WHO Wants AI Health Research on a Tighter Leash, and India Has Good Reason to Listen

A new WHO report says ethics checks on AI health research must continue well past the approval stage. India has new rules for AI medical software, but oversight of research still has gaps.

{{What WHO Actually Released}}

On **21 July 2026**, the World Health Organization published a 69-page report on the ethics review and oversight of health research that uses artificial intelligence. It is the product of roughly 18 months of work by WHO's Expert Group on Ethics and Governance of AI for Health.

The report looks at three kinds of work. The first is data science, where AI is used to mine large health datasets, including social media posts, for patterns. The second is research carried out with AI tools, such as models that generate synthetic patient data. The third is research that tests AI products themselves, for example a diagnostic algorithm trialled on real patients.

Its central argument is simple. The ethics system built for drug trials and classic clinical studies was not designed for AI, and it now has gaps. WHO wants oversight that follows a project from design to deployment and beyond, instead of a single sign-off at the start.

The report is not binding on any country. WHO guidance works as a reference that national regulators, ethics committees, funders and journals can adopt, adapt or ignore. But India has a direct stake in how it is received. One of the Expert Group's two co-chairs is **Partha Majumder**, National Science Chair of the Government of India, and a senior scientist from the Indian Council of Medical Research (ICMR) sits on the group.

{{Why "Lifecycle" Is the Key Word}}

In most countries, including India, a research ethics committee (REC) reviews a study before it begins. It checks consent forms, risks to participants and data handling. After that, oversight often thins out. International rules call for "continuing review" while a study runs, but WHO notes that this is frequently neglected because committees lack staff and money.

For AI research, that gap matters more than usual. WHO lists several reasons.

**Speed.** A new drug can take a decade or more to move from lab to market. An AI research finding can become a commercial product in as little as **12 months**. Risks missed early can spread quickly through hospitals and phone apps.

**Late-surfacing risks.** Bias in an algorithm often shows up only in later stages, once the tool meets a wider patient population. Researchers may also find new secondary uses for a dataset halfway through a project, uses the ethics committee never saw.

**Poor transfer between settings.** A model built on one population may not work on another. Deploying it without fresh testing can do harm.

**Low barriers to entry.** AI tools are easy to use, so people with little training in research ethics can run large health studies.

**Missing reviews.** Private companies may never submit their AI health research to an independent committee, or may use in-house committees that WHO calls a poor substitute.

This is why the report says RECs examine AI research "too early". Its answer is ongoing engagement with a project, shared with other bodies that can see what happens later.

{{The Risks WHO Names}}

The report goes beyond the usual list of bias and privacy.

On privacy, it warns that anonymising data does not settle the ethical questions. People may not want their records used for purposes nobody could foresee when they gave consent. Broad consent forms may not cover such uses.

On safety, it flags **automation bias**, where clinicians trust a machine's output and stop applying their own judgement. WHO says large language models make this worse, because they can produce confident but false answers.

On fairness between countries, it names two practices. **Health data colonialism** is the collection of health data from low- and middle-income countries by researchers or firms from richer nations, without due respect for consent, privacy and the interests of the community. **Ethics dumping** is when researchers run studies in places where they expect weaker oversight to allow practices that would be blocked at home.

The report also raises two issues that rarely feature in Indian debates. One is the treatment of "crowd workers", the low-paid people who label data for AI systems. The other is the carbon and water footprint of AI tools if they are scaled up across a health system.

{{What WHO Wants Each Player to Do}}

For ethics committees, the report asks institutions to provide more money, staff and training, and to bring in members who understand AI. It suggests that at least one patient or community representative sit on committees reviewing AI studies. Countries with little AI research could set up a single national or regional specialised committee.

Committees could also demand more information from researchers. WHO lists a risk classification for each project, an equity impact assessment covering bias and benefit sharing, an environmental impact assessment, and details of the datasets used to train and test a model, along with bias test results.

For researchers, the report asks for "ethics by design", meaning risks are considered from the first draft of a project. It asks them to disclose which AI tools they used and how, including the prompts given to generative models. It also asks them to share negative or inconclusive internal results with ethics committees.

