FDA Seeks Input on Regulatory Framework for Generative AI-Enabled Medical Devices
September 16, 2026On August 18, 2026, the U.S. Food and Drug Administration (FDA) issued a new discussion paper, Considerations for the Regulation of Generative AI-Enabled Medical Devices, and opened a public docket seeking stakeholder feedback on how generative artificial intelligence (GenAI)-enabled medical devices should be regulated.
The initiative, led by the Digital Health Center of Excellence within FDA’s Center for Devices and Radiological Health (CDRH), addresses a central challenge facing regulators and industry: GenAI-enabled devices may behave differently from traditional software and conventional AI-enabled devices in that they can accept open-ended inputs, generate variable outputs, evolve over time, and, in some cases, autonomously take actions. FDA is seeking input on risk assessment, premarket evaluation, postmarket monitoring, foundation models, and agentic AI systems.
Importantly, the discussion paper is not draft or final guidance and does not establish new regulatory requirements. Rather, FDA is seeking early stakeholder input as it considers how its existing regulatory framework may need to evolve. FDA also expressly states that the paper does not address whether the approaches under consideration fall within FDA’s existing statutory authority or whether additional legal authority may be needed.
Comments are due by October 19, 2026.
Why Generative AI Presents New Regulatory Challenges
FDA already regulates many AI-enabled medical devices. GenAI, however, has capabilities and characteristics that may make traditional approaches to device validation and oversight difficult to apply.
According to FDA, GenAI-enabled devices may:
- Accept open-ended inputs;
- Perform multiple subtasks;
- Produce different outputs in response to similar inputs;
- Change over time through updates to models, prompts, retrieval strategies, guardrails, orchestration logic, or user interfaces; and
- Rely on third-party foundation models into which the device manufacturer may have limited visibility or over which it has incomplete control.
These features can introduce risks arising from hallucinations or confabulations that appear credible to users, difficulty defining the boundaries of the device’s intended use, performance degradation in real-world settings, and uncertainty regarding the effect of changes to underlying third-party models.
FDA’s discussion paper suggests that these characteristics may require a regulatory model that relies more heavily on risk-proportionate evidence across the entire product life cycle rather than traditional premarket testing alone.
FDA Is Considering a New Risk Framework
One of the most significant concepts in the discussion paper is a possible two-axis framework for assessing the risk of GenAI-enabled device functions.
One axis considers the degree and independence of the activity performed by the device. The other considers the severity of harm that could result if a user relies on an incorrect output. Under the framework, risk generally increases as the device becomes more autonomous and the potential consequences of an incorrect output become more significant.
FDA discusses several general categories of activity:
- Non-directive informational functions provide information without directing the user toward a particular action.
- Action-directing functions may recommend or direct a patient or healthcare professional toward a particular clinical action.
- Action-taking functions may themselves initiate actions, such as assigning a diagnosis, prescribing medication, or initiating a clinical order.
FDA appears to view increasing autonomy as an important risk factor. However, the agency also recognizes that autonomy alone is not dispositive. The consequences of an incorrect output remain critical. An autonomous function performing a relatively low-risk task may present less overall risk than a highly directive function influencing a critical treatment decision.
This approach is consistent with FDA's treatment of AI-enabled clinical decision support (CDS) software, where the degree to which software interprets patient-specific information, directs clinical decision-making, and allows a healthcare professional to independently evaluate the basis for its output can determine whether the software falls within FDA's medical device regulatory framework. As discussed in Gardner Law's analysis of the FDA's CDS guidance, FDA has specifically emphasized the level of automation and the time-critical nature of clinical decision-making when assessing whether a clinician can realistically exercise independent judgment rather than rely primarily on a software recommendation. The same underlying principle is evident in FDA's GenAI framework under consideration: Regulatory concern increases as software moves from providing information, to directing decisions, to taking actions with less opportunity for meaningful human review. This is also consistent with FDA's broader lifecycle approach to AI-enabled CDS and Software as a Medical Device, which emphasizes that intended use, clinical risk, transparency, validation, human oversight, and ongoing performance must be considered together. An autonomous function performing a relatively low-risk task may therefore present less overall risk than a highly directive function influencing a critical treatment decision, while a system that both acts autonomously and can cause significant harm if incorrect would likely warrant the greatest regulatory scrutiny.
For manufacturers, FDA’s framework under consideration could ultimately affect device classification, the scope of premarket evidence, change-control expectations, and postmarket monitoring obligations.
