INNOVATION IN MEDICINE HAS ALWAYS BEEN CONSTRAINED by a fundamental ethical asymmetry. In every other domain of technology — consumer electronics, software, transportation infrastructure — products can be tested in production environments, failures can be observed and corrected, and iterative improvement can proceed at market speed. In medicine, this approach is impermissible. A software bug in a navigation app wastes fifteen minutes. A software error in a clinical decision support system can cost a life. This asymmetry has historically justified the elaborate, time-consuming, expensive evidentiary standards of medical device regulation: randomised controlled trials, independent validation studies, statistical power calculations, pre-market approval dossiers running to thousands of pages. It has also, inescapably, slowed the translation of genuinely beneficial innovations from laboratory to patient care. The regulatory sandbox model — a structured environment in which AI health tools can be tested in real-world clinical conditions under strictly supervised, time-limited relaxation of specific regulatory requirements — is the emerging answer to this tension.
The concept is not entirely new. Financial services regulators in the UK, Singapore, and Australia pioneered regulatory sandboxes for fintech products in the mid-2010s, allowing novel financial products to operate with limited-scope exemptions from specific regulations while generating evidence of their safety and effectiveness. The model’s application to healthcare AI is more recent, more complex, and more consequential — but the core logic is the same: create a protected space in which innovation can generate evidence under real-world conditions, without exposing the broader patient population to unvalidated risk.
The UK’s AI Growth Lab and MHRA Airlock
The United Kingdom has moved most decisively to institutionalise the sandbox model for healthcare AI. On 21 October 2025, UK Technology Secretary Liz Kendall announced the AI Growth Lab — a cross-economy regulatory sandbox designed to allow companies to test new AI products in real-world conditions with specific regulations temporarily relaxed under strict supervision. Healthcare was identified as a priority sector for the initial rollout. The initiative builds on the Medicines and Healthcare products Regulatory Agency’s existing AI Airlock programme, which had already completed two phases of company cohorts testing AI-enabled medical technologies. The MHRA published results from the second-phase Airlock cohort in late 2025, documenting progress in evidence generation, model validation, and post-market performance tracking for AI diagnostic devices. A full national regulatory framework for AI in healthcare, developed in conjunction with the National Commission into the Regulation of AI in Healthcare, is scheduled for publication in 2026.
The practical impact of the UK’s sandbox approach has already been demonstrated. AI-assisted clinical trial review at the Medicines and Healthcare products Regulatory Agency has halved the average approval time — from 91 days to 41 days — for certain trial categories, while maintaining the rigour of expert assessment. NHS England has run trials integrating AI as a second reader in breast cancer screening programmes. The National Institute for Health and Care Excellence announced an initiative to expand health technology assessment to include AI diagnostic tools, with pathways for NHS-wide implementation of products meeting validated standards.
The US Approach: FDA’s Evolving Framework
The US Food and Drug Administration has taken a parallel but structurally different approach. Rather than time-limited sandbox exemptions, the FDA has created pre-competitive spaces for healthcare AI through its Digital Health Center of Excellence, its pre-submission advisory meeting processes, and a series of guidance documents that clarify regulatory expectations before companies have committed to full development programmes. The FDA’s January 2025 draft guidance on AI-enabled device software functions — the most comprehensive regulatory framework for healthcare AI issued by any major regulator to date — applies a Total Product Life Cycle (TPLC) approach requiring model description, data lineage documentation, performance validation against clinical claims, bias analysis, human-AI workflow specification, monitoring plans, and, for adaptive AI, a Predetermined Change Control Plan (PCCP) specifying what changes the AI can make to itself autonomously post-deployment.
By late 2025, the FDA had cleared 1,451 AI-enabled medical devices cumulatively, with radiology imaging representing 76 percent of all authorisations. Aidoc’s CARE1 foundation model received FDA clearance in February 2025 — the first foundation-model-powered clinical AI to do so — signalling that the agency’s frameworks are beginning to accommodate the more complex, adaptable architectures that represent the frontier of healthcare AI development. The FDA’s press release language in December 2025, signalling intent to extend real-world evidence frameworks to drugs and biologics, adds further momentum to a regulatory posture actively seeking to reduce barriers to evidence generation for novel health technologies.
Synthetic Data: The Technical Enabler
A crucial technical enabler of the regulatory sandbox approach is synthetic clinical data — algorithmically generated datasets that replicate the statistical properties and clinical patterns of real patient records without containing any actual patient information. Synthetic data addresses one of the central challenges of healthcare AI development: patient privacy regulations make it difficult to share the large, diverse clinical datasets on which AI systems must be trained and validated. Synthetic data can be generated at any required scale, can be engineered to include rare conditions and demographic groups underrepresented in available clinical datasets, and can be shared freely across institutions and borders without privacy risk.
The MHRA’s Airlock programme explicitly recommends synthetic data fidelity testing as part of the evidence package for AI medical devices entering the sandbox. The FDA’s expanded RWE guidance allows synthetic data as a component of regulatory submissions where its fidelity to real-world clinical distributions can be documented. Academic and commercial synthetic data platforms — including companies such as Syntegra and MDClone — are developing increasingly sophisticated generation methods that allow AI developers to train and validate clinical systems on data that is simultaneously realistic and privacy-safe.
India’s Regulatory Opportunity
India’s regulatory framework for AI medical devices is at an earlier stage of development than the UK or US equivalents, creating both a risk and an opportunity. The Central Drugs Standard Control Organisation (CDSCO) and the Indian Council of Medical Research (ICMR) are both actively developing AI health product guidelines, with the ICMR’s 2021 Ethical Guidelines for Biomedical and Health Research Involving Human Participants providing foundational principles. The AI for Health initiative under the National Health Authority and the Digital Health Mission’s push toward interoperable electronic health records create the data infrastructure components that a future Indian healthcare AI sandbox would require. India’s combination of scale — 1.4 billion people, one of the world’s largest repositories of genetic and clinical diversity — and its emerging digital health infrastructure positions it to potentially generate the most clinically diverse AI training and validation datasets in the world. Establishing a formal sandbox framework, modelled on the UK’s AI Growth Lab but adapted for India’s regulatory and healthcare context, would be a high-value investment in both innovation and patient safety.
– Rashmi M



