
AI Medical Devices Keep Changing After Clearance. The FDA Is Asking the Public How to Regulate That.
The FDA's Digital Health Center of Excellence published a discussion paper saying its approval framework for AI-enabled devices was built for software that stops changing, and public comment on the replacement closes October 19, 2026.
Key Takeways
- The FDA's Digital Health Center of Excellence opened public comment on August 18, 2026 on how to regulate generative AI medical devices, with docket FDA-2026-N-7874 closing October 19, 2026.
- The FDA's existing tool for AI-enabled devices, the predetermined change control plan, assumes a model's behavior is fixed at clearance, which the discussion paper says generative AI does not do.
- The FDA proposes competency-based premarket evaluation modeled on medical training, plus postmarket monitoring scaled to risk: periodic benchmarking, sample-based clinician review, and performance-degradation tracking.
- Health systems, hospital AI governance leads, and clinicians can shape this framework directly by filing comments on docket FDA-2026-N-7874 before October 19, 2026.
The version of an AI medical device running in a clinic may not be the version the FDA reviewed. A vendor can update the model long after clearance, and nothing in the current approval framework was designed for that. On August 18, 2026, the FDA put that problem in writing. Its Digital Health Center of Excellence, part of the Center for Devices and Radiological Health, released a discussion paper on how to regulate generative AI medical devices. The paper's starting premise is that the agency's current approach was designed for software that stops changing.
That approach has a name: the predetermined change control plan. It was built for traditional machine-learning models. Those models get locked, validated once, and then updated only in ways the manufacturer specified in advance. The plan holds because everyone knows what the device will do tomorrow. Foundation models behave differently. A vendor can retrain or replace one after deployment. Outputs can drift on their own, in directions the original clearance never contemplated.
The FDA could have stretched the older plan over the new technology and called the matter closed. It went the harder way. This is a discussion paper, so the agency is thinking in public before it writes anything binding, and it carries more than 26 questions addressed to people outside the building. Public comment is open on docket FDA-2026-N-7874 at Regulations.gov through October 19, 2026.
By inviting input from the public, we are launching a transparent process to inform the development of an approach.
That is CDRH Director Michelle Tarver, in the agency's own announcement. Acting FDA Commissioner Kyle Diamantas put the stakes around leadership: "Artificial intelligence is transforming medicine, and the United States must lead in shaping how this technology is developed and used safely and responsibly." Rick Abramson directs the Digital Health Center of Excellence. He described the paper as a way to propel "a critical conversation about how to enable beneficial innovation." Three officials, one message: the answer is still being written, and they would like help.
What the FDA put on the table
The paper sketches three moving parts. The first sorts risk on two axes. One axis is how much the generative AI is actually doing, from non-directive support up to fully autonomous action. The other is how severe the consequence would be if an output were wrong. The shape will be familiar to anyone who works with ISO 14971, which already pairs probability of harm with severity of harm.
The second part borrows from how medicine trains its own people. Before a device reaches patients, it would face non-clinical benchmarking against reusable tests and datasets. Clinical confirmation would follow, through retrospective evaluation, shadow deployment, standardized patient interactions, clinician adjudication, or a prospective study. Competency, demonstrated, on the record. Physicians have been evaluated this way for a century. The paper asks whether the same logic can travel to the software sitting beside them.
The review cycle has to move as fast as the model
The third part is where this stops being a paperwork exercise. The FDA proposes postmarket monitoring scaled to risk: periodic benchmarking, sample-based clinician review, and watching for performance degradation over time. Read that as a standing job. Someone has to keep deciding whether the model is still right, on a system that keeps moving underneath them.
Watch any doctor turn a screen toward a patient and read out what the software suggests. Neither of them asks which version of the model produced that recommendation, or when it last changed. The patient assumes it was checked. The clinician assumes the same. Postmarket monitoring is the machinery that makes both assumptions true. The agency is asking now who should run it and how often.
This is the half-life of skills showing up on a hospital's compliance calendar. A clinician who learns one model's failure modes in 2026 is reviewing a materially different model by 2028. The judgment that made her good at that review has to be rebuilt on the new version. Institutions are designed to certify a person once and trust the certificate for years. The FDA's proposal puts a much shorter clock on that.
Where outside expertise can land right now
One legal analysis of the paper read it as the FDA being willing to accept greater premarket uncertainty in exchange for stronger postmarket monitoring. That is a real shift for an agency whose device work has leaned heavily on the front end. The same analysis observed that the device center has been reluctant to make that trade in other categories, so whether it holds here stays open. What is already settled is the timing. The question is being asked while the technology is still moving, with a date attached and a docket number.
The design problem underneath it runs through most current AI governance work: the thing being governed changes faster than the cycle built to govern it. It ran through the argument over who should be able to switch off a frontier AI system. It came up again when a frontier model crossed a cybersecurity capability threshold and the oversight had to be built while the capability was already live. Medicine is the highest-stakes version of the same problem, and the FDA has put it on the record.
I advise the California State University system on AI governance. The same question turns up there in plainer clothes: who rechecks the tool after it is approved, and how often. Anyone carrying that question inside a health system can answer it for the record before October 19. A hospital that has already run a shadow deployment knows what sample-based clinician review costs in staff hours. An AI governance lead knows which kinds of drift their team can actually detect. That is precisely the material the agency asked for. It counts for more filed on docket FDA-2026-N-7874 now than raised as an objection after the framework is written.
The comment period closes October 19, 2026. Whatever gets drafted afterward will be built from the evidence that made it onto the record. So here is the question worth carrying into your next clinical governance meeting: when the model behind one of your tools changes next quarter, who finds out, and how long does it take them?
How do I submit a comment to the FDA about AI medical devices?
Comments go to docket FDA-2026-N-7874 on Regulations.gov. Anyone can file one, without a lawyer or a formal affiliation. The discussion paper poses more than 26 specific questions, and a comment answering one of them with concrete operating detail carries further than general commentary. Everything filed becomes part of the public record the agency draws on when it drafts a real framework.
Does this proposal apply to AI scribes and other hospital software that is not a diagnostic device?
The discussion paper addresses generative AI-enabled medical devices, which sit under the Center for Devices and Radiological Health. Software that falls outside the definition of a medical device also falls outside this proposal. Where that line lands for newer tools is part of what the paper's open questions on foundation models and agentic AI systems are meant to surface. That is a reason for any hospital running such tools to read the docket rather than assume it stops short of them.
Does this change anything for AI devices the FDA has already cleared?
Nothing changes today. A discussion paper carries no binding requirement. A device already authorized under a predetermined change control plan keeps operating under the terms of that plan. For a health system already running cleared AI tools, the comment period is a chance to describe what monitoring actually costs in staff hours, since that evidence is what any future requirement gets built against.
Here is what makes Alex a credible voice on this topic: Alex advises the California State University system on AI governance, where the question the FDA is now putting to the public already comes up in plainer form: who rechecks an AI tool after it is approved, and how often.
If your institution is deciding what to put on the record before October 19, book a conversation →
