top of page

USFDA Discussion Paper: Considerations for Regulating Generative AI-Enabled Medical Devices

Generative artificial intelligence (GenAI) is creating new opportunities for medical devices while also introducing regulatory challenges that may differ from traditional software and AI-enabled devices. The U.S. Food and Drug Administration (FDA) is seeking public input on how GenAI-enabled medical devices could be evaluated and monitored while maintaining reasonable assurance of safety and effectiveness.


The FDA’s Center for Devices and Radiological Health (CDRH), through its Digital Health Center of Excellence, has issued a discussion paper covering risk assessment, premarket evaluation, postmarket monitoring, and other regulatory considerations for GenAI-enabled medical devices. The paper is intended to support discussion and gather stakeholder feedback and does not establish new regulatory requirements.


Why GenAI-Enabled Medical Devices Need New Regulatory Considerations

GenAI-enabled devices can accept open-ended inputs, perform multiple tasks, and produce different outputs for similar inputs. They may also change over time through updates to the underlying model, prompts, retrieval strategies, guardrails, orchestration logic, or user interface. Many devices may rely on third-party foundation models, where information about training data, architecture, and evaluation methods may be limited. These characteristics can provide benefits such as personalized outputs and adaptability to new inputs, but can also introduce risks.

Potential concerns include confabulations or hallucinations, uncertainty around intended use, limited visibility into third-party foundation models, and performance degradation across testing and real-world environments.


FDA’s Risk-Based Regulatory Approach

FDA does not regulate GenAI itself. It regulates medical devices, including devices containing GenAI-enabled software functions, using a risk-based approach based on the controls needed to provide reasonable assurance of safety and effectiveness.

The discussion paper presents a possible two-axis framework for considering risk. One axis relates to the activity performed by the device, including how independently it directs or takes action. The other considers the potential consequences of relying on an incorrect output.

Risk increases as the device performs more independent activities and as the potential harm from an incorrect output becomes greater. CDRH expects a risk-based and total product lifecycle (TPLC) approach to be important for GenAI-enabled devices.


Potential Competency-Based Premarket Evaluation

Traditional medical device evaluation may be difficult to apply to GenAI-enabled devices because they can have very large ranges of possible inputs and outputs. CDRH therefore discusses a potential competency-based approach for premarket evaluation.

The proposed concept could include:

  • Non-clinical device benchmarking

  • Clinical confirmation

  • Evaluation of the final user-facing device as intended for real-world deployment

  • Assessment tailored to the device’s intended use and risk

The amount and type of evidence could be influenced by the device activity and the consequences of an incorrect output.

The discussion paper presents these concepts for stakeholder feedback rather than establishing a new evaluation requirement.

Premarket Evidence and Performance Evaluation

CDRH recognizes that some GenAI-enabled devices may be difficult to fully evaluate before marketing because they can undergo continuous adjustments and may use open-ended inputs and outputs.

The agency highlights the potential need for new methodologies to evaluate performance and emphasizes the importance of maintaining device accuracy, relevance, and reliability after deployment. Premarket evidence may therefore need to be complemented by robust postmarket performance monitoring.

Postmarket Monitoring of GenAI Devices

Because GenAI-enabled devices may produce variable outputs and change after deployment, CDRH is considering risk-proportionate approaches to postmarket monitoring.

Possible approaches discussed include:

  • Periodic device benchmarking

  • Sample-based clinician review of real-world inputs and outputs

  • Performance degradation monitoring, including monitoring for drift

The frequency and level of evidence could vary according to the device’s risk profile. CDRH is also seeking feedback on whether machine-based supervisory agents could support certain postmarket monitoring activities.

Managing Changes After Marketing

GenAI-enabled devices may undergo different types of changes after deployment. These can include software updates, algorithm revisions, retraining, changes in intended functionality, continuous model evolution or changes to an underlying third-party foundation model.

Such changes may affect the safety and effectiveness of the device. CDRH is considering approaches ranging from documentation within a manufacturer's quality management system to FDA authorization before implementing certain changes.

A Predetermined Change Control Plan (PCCP) is identified as one possible mechanism for facilitating certain device changes without requiring a new premarket submission.


Foundation Models and Agentic AI

The discussion also considers devices incorporating different underlying model architectures, including multimodal models and generative or predictive world models.

The paper defines agentic AI systems as GenAI-enabled systems that can autonomously plan and execute multi-step tasks, use external tools, or take actions across a sequence of steps.

CDRH is seeking stakeholder input on whether the possible competency-based approach would be effective for different model architectures and what additional considerations may be needed.

Shared Responsibility Across the Ecosystem

While manufacturers remain responsible for postmarket monitoring of their devices, CDRH recognizes that GenAI-enabled devices operate within a broader ecosystem.

Clinicians, patients, healthcare institutions, payers, professional societies, public-private groups, standards-setting bodies, and government authorities may have roles in deployment, monitoring, reporting and ongoing evaluation. CDRH is seeking feedback on how these responsibilities could be shared across the ecosystem.

FDA Seeks Public Feedback

The FDA is seeking feedback from device manufacturers, clinicians, researchers, consumers, the public, and other interested parties on the discussion paper and its regulatory questions.

Comments should be submitted under docket FDA-2026-N-7874 through Regulations.gov by October 19, 2026. Stakeholders do not need to respond to every question and may provide feedback only on topics relevant to their expertise or experience.

References

Comments


I Sometimes Send Newsletters

Thanks for submitting!

  • LinkedIn
  • Facebook
  • Twitter
  • Instagram

DISCLAIMER

The views expressed in this publication do not necessarily reflect the views of any guidance of government, health authority, it's purely my understanding. This Blog/Web Site is made available by a regulatory professional, is for educational purposes only as well as to give you general information and a general understanding of the pharmaceutical regulations, and not to provide specific regulatory advice. By using this blog site you understand that there is no client relationship between you and the Blog/Web Site publisher. The Blog/Web Site should not be used as a substitute for competent pharma regulatory advice and you should discuss from an authenticated regulatory professional in your state.  We have made every reasonable effort to present accurate information on our website; however, we are not responsible for any of the results you experience while visiting our website and request to use official websites.

bottom of page