Funders, data-access committees, journals, medical societies and regulators each get their own tasks. Funders, for example, could require AI-specific ethics training as a condition of a grant. WHO also calls on the global standard-setters, the Council for International Organizations of Medical Sciences and the World Medical Association, to update their guidelines for AI research and revise them more often.

Notably, WHO does not want ethics committees to carry all of this. It warns that piling every AI question onto them could overwhelm a carefully balanced system, and says the burden should be shared.

{{Why India's Scale Raises the Stakes}}

India is building one of the world's largest digital health systems. Under the Ayushman Bharat Digital Mission, more than **97.61 crore** health accounts (ABHA IDs) were operational as of 17 September 2026, with nearly **120 crore** health records linked to them. The national registries list about **5.36 lakh** health facilities and **10.09 lakh** health professionals.

That is a vast pool of data for research, and it is growing. The mission's policy is that data is exchanged only with the patient's consent and that there is no central repository. But the sheer volume is exactly the kind of resource the WHO report has in mind when it discusses secondary use and consent that may not stretch to unforeseen purposes.

AI is also already inside public health programmes. The National Tuberculosis Elimination Programme uses **DeepCXR**, an ICMR-validated tool that reads chest X-rays. ICMR says it was trained on 75,000 X-rays from 12 states and 17 sites, and showed **92.2% sensitivity** and **77.4% specificity**. In plain terms, it catches most TB-suggestive X-rays but also flags a fair number of healthy ones for follow-up testing. The government has told Parliament it was deployed in eight states and Union Territories, and that the programme has more than 500 AI-enabled handheld X-ray units in the field, with 1,500 more being delivered.

These are the tools where WHO's lifecycle point bites. A screening model validated across 17 sites still has to be watched as it moves into new districts, new machines and new patient groups.

{{What India Already Has in Place}}

It would be wrong to say India has no framework. Its rules are spread across several bodies, and some are recent.

**ICMR's ethical guidelines (2023).** ICMR published guidelines for AI in biomedical research and healthcare in 2023. The WHO report cites them as an example of a national body adapting to AI. They cover principles such as safety, data privacy, accountability, equity and non-discrimination, set out an ethics review procedure for AI research, discuss how training and test populations are selected, and include a checklist for ethics committees. ICMR also requires ethics review for the secondary use of medical records and health datasets, which is stricter than some countries.

**CDSCO's medical device software guidance (2026).** On the same day WHO released its report, the Central Drugs Standard Control Organisation (CDSCO) issued guidance on software that counts as a medical device, including AI tools. It asks makers of AI software to disclose the demographic and geographic make-up of their training and test data. They must show evidence on bias and performance across sub-populations relevant to India. Evidence from abroad may need to be supplemented with validation in representative Indian populations.

The same guidance requires post-market monitoring for "algorithm drift", the gradual loss of accuracy as real-world data moves away from training data. It lists drift, bias and error rates among the things manufacturers must track after launch. That is close to what WHO means by lifecycle oversight, at least for approved products.

**Data protection.** The Digital Personal Data Protection Act, 2023 now has rules, notified on 13 November 2025. Most of the obligations on companies, including notice, consent, security and the research exemption, take effect only on **13 May 2027**.

**National AI policy.** The India AI Governance Guidelines released in November 2025 concluded that a separate AI law is not needed for now. They prefer existing laws and sector regulators, with targeted amendments where gaps appear.

{{Where the Gaps Remain}}

The CDSCO guidance is a clearer map, not a new law. It says so itself: it reflects current practice under the Medical Devices Rules, 2017 and "should not be misconstrued as a new regulatory control". It also treats an Algorithm Change Protocol, a plan for how a model may be updated safely, as something to be devised "wherever applicable", not as a requirement for every AI product.

Its reach is also limited to software with a medical purpose. General wellness apps, fitness trackers and administrative tools generally fall outside it. And it governs products seeking approval, not the research that comes before them. That earlier stage is the WHO report's focus.

On research oversight, capacity is the pressure point. The Department of Health Research runs the registry for ethics committees that review biomedical and health research. By its latest annual report, it had received about **2,004** registration applications, issued more than **1,625** provisional certificates and only around **576** final ones. A 2025 peer-reviewed study found that only about half of the 370 medical institutes recognised for postgraduate training had a committee registered with the department.

