"Patients and clinicians deserve a regulatory approach that keeps pace with the rapid innovation of digital health technologies.”
FDA Seeks Public Input on Regulatory Framework for Generative AI-Enabled Medical Devices
Key Takeaways
- A two-axis risk schema aligns functional autonomy (informational to autonomous action) with potential harm from incorrect outputs, stratifying oversight intensity as risk rises toward autonomous, high-consequence functions.
- Patient-facing GenAI functions may warrant heightened controls because limited domain expertise can impair error recognition and amplify downstream safety risk relative to clinician-facing implementations.
A new discussion paper from the FDA's Center for Devices and Radiological Health proposes a two-axis risk framework and competency-based evaluation approach for generative artificial intelligence-enabled medical devices.
The FDA has issued a discussion paper outlining potential approaches to regulating generative artificial intelligence (GenAI)-enabled medical devices, seeking public feedback on risk assessment, premarket evaluation, postmarket monitoring, and other related topics.1
The effort is led by the Digital Health Center of Excellence (DHCoE) within the FDA's Center for Devices and Radiological Health (CDRH) and supports the agency's strategic pillar on innovation and global leadership.
GenAI-enabled medical devices differ from traditional software and AI-enabled devices in that they may accept open-ended inputs, perform multiple subtasks, and produce variable outputs in response to similar inputs. Many are built on general-purpose foundation models developed by third-party entities, which offer varying levels of transparency into their training data, architecture, and evaluation methods.2
Risks specific to these devices include confabulations—also called hallucinations—that may appear authentic to users, uncertainty in the bounds of a device's intended use, and performance degradation across test environments and real-world applications.
"Patients and clinicians deserve a regulatory approach that keeps pace with the rapid innovation of digital health technologies," said Michelle Tarver, MD, PhD, director of CDRH, in an agency press release. "By inviting input from the public, we are launching a transparent process to inform the development of an approach that safeguards patients and consumers, advances innovation, and serves as a potential model for regulators around the world."
A two-axis framework for risk
The discussion paper proposes a possible two-axis framework for assessing the risk of GenAI-enabled device software functions. One axis represents the degree and independence of device activity, ranging from non-directive informational functions to fully autonomous action-taking functions. The other represents the consequences—or severity of harm—of relying on an incorrect device output. Risk increases from the lower-left to the upper-right of the framework.
The paper distinguishes between functions that provide non-directive information, functions that direct a user toward a particular action, and functions that autonomously take actions such as initiating a clinical order.
It also identifies patient-facing functions as potentially higher risk than healthcare professional-facing functions, noting that patients may lack the domain knowledge to independently evaluate or recognize an incorrect output.
Competency-based premarket evaluation
For premarket evaluation, the paper proposes a competency-based approach modeled at a high level on how human clinicians are trained and evaluated. The approach consists of two components: non-clinical device benchmarking and clinical confirmation.
Device benchmarking would assess whether a GenAI-enabled device demonstrates clinical knowledge, analytic capabilities, safety behavior, communication quality, and generalizability across relevant inputs and populations.
Clinical confirmation would then evaluate whether the device performs as intended under real or clinically representative conditions. CDRH notes that clinical confirmation would not require a prospective clinical study in every case, with the appropriate approach depending on the device's intended use and risk profile.
Postmarket monitoring and foundation models
Given the capacity of GenAI-enabled devices to evolve over time through changes to underlying models, prompts, or other components, the paper describes several possible postmarket monitoring approaches. These include periodic re-benchmarking against prespecified thresholds, sample-based clinician review of real-world inputs and outputs, and performance degradation monitoring to detect drift.
The paper also addresses devices built on third-party foundation models, noting that changes to those underlying models may be initiated by the model developer rather than the device manufacturer.
CDRH seeks input on a possible voluntary Foundation Model Device Master File program, under which foundation model developers could submit information about their models to FDA on a confidential basis for reference during premarket review.
Submission of such a file would not constitute authorization of the model for any intended device use, and device sponsors would remain responsible for independently demonstrating safety and effectiveness.
The public comment period closes October 19, 2026, with submissions accepted under docket FDA-2026-N-7874 on Regulations.gov.
References
- FDA Seeks Public Feedback to Inform Regulatory Approach for Generative AI-Enabled Medical Devices. News release. FDA. August 18, 2026. Accessed August 19, 2026.
https://www.fda.gov/news-events/press-announcements/fda-seeks-public-feedback-inform-regulatory-approach-generative-ai-enabled-medical-devices - Considerations for the Regulation of Generative AI-Enabled Medical Devices: Discussion Paper and Request for Feedback. FDA. August 2026. Accessed August 19, 2026.
https://www.fda.gov/media/194242/download





