Blog

Setting up healthcare AI governance for fragmented rules in the UK, EU and US

Healthcare organisations face overlapping AI rules across the UK, EU and US. Here is how to map the right requirements, oversight and vendor controls per use case.

· By

Three paper folders each with a different coloured marker tab arranged in a row on a desk, with a medical tablet at the front edge.
A single healthcare AI application falls under several separate rule sets that differ per country and per use case.Image: IamVera.ai — original editorial illustration

Do not treat healthcare AI governance as one universal policy, but map every AI application to the rules that actually apply: model, medical-device, privacy and sector rules. For each use case, map the oversight obligations, the required human oversight and the vendor controls, so you can demonstrate which choice applies where.

The immediate trigger is the report of the UK National Commission into the Regulation of AI in Healthcare, which on 10 September 2026 published recommendations for a future regulatory framework via GOV.UK. In our assessment, that is chiefly relevant because it confirms that healthcare AI cannot be captured with a single set of rules, but with a series of overlapping requirements that differ per country and per application.

What exactly does the UK commission on regulating AI in healthcare recommend?

According to the report of the National Commission into the Regulation of AI in Healthcare, a future UK framework should include, among other things, phased approvals, continuous monitoring in real-world practice and public safety information about AI-supported medical devices. The commission also sets out five principles for the safe adoption of AI.

The core message for decision-makers is that approval is not a one-off moment. An AI system that met the requirements at the time it was put into use should, according to the recommendations, be monitored continuously. That shifts part of the governance burden from the procurement phase to management throughout a system's entire lifecycle.

Why is regulation of healthcare AI in the UK, EU and US fragmented?

There is no single global framework that fully covers healthcare AI. Researchers at Mount Sinai presented an index of the policy landscape around healthcare AI in June 2026 and describe it as a patchwork of rules and institutional guidelines without one central point. A peer-reviewed article on the Health and AI Policy Index on PMC/NIH confirms that oversight in the United States is spread across federal agencies, state legislatures and professional and standards organisations, without one overarching healthcare AI law.

In the European Union a separate layer is added on top. The trade publisher RAPS described in February 2026 how the EU AI Act places its own formal framework over AI systems with a health component, including high-risk systems and AI-supported medical devices. Those requirements come on top of the already existing rules for medical devices and data protection. We see a comparable dynamic with the US states with their own AI laws, where separate rules exist side by side.

How do I map the right rules, oversight requirements and vendor controls per AI application?

The practical consequence is that one universal AI policy is insufficient. In our assessment it works better to draw up a short inventory per concrete application. The following steps help with this:

  • Describe the use case functionally. What does the system do, which decision does it support and does it affect a patient directly or indirectly?
  • Determine the legal qualification. Is it a medical device, a high-risk system under the EU AI Act, a privacy-sensitive processing activity under the GDPR, or a combination of these?
  • Record the oversight obligations. Think of continuous monitoring and safety information as the UK commission proposes.
  • Define the human oversight. Who checks the output, at which moment and with what authority to deviate?
  • Arrange the vendor controls. Which agreements apply to model provenance, updates and liability?

This mapping per phase aligns with recording GDPR responsibilities per phase of your AI workflow, where the same logic applies: responsibility follows the place in the process, not one central policy document.

Which governance framework can I concretely use as a healthcare organisation?

The Coalition for Health AI (CHAI) published extensive governance playbooks in May 2026. According to the announcement from CHAI, these cover, among other things, policy, organisational structures, lifecycle management, risk assessments, data management, third-party management, training and feedback.

Such a framework gives a concrete structure for ordering the fragmentation. We see it mainly as a way to set up governance not as separate compliance islands, but coherently. That aligns with the idea of one governance system for privacy, cyber and AI. You can find more depth on this subject in our topic hub on AI governance and policy.

Where does a verification layer help make these choices visible and reviewable?

If governance has to demonstrate per use case which rules applied and which controls were carried out, visibility of the processing becomes important. Vera is a privacy-focused verification layer for professionals working with confidential information; it is not a chatbot and not its own language model. Vera can route a task through selected independent AI models and make verification steps, corrections, disagreements and sources visible for inspection. That supports review, but does not remove the risk of hallucinations and does not by itself confirm that the output is correct.

For sensitive documents the architecture is set up so that pre-processing and anonymisation take place on EU infrastructure and the workflow is designed to send only anonymised content to the selected models; when a privacy check fails, nothing is sent onward. This is not a legal guarantee of the anonymisation or of full GDPR compliance. The final professional judgement always remains with the user.

Sources and references

  1. National Commission into the Regulation of AI in Healthcare: recommendations for a future regulatory frameworkGOV.UK / National Commission into the Regulation of AI in Healthcare · 2026-09-10
  2. Researchers Create First-of-Its-Kind Index of Evolving Policy Landscape Around Health Care AIMount Sinai newsroom · 2026-06-01
  3. Mapping AI regulation in health care with the Health and AI Policy IndexPMC / NIH · 2026-05-25
  4. Coalition for Health AI (CHAI) releases comprehensive governance playbooksCoalition for Health AI (CHAI) · 2026-05-27
  5. EU publishes regulation governing use of AI in medical devicesRegulatory Affairs Professionals Society (RAPS) · 2026-02-16

Sources: The article draws on the report of the UK National Commission into the Regulation of AI in Healthcare (GOV.UK), the Mount Sinai policy index, a PMC/NIH article on the Health and AI Policy Index, CHAI's governance playbooks and a RAPS analysis of the EU AI Act.

← All articles in this topic ← All articles