FDA Opens Docket for Input on Generative AI Medical Devices
August 21, 2026


The U.S. Food and Drug Administration is asking how it should regulate generative AI medical devices. On 18 August 2026 the agency’s Center for Devices and Radiological Health (CDRH) released a discussion paper on the topic and opened a public docket for comment. It is a request for feedback, not draft guidance.
CDRH is explicit that it is not proposing policy changes and not signalling what evidence it will expect in future marketing submissions. The agency wants early input from manufacturers, clinicians, researchers, and patients before it settles on a framework. Comments can be filed under docket FDA-2026-N-7874 on Regulations.gov until 19 October 2026.
A two-axis view of risk
The paper opens with a framework for thinking about risk, built on two axes. One tracks device activity: how independently a function directs or takes action, from non-directive information such as a cardiovascular risk score up to fully autonomous action. The other tracks consequences: the severity of harm from relying on an incorrect output. An incorrect suggestion for an over-the-counter remedy sits at the low end. An incorrect insulin dose adjustment sits far higher.
CDRH flags several factors it may treat as higher risk. Action-directing and action-taking functions, such as assigning a diagnosis or prescribing a medication, rank above plain information. Patient-facing functions may sit higher than clinician-facing ones because a patient often cannot tell when an output is wrong. Measurement and signal-processing functions also rank higher, since the user cannot independently check the basis for the result. The agency asks whether other dimensions, such as reversibility, downstream safeguards, time pressure, and traceability to source material, belong in the framework.
How generative AI medical devices would be assessed
The paper’s central proposal is a competency-based approach to premarket evaluation, inspired at a high level by how clinicians are trained and credentialed rather than by exhaustive testing of every possible input. It has two parts: non-clinical device benchmarking and clinical confirmation.
Benchmarking would test whether the device, in its deployed configuration, shows the clinical knowledge, analytic ability, safety behaviour, and generalisability needed for its intended use. CDRH groups the elements under safety (recognition of safety-critical states and escalation, scope boundaries, and calibration or uncertainty), clinical proficiency (knowledge, information gathering, quantitative analysis, and communication), generalisability (robustness and subgroup performance), and agentic capabilities.
Clinical confirmation would then check how the device performs in real or representative use. CDRH suggests a ladder of approaches in increasing rigour: retrospective evaluation on real patient inputs, shadow deployment where outputs never reach clinicians, standardised patient interactions, clinician adjudication of real cases, and prospective clinical study. A prospective trial would not be required in every case. For open-ended outputs, performance might be measured against a panel of qualified clinicians or a median clinician in practice, and against human-AI teams as well as the device working alone.
Monitoring after launch and managing change
CDRH has long favoured a total product life cycle approach to device oversight, and it leans on that here. Because these devices produce varied outputs and can keep changing after deployment, the agency is weighing whether to accept more premarket uncertainty in exchange for stronger postmarket monitoring. Possible approaches include periodic re-benchmarking against prespecified thresholds, sample-based review of real-world inputs and outputs by independent clinicians, and monitoring for performance degradation or drift.
The paper also grapples with how to handle change. Some changes are deliberate updates. Others happen as the device learns or adapts in use. Still others arrive unplanned when a third-party foundation model is updated. A Predetermined Change Control Plan could let certain changes proceed without a new premarket submission, using the premarket competency assessment as the baseline to re-check against. Independent third parties could also play a role in testing, much as the agency’s ASCA and Medical Device Development Tool programs do for conventional devices.
Foundation models and agentic AI
Many of these devices are built on third-party foundation models, which can control refusal behaviour, content policies, and safety-critical features while offering limited transparency into training data and architecture. CDRH is exploring voluntary Foundation Model Master Files, built on the existing Device Master File program, under which model developers could submit structured model cards and system cards for FDA to hold confidentially and reference in individual device submissions.
The paper separately asks about agentic AI systems, which plan and execute multi-step tasks and use external tools. These may raise additional evaluation questions beyond other generative AI devices, including how to reflect the reduced opportunity for human review in acceptance criteria.
How to respond
“Patients and clinicians deserve a regulatory approach that keeps pace with the rapid innovation of digital health technologies,” said CDRH Director Michelle Tarver, M.D., Ph.D. “By inviting input from the public, we are launching a transparent process to inform the development of an approach that safeguards patients and consumers, advances innovation, and serves as a potential model for regulators around the world.”
“Generative AI-enabled medical devices are poised to reshape the health technology landscape, and the FDA has an important responsibility to provide thoughtful leadership for this new era,” said DHCoE Director Rick Abramson, M.D. “This discussion paper advances the frontiers of regulatory science and propels a critical conversation about how to enable beneficial innovation, protect public health, and preserve trust.”
The paper poses 26 discussion questions across risk assessment, premarket evaluation, postmarket monitoring, and foundation models. Comments should be submitted under docket FDA-2026-N-7874 on Regulations.gov by 19 October 2026.
Source: FDA CDRH discussion paper
Let Google know we are your trusted source.
Add our editorial as a preferred source in your search results.
Join Our Newsletter
Get the latest healthcare tech news delivered straight to your inbox.





