FDA Compliance

FDA AI/ML Medical Device Guide

Guide to FDA regulation of AI/ML-enabled medical devices, including the August 2025 final PCCP guidance, submission pathways, lifecycle management, and real-world monitoring.

22 min read 5,500+ words
Joe Braidwood
Joe Braidwood
CEO, GLACIS
22 min read

Executive Summary

FDA issued its final guidance for Predetermined Change Control Plans (PCCPs) for AI-enabled device software functions on August 18, 2025. FDA reviews a proposed PCCP as part of a 510(k), De Novo, or PMA marketing submission; modifications that stay within an authorized PCCP can be implemented without a separate marketing submission for each change. The guidance contains nonbinding recommendations, not a standalone implementation deadline.[1]

The AI-enabled device software lifecycle draft guidance (January 2025) describes FDA’s current thinking on monitoring strategies and documentation of real-world performance. FDA’s February 2026 cybersecurity guidance provides risk-based, nonbinding recommendations for devices with cybersecurity risk, including threat modeling, vulnerability management, and update planning; it does not prescribe one universal cryptographic architecture for every software device.[2][3]

August 2026 currentness note: FDA released a discussion paper on generative-AI-enabled medical devices and requested public feedback on August 18, 2026. It is a discussion paper, not guidance or a new binding requirement.[10] Manufacturers should separate current law, final guidance, draft guidance, and open policy questions in their regulatory files.

List boundary: FDA’s public AI-enabled-device list changes over time and FDA says it is not comprehensive. Static totals and pathway percentages can become misleading, so this guide uses the current list as a discovery aid rather than a denominator for all AI-enabled devices.[4]

In This Guide

FDA Regulatory Framework for AI/ML Devices

The U.S. Food and Drug Administration (FDA) regulates AI/ML-enabled medical devices under the Federal Food, Drug, and Cosmetic Act (FD&C Act). Unlike traditional software that follows deterministic logic, AI/ML algorithms can learn from data and evolve. That evolution presents unique regulatory challenges, which FDA has addressed through a series of guidance documents and policy frameworks.[1][2]

Evolution of FDA’s AI/ML Approach

FDA’s journey toward comprehensive AI/ML regulation began with the 2019 discussion paper “Proposed Regulatory Framework for Modifications to Artificial Intelligence/Machine Learning-Based Software as a Medical Device.” This established the conceptual foundation for what would become the Total Product Lifecycle (TPLC) approach. TPLC is a regulatory model that acknowledges AI/ML devices may change over time while maintaining safety and effectiveness.[6]

Key milestones in FDA’s AI/ML regulatory evolution:

Scope of FDA Oversight

FDA regulates AI/ML-enabled devices that meet the definition of a “device” under the FD&C Act. That definition covers products intended for use in diagnosis, cure, mitigation, treatment, or prevention of disease. This includes:

Software as a Medical Device (SaMD) Classification

IMDRF publishes a nonbinding SaMD risk-categorization framework based on the significance of the information provided and the healthcare situation or condition. It is useful context, but FDA classification and submission requirements arise from U.S. law, intended use, device risk, and the applicable FDA pathway.[7]

IMDRF Risk Categorization Matrix

SaMD Risk Categories

State of Healthcare Situation Treat or Diagnose Drive Clinical Management Inform Clinical Management
Critical IV (Highest) III II
Serious III II I (Lowest)
Non-Serious II I I

FDA’s public AI-enabled-device list is heavily weighted toward radiology and 510(k) authorizations, but FDA says the list is not comprehensive and it changes over time. Classification and submission requirements must be determined from the device’s intended use, risk, applicable classification regulation, predicates where relevant, and current FDA pathway.[4]

Device Classification Examples

Class I (Low Risk)

  • • General wellness applications
  • • Administrative workflow tools
  • • Non-clinical decision support

Generally exempt from premarket submission

Class II (Moderate Risk)

  • • Radiology AI (CADe/CADx)
  • • ECG analysis software
  • • Diabetic retinopathy screening

510(k) or De Novo pathway required

Class III (High Risk)

  • • Autonomous diagnostic systems
  • • AI-driven treatment recommendations
  • • Life-sustaining device algorithms

