

In a radiology reporting room at a district general hospital, a consultant scrolls through a backlog of chest scans while a vendor explains that the software on screen has been cleared in the United States for years. The clinical safety officer asks a different question. Who validates it on this trust's scanners and this trust's patients, and who answers when performance slips in month eighteen? Nobody in the room has a ready answer.
That exchange is the UK version of a story now told most clearly in Washington. The US regulator reports more than 1,600 AI-enabled medical devices authorised for the market, covering retinal screening, skin cancer imaging, cardiac risk estimation and automated insulin dosing. More significant than the count is the shift in method. Predetermined change control plans let developers set out in advance how an algorithm may be updated, so that a learning system does not need a fresh submission for every revision. Oversight is moving from a single approval decision towards management across the whole product lifecycle.
Britain has reasonable grounds to be uneasy by comparison. The medical device rules still carry the structure inherited from the European system, which was written for static hardware. The MHRA has strengthened post-market surveillance, run an AI regulatory sandbox and signalled a greater willingness to rely on approvals from trusted overseas regulators. A national commission has been examining how AI in healthcare should be regulated. These are sensible steps, but they amount to a framework under construction. A developer wishing to update a model in the UK still faces less certainty than one working to the American process.
Yet regulatory speed is the secondary problem. The primary one sits between a marketing authorisation and a working clinical pathway. The NHS carries a waiting list measured in millions, persistent diagnostic backlogs and a workforce with little slack. Imaging, pathology and triage are exactly where AI promises capacity. The system then asks more than two hundred trusts to conduct their own clinical safety cases, data protection assessments and procurement exercises, often with small teams and uneven digital maturity. Promising tools stall in pilot. Others are adopted on the strength of one enthusiastic clinician and never evaluated properly.
Adaptive technology makes this harder. An algorithm that changes, or that meets a different patient population, can drift. Regulators depend largely on manufacturers to report problems. The NHS holds the data that could reveal drift, but it has no routine, site-level capability to measure how a cleared device performs against local outcomes. The federated data platform and the wider push on health data could eventually supply that capacity, yet public trust in data use remains fragile and easily damaged by a single badly handled project.
The practical implications differ by audience. Trust leaders need a repeatable assurance model, preferably shared across integrated care systems, so that every deployment does not begin from zero. Policymakers should decide quickly who holds liability when a clinician follows, or overrides, an algorithmic recommendation, because ambiguity will slow uptake more than any licensing delay. Life sciences and health-tech firms need clarity on change control, and a reliance route from overseas approvals will help only if the NHS can absorb what arrives. Patients need to know when AI has influenced their care and where to direct a complaint.
The UK has a credible claim to being a good place to test these tools, given a single national system, rich data and a strong research base. That claim is worth something only if the NHS can turn it into evidence. A device cleared in Washington or London means little until a trust can show, with its own data, that it works on its own patients. Until that is routine, authorisations will keep climbing elsewhere and adoption here will depend on the goodwill of individual clinicians.