Skip to content
Wednesday, October 7, 2026
iInnovate MagSTARTUPS · INNOVATION · GADGETS · AI
AI

How AI Entered Medicine for Real — The FDA's Device Record Explained

AI entered American medicine through the medical-device pathway, not a general AI law: the FDA does not regulate AI as such — it regulates medical devices, including AI-enabled devices, through 510(k) clearance, De Novo classification, and premarket approval (regulatory, FDA). On January 7,…

Mei-Ling Chen · May 14, 2026 · 6 min read
ShareXFacebookLinkedInTelegramEmail
A clinician's hands scrolling a patient-scan viewer on a widescreen monitor in a warm dim reading room, graphite console, one teal status light as accent.
A clinician's hands scrolling a patient-scan viewer on a widescreen monitor in a warm dim reading room, graphite console, one teal status light as accent.

AI entered American medicine through the medical-device pathway, not a general AI law: the FDA does not regulate AI as such — it regulates medical devices, including AI-enabled devices, through 510(k) clearance, De Novo classification, and premarket approval (regulatory, FDA). On January 7, 2025, the agency issued draft guidance setting lifecycle and marketing-submission expectations for AI-enabled device software functions.

How does an AI-enabled medical device reach the US market?

The route is the one pacemakers and imaging machines take, adapted for software that changes. A manufacturer classifies its device, gathers evidence of safety and effectiveness, and files through a premarket pathway — 510(k) clearance for substantial equivalence to an existing device, De Novo classification for novel lower-risk devices, or premarket approval for high-risk ones. The FDA also reviews modifications that could significantly affect safety or effectiveness, which is where adaptive software strains a framework built for static hardware.

The January 2025 draft guidance addresses exactly that strain. The document, listed on the FDA's guidance page as Artificial Intelligence-Enabled Device Software Functions: Lifecycle Management and Marketing Submission Recommendations, provides recommendations on the contents of marketing submissions for devices with AI-enabled software functions, per the FDA guidance record.

What does the lifecycle guidance actually ask for?

According to the guidance document, the recommendations cover what documentation and information will support the FDA's evaluation of safety and effectiveness, and reflect a comprehensive approach to managing risk throughout the device total product life cycle. The draft also proposes recommendations for the design, development, and implementation of AI-enabled devices that manufacturers may consider across that life cycle.

Read as an industry map, the guidance tells builders three things. First, evidence expectations now extend across the full life of the device, not just the submission moment. Second, documentation is the deliverable: how the model was built, trained, validated, and monitored becomes review material. Third, planned change is a first-class subject — the framework is being reshaped around software that legitimately updates after clearance.

What are the Good Machine Learning Practice principles?

Underneath the guidance sits a practice layer. The FDA's Good Machine Learning Practice page describes 10 guiding principles developed through international cooperation: the final document comes from the IMDRF, the international medical device regulators' forum, and builds on guiding principles released in October 2021 by the FDA, Health Canada, and the UK's MHRA. The page describes the principles as a call to action to standards organizations, international regulators, and other collaborative bodies to further advance GMLP, with content current as of December 19, 2025 on the FDA's GMLP page.

For hospitals and digital-health builders, the principles function as the audit checklist regulators are converging on: data quality and representativeness, independence of training and test sets, human performance in deployment, and monitored updating. A vendor who cannot answer questions mapped to these principles is signaling where the regulatory conversation will stall.

What is the difference between clearing a device and regulating software in general?

The FDA's position, stated plainly in its own materials, is that the trigger is the device definition, not the algorithm. Software intended for diagnosis, cure, mitigation, treatment, or prevention of disease — or to affect the structure or function of the body — is a device; the same code deployed for administrative scheduling would not be. That is why hospital AI shows up in some departments and not others: the dividing line runs through intended use, not through model architecture.

The consequence for builders is that "we use AI" is not a regulatory category. A triage tool that flags scans for a radiologist is a device with a cleared claim; a documentation assistant that drafts notes for a clinician to sign may fall outside device review entirely. The January 2025 guidance is addressed to the first kind — AI-enabled device software functions — and its life-cycle recommendations only bind once a product sits inside the device perimeter.

For buyers, the same logic converts into a question to ask any vendor: is this cleared, and for what claim? A precise answer is a good sign. A vague one usually means the product lives outside the regulated perimeter, which may be fine — and means the buyer, not the FDA, is the quality control.

Where is this technology actually deployed?

The documented deployments cluster where a regulatory pathway already existed: software that analyzes images, flags readings for clinician review, or augments a measurement, authorized as devices through the pathways above. The pattern matters for expectations. Hospital AI arrives as cleared tools embedded in existing workflows — not as autonomous decision-makers.

That framing also explains the pace. Software in medicine updates on regulatory time, not software time: each significant change can itself be reviewed, per the FDA's stated approach to modifications that could significantly affect safety or effectiveness. The parts of healthcare adopting AI fastest are the ones whose risk tolerance fits that cadence — diagnostics support, workflow triage, and measurement tools, each cleared for a specific claim.

It also explains the vocabulary hospital vendors use. Products are described by their cleared function — flag, detect, measure, prioritize — rather than by what the underlying model could conceivably do. The cleared claim is the product; the model is a component. Teams evaluating multiple vendors should compare claims, not model announcements, because the claim is what the evidence supports and what the regulator reviewed.

How should a hospital evaluate an AI-enabled device?

A disciplined evaluation follows the regulatory record:

  1. Confirm the device's authorization status and pathway in the FDA's public guidance and device records.
  2. Read the cleared indication — what population, what task, and what the output is for.
  3. Ask the vendor for validation evidence and how it maps to the GMLP principles.
  4. Establish local monitoring for performance drift and a change-control process for updates.
  5. Train clinical staff on the device's documented limits, not its marketing claims.

The evaluation list also works in reverse for vendors. A company that can answer all five steps from documented evidence — authorization record, cleared indication, validation mapped to GMLP, drift monitoring, and staff training on limits — has effectively pre-answered the questions a hospital committee and a regulator will ask. The January 2025 guidance moves the whole industry toward that posture, because it makes life-cycle documentation part of what is reviewed rather than an afterthought.

The comparison with other industries is stark. In consumer software, a model update ships on a Friday and reverts on a Monday if metrics dip. In regulated medicine, the same update is a documented event with a risk assessment attached. Neither cadence is wrong for its context — but any team building AI for healthcare should understand which industry it is actually in before writing the deployment plan.

AI in healthcare is best understood as a regulated-device story with an unusually fast-moving technology inside it. The FDA record — pathways, lifecycle guidance, and international practice principles — is the map of where it actually works.

Sources

  1. Artificial Intelligence-Enabled Device Software Functions: Lifecycle Management and Marketing Submission Recommendations — U.S. Food and Drug Administration
  2. Good Machine Learning Practice for Medical Device Development: Guiding Principles — U.S. Food and Drug Administration

More from our brands

Part of the VUGA Network