PMA with clinical trials required

Clinical Decision Support (CDS) Exemptions

  • • Basis for recommendation is transparent
  • • Provider can independently review basis
  • • Not intended to replace clinical judgment

May be exempt per 21st Century Cures Act

Predetermined Change Control Plans (PCCP)

FDA issued final PCCP guidance tailored to AI-enabled device software functions on August 18, 2025. A PCCP included in a 510(k), De Novo, or PMA submission can describe specified future modifications, the methods for developing, validating, and implementing them, and an impact assessment. Once FDA authorizes that PCCP as part of the device submission, changes within its scope can proceed without a separate marketing submission for each modification. The guidance states FDA’s current, nonbinding recommendations; it did not establish a separate “full implementation” date.[1]

PCCP Requirements

A PCCP submitted as part of a marketing application must include:

PCCP Core Components

Component Description FDA Expectation
Description of Modifications Specific types of changes that may be made to the device Clear boundaries on what changes are pre-authorized
Modification Protocol Methodology for developing and implementing changes Documented development process with quality controls
Impact Assessment Methods to evaluate the effect of modifications on safety/effectiveness Quantitative metrics and acceptance criteria
Verification and Validation Testing protocols for each type of modification Evidence that changes meet performance specifications
Traceability Documentation linking modifications to assessments Documented traceability between in-scope modifications, assessments, and verification results

Modifications Requiring New Submissions

Even with an approved PCCP, certain modifications fall outside its scope and require new marketing submissions:

PCCP Documentation Best Practices

Organizations implementing PCCPs should maintain:

Submission Pathways for AI/ML Devices

Common premarket routes for AI/ML medical devices include 510(k), De Novo, and PMA. Other statutory pathways, exemptions, and postmarket requirements may apply; the correct route depends on the specific device and current FDA framework.[5]

510(k) Premarket Notification

The 510(k) pathway is used when a device is substantially equivalent to a legally marketed predicate device. Many entries in FDA’s public AI-enabled-device list use this route, but that evolving, non-comprehensive list should not be turned into a universal pathway percentage.

510(k) Key Requirements

  • • Identify legally marketed predicate device
  • • Demonstrate same intended use and similar technological characteristics
  • • Performance testing comparing device to predicate
  • • Software documentation per FDA guidance

Timing: FDA review clocks, interactive review, requests for additional information, and total elapsed time vary by submission and pathway. Confirm the current statutory and performance-goal framework for the specific device.

De Novo Classification

The De Novo pathway is for novel, low-to-moderate risk devices without a predicate. Many innovative AI/ML devices use this pathway when no substantially equivalent device exists.

De Novo Key Requirements

  • • Demonstrate device is low-to-moderate risk
  • • General and special controls adequate to provide reasonable assurance of safety and effectiveness
  • • Propose device classification and product code
  • • Clinical or analytical validation data

Timing: statutory review goals and actual elapsed time depend on the pathway, submission quality, interactive review, requests for information, and sponsor response. Confirm the current system-specific plan with FDA and regulatory counsel.

Premarket Approval (PMA)

PMA is required for Class III devices that pose the highest risk. This pathway requires the most extensive clinical evidence and FDA review.

PMA Key Requirements

  • • Valid scientific evidence demonstrating safety and effectiveness
  • • Clinical trials typically required
  • • Manufacturing quality systems inspection
  • • Post-market surveillance commitments

Timing: The PMA review clock is 180 days after filing; actual elapsed time varies with filing completeness, interactive review, requests for information, inspections, and sponsor response.

Total Product Lifecycle (TPLC) Approach

FDA’s Total Product Lifecycle approach recognizes that AI/ML devices are fundamentally different from traditional medical devices. They’re designed to learn, adapt, and improve. The January 2025 AI-enabled device software lifecycle draft guidance proposes expectations for managing these devices throughout their entire lifecycle.[2]

TPLC Core Principles

Good Machine Learning Practice (GMLP)

FDA, Health Canada, and UK MHRA jointly published 10 guiding principles for GMLP covering data quality, model design, performance evaluation, and ongoing monitoring. These principles form the foundation of lifecycle management expectations.

Algorithm Change Protocol

Manufacturers must establish protocols for how algorithm changes are developed, validated, and deployed. This includes defining what constitutes a “significant” change requiring new submission versus a change manageable under a PCCP.

