By PHARMExcel, a Clinical Research Organisation specialising in Medical Device CRO Services

For much of the history of medical device regulation, market access has centred heavily on a defined pre-market conformity assessment, alongside post-market surveillance and vigilance requirements once a device is in use. Artificial intelligence as a medical device (AIaMD) puts increasing pressure on that model. Software can be updated, retrained or deployed in settings its developers did not fully anticipate, and its performance may change as data, workflows and clinical environments change.
Two UK publications released in 2026 show regulators and policymakers moving towards a more explicitly lifecycle-based model of oversight. That shift has implications well before a device reaches the market, including for how early-stage clinical research is designed today.
An Update to UK Regulation
The Medicines and Healthcare products Regulatory Agency (MHRA) launched the AI Airlock in 2024 as a regulatory sandbox for AIaMD, bringing manufacturers, the MHRA, NHS teams and Approved Bodies together to test real AI-enabled devices under close supervision. The Phase 2 programme report, published in June 2026, draws on seven case studies and sets out a series of findings that go beyond any single product. While the report does not constitute formal MHRA guidance, its findings provide an important indication of the regulatory challenges being explored for AIaMD.
Several of those findings point in the same direction. The report notes that “real-world performance is not sufficiently replicated or represented by controlled testing alone”, and that AI medical devices benefit from a lifecycle approach in which post-market monitoring complements pre-market evidence.
It suggests manufacturers can design validation studies with real-world deployment in mind, identifying which assumptions about user behaviour, data quality and clinical context may not hold in practice. Human oversight is not static either: as a system proves reliable, users may apply less scrutiny, so oversight has to be monitored across the lifecycle rather than assumed. Performance thresholds should also be grounded in clinically meaningful outcomes, not statistical significance alone.
One finding is particularly relevant to early-stage research. The report concludes that “the regulatory significance of a change cannot be determined from the type of change in isolation”. Instead, assessment “will need to start with intended purpose but extend to function, clinical role, user interaction, level of autonomy, deployment environment, benefit-risk impact and human oversight.”
The programme has now moved into a third phase, supported by £1.2 million a year of funding through to 2029, with an increasing focus on translating these insights into practical approaches to lifecycle regulation, including post-market surveillance.
In September 2026, the independent National Commission into the Regulation of AI in Healthcare published 44 recommendations for a future regulatory framework. On 6 October 2026, the Government accepted all 44 recommendations and set out plans to take them forward.
They include staged authorisation pathways, likened to “L-plates for learner drivers”, under which appropriate new AI systems could initially be deployed under tight controls while further evidence is generated before progressing towards fuller authorisation; more proportionate and continuous real-world monitoring throughout a device’s operational life; improved public access to safety information; a proportionate approach to informing patients about the use of AI in their care; and stronger enforcement mechanisms for the MHRA.
Taken together with the Airlock findings, these developments point towards a clear policy direction: the regulation and assurance of AI in healthcare is becoming something that runs alongside a device throughout its lifecycle, rather than being centred predominantly on a single pre-market assessment.
The Forest 1 Case Study
PHARMExcel is currently managing a UK neuroscience research programme that shows why lifecycle thinking can matter for studies taking place long before any future market-access decision.
Run in partnership with Barking, Havering and Redbridge University Hospitals NHS Trust and funded by the UK’s Advanced Research and Invention Agency (ARIA), the programme is a feasibility and early-safety study of Forest 1, an ultrasonic neural interface and whole-brain computer interface developed by US-based Forest Neurotech.
Forest 1 uses ultrasound to measure brain activity, rather than relying on the implanted electrodes typical of some earlier brain-computer interface approaches. The study recruits participants who have previously undergone a decompressive craniectomy, as the resulting gap in the skull allows ultrasound to reach brain tissue that intact bone would otherwise block.
For the purposes of the current study, Forest 1 is being used as a research tool in an exploratory research study rather than for clinical care. The study is being conducted under the research-governance framework applicable to its current use.
Whether later versions or uses of the technology fall within medical-device clinical-investigation requirements will depend on factors including their intended purpose, function, risk profile and the evidence being generated. As the technology develops towards neuromodulation and potential therapeutic applications, those factors — and the associated regulatory requirements — may change.
As the contract research organisation managing the study, PHARMExcel supports the investigators and the Trust with its day-to-day delivery, including study set-up, approvals, participant safety monitoring and data quality.
The current study is overseen through research ethics review, Health Research Authority approval, NHS research governance and the sponsor’s own quality processes. The study is exploratory, and there are no anticipated immediate clinical benefits to participants.
What the 2026 Reports Mean for Studies Like Forest 1
The AI Airlock and the National Commission focus specifically on AI-enabled healthcare technologies. Their recommendations do not themselves establish regulatory requirements for Forest 1 or for other non-AI technologies.
However, some of the underlying questions they raise — particularly around intended purpose, changing functionality, real-world evidence and staged development — provide useful parallels for other novel technologies whose functions and regulatory status may evolve during development.
The first is that a change in function can matter as much as a change in technology. Forest 1 illustrates why intended purpose and function need to be considered early in development.
A platform used initially to measure brain activity may have a very different risk and regulatory profile when developed towards neuromodulation and potential therapeutic use, even where much of the underlying technology remains the same. Recognising that early, rather than treating the later stage as a completely separate project, allows research to be planned with the next stage of development in view.
The second is that lifecycle thinking can start in research, not only at market access. If future validation studies are expected to take real-world deployment into account, the earliest studies are one place where that planning can begin.
For sponsors of experimental studies, that raises practical questions: which data collected now may remain useful once the technology enters a regulated pathway; how design decisions and their rationale are documented; and how outcomes that are clinically meaningful, rather than merely statistically significant, are defined from the outset.
For a study like Forest 1, these are not abstract questions. The possibility of moving from measurement towards modulation is already anticipated, so the evidence gathered in the current phase sits at the beginning of a potentially much longer development and regulatory journey.
The third is that staged, supervised progression is already familiar territory in clinical research. The Commission’s “L-plates” model describes new AI systems moving from tightly controlled use towards fuller authorisation as evidence develops.
Novel technologies in early research can follow a comparable developmental path, from exploratory study to regulated investigation where required and, eventually, towards conformity assessment and market access, with the level and type of oversight changing at each stage.
The Commission’s emphasis on continuous monitoring and on proportionate transparency about how technology is used in patient care also reflects questions that research teams deal with from the first participant onwards, through safety monitoring and informed consent.
In Conclusion
The 2026 publications, together with the Government’s acceptance of the National Commission’s recommendations, indicate a clear policy direction: the most important regulatory questions for AI and other novel medical technologies are increasingly concerned not only with whether and how a device reaches the market, but with how it is evaluated and overseen throughout its development and operational life.
For sponsors working at the earliest stages of development, that means considering the full lifecycle of a technology from the first study onwards, and collaborating with research partners, such as CROs, who can support the generation of robust evidence for today’s research questions while anticipating the regulatory, clinical and operational requirements that may come next.
PHARMExcel’s work on Forest 1 is an example of that kind of early-stage research: a novel technology studied under the governance that fits its current use, while recognising that its regulatory pathway may evolve as its intended purpose, function and potential applications develop.
This advertorial was supplied by PHARMExcel. References to the MHRA, the National Commission into the Regulation of AI in Healthcare, ARIA, Barking, Havering and Redbridge University Hospitals NHS Trust and Forest Neurotech do not imply endorsement of PHARMExcel unless expressly stated.
