AIRiskAware
UK sectors
MHRACQCICONHS

AI governance in UK healthcare & nhs.

Healthcare AI in the UK is regulated at the intersection of medical device law (MHRA), data protection (UK GDPR and common law confidentiality), NHS governance requirements (DSPT, Evidence Standards Framework), and professional accountability (GMC, NMC, Royal Colleges). Clinical AI must have appropriate MHRA regulatory status before NHS deployment, and NHS trusts must demonstrate AI systems meet data security standards through annual DSPT assessments.

Regulatory obligations at a glance

Key frameworks applying to AI in UK healthcare & nhs.

UKCA / SaMD
MHRA

AI used for diagnosis, treatment recommendation, or risk prediction is regulated as a Software as a Medical Device. UKCA marking is required before clinical deployment — using uncleared AI in clinical settings creates significant legal exposure.

High
DSPT Assessment
NHS England

NHS trusts must complete the Data Security and Protection Toolkit assessment covering AI tools processing patient data. AI systems must meet NHS data security standards before clinical deployment.

High
UK GDPR / Confidentiality
ICO

Patient data processed by AI systems requires a lawful basis, DPIA for high-risk processing, and compliance with the common law duty of confidentiality. Data Processing Agreements must be in place with AI vendors.

High
Evidence Standards
NHS England

The NHS Evidence Standards Framework for Digital Health Technologies sets the evidence required before AI adoption into NHS clinical pathways — from analytical validity to clinical effectiveness depending on risk level.

High
CQC Inspection
CQC

CQC inspects how care providers use technology including AI in patient care. AI governance including risk assessment, staff training, and incident processes is increasingly examined in inspections.

Medium
GMC / NMC Duties
GMC/NMC

Clinicians retain professional responsibility for AI-assisted decisions. Reliance on AI without understanding its limitations and failure modes may breach the professional duty of care.

High

Guidance and analysis

AI in UK Healthcare: What NHS Trusts and Private Healthcare Providers Must Do

9 min read

AI in the NHS: Your Rights as a Patient When Algorithms Inform Your Care

9 min read

UK governance hub All UK sectors