A continuaciónSiguiente guía
Regulación de la IA
sociedad
GUÍA de industrias
In the United States, AI software that diagnoses, treats, or informs care for a patient is usually regulated by the FDA as a medical device.
It reaches the market through one of three main routes: 510(k) clearance, De Novo classification, or premarket approval (PMA). This matters because it decides what evidence a developer must produce, how an AI model can be updated after launch, and how much doctors and patients can trust the tool.
The FDA regulates software by its intended use, not by the technology inside it. If software is meant to diagnose, treat, prevent, or mitigate disease, it is generally a device; standalone software of this kind is called Software as a Medical Device (SaMD). Devices fall into Class I, II, or III by risk, and the class largely sets the pathway. Most AI-enabled devices reach the market through 510(k) clearance, in which the manufacturer shows substantial equivalence to a legally marketed "predicate" device. When a novel device is low to moderate risk and has no predicate, the De Novo pathway creates a new classification that later devices can use as a predicate. Premarket approval (PMA), the strictest route, is reserved for high-risk Class III devices and usually requires clinical evidence. The FDA's public list of authorized AI-enabled devices now runs to more than a thousand products, most of them in radiology. Not all health software is a device. The 21st Century Cures Act (2016) excludes certain clinical decision support tools. To qualify, the tool must show clinicians the basis for its recommendations so they can review them independently, and it must not analyze medical images or signals. Traditionally, a significant change to a cleared device needs a new submission. The Food and Drug Omnibus Reform Act of 2022 gave the FDA authority to approve predetermined change control plans (PCCPs), and the FDA finalized guidance for AI-enabled devices in December 2024. A PCCP lets a manufacturer make specified, pre-validated changes without filing again. A common misconception is that cleared AI devices learn on their own in the field. Most authorized models are "locked": they change only through controlled, versioned updates. In the EU, the Medical Device Regulation (MDR) classifies software under Rule 11, which puts most diagnostic software in Class IIa or higher and so requires notified body review. The EU AI Act adds high-risk AI obligations for these devices, phasing in later than most of the Act.
El contexto de la industria determina si las ideas de IA sobreviven al contacto con la realidad.
Las restricciones de dominio influyen en las tasas de error aceptables y en los modelos de supervisión.
Las implementaciones exitosas alinean la capacidad técnica con los flujos de trabajo de primera línea.
The main open question is generative AI. Large language models produce open-ended output that is hard to validate the way a fixed classifier is validated. The FDA's Digital Health Advisory Committee held its first meeting on generative AI-enabled devices in November 2024. Expect more attention to monitoring real-world performance after deployment, to transparency about training data, and to greater use of PCCPs as manufacturers learn what the FDA will accept. In Europe, companies face overlapping MDR and AI Act requirements. Guidance on how the two fit together, and whether notified bodies have enough capacity, will shape how quickly AI devices reach patients there.
A radiology startup builds software that flags suspected brain bleeds on CT scans and moves them up the reading queue. It gets 510(k) clearance by showing substantial equivalence to a triage tool that is already cleared.
IDx-DR (now LumineticsCore) detects diabetic retinopathy in retinal photos without a specialist reading the image. There was no predicate device, so the FDA authorized it through the De Novo pathway in 2018.
A maker of ECG analysis software submits a predetermined change control plan (PCCP) with its application. The plan describes how the company will retrain the model on new data and what tests each update must pass, so those updates do not each need a new submission.
A company selling the same imaging AI in Europe must get a CE mark under the EU Medical Device Regulation through a notified body. It must also prepare for the EU AI Act, which treats such products as high-risk AI systems.
Los requisitos reglamentarios pueden invalidar prototipos que de otro modo serían sólidos.
Los datos históricos pueden codificar sesgos que perjudican a comunidades específicas.
Los sistemas heredados pueden crear cuellos de botella en la integración y costos ocultos.
Involucrar a expertos en el campo desde la formulación del problema hasta la evaluación.
Diseñar pistas de auditoría y documentación antes del lanzamiento.
Valide anticipadamente las obligaciones de cumplimiento y seguridad.
Implementación en fases con criterios claros de parada y reversión.
Free newsletter
Three verified AI stories every weekday morning, written in plain English. Free forever, no ads.
One email each weekday. Unsubscribe in one click. We never sell or share your address.
Test yourself
Instant feedback on every answer, and a shareable certificate with a verifiable ID once you pass a course.
Support free AI education. AI Understanding is a 501(c)(3) nonprofit — no ads, no paywall, ever. Make a donation
In the United States, AI software that diagnoses, treats, or informs care for a patient is usually regulated by the FDA as a medical device. It reaches the market through one of three main routes: 510(k) clearance, De Novo classification, or premarket approval (PMA). This matters because it decides what evidence a developer must produce, how an AI model can be updated after launch, and how much doctors and patients can trust the tool.
A 510(k) rests on substantial equivalence to an existing predicate. Most AI-enabled devices reach the market this way.
De Novo is for novel low-to-moderate-risk devices with no predicate. Once a device is authorized this way, later devices can use it as a predicate.
A PCCP authorizes planned changes, such as retraining, in advance, along with the protocol used to validate them. Changes outside the plan still need a new submission.
A PCCP describes the planned changes, sets out how they will be developed and validated, and assesses their benefits and risks.
Most authorized AI models are locked. Updates come as controlled versions, and radiology, not dermatology, accounts for most authorized AI devices.
sigue aprendiendo
Más guías seleccionadas para este tema.
A continuaciónSiguiente guía
Regulación de la IA
sociedad