How to buy AVT: 2026 update
If you are buying AVT in the NHS today, you have just been handed an assurance job that used to sit with a regulator and an external auditor. That is the decision in front of you, and it is worth being clear about what it costs before you sign anything.
Here is how we got here.
The MHRA recently released guidance to deregulate some ambient voice products on the market, specifically those that don't intend to influence the clinical diagnosis. Products solely intended to transcribe and summarise clinical conversations, draft correspondence or suggest clinical codes for review by a clinician are no longer to be regulated as medical devices under MDR 2002. Products intended to support diagnosis, treatment and automated clinical actions remain regulated. This removes the Class I requirement that NHS England's earlier guidance had applied to summarisation, and opens the market wider to less regulated products, such as those bundled with EPRs. The risk and liability of choosing an AVT now falls to the systems that buy them in the UK.
At the same time, NHS England and the MHRA wrote jointly to all Trusts and ICBs accompanying this move, specifying 18 things boards and executive teams must now assure themselves are in place - from monitoring at AI model update milestones to processes for reviewing changes in functionality that alter a product's regulatory status.
Almost immediately the Royal College of Physicians pushed back. Their position was that not regulating all AVT means “responsibility will fall more heavily on individual clinicians and trusts, rather than being shared within a regulated device framework”, and they explicitly disagreed that transcription and summarisation don't impact clinical decision-making. New confusion in the market, even as the MHRA attempt to achieve clarity. And on the heels of that the HSSIB have now commenced an investigation into the safety of AI Scribe products in clinical settings, particularly acute adult secondary care. Their stated reason is worth reading carefully: “adoption of AVT is accelerating while the safety implications are not fully understood”, national activity “has focused more strongly on efficiency benefits than on patient safety risk”, and “routes for recognising and reporting AI-related incidents are not yet mature enough to provide confidence that emerging risks are being identified.”
The NHS remains committed to rolling out AVT nationally, providing capital for implementation and change management support, commercial guidance and a benefits framework - and NOT for software licences themselves, although it remains unclear how one achieves increases in productivity without buying the actual system. The King's Fund made the same point in July, recommending that national funding “should encompass purchase of the technology and investing in the capabilities to change services”.
All of which to say is - if you're a buyer of AVT in the NHS, it's confusing, potentially still moving, and you are going to have to create your own AI capability, AI monitoring team and stand-up expertise that's expensive and hard to find at pace.
This is the dilemma CCIOs, CEOs and CFOs looking at AVT now face.
So what to do?
Full conflict of interest declaration - I am the co-founder and CEO of TORTUS. As a clinician I've studied ambient scribe technology safety, security and complexity exclusively for nearly four years, including the building, deployment and data implications - essentially every single aspect of a very niche and singular technology, relentlessly since 2022. TORTUS is the first AVT in the market to achieve UKCA Class IIa certification, assessed by Scarlet (UK Approved Body 8536) in June 2026, and we very much intend to influence the clinical workflows we support. So here's what I would do, if I were a buyer of AVT in the NHS today.
I would buy a Class IIa certified medical device AVT system.
There are several vendors in the space, and the reasoning underpinning this applies to all of them. I can't speak from my expertise without inevitable bias, so I'd take all of this with that in mind, and feel free to ignore or dismiss this argument entirely. But here's our thoughts.
The short version: you have two clear paths
Everything below sets out the evidence for this. As a buyer, in my admittedly biased opinion, your options are:
Buy a non-medical device
Often via your EPR vendor
- ×Neatly integrated
- ×Likely expensive given limited competition (e.g. a native EPR add-on)
- ×Without any external validation of safety and accuracy
- ×Often not purpose-built for clinical settings, lacking specialist product knowledge
- ×You will have to create (and fund) a specialist AI assurance function to monitor it indefinitely
- ×Your conversational data may be locked up, limiting higher-risk use cases
- ×You may lose control of the foundations of AI change in your systems
- ×You take on the liability for the Trust directly — and potentially personal accountability too
Buy a Class IIa AVT product
Independently audited medical device
- ✓Most are readily integrated
- ✓Market-competitive, usually below native EPR solutions
- ✓Specialist products designed specifically for rapid adoption and implementation
- ✓Continuous monitoring for post-market performance
- ✓Continuous validation of any significant change in the future
- ✓External compliance, at the vendor's expense, via the Approved Body
- ✓You retain full control of the conversational data
- ✓Opportunity to evolve safely into higher-risk areas such as clinical decision support
- ✓Build a partnership with a company that takes on some of the liability for quality and accuracy
1. The MHRA guidance is a good thing, but not for the reasons you think
The MHRA declassifying AVT to non-medical device is not going to achieve the stated aim of rolling out safely and effectively - given the confusion it's immediately created, probably the opposite. However, removing the Class I requirement is a very good thing, because Class I medical device status is self-declared. There is no independent, pre-market audit and no external certification process. You register with the MHRA, you are supposed to keep a technical file, and unless and until the MHRA asks to see it, your declaration stands on your own word alone. This creates the effect of a 'badge' without visible substance, and Class I in general doesn't really serve anyone - the system, the vendor, the patient - at all. So by removing the requirement, we remove certain vendors in the system coming to market stating compliance with Class I but without actually doing the underlying work. This actually does create clarity - the world now divides into non-medical devices, and medical devices with a clear and externally audited system (Class IIa).
