As the UK publishes its second AI Airlock report, Indian med-tech firms confront a fragmenting global rulebook: London’s agile model on one side, the EU’s rights-based AI Act on the other.
The United Kingdom’s flagship experiment in regulating medical artificial intelligence, the AI Airlock, has moved decisively from pilot to permanent fixture. Contrary to some recent summaries, the Airlock was not launched this month: it was created by the Medicines and Healthcare products Regulatory Agency in spring 2024 as the world’s first regulatory sandbox for AI as a medical device. What is genuinely new is its consolidation. In April 2026 the MHRA committed £3.6 million over three years, locking the sandbox in as a standing component of UK regulation through 2028, and in June 2026 it published the programme report from the Airlock’s second phase.
What the Airlock does
A regulatory sandbox is a controlled, regulator-supervised environment in which developers test novel or high-risk technologies against real regulatory questions before full market authorisation. The Airlock pairs manufacturers with the MHRA, the National Health Service and designated approved bodies to work through problems that conventional clinical-trial frameworks handle poorly, chief among them the challenge of software that continues to learn and change after approval. The first cohort, which closed in 2025, examined four products, including a generative-AI tool that drafts the summary section of radiology reports. The second phase, running from April 2025 to May 2026, worked with seven innovators across three regulatory challenges.
Crucially, the phase reports do not themselves constitute formal guidance. Their findings feed a larger process: a National Commission into the Regulation of AI in Healthcare, which draws together clinicians, regulators and technology companies and is expected to shape both Britain’s domestic framework and, potentially, its influence on international norms.
Two philosophies, one device
The strategic significance lies in the contrast now hardening between the world’s major regulators. The UK is pursuing an iterative, evidence-generating, innovation-forward model that adapts existing medical-device rules to AI. The European Union, by contrast, is implementing the AI Act, a comprehensive, rights-based statute under which most medical AI qualifies as high-risk and must satisfy enforceable obligations on risk management, data governance, transparency, human oversight and post-market monitoring. The timelines are themselves in flux: a proposed EU Digital Omnibus would push key high-risk obligations from August 2026 towards late 2027, so even the European deadline is currently a moving target.
For a device-maker, the same product can therefore face a collaborative, case-by-case conversation in London and a prescriptive conformity-assessment regime in Brussels. That divergence is the dual-regulation problem: not two sets of paperwork so much as two incompatible regulatory philosophies to satisfy simultaneously.
Why this lands in India
India’s medical-AI sector is exposed on both flanks, as an exporter to the UK and EU and as a market building its own rules. In October 2025 the Central Drugs Standard Control Organisation released draft guidance on medical device software under the Medical Devices Rules, 2017, its most substantial attempt yet to clarify how software, including AI-enabled and cloud-hosted applications, is classified and licensed. The guidance distinguishes Software in a Medical Device from Software as a Medical Device, applies a risk-based Class A to D framework aligned with international IMDRF norms, and, importantly, introduces an Algorithm Change Protocol allowing bounded AI and machine-learning updates without constant re-licensing. Separately, CDSCO has moved to classify AI-based cancer-detection software as a moderate-to-high-risk Class C device requiring approval and continuous monitoring.
The Indian draft is deliberately clarifying rather than expansive: legal analysts note it interprets existing rules rather than creating new ones, and unresolved questions remain around cloud deployment, which updates trigger fresh approval, and how responsibility is assigned when software is built, hosted and marketed by different entities. Those are precisely the questions the UK Airlock was built to interrogate in practice.
The tradeoffs
For Indian exporters, three implications follow. First, market access will increasingly hinge on regulatory strategy rather than product quality alone; a diagnostic tool cleared under India’s Algorithm Change Protocol may still need a different evidence dossier for the EU’s high-risk regime. Second, the UK sandbox offers a template India’s own roadmap has already flagged an appetite for, as the bioeconomy blueprint’s call for regulatory sandboxes suggests. Third, the deeper choice is philosophical. The sandbox model accelerates innovation and surfaces real-world problems early, but concentrates discretion in the regulator and generates guidance rather than binding rights. The AI Act model front-loads legal certainty and protection but risks slowing deployment and burdening smaller firms. India, still drafting, has the rare advantage of watching both experiments run before committing to either.
-Kshipra Iyer, from London



