FDA Evaluation of AI-Enabled Medical Devices

Blog |

Artificial intelligence is changing how medical devices detect disease, analyze images, support decisions, and monitor patients. Manufacturers must show that these products are safe, effective, and reliable for their intended users and populations.

FDA evaluation of AI medical devices extends beyond overall accuracy. Reviewers may examine intended use, model architecture, data, subgroup performance, human factors, cybersecurity, labeling, and lifecycle plans.

This guide provides a practical regulatory roadmap and submission checklist for companies developing AI-enabled medical devices.

What Is an AI-Enabled Medical Device?

Artificial intelligence broadly refers to systems that perform tasks commonly associated with human intelligence. Machine learning uses data to identify patterns and generate outputs. Supervised learning uses labeled examples; unsupervised learning identifies patterns without predefined labels.

An AI-enabled function may be “locked,” meaning its behavior does not change after release, or designed for controlled modifications. AI can appear in Software as a Medical Device (SaMD), embedded software, or a hybrid system.

First determine whether the software function meets the definition of a medical device. Some low-risk functions may fall outside FDA oversight or within enforcement discretion, but that conclusion requires a product-specific analysis.

Which FDA Pathway Applies?

AI-enabled medical devices use the same principal pathways as other medical devices:

  • 510(k): The manufacturer demonstrates substantial equivalence to a legally marketed predicate device.
  • De Novo: The product is a novel, low- or moderate-risk device without a suitable predicate.
  • Premarket Approval: A higher-risk Class III device requires evidence supporting reasonable assurance of safety and effectiveness.

Identify the likely classification, product code, predicates, and evidence requirements early. A Q-Submission can obtain FDA feedback on the pathway, testing strategy, clinical protocol, or Predetermined Change Control Plan (PCCP).

FDA maintains a list of AI-enabled devices authorized in the United States. They are not all “FDA-approved”: 510(k) devices are cleared, De Novo devices are granted, and PMA devices are approved. Radiology represents a substantial portion, with other products spanning cardiovascular, neurology, and additional specialties.

What Evidence Does FDA Evaluate?

A strong submission begins with precise intended use and indications for use. Explain the model's inputs, outputs, users, population, environment, clinical role, and limitations.

Dataset documentation should identify provenance, collection methods, selection criteria, reference standards, sample size, and demographic and clinical characteristics. Training, tuning, and test datasets should be separated to reduce leakage.

Report clinically justified performance metrics with confidence intervals and prespecified acceptance criteria. Evaluate relevant subgroups and investigate differences that could create bias or reduce performance.

Depending on the device's intended use, risk, and available evidence, external or multicenter validation may help demonstrate that the model generalizes beyond its development environment. Study design and analysis should reflect the intended use, not simply the model's best technical performance.

FDA's Total Product Lifecycle Approach

FDA's January 2025 draft guidance proposes a Total Product Life Cycle approach. Although not for implementation, it shows FDA's thinking on risk management across design, submission, deployment, monitoring, and modification.

Good Machine Learning Practice emphasizes representative datasets, independent testing, fit-for-purpose reference standards, the human-AI team, clear user information, reproducible training records, and ongoing monitoring.

Transparency should cover clinical workflow, expected performance, limitations, potential biases, and when users should not rely on an output. A model card may organize this information but does not replace labeling or submission documentation.

When Should a PCCP Be Included?

A PCCP proposes specific future modifications for review with the original submission. If authorized, covered modifications may be implemented without a new submission for each change.

FDA's final PCCP guidance recommends three core sections:

  • A description of the planned modifications
  • A modification protocol describing how changes will be developed, verified, validated, and implemented
  • An impact assessment evaluating benefits, risks, and risk controls

The PCCP should be focused and bounded, defining metrics, acceptance criteria, data requirements, version control, monitoring, and rollback. It is not open-ended permission for unspecified changes.

Cybersecurity and Postmarket Monitoring

AI devices may introduce risks involving model files, data pipelines, cloud services, interfaces, and dependencies. Connect AI threat modeling with cybersecurity risk assessment, testing, updates, and the Software Bill of Materials (SBOM) where applicable.

Postmarket plans should identify performance metrics, data sources, review frequency, drift thresholds, complaint inputs, escalation criteria, and corrective actions. Changes in populations, clinical practice, hardware, data quality, or workflow may affect performance.

Common FDA Submission Gaps

AI submissions often encounter problems when:

  • Dataset demographics or provenance are incomplete.
  • The test set is not independent or representative.
  • External validation is absent without justification.
  • Subgroup performance and bias are inadequately assessed.
  • Requirements, risks, testing, and results are not traceable.
  • Labeling does not explain limitations or user responsibilities.
  • Cybersecurity or SBOM documentation is incomplete.
  • A proposed PCCP is too broad or lacks measurable controls.

Use searchable files, performance tables, architecture diagrams, and a traceability matrix linking requirements and risks to verification and validation evidence.

AI-Enabled Medical Device Submission Checklist

Before submission, confirm that the team has:

  • Selected and documented the regulatory pathway
  • Defined intended use, users, population, workflow, and limitations
  • Documented training, tuning, and test data
  • Justified metrics, statistical methods, and acceptance criteria
  • Evaluated performance across relevant subgroups
  • Completed software, risk, human-factors, and cybersecurity documentation
  • Developed transparent labeling and user information
  • Evaluated whether a PCCP is appropriate for specific anticipated modifications
  • Established a risk-appropriate postmarket performance-monitoring plan

Healthcare workforce predictions fall outside FDA device review. FDA evaluates regulated products and how people use them; it does not predict which jobs will “survive AI.”

How Quality Commercial Consultants Can Help

Quality Commercial Consultants helps sponsors of AI/ML-enabled medical devices translate technical artifacts into clear, submission-ready documentation. QCC supports AI/ML feature descriptions, dataset summaries, performance and robustness evidence, risk-based narratives, traceability documentation, cybersecurity evidence, and regulatory gap analyses.

Contact Us Today

We provide clear regulatory guidance that meets you where you are today. Contact our team to discuss your AI-enabled medical device, submission timeline, and current documentation.

Contact Us Today

We provide clear regulatory guidance that meets you where you are today.