Key takeaways
- A new UK regulatory review argues that AI cannot be adequately governed through a one-off assessment before deployment.
- AI governance needs to continue throughout the technology’s lifecycle because systems, models, data and real-world performance can change.
- New Zealand professional services firms should apply the same principle by monitoring higher-risk AI after implementation, rather than treating approval as the end of governance.
The UK’s National Commission into the Regulation of AI in Healthcare published its recommendations on 10 September 2026, proposing a significant change in how AI should be governed.
Its central conclusion is straightforward: traditional regulatory approaches designed around relatively static products are not enough for AI. Instead, oversight needs to be proportionate to risk and continue throughout the AI system’s lifecycle.
The recommendations are directed at healthcare, where the consequences of AI failure can be particularly serious. However, the governance principle is much wider. For New Zealand professional services firms adopting AI across legal, financial, consulting and other workflows, approving an AI tool once and assuming it remains safe is becoming increasingly difficult to justify.
AI changes after you approve it
Traditional technology governance often follows a familiar process. A product is assessed, security and privacy risks are reviewed, contracts are approved and the technology is released to staff.
That approach assumes the product being assessed will remain substantially the same.
AI complicates this. Providers regularly update models, features and integrations. An AI system may behave differently when used with new data, connected to additional systems or deployed across different business processes. Performance can also change as the environment around the technology changes.
The UK Commission specifically identifies this problem, noting that AI-enabled products may evolve over time and perform differently depending on their deployment environment. It recommends greater use of continuous monitoring and real-world evidence rather than relying primarily on assessment before deployment.
For professional firms, that means the question should no longer be simply, “Did we approve this AI tool?” It should also be, “Is it still operating within the conditions under which we approved it?”
Governance needs a lifecycle
The Commission proposes what it calls proportionate lifecycle regulation. In practical terms, oversight should reflect the risk and benefit of the AI system and continue from development and deployment through monitoring, updates and real-world use.
That is a useful model for internal AI governance as well.
A low-risk AI tool used to brainstorm internal content does not need the same oversight as an AI system reviewing client documents, generating professional advice or accessing confidential information. Governance should be proportionate to what the system can do and what happens if it gets something wrong.
Higher-risk systems may require periodic review of accuracy, access permissions, provider changes, data handling, integrations and human oversight arrangements.
This turns AI governance from an approval process into an operating process.
Connected AI makes this more important
The move towards AI agents makes lifecycle governance particularly relevant.
An AI assistant may initially be approved for drafting or summarising information. Later, it may gain access to email, document repositories, customer records or other business applications. New agent capabilities may allow it to retrieve information and complete tasks rather than simply generate text.
The risk profile has changed even though the organisation may still think of it as the same approved AI product.
This is why firms need visibility over material changes in capability and access. A significant new integration, autonomous function or data source should be capable of triggering another risk review.
Responsibility needs to remain clear
Another important part of the UK recommendations is system-wide responsibility. Safe AI use cannot be left solely to the technology provider or regulator.
The Commission identifies responsibilities across manufacturers, healthcare providers, professionals, regulators and policymakers, alongside the need for organisational readiness, workforce capability and governance.
There is a direct parallel for professional services.
Buying an enterprise AI product does not transfer responsibility for how the organisation uses it. The provider may be responsible for the technology, but the firm still determines what information the AI can access, what tasks it performs, who relies on its output and what human checks apply.
This becomes especially important where AI contributes to professional judgements or decisions affecting clients.
New Zealand already has the foundations
New Zealand does not currently have a comprehensive standalone AI law. Instead, AI use sits within existing privacy, professional, contractual, security and other legal obligations, supported by government and sector guidance.
That makes internal governance particularly important.
An organisation may not have a regulator telling it exactly how often an AI system should be reassessed. It still needs a defensible way to demonstrate that risks are identified and managed as the technology changes.
The lifecycle approach provides a practical way to do this without creating unnecessary bureaucracy. Lower-risk AI can receive lighter oversight, while systems with access to sensitive information or influence over important decisions receive more structured monitoring.
What this means for your organisation
Maintain an AI inventory. Record the significant AI systems being used, their purpose, owner, information access and risk level.
Record the approval conditions. Document why higher-risk AI was approved, including its intended use, permitted data, integrations and required human oversight.
Monitor material changes. Identify model, feature, integration, data-access or workflow changes that could alter the original risk assessment.
Set review periods according to risk. Higher-risk AI should be reassessed more frequently than low-risk productivity tools.
Review real-world performance. Governance should consider how AI actually performs after deployment, including errors, complaints, unexpected behaviour and incidents.
Reassess connected and agentic AI. When an AI system gains new access or the ability to take actions, treat that as a potential change in risk rather than simply another software feature.
Keep accountability human. Make it clear who owns the system, who monitors it and who remains responsible for decisions or professional work supported by AI.
Approval is the beginning, not the end
The UK Commission’s recommendations are healthcare-focused and are not rules for New Zealand professional services firms. However, the governance principle behind them is highly transferable.
AI is increasingly difficult to govern as a static technology. Models change, capabilities expand, integrations increase and actual performance only becomes fully visible once systems are being used.
For firms developing AI governance now, the practical shift is simple: do not build a process that ends when an AI tool is approved. Build one that continues to check whether the technology remains appropriate, controlled and accountable throughout its use.
Sources
- UK Government – National Commission into the Regulation of AI in Healthcare: Recommendations for a future regulatory framework
- UK Government – Independent Commission sets out blueprint to accelerate safe AI adoption in healthcare