2. AVT IS a medical device, and we intend it to be so
TORTUS's company mission statement is “To Eliminate Error In Medicine”. It is not “less admin”, “slicker EHRs”, “quicker notes”. Our job is to return time to clinicians, de-noise their workflows, and support them to give better care, above the standard of today, not simply faster. Our intent by building an interface that can understand their encounter is to support that mission. As we progress into more complex systems, suggesting diagnosis, creating orders, checking prescription accuracy and drug interactions, summarising records - we are deliberately influencing that clinical workflow. Two points to make here.
a) AVT use does influence the clinical workflow, in both directions. In our experience clinicians frequently report acting on data the AI system heard and recorded but they had forgotten during the consultation. Usually secondary things to the main consultation, like incidentally identifying a high blood pressure, or a high blood sugar. It's very hard to argue that the use of a system that takes over part of the cognitive workflow of a clinician, composing the relevant details from an encounter and drafting their plan, does not in any way influence that process.
The negatives we have also seen - hallucinations in the output, especially once committed to the record, will influence the clinical outcome of the patient. Fortune reported a case in which an AI-generated record summary gave a healthy man in his mid-20s, who had attended hospital with tonsillitis, a set of diagnoses he did not have - chest pain and shortness of breath attributed to “likely angina due to coronary artery disease”, plus diabetes. He was subsequently invited to a diabetic screening appointment. The tool in question was a record summarisation product rather than an ambient scribe, and the NHS characterised it as a one-off human error, but the mechanism is exactly the one that matters: a fabricated clinical fact entered the record, and the system then acted on it. Systems today don't have the ability to discern between human-generated and AI-generated text at all - the data model doesn't support it. Without a doubt, in our view, if you add an AI into the system to do the work of a clinician, however minor or 'low-risk' non-clinicians think this is, it absolutely has a downstream effect.
So regardless of the current regulatory position that AVT doesn't directly influence clinical care - in my personal opinion as a clinician in this space for four years - it's wrong.
b) Class II features cannot be bolted on after the fact. Any of the obviously Class II features that directly influence the clinician, e.g. suggesting the correct diagnosis, or the appropriate treatment - cannot be added later. You can't add a clinical decision support system as a Class IIa device to action the outputs of an AVT system that isn't a device - the provenance and evidence for how that AVT system works is absent, and therefore you can't certify the inputs are accurate, therefore you can't certify the outputs are to any reasonable standard.
0.9% saline can be mixed in your kitchen in a measuring jug with salt and tap water, but no clinician on the planet is going to be willing to put that into your bloodstream. The process, and the evidence that underpins it, is the product - not the components.
3. Class IIa requires an external third party to verify and validate
Class II devices and above are a different beast entirely from a Class I. You have to submit your entire Quality Management System, hundreds of documents that attest to every aspect of your system, from conception, to development, to testing, to post-market surveillance, to an independent third party. For UKCA marking that third party is a UK Approved Body; for CE marking in Europe it's a Notified Body. Either way there are only a handful of them, and the review takes 12-18 months of querying to demonstrate that you are doing what you are saying you are doing and that the system performs as you claim, to the standard you claim it performs at. Like an MOT, which means your car is safe on the road - you don't do it yourself, and you don't drive without one.
This is a legal process - medico-legal liability is very high for medical devices that do not function and perform as they claim, and as a vendor we wouldn't want it to be otherwise. There are very few AI companies that have achieved this level of capability, and even fewer in the AVT space, but the level of assurance and safety in the system is baked in to a really long and expensive process. 268,000 words, 130 documents, 5,000 pages, 2 years of work and £1.5m in resources is approximately what our Class IIa for AVT cost and requires.
For scale on the other side of the market: there are now 24 suppliers on NHS England's self-certified AVT Supplier Registry. One of them holds UKCA Class IIa.
4. NHS England has decentralised a job an Approved Body does once, to every trust and practice individually
This is the crux of it.
If you read the 18 assurance expectations NHS England is now asking boards and executive teams to satisfy themselves about - at a time when the HSSIB is actively investigating AVT safety in hospitals, and the RCP does not support the use of non-medical devices - it reads a lot like what an Approved Body already does as part of the process of device certification anyway. Except now more than 200 NHS trusts, plus thousands of GP practices, are each being asked to do a version of it themselves, in perpetuity, without direct access to the technology.