If many committees struggle to complete registration, it is fair to ask how many can review AI protocols in depth or carry out the continuing review WHO calls for. There is no public data on how many Indian committees have members trained in AI.

Data protection leaves another open question. Under Rule 16 of the new data rules, processing for research, archiving or statistics is exempt from the Act if it follows standards set out in a schedule. How that exemption works in practice for AI training on health data will matter a great deal once it takes effect.

{{The Fair Framing}}

This is not a story of India failing where others succeed. WHO's own report says ethics committees across the world are not equipped for AI research, and that standards are not harmonised even within countries. India is ahead of many peers in having dedicated ICMR guidelines and a regulator that now names drift and bias in writing.

There is also a real counter-argument. Heavy, slow review can delay tools that could help the patients India most needs to reach, such as rural TB patients who never see a radiologist. The India AI Governance Guidelines lean towards flexibility for this reason, and WHO itself warns against overloading committees.

The useful accountability question is narrower. India has rules for AI products at the point of approval and after launch. It has principles for AI research. What it lacks is evidence that the research stage, where datasets are gathered and models are first tested on people, is being watched with the continuity and expertise the WHO report describes.

{{Questions Readers Are Asking}}

**Does the WHO report ban anything?**

No. It sets out considerations for ethics committees, researchers, funders, journals and regulators. Countries decide whether to adopt them.

**Is my health data from ABHA being used to train AI?**

The mission's stated design is that records are shared only with the patient's consent and are not held in a central database. The report's point is that consent and anonymisation need closer scrutiny when data is reused for purposes that were not foreseen.

**Who approves an AI diagnostic tool in India?**

If the software has a medical purpose, it is regulated as a medical device under the Medical Devices Rules, 2017, with CDSCO or state licensing authorities depending on its risk class.

**What is algorithm drift?**

It is the slow decline in an AI model's accuracy when the patients, machines or disease patterns it meets in real use differ from the data it learned from. It can happen without anyone noticing unless performance is tracked.

**Why does WHO focus on poorer countries?**

Because datasets used to build AI are often skewed towards people in rich countries, and because studies may be run in poorer countries with weaker oversight. Both can leave people in those countries with tools that serve them less well.

{{What to Watch}}

**13 November 2026.** Rules on consent managers under the data protection law come into force. These platforms will let people give and withdraw consent across services, and could shape how health data is shared.

**13 May 2027.** The main data protection obligations and the research exemption take effect. Watch whether the standards for research use are clarified for health and AI.

**First approvals under the CDSCO guidance.** Watch whether regulators publish which AI tools are licensed, in which risk class, and whether any drift or safety reports from post-market monitoring are made public.

**An update to ICMR's 2023 guidelines.** They predate the spread of large language models in healthcare. Any revision that covers generative AI, continuing review and private-sector studies would bring India closer to the WHO report.

**Field data on public-sector AI.** State-wise performance figures for DeepCXR as the TB programme expands would show whether accuracy holds across India's varied settings.

**The ethics committee registry.** A rising share of final registrations, and any move to train committees in AI review, would be a concrete sign of capacity being built.

**Global standards.** Watch whether the Council for International Organizations of Medical Sciences and the World Medical Association act on WHO's call to update their research ethics guidelines for AI.

{{The Bottom Line}}

WHO's report is guidance, not law. Its core message is that AI health research can move from lab to patient faster than the current ethics system can follow. India has already written some of the answer: ICMR's principles and CDSCO's demands on bias, Indian validation and drift monitoring. The open question is the research stage itself. Oversight there rests on ethics committees that are still building basic capacity, and on data protection rules that are not yet in force. The test is whether that gap closes before a widely used AI health tool fails in public, not after.

**Note on perspective**: {{Based on the WHO report of 21 July 2026, CDSCO and ICMR guidance, Government of India data and parliamentary replies as of 25 September 2026. The piece assesses India's oversight of AI health research against WHO's recommendations, recognising both existing safeguards and remaining gaps.}}

View on PublicSlate