AI medical devices go live in the NHS, the controls that make it safe
Live NHS deployment of AI medical devices is safe only when every output is provable, humanly overseen and held on infrastructure the trust controls.

Safe live deployment of AI medical devices depends on three things a sandbox cannot supply by itself: evidence of every output the system produced, enforced human oversight of decisions that touch a patient, and patient data that never leaves the clinical network. On 10 June 2026 the MHRA launched London Region I, a regulatory sandbox run with NHS England and the London Health Innovation Networks for the controlled deployment of AI medical devices in live NHS settings. It follows an April 2026 funding boost that expanded the regulator's AI Airlock programme, and it moves the conversation from whether AI belongs in the clinic to how it must behave once it is there.
What did the MHRA announce on 10 June 2026?
The MHRA launched London Region I, a regulatory sandbox that allows AI medical devices to be deployed in live NHS settings under controlled conditions, run jointly with NHS England and the London Health Innovation Networks. The launch builds on the regulator's AI Airlock programme, which received a funding boost in April 2026 that enabled its expansion. The significance sits in the word live. Airlock's earlier work examined AI medical devices in contained conditions. London Region I is designed to let those devices operate inside real clinical workflows, with real patients, under regulatory observation. We think that is the right direction for the NHS, and we also think it changes what every participating trust must be able to prove.
Why does live NHS deployment raise the stakes on traceability?
Because a wrong output in a live setting can reach a patient, the evidential standard rises the moment a device leaves contained testing. In a simulation, a fabricated finding is a data point. In a live care pathway, it is a clinical incident, and the questions that follow arrive quickly. What did the model see, what did it return, which version was running, who reviewed the output, and did anyone override it. A trust that cannot answer those questions from records made at the time is left reconstructing events from memory and screenshots, which satisfies nobody, least of all a regulator observing the deployment.
This is where we believe infrastructure decides outcomes. Traceability bolted on after the fact is testimony. Traceability designed into the operating system that runs the AI is evidence.
What evidence will post-market surveillance actually ask for?
A reviewer examining an AI medical device in live service will want a contemporaneous, tamper-evident account of behaviour, not a summary assembled afterwards. In practice, that means records able to establish:
- The exact input each AI action received and the output it returned, tied to the model version in service at that moment
- Which clinician saw the output, what they decided, and whether the recommendation was accepted, amended or overridden
- When the device's behaviour changed, under what change control, and who authorised the change
- That the record itself has not been altered since it was written, provable without taking the supplier's word for it
- That all of this survives even if the supplier relationship, or the network connection, does not
None of that is exotic. It is the same chain of custody expectation that pathology and pharmacy have lived with for decades. The novelty is applying it to a system whose outputs are probabilistic, which is exactly why the record must be mechanical and automatic rather than a policy that busy clinical staff are asked to remember under pressure.
How does a sovereign operating system keep the evidence, and the data, inside the trust?
Our answer is to run the entire AI capability on the trust's own hardware, inside the clinical network, with the audit machinery built into the operating system itself. Mickai is a Sovereign Intelligence Operating System (a SIOS). It operates on premise and fully air-gapped where the environment requires it, so patient data is worked on inside the perimeter and the AI never becomes another route out of the building. Every action the system takes is written to the Open Audit Record, cryptographically signed with post-quantum algorithms, tamper-evident, and verifiable offline, so a trust can prove what its AI did without depending on any external connection, including one to us.
Sensitive actions face two further controls. Our cooperative multi-model consensus substrate requires specialist models to agree before any sensitive action runs, so a single model's confident error does not travel alone into a clinical workflow. And sensitive operations are gated behind voice-biometric confirmation, anchored to a hardware-held root of trust, so approving a material step takes an accountable human being, not just a logged-in session.
“In live clinical settings the standard is simple. If a system cannot prove what it did, it should not be doing it near a patient.”
What should trusts and device makers do during the sandbox period?
Treat London Region I as a rehearsal for the evidential questions that will follow AI into routine care, and build the record keeping before the deployment rather than after the first incident. For device makers, that means designing so that behaviour in live service is observable and provable by the organisation that carries the clinical risk. For trusts, it means asking three questions of any supplier: where does the AI actually run, who holds the logs, and would the evidence survive a supplier failure. We would rather be asked those questions early and directly. Our architecture is covered by 104 filed UK patent applications across 2,340 claims (filed, not granted), but in a clinical setting the paperwork behind a design matters far less than whether the controls hold when a real patient is on the other side of the output.
The MHRA has opened the door to live AI in the NHS, and done so carefully. Walking through it responsibly is an infrastructure decision, and it is one a trust can make on its own hardware, under its own control, with evidence that stands on its own.
Frequently asked questions
What is London Region I?
London Region I is a regulatory sandbox launched by the MHRA on 10 June 2026, run with NHS England and the London Health Innovation Networks, for the controlled deployment of AI medical devices in live NHS settings. It follows an April 2026 funding boost that expanded the MHRA's AI Airlock programme.
Why does air-gapped operation matter for NHS AI?
Air-gapped operation removes the AI system as a route for patient data to leave the clinical network. Mickai runs entirely on the trust's own hardware and can operate with no external connection at all, so a compromise elsewhere in the supply chain does not automatically become a patient data exposure.
What is the Open Audit Record?
The Open Audit Record (OAR) is the evidence layer built into Mickai. Every action the operating system takes is cryptographically signed with post-quantum algorithms, made tamper-evident, and can be verified offline, giving a trust a contemporaneous record of AI behaviour for clinical oversight and post-market surveillance.
How does Mickai stop a single model's error reaching a patient?
Through a cooperative multi-model consensus substrate, in which specialist models must agree before any sensitive action runs. Sensitive operations are additionally gated behind voice-biometric confirmation anchored to a hardware-held root of trust, so an accountable human remains in the loop for material steps.
What is MICKAI?
MICKAI is a Sovereign Intelligence Operating System (a SIOS) that runs on the customer's own hardware, on premise and air-gapped, using our own sovereign models. Every action is recorded in the Open Audit Record, a cryptographically signed, post-quantum secure, tamper-evident log that can be verified offline. The operating system spans 87 studios, with ten production-ready at launch and 77 in development, and is supported by 104 filed UK patent applications across 2,340 claims (filed, not granted).