Setting up healthcare AI governance for fragmented rules in the UK, EU and US
Healthcare organisations face overlapping AI rules across the UK, EU and US. Here is how to map the right requirements, oversight and vendor controls per use case.
You must map each AI application to the specific rules that apply to it—model governance, medical-device regulation, privacy law and sector rules—and document which oversight obligations and vendor controls you have chosen for each use case. Approval is not a single moment; continuous monitoring throughout the system's lifecycle is now the standard.
The prompt is an analysis of 10 September 2026 of overlapping AI rules across the UK, EU and US in healthcare, which argues that a single universal AI policy cannot capture the fragmented regulatory landscape, and that governance must instead follow the specific rules that apply to each application. The UK National Commission into the Regulation of AI in Healthcare published recommendations for phased approvals, continuous monitoring in real-world practice and public safety information about AI-supported medical devices. In our assessment, this confirms that healthcare AI governance cannot rest on one framework, and that your obligation is to demonstrate per use case which rules apply and which controls you have put in place.
Why one universal policy will not work
The regulatory landscape for healthcare AI is not centralised. In the United States, oversight is distributed across federal agencies, state legislatures and professional standards bodies, with no single overarching healthcare AI law. The European Union layers its own AI Act framework on top of existing medical-device and data-protection rules. Individual US states have introduced their own AI laws, creating parallel requirements. This fragmentation means that an AI system used across multiple jurisdictions faces different approval pathways, monitoring obligations and vendor controls depending on where it operates and what it does.
What changes in the approval and monitoring cycle
Traditional healthcare AI governance treated approval as a discrete event: the system met requirements at deployment, and oversight ended. The UK Commission's recommendations shift this model. Continuous monitoring in real-world practice is now the expected standard. An AI system that satisfied requirements at the time it entered use must be monitored throughout its entire lifecycle. This moves part of your governance burden from procurement to ongoing management, and it means you must establish processes to detect when a system no longer meets the standards it was approved under.
Which rules and oversight obligations apply to your use case
Mapping governance per application requires you to identify four layers of rules:
- Model governance frameworks — requirements specific to how the AI model is developed, tested and updated.
- Medical-device regulation — approval and post-market surveillance obligations if the system qualifies as a medical device.
- Privacy and data-protection law — GDPR in the EU, state privacy laws in the US, and UK data-protection rules, each with different scope and obligations.
- Sector-specific rules — healthcare licensing, professional standards and institutional guidelines that apply to the clinical context.
- AI-specific regulation — the EU AI Act's risk-based classification and high-risk system requirements, and equivalent state-level AI laws.
For each use case, you then identify which of these layers applies, what approval or notification is required, and what continuous monitoring looks like in practice.
What concrete controls must you be able to demonstrate
- Document the application and its legal basis — record which AI model is used, what clinical or operational task it performs, and which rule or rules make it subject to oversight.
- Establish approval and monitoring checkpoints — define the approval pathway for each layer of regulation, and the intervals and methods for continuous monitoring in real-world use.
- Define vendor responsibilities and audit rights — specify which controls the vendor must provide, which you retain, and how you will verify compliance throughout the system's lifecycle.
- Record decisions and disagreements — maintain an audit trail of which rules you applied to each use case, why you chose that classification, and what evidence supports it.
- Plan for change management — document how you will detect when a system no longer meets its approval requirements, and what process you will follow to update, restrict or withdraw it.
How to structure governance coherently across privacy, cyber and AI
The Coalition for Health AI published governance playbooks covering policy, organisational structures, lifecycle management, risk assessment, data management, third-party management, training and feedback. This framework helps you order the fragmentation not as separate compliance silos but as one coherent system. The same logic applies to GDPR responsibility mapping: responsibility follows the place in the process, not a single central policy document. Use this structure to ensure that privacy governance, cybersecurity governance and AI governance reinforce each other rather than working at cross-purposes.
No tool can remove your professional judgement about whether an AI system is fit for its purpose or whether the output is correct. Visibility of processing—what data went in, which model processed it, what steps were taken to verify the result—supports your review. But visibility is not verification, and it does not guarantee that the output is accurate or that all risks have been mitigated. The final responsibility for the decision remains yours.
Sources: This article draws on reporting and guidance from GOV.UK, National Commission into the Regulation of AI in Healthcare, Mount Sinai newsroom, PMC, NIH, Coalition for Health AI (CHAI) and Regulatory Affairs Professionals Society (RAPS).
Written by
Marit Halversen
Covers AI governance and regulatory design, with a focus on how compliance obligations land on architecture rather than on paperwork.