Adopting AI Scribes in UK Healthcare: The MHRA Line, the Checks You Cannot Skip, and the Mistake Almost Everyone Makes
Whether your AI scribe is a regulated medical device does not depend on how clever it is. It depends on whether a clinician reviews the output before anything happens — which makes it a workflow decision, not a software one.
The business case for AI scribes in UK healthcare is settled. St George’s measured 47 minutes saved per clinician per shift. Great Ormond Street clinicians reported nearly a quarter more time with patients. Nobody needs persuading that it works.
What is not settled, in most organisations, is how to deploy one legally. And in July 2026 the MHRA drew a line that decides whether the tool you are about to buy is an ordinary piece of software or a regulated medical device — a line that turns on something most buyers never think to ask about.
This is a practical guide to adopting AI tools in a UK health or care setting: what the rules actually say, the checks you cannot skip, and the mistake almost everyone makes.

The question that decides everything
Buyers ask “is this a medical device?” and expect the answer to depend on how clever the software is. It does not. It depends on whether a clinician reviews the output before anything happens.
The MHRA published guidance on 29 July 2026, developed with NHS England, setting out how existing medical device law applies to ambient voice technology in Great Britain. The split is clean:
Not regulated as a medical device — products solely intended to:
- Transcribe a clinical conversation
- Summarise a consultation
- Draft correspondence for a clinician to review
- Suggest clinical codes for a clinician to review
Regulated as a medical device — products intended to:
- Support diagnosis
- Support treatment or prevention decisions
- Take automated clinical action without clinician review — creating discharge summaries, ordering medicines, ordering diagnostic tests
Read those two lists again and notice what actually separates them. It is not capability. The same underlying model can sit on either side. The pivot is the phrase “for review by a clinician“. Draft a letter for a human to check and you are outside the regulation. Let the same system send the letter, or place the order, and you are inside it.
Which means your workflow design determines your regulatory status. That is a procurement decision and a clinical governance decision at the same time, and it is worth settling before you shortlist products rather than after.
Your regulatory status is not fixed at purchase
Here is the part that gets missed almost universally.
NHS England requires organisations to have “processes in place to review any change in functionality that may alter the regulatory status of a product”. Not a one-off check at procurement — an ongoing obligation.
Think about what that means with modern software. Your supplier ships updates continuously. One release adds an “auto-file to the record” option, or an order-drafting feature, or a suggestion engine that quietly stops requiring confirmation. Nothing in your contract changed, nobody in the organisation was asked, and a tool you assessed as unregulated has moved into regulated territory.
Build the review into your supplier relationship: release notes reviewed by someone who understands the line, and a contractual duty on the supplier to flag functional changes affecting classification.
“Not a medical device” does not mean “no clinical safety work”
The most expensive misunderstanding in this space is the relief people feel when they establish their scribe is not a medical device. They assume the assurance burden has gone. It has not.
DCB0129 applies to all digital products used in the NHS, regardless of whether the product is considered a medical device. That is the supplier’s clinical safety case report, and you should expect to be given it.
Alongside it:
- DCB0160 — your organisation’s own clinical safety case, hazard log and ongoing monitoring framework. This one is yours, not the supplier’s, and it is the piece most often skipped.
- DTAC — the Digital Technology Assessment Criteria, which the supplier must complete.
- DPIA — a data protection impact assessment, completed before processing begins, not after go-live.

Use the AVT Supplier Registry
NHS England maintains an Ambient Voice Technology Supplier Registry, and GP practices, ICBs and acute trusts are expected to use it as part of their governance checks and to find a compliant route to market. Supplier applications reopened on 3 February 2026 and remain open.
To be listed, a supplier has to evidence:
- A completed DTAC
- MHRA registration where applicable
- Integration capability with electronic patient records
- Evidence of real-world benefit of the product in the NHS
For a large trust with a procurement function, that is a useful shortcut. For a single practice with no procurement function at all, it is close to essential — it front-loads due diligence you realistically cannot perform yourself.
Transparency, consent and the patient
A recording device in a consultation room is a significant processing change and has to be handled as one:
- Update your privacy notices before processing begins
- Be clear with patients about what is being recorded and how the output will be used
- Obtain consent where it is required under UK GDPR
- Be transparent about how information is used and shared in your setting
Doing this after go-live is not a tidy-up exercise; it means you were processing without the basis in place.