A “Competency-Based” Approach to Premarket Evaluation
Perhaps the most novel concept in the discussion paper is FDA’s consideration of a competency-based approach to premarket evaluation.
FDA draws a high-level analogy to how physicians are trained and evaluated. Rather than attempting to test every possible scenario that a GenAI-enabled device could encounter, FDA is considering whether manufacturers could demonstrate that a device possesses defined competencies relevant to its intended use.
Under the possible framework, evaluation could consist of two components:
- Non-clinical device benchmarking; and
- Clinical confirmation.
The final user-facing device, in the configuration intended for real-world deployment, would be evaluated rather than the underlying foundation model in isolation. The rigor and amount of evidence could then be scaled according to the device’s risk profile.
Potential benchmarking elements discussed by FDA include clinical knowledge, reasoning, communication, generalizability, safety behavior, and the ability to appropriately recognize uncertainty or defer to a human clinician.
This represents a potentially significant departure from traditional software validation models. For GenAI-enabled devices capable of receiving virtually unlimited inputs and generating variable responses, exhaustive testing may be neither technically feasible nor scientifically meaningful. A competency-based model could instead focus on whether the device consistently demonstrates acceptable performance across defined domains.
For manufacturers, however, the critical questions will be how those competencies are defined, what constitutes adequate validation, what benchmarks FDA will accept, and how manufacturers establish objective acceptance criteria for systems with inherently variable outputs.
FDA May Rely More Heavily on Postmarket Monitoring
FDA also recognizes that premarket testing may not fully characterize the performance of GenAI-enabled devices once they are deployed.
The agency is therefore considering whether, in appropriate circumstances, greater uncertainty could be accepted during premarket review in exchange for more robust postmarket monitoring.
Potential monitoring approaches include:
- Periodic re-benchmarking against pre-established performance criteria;
- Periodic clinician review of samples of real-world inputs and outputs;
- Monitoring for model drift and other forms of performance degradation; and
- Potential use of machine-based supervisory agents to monitor device performance.
FDA suggests that the frequency and rigor of monitoring could vary based on device risk.
This could represent an important shift in how manufacturers demonstrate continued safety and effectiveness. Rather than treating market authorization as the conclusion of the evaluation process, manufacturers of GenAI-enabled devices may need to structure their quality systems and postmarket surveillance programs around continuous performance assessment from the outset.
Change Control May Become Increasingly Complex
Postmarket modifications present another significant challenge.
FDA identifies at least three types of changes that may occur after a GenAI-enabled device is authorized:
- Intentional modifications initiated by the manufacturer, such as software updates or model revisions;
- Continuous or incremental changes resulting from a device designed to learn or adapt during use; and
- Changes initiated by a third-party developer to an underlying foundation model.
FDA is considering regulatory approaches ranging from documentation within the manufacturer’s quality management system to FDA authorization before implementation. Predetermined Change Control Plans, or PCCPs, could potentially allow some anticipated modifications to be implemented without a new premarket submission.
The third-party foundation model issue may prove particularly difficult. A device manufacturer remains responsible for the safety and effectiveness of its device even when an important underlying component is controlled by another company.
Manufacturers relying on third-party models should therefore consider how contractual provisions, technical controls, change-notification requirements, version controls, and ongoing validation activities can provide sufficient visibility into model changes.
FDA Is Considering Foundation Model Master Files
FDA is also considering whether its existing Device Master File program could be adapted to support GenAI-enabled devices.
Under a possible voluntary Foundation Model Master File framework, developers of foundation models could provide FDA with information about their models that device manufacturers could then reference in individual premarket submissions.
Potential information could include:
- Model architecture;
- Training data provenance;
- Intended supported uses;
- Known limitations and failure modes;
- Healthcare-related evaluation results;
- Performance across clinically meaningful subgroups;
- Guardrails and safety controls;
- Update-notification commitments; and
- Audit-log capabilities.
The model developer’s information would remain confidential with FDA, while manufacturers could reference the Master File with the developer’s authorization.
Importantly, FDA states that submission of a Foundation Model Master File would not constitute FDA authorization of the underlying model. The medical device manufacturer would remain responsible for demonstrating that its own device is safe and effective for its intended use.
If implemented, this type of framework could be particularly useful where manufacturers cannot obtain proprietary information about third-party foundation models directly. At the same time, because participation would be voluntary, its usefulness may depend heavily on whether major foundation model developers are willing to participate.
