Summary
- The government has accepted a recommendation for dedicated cybersecurity guidance covering software and AI-enabled medical devices.
- The MHRA will develop draft guidance and educational resources addressing security throughout the product lifecycle.
- Further detail is due by spring 2027, so the specific requirements have not yet been finalised.
The Medicines and Healthcare products Regulatory Agency will develop dedicated cybersecurity guidance for software and AI-enabled medical devices as the UK government begins implementing recommendations from the National Commission into the Regulation of AI in Healthcare.
In its formal response, the government accepted the recommendation that the MHRA provide guidance and educational material setting out cybersecurity expectations for those products.
The planned work will cover security practices throughout the operating life of a device so that cybersecurity remains part of its safety and performance after deployment. Further detail is expected by spring 2027.
The recommendation treats cybersecurity as part of medical device safety rather than a separate IT concern. The commission said threats against connected software and devices can affect their effectiveness and create the potential for harm at scale.
The commitment does not yet define the detailed technical controls manufacturers will have to meet. The MHRA still has to develop the guidance and determine how it fits into the wider medical device regulatory framework.
Security risk changes after deployment
Software does not remain technically static after it enters clinical use. New vulnerabilities can be discovered, suppliers can change services, software can be updated and an AI-enabled system may be modified as models and supporting infrastructure evolve.
The wider government response therefore addresses monitoring after market entry, management of product changes, transparency and the information manufacturers need to provide about technologies on which their products depend.
Procurement is also part of the programme. The government says the MHRA will work with health departments to introduce relevant information expectations into procurement processes and contract terms for software and AI-enabled medical devices.
That gives health organisations another mechanism for assessing cyber risk. Regulation can define expectations around the product itself, while procurement can determine what evidence a buyer requires from a supplier before deploying the technology.
Traceability becomes more important as software changes. The government response also considers unique device identifiers and version information so that organisations can distinguish between releases deployed in clinical environments.
If a vulnerability affects only particular software versions, that information can help providers identify where the affected release is still in use. The current policy response does not itself create the complete technical system required to do that, but it places version tracking inside the regulatory programme.
The commission also considers how changes to adaptive AI systems should be controlled and how manufacturers should disclose dependencies on more general models and platforms.
Those issues make cybersecurity part of a broader question about how medical technology is managed after approval. A device can remain clinically useful while its software dependencies and cyber risk change around it.
The government’s acceptance of the recommendation should not be read as though new detailed cybersecurity requirements are already in force. The confirmed development is that the MHRA will produce draft guidance and educational resources, with further detail promised by spring 2027.





