Signal Scanner · HEALTH, LIFE SCIENCES & CARE SYSTEMS · 9 August 2026

Out of Scope by Design: Clinical AI Accountability Lands on the Clinician

Europe deferred its high-risk AI rules and Britain placed AI scribes outside device regulation, both on the premise that a clinician checks the output. The safety control for clinical AI is now an unfunded human verification duty.

The story told about clinical AI regulation this summer is one of relief: Brussels postponed the hard part, London clarified the easy part, hospitals can deploy. What happened is a transfer. Both moves rest on the same load-bearing assumption, that a clinician reads and verifies what the machine produced. The MHRA made that explicit on 29 July, placing transcription and summarisation tools outside medical device regulation precisely because a clinician reviews them (MHRA, 29/07/2026). The safety control for the fastest-scaling category of clinical software is not a conformity assessment. It is a per-encounter human act that nobody funds, measures or audits.

Signal Identification

A regulatory pivot with a workforce consequence. This is not deregulation; both regimes still bite on diagnostic and autonomous tools. The perimeter has been drawn at the point of human review, so the residual risk of the largest deployed class of clinical AI sits with the reviewing clinician rather than with the product.

Time horizon: 2-6 years (GB perimeter live since July 2026; EU stand-alone rules from 2 December 2027, embedded from 2 August 2028; liability case law into the 2030s)
verification duty carries the risk2026202720282029liability cases to 2030s
Plausibility band: Medium–High
LowMediumHigh
Geographic / Jurisdictional Scope: Primary: Great Britain and the EU-27. Spillover: US health systems, health-AI vendors selling into both, and medical indemnity insurers.
PrimaryGreat BritainEU-27
SpilloverUnited StatesHealth-AI vendorsIndemnity insurers
Sectors exposed:
Hospital and primary care providersClinical informaticsHealth-AI vendorsMedical indemnity insuranceNotified bodiesNHS procurementMedical education

What's Changing

Two regulators moved within a month. Parliament approved the Digital Omnibus amendments on 16 June by 423 votes to 57 with 174 abstentions (European Parliament, 16/06/2026); the Council confirmed on 29 June, pushing high-risk obligations to December 2027 for stand-alone systems and August 2028 for AI embedded in regulated products. The same act creates a mechanism covering “sectors such as medical devices, toys, lifts and watercraft” that can limit the AI Act where sectoral law already imposes similar requirements (Council of the European Union, 29/06/2026). Health AI is routed into the device regime.

Britain then drew its device line at the clinician. The MHRA guidance places tools intended solely for transcription, summarising, letter drafting or code suggestion outside device regulation, while anything supporting diagnosis or acting without review stays inside, and states that clinicians “remain responsible for reviewing and verifying AI generated transcripts, summaries and other outputs before they are used in patient care” (MHRA, 29/07/2026).

The volume that duty now covers is no longer trivial. A Spanish hospital network recorded 11,599,484 outpatient visits between September 2024 and December 2025, of which 2,339,281 used an ambient scribe, a usage rate of 20.17% (Frontiers in Digital Health, 06/07/2026). In the United States, 1,744 Epic-running hospitals had deployed ambient documentation by mid-2025, and physician use of voice-based documentation rose from 20 to 29 percent in under a year (HIT Consultant, 06/08/2026).

Scale arrived first; the perimeter arrived second

Spanish network outpatient visits, Sept 2024 to Dec 2025 2,339,281 scribe-assisted of 11,599,484 visits 20.17% overall usage rate Every assisted encounter carries a clinician verification step that no regime measures. Where the rules land 29 Jul 2026 GB perimeter set at clinician review 2 Aug 2026 original EU date 2 Dec 2027 EU stand-alone high-risk rules 2 Aug 2028 EU embedded rules Interval in which human review is the binding control Bars and markers are positioned by date, not to scale.

Deployment figures from the Frontiers in Digital Health evaluation of a Spanish hospital network; regulatory dates from the Council of the European Union and the MHRA.

Disruption Pathway

Three stages. Now to late 2027: adoption continues under a regime whose only safety control for documentation AI is clinician review, with no requirement to record that the review happened. Late 2027 to 2028: EU high-risk obligations arrive, but the sectoral mechanism routes much health AI into device law, so the horizontal duties on deployers never reach the documentation layer. Beyond that: liability cases test whether a clinician who accepted an AI-generated summary under time pressure met the standard of care, which prices the verification duty retrospectively.

Stress concentrates in three places. Clinician time first: the tools were bought to remove documentation minutes and the verification duty puts some back, one reason only 8 percent of adopters reached positive return in year one (HIT Consultant, 06/08/2026). Feature creep second: a scribe that starts suggesting care gaps or pre-populating orders crosses into the device perimeter without a procurement decision. Indemnity third, since insurers are pricing a duty with no audit trail. Two adaptations follow: providers logging verification as a discrete evidenced step, and buyers moving output-accuracy warranties onto vendors, because the regulatory route to that assurance has closed.

Why This Matters Now

Provider boards and medical directors own a control that sits outside every existing assurance process: clinical governance covers decisions, information governance covers data, device regulation covers products, and nothing covers whether a summary was read before it entered the record. Three things need revision this cycle. Clinical safety cases should state the expected verification time per encounter and where it comes from. Procurement should treat a move from documentation into suggestion as a change of regulatory class, not a release note. Indemnity should be tested against an unverified AI summary reaching the record. Vendors should expect the warranty question before the certification question.

Decision-action posture for this signal: Prepare — the perimeter is already live in Great Britain and the evidence base is thin, so the work is to instrument verification and set the trigger at the first published case or the National Commission's recommendations.

Counter-Argument

The strongest objection is that this is how medicine has always worked. Clinicians already sign off dictated letters, laboratory results and junior colleagues' notes; one more class of reviewable output changes nothing in principle, and a perimeter drawn at review is the proportionate line that lets low-risk tools scale. The MHRA presents clinician responsibility as unchanged (MHRA, 29/07/2026): a claim of continuity, not of novelty.

The counter-counter is that continuity assumes review remains possible. Clinicians “remain responsible for AI-assisted decisions without remaining able to meaningfully review the basis of the output” (Journal of Medical Systems, 01/08/2026), which is different from checking a dictated letter against one’s own memory of the consultation. Nature’s reading is that legal uncertainty of this kind leaves people who are harmed in “liability gaps in which no one has clearly broken a rule” (Nature, 28/07/2026).

Implications

This looks durable, because the perimeter is written into two regimes at once and the deferral gives it two years of clear road, running to August 2028. Vendors of documentation-only tools gain: they scale without conformity assessment while diagnostic competitors carry device costs. Provider organisations and individual clinicians absorb the residual risk, and indemnity insurers price it blind. Taken together, the sources suggest the binding constraint on clinical AI to 2028 is not model performance or budget but the availability and evidencing of human attention, the one input health systems have least of.

Early Indicators to Monitor

Disconfirming Signals

Strategic Questions

Keywords

Ambient voice technology; AI scribes; clinical AI governance; EU AI Act; Digital Omnibus; medical device regulation; MHRA; clinician oversight; medical liability; NHS AI adoption

Bibliography

Source tiers: Tier 1, governments, regulators and intergovernmental bodies. Tier 2, think-tanks, academic institutes, major consultancies and quality data providers. Tier 3, quality journalism and specialist trade press. Tier 4, vendor, company and practitioner sources, used only as directional corroboration.


Prepared by Shaping Tomorrow: 9 August 2026