Agentic AI Raises an Additional Level of Regulatory Concern
The discussion paper separately addresses agentic AI systems, which FDA describes as “GenAI-enabled systems that can autonomously plan and execute multi-step tasks, use external tools, or take actions across a sequence of steps.”
Some agentic systems used for administrative or workflow functions may fall outside FDA’s medical device jurisdiction. Others may qualify as devices, particularly where autonomous actions affect clinical care or control another medical device. FDA specifically asks whether the increased risks associated with autonomous multi-step actions, tool use, and reduced opportunities for human review warrant additional premarket and postmarket controls.
For device manufacturers, agentic AI raises issues beyond traditional algorithm performance. Validation may also need to evaluate whether the system appropriately sequences actions, recognizes when a proposed action exceeds its intended use, responds safely to tool failures, complies with required human-oversight checkpoints, and resists manipulation such as adversarial prompting, prompt injection, or emotional manipulation.
What Manufacturers Should Do Now
Although FDA has not yet proposed formal regulatory requirements, manufacturers developing or evaluating GenAI-enabled medical devices should not wait for final guidance to begin addressing these issues.
Manufacturers should consider taking several steps now:
- Define the intended use and boundaries of the system carefully. Broad or poorly defined functionality may make both risk assessment and validation significantly more difficult.
- Develop a GenAI-specific risk management framework. Traditional software hazards should be supplemented with risks associated with hallucinations, variable outputs, model drift, inappropriate autonomy, prompt manipulation, third-party model changes, and limitations in model transparency.
- Establish objective performance criteria early. Manufacturers should consider how competency, benchmarking, and acceptance criteria can be defined in measurable terms before beginning formal validation.
- Design postmarket monitoring before commercialization. Performance monitoring should not be treated as an afterthought. Manufacturers should consider how they will detect model drift, changing performance, new failure modes, and emerging real-world risks.
- Strengthen controls over third-party foundation models. Supplier agreements should address model updates, notice of changes, access to validation information, cybersecurity, version control, incident reporting, and other information necessary to maintain device compliance.
- Consider whether a PCCP may be appropriate. Manufacturers expecting regular changes to an AI-enabled function should assess whether anticipated modifications can be incorporated into a Predetermined Change Control Plan.
- Document human oversight. For systems providing clinical recommendations or taking actions, manufacturers should clearly define when human intervention is required and how the device communicates uncertainty or defers appropriately.
- Engage FDA early. For novel GenAI-enabled devices, a Pre-Submission may be valuable to obtain FDA feedback on risk classification, validation methodology, clinical evidence, change-control strategy, and postmarket monitoring before significant development resources are committed.
Industry Has an Opportunity to Shape FDA’s Approach
The discussion paper is notable not only for the concepts FDA is considering, but also because the agency is requesting stakeholder input before establishing formal regulatory expectations. FDA has posed 26 questions spanning risk classification, benchmarking, clinical confirmation, postmarket monitoring, PCCPs, third-party foundation models, and agentic AI. Medical device manufacturers, software developers, healthcare organizations, and other stakeholders therefore have an opportunity to influence how FDA approaches one of the most consequential emerging areas of medical device regulation.
Comments may be submitted under Docket No. FDA-2026-N-7874 through October 19, 2026.
Key Takeaway
FDA’s discussion paper does not establish new requirements for GenAI-enabled medical devices, but it does provide an unusually detailed view of how CDRH is thinking about their future regulation.
The emerging framework is likely to remain risk-based and grounded in FDA’s total product life cycle approach. At the same time, GenAI may require manufacturers to rethink conventional approaches to validation, change control, supplier oversight, and postmarket surveillance.
The most significant message for manufacturers is that demonstrating acceptable performance at the time of submission may not be sufficient. For GenAI-enabled devices that generate variable outputs, depend on evolving foundation models, or act with increasing autonomy, manufacturers may need to demonstrate that the device can remain safe and effective throughout its lifecycle.
How Gardner Law Can Help
Gardner Law advises medical device and digital health companies on FDA regulation of software, artificial intelligence, quality systems, risk management, and premarket submissions. We can help manufacturers evaluate whether AI-enabled functionality is regulated as a medical device, develop regulatory and validation strategies for novel AI technologies, prepare Pre-Submissions and marketing applications, structure Predetermined Change Control Plans, and develop quality and postmarket controls for evolving AI systems. We can also assist companies interested in submitting comments to FDA on the GenAI discussion paper.