The National Commission's blueprint for AI regulation is a welcome step forward. Now the NHS needs the people, time and infrastructure to make it work.

The National Commission's proposed approach to regulating AI in healthcare is a welcome step towards regulating a technology that changes over time. But regulation will only work if the NHS has the people, the time and the infrastructure to evaluate AI safely in real-world care. The Commission's recommendations point in the right direction. What follows is where we think the effort now needs to go.

1. AI regulation has to continue after approval

AI tools cannot be checked once and then left alone. Because they can learn, change, or perform differently in different settings, they need to be monitored after they are introduced into real care.

The Commission's shift from one-off approval to lifecycle oversight is a sensible response to that problem. Its proposals for staged authorisation and predetermined change control plans would help regulation keep pace with the technology.

A staged approach also allows the level of regulation to match the level of risk, as the Academy has called for. AI used to analyse operational data carries a different risk to patients than AI used to help decide clinical interventions, as triage and decision support tools are now doing in dermatology and elsewhere. The regulatory barrier should be proportionate to the risk.

2. Real-world evidence depends on research capacity in the NHS

The Commission is right to emphasise real-world evidence. Regulation cannot rely only on evidence produced before a product enters the health system. It also needs evidence about how technologies perform in routine practice and across different patient groups.

That evidence does not appear automatically. It requires access to high-quality data, systems that can link that data safely, and people with the skills to spot when an AI tool is no longer working as expected.

This matters for fairness too. A tool that works well in one hospital, or for one group of patients, may not work as well everywhere. Without the right data, systems and research capacity, lifecycle regulation risks becoming an aspiration rather than a reality.

3. The NHS becomes part of the assurance system

Under the traditional model, manufacturers generate evidence, regulators assess it, and healthcare organisations use the resulting products. Under a lifecycle approach, NHS organisations, researchers and clinicians also help check whether AI remains safe and effective once it is in use.

The challenge is therefore not only whether regulators can oversee AI effectively, but whether the wider health and research system has the people, the time and the capability to support that oversight in practice.

4. Protected research time is what makes lifecycle regulation work

The burden does not fall evenly. An approach that is more permissive at the point of entry asks less of manufacturers and more of providers and clinicians after deployment, and they are the ones with the least spare capacity.

The Commission recognises that workforce capability matters. But its focus is on the workforce that uses AI. Lifecycle regulation also depends on the workforce that evaluates it, and that is a research question rather than a training one.

Monitoring how an AI tool performs in practice means designing evaluations, interpreting the findings, and understanding why performance varies between settings and patient groups. It has to continue for as long as the product is in use, and it needs funded time.

Clinical academics in NHS trusts and universities are already leading some of the most promising work in this field, and they will be central to both AI implementation and its regulation. But a lack of funded research time is one reason experienced consultants are stepping away from clinical academic roles. If that continues, lifecycle regulation will be harder to deliver.

The problem will grow as AI develops faster. If products can change quickly, the systems used to evaluate them have to keep pace.

What happens next

The Commission has produced a credible blueprint, and whether it works now depends on implementation. The immediate priority should be protected, funded research time within NHS providers, so that clinicians and researchers can evaluate AI tools properly in real-world care. Data systems, adoption support and public engagement all matter, but without research capacity in the NHS, lifecycle regulation will be hard to deliver.

The Academy is developing a longer-term programme of work on the responsible, effective and equitable use of AI and data across the biomedical sciences. We recently submitted evidence to the Department for Business, Innovation, Science and Trade's consultation on data regulation in the age of AI, and earlier this year we responded to a House of Lords Science and Technology Committee inquiry on the use of AI in personalised medicine. We will continue to bring together regulators, developers, providers, funders, clinicians and patients to look at this question from different angles.