Here's the mapping, criterion by criterion.
| # | Domain | NHS England expectation (29 July 2026 letter) | ⚠Non-device: what the Trust must build and own | Class IIa: what is already externally audited |
|---|---|---|---|---|
| 1 | Oversight and accountability | Users remain responsible for reviewing, validating and approving any information generated by AVT before it is relied upon for patient care | Local policy, training and audit to evidence review actually happens | Human verification is a certified condition of the intended purpose, evidenced in the technical file and audited |
| 2 | Oversight and accountability | Appropriate professional judgement is maintained when using AI-generated outputs | Trust designs its own automation-bias controls from scratch | Usability engineering and automation-bias mitigation required under IEC 62366 and reviewed by the Approved Body |
| 3 | Oversight and accountability | Clear lines of accountability exist for decisions informed by AVT outputs | Trust holds the accountability gap alone | Manufacturer carries defined legal liability for device performance; accountability is shared, not transferred |
| 4 | Local governance | Deployment supported by appropriate clinical safety, IG and digital assurance processes | Trust writes DCB0160, safety case and hazard log largely unaided | Supplier DCB0129 plus certified ISO 13485 risk management; Trust inherits a populated hazard log to sign off against |
| 5 | Local governance | Organisations understand the intended purpose and capabilities of the product, especially beyond transcription and summarisation | Intended purpose is whatever the vendor's marketing says it is | Intended purpose is a legally binding, externally assessed statement; operating outside it is off-label and identifiable |
| 6 | Local governance | Processes in place to review any change in functionality that may alter regulatory status | Trust must detect and classify vendor feature changes itself, forever | Every Significant Change goes back through the Approved Body before release; classification is the manufacturer's legal duty |
| 7 | Staff training and awareness | Staff receive appropriate training on capabilities and limitations | Trust authors its own training from an unvalidated evidence base | Instructions for use, training materials and limitations are regulated labelling, validated and version-controlled |
| 8 | Staff training and awareness | Users understand outputs may contain inaccuracies and require review | Trust asserts an error rate it cannot independently measure or monitor | Performance claims and residual risks are quantified, evidenced and externally verified and continuously monitored |
| 9 | Staff training and awareness | Safe use embedded within existing clinical workflows and governance | Trust does its own workflow safety analysis | Summative usability validation in representative clinical use is mandatory evidence |
| 10 | Risk management | Risks relating to privacy, consent, information quality and automation bias are considered | DPIA plus a bespoke bias and quality assessment, built locally | Same DPIA, but bias, information quality and automation bias sit inside the certified risk file |
| 11 | Risk management | Incident reporting arrangements are clear and understood | No statutory reporting route for a non-device; HSSIB notes these routes are not yet mature | MHRA Yellow Card and vendor vigilance reporting are mandatory, with defined timelines |
| 12 | Risk management | Learning from implementation and use is shared through governance processes | Learning stays inside one organisation | Post-market surveillance aggregates learning across all deployments and feeds it back into the device |
| 13 | Risk management | Clear accountability for the review and use of AVT outputs | Rests with the clinician and the Trust | Shared between clinician, Trust and manufacturer under the device framework |
| 14 | Risk management | Ongoing monitoring of risks, benefits and implementation outcomes | Trust stands up a permanent AI monitoring function | Post-Market Surveillance and PMCF plans are legally required, resourced by the vendor and audited annually |
| 15 | Commercial and procurement | Procurement assesses clinical safety, IG, cyber security, interoperability and regulatory compliance | Trust runs the full assessment itself | Most of it is discharged by the UKCA certificate and QMS evidence pack |
| 16 | Commercial and procurement | Decisions account for long-term interoperability, scalability and ability to safely adopt future functionality | Higher-risk functionality cannot be safely adopted later without starting again | A certified base allows staged expansion into Class IIa features on existing evidence |
| 17 | Commercial and procurement | Due diligence to understand functionality, limitations and deployment arrangements | Trust relies on supplier self-declaration | Technical documentation is independently assessed; claims are auditable |
| 18 | Commercial and procurement | Contractual rights to monitor performance, audit compliance, manage functionality changes and address emerging risks, including at AI model update milestones | Trust must negotiate and then actively police model-update oversight it cannot see inside | Model changes are governed by the QMS and change-control process; a PCCP defines in advance what can change and how |
Post-market surveillance is the one I'm genuinely not sure a Trust can do by itself. It will end up spending money on external vendors who also will not be able to demonstrate it, as they have no access to the technology directly. Monitoring for model changes and scope creep - without any certifications or medico-legal framework in place governing these changes, Trusts have to stand these up themselves, plus the expertise to evaluate both of the above. Usability testing, monitoring for things like automation bias - all of this is baked in to the QMS and reporting systems for Class IIa devices, and externally reviewed by the Approved Body, with every significant change.