The human-in-the-loop is not optional
Repeated throughout the guidance, and worth stating bluntly: clinicians remain responsible for reviewing and verifying AI-generated transcripts, summaries and other outputs before they are used in patient care.
Two practical consequences. First, if your efficiency case assumes clinicians will not read the output, your efficiency case is non-compliant — the saving comes from not typing, not from not checking. Second, staff training has to cover the tool’s limitations, not just its features, because a clinician can only meaningfully verify something they understand the failure modes of.
An adoption checklist
- Decide your workflow first. Review-before-action, or automated action? This sets your regulatory status before you look at a single product.
- Shortlist from the AVT Supplier Registry.
- Get the supplier’s DCB0129 clinical safety case report and read it.
- Confirm MHRA status in writing, matched to the workflow you actually intend to run.
- Write your own DCB0160 safety case, hazard log and monitoring framework.
- Complete the DPIA and update privacy notices before processing starts.
- Check EPR integration genuinely works in your environment, not just in principle.
- Train staff on limitations as well as use.
- Set up ongoing monitoring — accuracy in practice, and a standing review of supplier release notes for changes that alter classification.
- Get board-level assurance: NHS England expects boards and executive teams to satisfy themselves that deployment has clinical oversight, governance, training and proper procurement behind it.
NHS England has said further material is coming during 2026, including risk-assessment templates and a consistent approach to evaluation, which should make steps five and nine considerably less painful.

The honest summary
Ambient scribing is one of the few AI deployments in healthcare where the benefit is already measured, published and uncontested. That makes the risk profile unusual: the thing most likely to go wrong is not the technology failing to deliver, it is an organisation deploying it without the safety case, the DPIA, or a way of noticing when the product quietly changes what it does.
Get the workflow decision and the paperwork right and this is among the safest AI investments a health or care organisation can make. Skip them and you have a governance incident attached to a tool everyone likes.
For the wider market picture — what the NHS is funding and where the commercial opportunities sit — see our analysis of where the NHS is actually spending on AI. If you are building rather than buying, our guide to UK business growth funding covers grant and equity routes for a long evidence cycle.

Frequently asked questions
Is an AI scribe a medical device in the UK?
It depends on what it is intended to do. Products solely intended to transcribe, summarise, draft correspondence or suggest clinical codes for a clinician to review are not regulated as medical devices. Products intended to support diagnosis or treatment, or to take automated clinical action without clinician review, are regulated.
What did the MHRA guidance of 29 July 2026 change?
It clarified how existing medical device law applies to ambient voice technology in Great Britain, drawing the line at whether a clinician reviews the output before it is acted on, and asked NHS boards to assure themselves that deployments have appropriate oversight, governance, training and procurement.
What is the AVT Supplier Registry?
An NHS England register of ambient voice technology suppliers who have self-certified against requirements including DTAC, MHRA registration where applicable, EPR integration and real-world NHS evidence. GP practices, ICBs and acute trusts are expected to use it in their governance checks. Supplier applications reopened on 3 February 2026.
Do I still need a clinical safety case if the product is not a medical device?
Yes. DCB0129 applies to all digital products used in the NHS regardless of medical device status, and your organisation still needs its own DCB0160 safety case, hazard log and monitoring framework.
Do patients have to consent to being recorded?
You must update privacy notices before processing begins, be clear about what is recorded and how outputs are used, and obtain consent where it is required under UK GDPR. Treat it as a significant processing change, not a minor one.
Who is responsible if the AI gets the note wrong?
The clinician. Guidance is explicit that clinicians remain responsible for reviewing and verifying AI-generated transcripts, summaries and outputs before they are used in patient care.
Can a product’s regulatory status change after we buy it?
Yes, and this is a real risk with continuously updated software. NHS England requires organisations to have processes to review any change in functionality that may alter regulatory status, so supplier release notes need someone reviewing them.
Based on MHRA and NHS England guidance published to July 2026 and applying to Great Britain. Guidance in this area is actively developing — check the current NHS England and MHRA positions before deploying. General information, not legal advice.
Sign up to our news alerts
The day's business headlines in your inbox each morning.
Unsubscribe from any email.