Performance Monitoring Strategy

Continuous monitoring of real-world performance is expected, including detection of performance drift, monitoring across subpopulations, and processes for addressing performance degradation.

Re-Training Protocols

For adaptive algorithms, manufacturers must document how re-training decisions are made, what data is used, how validation is performed, and how updates are deployed while maintaining device safety.

Locked vs. Adaptive Algorithms

FDA distinguishes between two fundamental types of AI/ML algorithms:

Locked Algorithms

Algorithm produces same result each time same input is applied. Does not change after deployment.

  • → Traditional regulatory pathway applies
  • → Changes require new submission or PCCP
  • → Simpler post-market monitoring

Adaptive Algorithms

Algorithm changes its behavior over time based on new data or learning from deployed use.

  • → PCCP strongly recommended
  • → Continuous monitoring required
  • → Re-training protocols must be documented

Cybersecurity Requirements for AI Devices

FDA’s February 2026 Cybersecurity in Medical Devices guidance provides recommendations for devices with cybersecurity risk and supersedes the June 2025 final guidance. It recommends risk-based cybersecurity design and premarket documentation, including threat modeling, security-risk management, vulnerability handling, and update planning. It does not apply an identical control set or universal cryptographic requirement to every software device.[3]

Core Cybersecurity Requirements

Cybersecurity Submission Elements

Requirement Description AI-Specific Considerations
Threat Modeling Identification and analysis of potential cybersecurity threats Adversarial inputs, model poisoning, data manipulation
Security Risk Assessment Evaluation of exploitability and severity of identified threats Model extraction, inference attacks, training data leakage
Security Controls Technical measures to mitigate identified risks Input validation, anomaly detection, model integrity checks
Software Bill of Materials Inventory of all software components including ML libraries Model dependencies, training frameworks, inference engines
Vulnerability Management Processes for identifying and addressing vulnerabilities Model vulnerability scanning, adversarial testing

AI-Specific Security Concerns

AI/ML devices face unique cybersecurity threats beyond traditional software:

Real-World Performance Monitoring

FDA increasingly emphasizes the importance of monitoring AI/ML device performance in real-world clinical settings. The September 2025 request for public comment on AI device performance underscores the agency’s focus on developing standardized approaches to real-world evidence collection.[8]

Monitoring Expectations

Manufacturers should implement monitoring systems that track:

Evidence Infrastructure Requirements

Effective real-world monitoring requires infrastructure capable of:

Per-Inference Logging

For covered events, preserve purpose-appropriate fields or references for inputs, outputs, declared model version, and what configured guardrails reported. Decide separately when full payload retention is lawful and necessary.

Tamper-Evident Audit Records

Logs should be tamper-evident and independently verifiable. Regulatory submissions may require demonstrating that records haven’t been altered.

Automated Alerting

Systems should automatically detect performance degradation and alert appropriate personnel when metrics fall outside acceptable ranges.

Reporting Capabilities

Generate reports suitable for regulatory submissions, including MDR (Medical Device Report) documentation when adverse events occur.

Frequently Asked Questions

What is a Predetermined Change Control Plan (PCCP)?

A PCCP is reviewed by FDA as part of a marketing submission and can cover specified future modifications to an AI-enabled device software function. FDA issued its final AI-enabled device PCCP guidance on August 18, 2025. The guidance recommends describing the planned modifications, the methods for developing, validating, and implementing them, and an impact assessment. It contains nonbinding recommendations; it did not create a separate August 2025 compliance deadline.

What are the FDA submission pathways for AI/ML medical devices?

AI/ML medical devices can be cleared or approved through three main pathways: 510(k) Premarket Notification for devices substantially equivalent to predicate devices, De Novo Classification for novel low-to-moderate risk devices without predicates, and Premarket Approval (PMA) for high-risk Class III devices. The pathway depends on device classification, risk level, and whether a suitable predicate exists.

What is SaMD and how does FDA regulate it?

Software as a Medical Device (SaMD) is software intended for one or more medical purposes that performs those purposes without being part of a hardware medical device. IMDRF publishes a nonbinding risk-categorization framework, while FDA classification and submission requirements depend on U.S. law, intended use, device risk, and the applicable pathway.

What cybersecurity requirements apply to AI medical devices?

