FDA Floats Competency-Based Regulatory Path for Generative AI Devices
核心洞察
CDRH (搜索) released an August 18, 2026 discussion paper proposing new approaches to regulating generative AI-enabled medical devices (搜索), with stakeholder comments due by October 19, 2026.
The paper proposes a two-axis risk framework plotting degree of device activity against severity of consequences from an incorrect output.
CDRH (搜索) also outlines a competency-based premarket model combining device benchmarking with clinical confirmation, plus postmarket monitoring and voluntary Foundation Model Master Files.
The FDA's Center for Devices and Radiological Health (CDRH (搜索)) released a discussion paper on August 18, 2026 proposing new approaches to regulating medical devices enabled by generative artificial intelligence, and is requesting stakeholder feedback by October 19, 2026. The paper is not guidance, but it sets out how the agency is thinking about the risks and evidentiary challenges these devices pose, following a November 2024 Digital Health Advisory Committee meeting at which CDRH identified challenges in applying a risk-based classification approach and in determining valid scientific evidence across the total product life cycle.
The first proposal is a two-axis risk framework, with the horizontal axis representing the degree and independence of a device's activity and the vertical axis representing the severity of consequences if a user relies on an incorrect output. CDRH (搜索) suggests several factors that would shift a function's risk classification, including genAI-enabled in vitro diagnostic, measurement and signal processing functions, whose outputs a user typically cannot independently assess, and patient-facing informational functions, which the agency proposes to treat as higher risk than the same functions delivered to healthcare professionals. CDRH also flags action-directing versus action-taking functions, generalist versus specialist-facing functions, multi-turn conversations that migrate from informational to action-directing, and care escalation functions, and asks stakeholders to refine those distinctions.
For premarket evaluation, CDRH (搜索) is considering a two-part competency-based model, since testing across a representative sample of inputs and outputs is unlikely to be practical for genAI devices. Device benchmarking would be a scalable nonclinical evaluation of competencies including safety, clinical proficiency, generalizability and agentic-specific capabilities, followed by clinical confirmation that could range from retrospective evaluation on real patient data to prospective studies or randomized controlled trials, with scope and rigor scaled to the device's position on the risk framework. The paper also discusses postmarket monitoring through periodic benchmarking, sample-based clinician review by independent adjudicators, and performance degradation monitoring, and asks whether machine-based supervisory agents could support oversight. CDRH additionally seeks feedback on voluntary Foundation Model Master Files, under which foundation model developers could confidentially submit model information to FDA for reference by device sponsors, without that submission constituting authorization of the model for any intended use.
Commenters to date have argued the risk framework should add considerations such as detectability, reversibility and traceability of incorrect outputs, and cautioned that postmarket monitoring is not an adequate substitute for premarket evidence where harm may be severe, fast-acting or irreversible. Others questioned the feasibility of Foundation Model MAFs given that some models are updated hundreds of times a day. CDRH (搜索) has not proposed new regulatory policy at this stage, but notes that discussion papers have historically foreshadowed its regulatory direction.
Source: Cooley