Do Trusts have the ability to monitor AI changes, occurring monthly or even more frequently, with potential changes to device status, in perpetuity? Of course not. It's a massive resource to stand up internally and to maintain, and also an unlimited, continuous and permanent liability gap for the Trust that they have to work forever to close, without any direct control or access to the technology either.
It's worth putting a number on that, because it's the part business cases miss. A credible internal AI assurance function for a single Trust is not one person: it's clinical safety officer time, a data or evaluation analyst to audit output accuracy at sample scale, information governance input, and someone senior enough to make regulatory-status calls when a vendor ships a model update. Call it two to three FTE at mid-band and on-cost, plus external evaluation support, and you are into a recurring six-figure annual cost - against an AVT licence line that may be in fact below that. The assurance is the expensive part, and on the non-device path you buy all of it.
With a Class IIa device, most of this work is already baked in. Every Significant Change has to go through the same Approved Body process - if we want to add, let's say, a Guidelines suggestion feature, we have to validate it in the same way. Scope creep, intended use, post-market surveillance, safety evidence - it's all baked in. This then filters into our Hazard Log, we sign that off together, and we are there. Evolving together. Which I think is the most fundamental point.
5. AI is moving so rapidly, don't buy from a vendor. Build a partnership.
Class IIa allows us to continue to evolve in the direction Trusts need to solve their actual problems - improving quality of decisions, auditing, real-time translation, placing semi-autonomous orders and workflows, functioning like an in-sourced clinical AI service, as opposed to buying a button in your EPR. The problems the NHS faces today, and the way software is procured currently, don't fit together in the age of AI. We need a new model that allows us to work together, safely, regulated, and to a large extent bespoke trust-by-trust. This isn't only our view: the King's Fund's July 2026 analysis calls explicitly for value-based procurement and “risk-reward partnerships with suppliers” rather than conventional software purchasing.
Software itself is far more fluid, rapidly developing and agile than ever before. For most workflows facing a clinician, AVT is the foundation of that journey, whether that's capturing an encounter in ED or a patient complaint - that data is the fundamental fuel for the system change to come. If it's locked in to a vendor that can do nothing with it, and has no interest in doing so, it's effectively lost. The opportunity cost of choosing a non-device path, which is essentially a cul-de-sac, is large when the future of clinical AI is much, much more capable than where we are today.
To give a flavour of this, model cost, quality and latency has improved roughly 50% every 6 months I've been running TORTUS. When we first started it took around 2-3 minutes to process even a very short consultation with moderate accuracy; now we are around 6-7 seconds with extremely high accuracy. That exponential improvement in such a short amount of time is the norm for AI - you have to ride the wave of technological change, or you will be left behind by it.
The counter-argument
I should put the other side properly, because it exists.
The honest case for the non-device path is this: Class IIa costs 12-18 months and, in our case, £1.5m. That is a real barrier to entry, it favours incumbents with balance sheets if willing to take on the risk (most however aren't), and it can slow the shipping of genuinely useful features. If your AVT is doing nothing but producing a draft note that a clinician reads, edits and signs every single time, a reasonable person can argue the marginal risk is low and the regulatory overhead is disproportionate. The MHRA clearly thinks so, and they say the clarification will “help to unlock faster uptake of lower risk tools”.
My answer is that the barrier is the point, and that the “clinician reads everything” assumption is the weakest link in the argument. It relies on sustained human vigilance against a system that is right most of the time, which is precisely the condition under which automation bias appears - and which is precisely what the HSSIB has now been asked to look at. It also assumes the product you buy today stays the product you bought, in a market where models change monthly. If you're confident on both counts, the non-device path is defensible. I'm not confident on either.
Cost, quality and speed aren't always at odds with each other. If you want reassurance in the market that you are buying a clinical AI service that is safe to handle patients to the highest possible standard, then Class IIa is really the only reliable option.
The alternative is viable only if you are genuinely willing to wear the risk and you already have a distributed solution that will be fast to get into the hands of clinicians. But adoption is unlikely to be rapid, you will therefore struggle to find productivity benefit, and you will have to do all of it on your own anyway.
Overall the buying decision for which AVT vendor you are going to use, or even whether to build your own, lies with every Trust. It seems a no-brainer to me that if there are vendors on the market that have already been externally assured to the level you require, then taking on the assurance yourself is a poor use of resource and an exposure to medico-legal liability without any material benefit, but that is the dilemma to resolve for every Trust now as the true roll-out of clinical AI in the NHS begins.
Dr Dom Pimenta
MBBS MRCP BSc (Hons)
CEO and Founder, TORTUS AI
Questions? Concerns?
Get in touch at [email protected]
