Skip to main content
Apps available in

Blog & News

The National Commission's report on AI in healthcare: what it asks of NHS trusts

Could your organisation say today how AI is governed?
| Aden Maine | Blog

The National Commission into the Regulation of AI in Healthcare published its recommendations for a future regulatory framework on 10 September 2026. It runs to 119 pages and makes 44 recommendations. Most coverage has picked up four of them. The ones that matter most to NHS trusts sit in the middle of the document.

What the report says

The recommendations are organised around three principles: proportionate lifecycle regulation, system-wide responsibility and safe management, and trust, transparency and predictability.

Chapter 1 is largely addressed to the MHRA — how AI-enabled devices should be classified, brought to market and monitored. Chapter 2 is different. It is addressed to DHSC, the devolved health departments and to providers themselves. That is where trusts appear, and it is the part nobody is writing about.

What the report asks of NHS trusts on AI governance

Recommendation 29 asks government to co-develop an adaptable AI readiness toolbox, so providers can self-assess their readiness to deploy a particular AI product, deliver the risk controls that product requires, and articulate the governance structures they have in place to deploy it safely.

Recommendation 26 asks manufacturers to specify the operational conditions needed for safe deployment, including controls that must exist in the user environment: cybersecurity, user training and institutional AI readiness. Those controls then become the provider's to deliver — and under Recommendation 28, to allocate contractually.

Recommendation 33 says providers must ensure staff undertake technology-specific training aligned to the AI technologies used in their practice. It is the only place in 119 pages the report says "must" to a provider.

Recommendation 20 asks that deployed AI carries version control and a unique device identifier in the patient record, so providers can identify and audit the outcomes of patients whose care involved a particular device.

Recommendation 30 asks for national baseline governance expectations to minimise local disparities in AI readiness, adoption and governance — and a national learning function, because implementation learning is currently siloed between trusts.

So three questions worth asking at your next governance meeting:

  • Who could name every AI-enabled product currently in use across the organisation, and which version each is running?
  • Where is the evidence that the people using those products have been trained on them specifically?
  • If your board asked tomorrow how AI is governed here, what single document would you hand over?

If the answers live across procurement records, IG documentation, digital team spreadsheets and clinical governance minutes, that is the inconsistency Recommendation 30 is describing.

What the report doesn't say

Worth being precise, because a few things have been reported that the document does not support.

It is not law. It is advice to government, and a cross-government response will follow separately with no date given. It does not reallocate liability — it acknowledges the "liability sinks" that push responsibility onto professionals and providers, then says wider reform may be needed and will take time. Monitoring is proportionate to a device's risk, not blanket. And LFPSE is not mentioned once: Recommendation 18 looks at improving the Yellow Card scheme for AI and software-enabled devices instead.

Where to go next

The national toolbox in Recommendation 29 does not exist yet. While government considers it, we have published our own sector view on AI readiness — our AI readiness guides set out what to think about before you deploy, by sector.

If you would rather talk it through: our Harness AI in Healthcare summit covers exactly this ground, and our whitepaper on AI in patient safety goes deeper on governance and oversight.

Frequently asked questions

Is the National Commission's report legally binding?

No. The Commission is an independent advisory body established by the MHRA. Its report makes recommendations to government, and a cross-government response will follow separately. No implementation timeline has been published.

What does the report ask NHS trusts to do?

Chapter 2 asks providers to self-assess AI readiness, deliver the risk controls a manufacturer specifies, evidence AI-specific staff training, and articulate their AI governance structures. Recommendation 33 is the only obligation stated as a "must".

Does the report change liability for clinicians using AI?

No. It acknowledges that responsibility currently falls disproportionately on healthcare professionals and providers, and says wider legal reform may be needed but will take time. It recommends clarity on how responsibility is distributed rather than reallocating it.

In just a click, your job gets easier.
Speak to the team.