FDA's Draft Guidance Reshapes AI Medical Device Safety with Focus on Model Drift, Bias, and Data Poisoning
核心洞察
The FDA's 2025 draft guidance for AI-enabled medical devices introduces a framework that acknowledges AI's evolving nature while prioritizing patient safety, transparency, and accountability.
Manufacturers must implement predetermined change-control plans addressing risks unique to AI, including model drift, bias, and data poisoning, rather than relying on static models.
Phil Englert of Health-ISAC (搜索) emphasizes that collaboration between manufacturers and healthcare providers is essential, requiring clear governance policies and staff education programs.
The Food and Drug Administration has issued a draft guidance in 2025 that fundamentally alters how regulators approach artificial intelligence-enabled medical devices, acknowledging that unlike traditional medical software, AI systems evolve over time. The framework, while non-binding, signals a paradigm shift in medical device regulation by recognizing AI's capacity for change while reinforcing safeguards around patient safety, transparency, and accountability.
Phil Englert, vice president of medical device security at the Health Information Sharing and Analysis Center (Health-ISAC (搜索)), described the guidance as a response to the inherent tension between AI's dynamic nature and the regulatory expectation that medical devices remain stable and reproducible. "A regulated medical device is meant to be stable, accurate and repeatable, right? And AI changes over time, it evolves its output, and so the FDA wanted to recognize that that's the case and put in some guidance, so that manufacturers and healthcare… understand these additional risks," Englert said.
Predetermined Change-Control Plans Replace Static Expectations
Central to the draft guidance is the requirement that manufacturers develop predetermined change-control plans rather than submitting static models for approval. These plans must support ongoing monitoring, testing, and auditability throughout the device lifecycle. The FDA identified several risks unique to AI systems that these plans must address: model drift, where algorithm performance degrades over time; bias, which can produce inequitable outcomes across patient populations; and data poisoning, a cybersecurity concern involving malicious manipulation of training data.
Englert, speaking during the HealthSec conference in Boston, predicted that the FDA will finalize the draft guidance next year. His assessment underscores the urgency with which regulators and industry stakeholders are approaching AI governance in healthcare.
Collaboration and Governance as Cornerstones
Beyond manufacturer obligations, Englert stressed that effective implementation requires close collaboration between device makers and healthcare delivery organizations. He called for healthcare providers to establish clear governance policies, maintain inventories of approved AI tools, and implement staff education programs designed to manage emerging risks while protecting sensitive patient data.
Health-ISAC (搜索) has contributed to this effort by releasing its own guidance document, "Policies and Safeguards for the Safe Use of AI," which outlines critical elements for AI governance in healthcare settings. The document complements the FDA's regulatory framework by providing operational guidance for healthcare organizations navigating the adoption of AI-enabled medical devices.
Cybersecurity and Patient-Safety Integration
The draft guidance also addresses the intersection of cybersecurity and patient safety, reflecting growing concern about vulnerabilities unique to AI systems. Data poisoning, in particular, represents a threat vector not present in conventional medical devices, requiring new approaches to risk assessment and mitigation. Englert's remarks highlighted that the FDA's approach integrates cybersecurity considerations directly into the safety and effectiveness evaluation, rather than treating them as separate domains.
With more than 30 years of technical and operational leadership experience in healthcare and life sciences, including previous roles as chief product officer for MedSec and global leader for medical device cybersecurity at Deloitte, Englert brings extensive perspective to the evolving regulatory landscape. His analysis suggests that the draft guidance represents not merely an incremental update but a foundational shift in how regulators conceptualize medical device software in the era of artificial intelligence.