FDA’s February 2026 cybersecurity guidance provides nonbinding recommendations for devices with cybersecurity risk. Recommended premarket material includes threat modeling, security-risk assessment, vulnerability management, and update planning. Select controls from the device’s architecture and risk analysis; neither the guidance nor AI functionality creates a universal cryptographic-control checklist.

What is the Total Product Lifecycle (TPLC) approach for AI devices?

The Total Product Lifecycle (TPLC) approach is FDA’s framework for regulating AI/ML devices throughout their entire lifecycle, from development through post-market surveillance. It emphasizes continuous learning, real-world performance monitoring, and iterative improvement while maintaining safety and effectiveness. The TPLC approach supports the Good Machine Learning Practice (GMLP) principles and enables PCCPs for controlled algorithm updates.

How does FDA define locked vs. adaptive AI algorithms?

Locked functions do not change their behavior after deployment; adaptive functions may change through a defined update process. An FDA-authorized PCCP can cover specified planned modifications, but a PCCP is not mandatory for every adaptive function or every change. Whether a modification needs a new submission depends on the authorized device, applicable guidance, the change, and any authorized PCCP. The January 2025 lifecycle document remains draft, non-binding guidance.

What real-world performance monitoring does FDA expect for AI devices?

FDA expects manufacturers to monitor AI/ML device performance in real-world clinical settings through post-market surveillance. This includes tracking algorithm accuracy, detecting performance drift, monitoring for unexpected outputs, and assessing performance across different patient populations. The September 2025 request for public comment signals FDA’s focus on standardized approaches to real-world evidence collection for AI devices.

When do AI device changes require new FDA submissions?

AI device changes require new FDA submissions when they: (1) affect safety or effectiveness beyond what was originally authorized, (2) fall outside an approved PCCP, (3) change the intended use, or (4) introduce new risks. Minor changes within an approved PCCP may proceed without new submissions, but manufacturers must document all modifications and maintain evidence that changes meet PCCP criteria.

References

  1. [1] U.S. Food and Drug Administration. “Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions.” Final guidance, August 18, 2025. fda.gov
  2. [2] U.S. Food and Drug Administration. “Artificial Intelligence-Enabled Device Software Functions: Lifecycle Management and Marketing Submission Recommendations.” Draft Guidance, January 6, 2025. fda.gov
  3. [3] U.S. Food and Drug Administration. “Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions.” Final guidance, February 2026; supersedes the June 2025 final guidance. fda.gov
  4. [4] U.S. Food and Drug Administration. “Artificial Intelligence and Machine Learning (AI/ML)-Enabled Medical Devices.” Updated 2025. fda.gov
  5. [5] U.S. Food and Drug Administration. “Premarket Submission for Device Software Functions.” November 2021. fda.gov
  6. [6] U.S. Food and Drug Administration. “Proposed Regulatory Framework for Modifications to Artificial Intelligence/Machine Learning-Based Software as a Medical Device.” Discussion Paper, 2019; indexed in FDA’s AI publications collection. fda.gov
  7. [7] International Medical Device Regulators Forum (IMDRF). “Software as a Medical Device (SaMD): Possible Framework for Risk Categorization and Corresponding Considerations.” 2014. imdrf.org
  8. [8] U.S. Food and Drug Administration. “Request for Public Comment: Measuring and Evaluating Artificial Intelligence-Enabled Medical Device Performance in the Real-World.” September 30, 2025. fda.gov
  9. [9] FDA, Health Canada, UK MHRA. “Good Machine Learning Practice for Medical Device Development: Guiding Principles.” October 2021. fda.gov
  10. [10] U.S. Food and Drug Administration. “FDA Seeks Public Feedback to Inform Regulatory Approach for Generative AI-Enabled Medical Devices.” Discussion paper announcement, 18 August 2026. fda.gov
  11. [11] U.S. Food and Drug Administration. “Digital Health Center of Excellence.” fda.gov

Scoped operational evidence for FDA review preparation

GLACIS can preserve bounded control-execution records for an in-scope medical-AI workflow and help assemble them for review. The evidence may support a PCCP or submission package; it does not establish that a control was effective or that FDA requirements are met.

Talk to us

Related Guides

Role-Specific Guides

FDA AI/ML compliance requires cross-functional collaboration. These guides provide tailored action plans for key stakeholders: