FDA sets up a class II category for AI software that flags heart-disease risk
A final order files AI tools that flag possible cardiovascular disease as class II with special controls, letting similar triage software clear via 510(k). The controls require real-world, subgroup-tested validation.
The US Food and Drug Administration has created a formal device category for artificial-intelligence software that flags a person's likely risk of a cardiovascular disease, classifying it as class II — the middle of the agency's three risk tiers — with a set of mandatory "special controls" [s1]. The practical effect of the final order, published in the Federal Register on 11 September 2026 and codified at 21 CFR 870.2380, is that future tools of this type can reach the market through the lighter 510(k) pathway rather than a case-by-case review, provided they meet validation rules aimed squarely at accuracy and bias [s1].
What the device is
The new generic type is named "cardiovascular machine learning-based notification software," and the order defines it narrowly [s1]. It is software that uses machine-learning techniques to suggest the likelihood of a single cardiovascular disease or condition, based on one or more non-invasive physiological inputs, as part of routine medical care [s1]. Its output is a prompt for further referral or diagnostic follow-up — it is "intended as the basis for further testing and is not intended to provide diagnostic quality output," and it is explicitly not intended to identify or detect arrhythmias [s1].
In plain terms, this is a triage-and-notification tool: something that reads a routine measurement and raises a hand to say a patient may warrant a closer look. It is not meant to make the diagnosis itself. That boundary is what places it in class II rather than the top-risk class III.
Why the classification matters
The mechanics here are the story. FDA can regulate a genuinely novel device through "De Novo" classification under section 513(f)(2) of the Food, Drug, and Cosmetic Act — a route for low-to-moderate-risk devices that have no existing equivalent [s1]. The classification underlying this order was in fact made applicable on 3 August 2023; the final order now writes that decision into the regulations for the whole device type [s1].
Once a device type is classified and its special controls are codified, later devices of the same type no longer need their own De Novo review. They can instead file a 510(k) premarket notification, demonstrating they are substantially equivalent to the established type and that they meet the special controls. FDA states the aim directly: the action "will provide a reasonable assurance of the safety and effectiveness of the device" and "will also enhance patients' access to beneficial innovative devices, in part by reducing regulatory burdens" [s1]. This is the agency building a paved road for a class of AI product it expects to see more of.
The safeguards attached
The special controls are where the order tries to keep the lighter pathway from becoming a lax one. Clinical performance testing must show the device works as intended under anticipated conditions of use, validated on a test dataset of real-world data drawn from a representative patient population [s1]. That test data must be independent of the data used to train or develop the model — a guard against the familiar failure of an AI system that looks accurate only because it is being graded on material it has already seen [s1].
Two requirements target bias directly. The validation dataset must contain enough cases from important cohorts — demographic groups, subsets defined by clinically relevant confounders and comorbidities, and subsets defined by the hardware and acquisition characteristics of the input — that the device's performance estimates and confidence intervals can be assessed for those subgroups, not just on average [s1]. The order lists the risks it is designed to mitigate, including a false positive or false negative leading to incorrect treatment or diagnosis, and incorrect results arising from model bias, with clinical and non-clinical testing and labelling as the mitigations [s1].
The gap it does not close
Special controls set what a manufacturer must demonstrate to enter the market; they do not, by themselves, track how these tools perform once deployed at scale. That post-market blind spot is a documented problem for digital devices generally. An analysis of two decades of FDA authorisations found that the number of authorised devices with digital components has grown substantially, with wide variation across clinical specialties — and that US data systems are not built to systematically identify which authorised devices even contain software, limiting regulators' ability to fold software-specific concerns into ongoing surveillance [s2].
For AI diagnostics specifically, the recurring criticism has been that devices clear on measures of accuracy without evidence that they change what happens to patients. That tension runs through our earlier coverage — of an FDA clearance for ECG-based AI that screens for pulmonary hypertension, of the broader gap in how AI imaging devices are tested before clearance, and of how foundation-model ECG tools are being validated. A subgroup-tested validation requirement is a meaningful step; it is not the same as proof that flagging more patients earlier improves survival or avoids harm.
What to watch
The signal to follow is how many devices now clear as 510(k)s citing this new type, and whether their validation data genuinely reflect the populations and equipment they will meet in practice. The order takes effect on 11 September 2026 under Docket No. FDA-2026-N-9907 [s1]. Whether "reducing regulatory burdens" and "reasonable assurance of safety and effectiveness" stay in balance will be judged not at clearance but in the years of use that follow it.
Sources
- [s1] Medical Devices; Cardiovascular Devices; Classification of the Cardiovascular Machine Learning-Based Notification Software, Food and Drug Administration (Federal Register), 11 September 2026. https://www.federalregister.gov/documents/2026/09/11/2026-18612/medical-devices-cardiovascular-devices-classification-of-the-cardiovascular-machine-learning-based
- [s2] Two decades of growth and trends in the FDA authorization of digital medical devices, npj Digital Medicine, 17 June 2026. https://doi.org/10.1038/s41746-026-02692-5
Sources
- Medical Devices; Cardiovascular Devices; Classification of the Cardiovascular Machine Learning-Based Notification Software — Food and Drug Administration (Federal Register) , September 11, 2026
- Two decades of growth and trends in the FDA authorization of digital medical devices — npj Digital Medicine , June 17, 2026
How the FDA lets an AI device update itself without a new clearance
A predetermined change control plan is the FDA's answer to a model that keeps learning: pre-approve a bounded set of future changes, and the manufacturer can ship them without returning for a fresh review.
The FDA's blueprint for AI medical devices: what a maker must show, cradle to grave
A January 2025 draft guidance lays out the documentation the agency expects across an AI device's whole life, including bias checks across demographic groups and postmarket monitoring. It is not yet binding.
The EU AI Act makes most medical AI 'high-risk.' The hard part starts in 2027
Under Article 6, AI that is or sits inside a device already needing an independent safety check counts as high-risk. A 70-study review finds the trouble is overlap with existing device law.
FDA opens comment on how to regulate AI medical devices that generate their own answers
A new discussion paper proposes a two-axis risk framework and a physician-training analogy for evaluating generative AI devices. It is not a rule, and the agency is asking what one should look like.