boundary separates the published commitment from a proposed local design and the classification that still depends on an activity’s purpose, design and context.

The government response accepts work on lifecycle management and evaluation guidance, with more detail due in Spring 2027. A local evaluation charter is an architectural inference. The response does not classify a particular activity or replace existing governance decisions.

Reviewed 2026-10-08

Keep four decisions visible

A useful evaluation can answer whether a product behaves acceptably in a local pathway, for the intended users and population. It can also reveal a problem early enough to narrow use or stop a rollout. But the evaluation question sits beside other decisions, not above them.

First, establish what the product is intended to do and which version is being assessed. The Commission’s report says that AI used in healthcare falls under different regimes depending on intended purpose, functionality and context. Some products qualify as medical devices. Others may be governed through data protection law, professional standards, organisational governance or other sector-specific rules. A generic category such as “clinical AI” does not determine which applies. (National Commission report, introduction and scope)

Second, keep manufacturer and provider clinical-safety evidence distinct. NHS England describes DCB0129 as the manufacturer’s clinical risk management standard and DCB0160 as the corresponding process for a care organisation deploying and using health IT. The Government response says these standards are under review and proposes further guidance. A local evaluation should identify the supplier evidence it relies on and the provider’s own pathway-specific safety review. One does not stand in for the other. (NHS England digital clinical safety guidance and Government response, recommendation 31)

Third, determine how the evaluation itself is governed. The HRA’s existing guidance distinguishes research from service evaluation and explains that post-deployment monitoring may involve different review routes. The Government’s new response is explicit that more guidance is needed for methods such as silent local evaluation. A test that does not alter care may still use confidential patient information, depend on local data-access controls or require clinical-safety oversight. Research approval, clinical safety review and information governance answer different questions. (HRA guidance on development, deployment and monitoring of data-driven technologies and Government response, recommendation 44)

Put the route in the adoption decision

Before collecting evaluation data, the provider’s clinical safety owner and research or service-evaluation office should agree a short record that captures:

  • the question being tested, its purpose and the decision the result may inform
  • the product, model or software version, intended use, care setting, cohort and comparison method
  • whether outputs can affect a patient’s care during the evaluation, and how an unexpected result will be escalated
  • the data source, access route, confidentiality and information-governance review
  • who owns the evaluation classification, the clinical risk review and the decision to continue, narrow, pause or stop.

For a hypothetical local assessment of imaging software, this record could specify that an offline comparison uses a defined patient cohort and existing clinical outcomes, that the software result does not reach treating clinicians, and that a clinical safety owner reviews any concerning divergence. Those facts describe the proposed method. They do not, by themselves, settle whether it is research or prove that the product is safe. The local research office and other relevant governance owners must assess the actual activity.

This small piece of planning creates a practical opportunity. A provider can ask for the supplier’s evidence in a form that supports local review, plan evaluation before procurement is complete and avoid trying to reconstruct the assessed product version after a concern appears. It also makes later national guidance easier to apply because the service has already documented its purpose, method, data and owners.

Do not turn acceptance into a new rule

The Commission’s 10 September report is advice for a future regulatory and assurance framework. The 6 October response accepts its recommendations and sets out government intentions, delivery partners and timelines. Recommendation 31 refers to DCB guidance currently under review. Recommendation 44 promises clearer HRA guidance. Neither publication is itself the new guidance or a replacement for the existing standards. (Commission report and Government response)

The HRA’s public page on data-driven technology monitoring was last updated in December 2022, which is another reason to avoid treating an old example as a universal answer for newer AI methods. The new response says the eventual classification must follow the activity’s purpose, design and context. That is the defensible test to prepare for, but a specific assessment remains local and fact-dependent. (HRA guidance, last updated 5 December 2022)

For the next healthcare AI adoption decision, name the evaluation owner and route before the first local data is collected. Keep that route linked to the product version, clinical-safety evidence and intended use. Then revisit it when the technology, evaluation question or role in care changes.

Filed under · Governance · Healthcare AI · Evaluation · Clinical safety Inference Institute · 08 Oct 2026

Related engagement

The decision behind this article

Governance your organisation can operate, with clear owners and decision criteria.

Explore AI Governance →

Bring us the question

Reading this because it is on your desk right now?

That is the conversation we are best at. Thirty minutes, a written summary, no obligation.