The FDA's blueprint for AI medical devices: what a maker must show, cradle to grave
A January 2025 draft guidance lays out the documentation the agency expects across an AI device's whole life, including bias checks across demographic groups and postmarket monitoring. It is not yet binding.
In January 2025 the US Food and Drug Administration published a draft guidance setting out, in one document, the evidence and documentation it expects a company to provide for a medical device that contains artificial intelligence — from how the model is designed and built through to how its performance is watched after it goes on sale [s1]. It is the agency's most comprehensive attempt yet to define what an AI device maker must show to prove the product is safe and effective and stays that way, and it remains a draft: not final, and not binding on anyone [s1].
What the guidance covers
The document is titled "Artificial Intelligence-Enabled Device Software Functions: Lifecycle Management and Marketing Submission Recommendations," and it applies to the AI-enabled software functions inside a device [s1]. Its organising idea is the total product lifecycle, or TPLC — the principle that an AI device should be managed as something that continues to change and must be monitored, not a fixed object certified once and forgotten [s1]. The recommendations span design, development and implementation, the contents of the marketing submission itself, and performance after the device is deployed [s1].
Its reach is unusually broad within the agency: it was issued jointly by the centres for devices, biologics and drugs, reflecting that AI now appears in products regulated across all three [s1]. It builds on earlier FDA work, including the guiding principles for good machine learning practice and for transparency of machine-learning-enabled devices [s1].
The parts that go beyond box-ticking
Two elements are worth singling out because they ask for things the current market does not reliably provide.
The first is bias and transparency. The draft says that, when finalised, it will include the FDA's thinking on collecting evidence to evaluate whether a device benefits all relevant demographic groups — it names race, ethnicity, sex and age — similarly [s1]. That is a request to show a device works across the population it will be used on, not only on the average patient in the training data, and it is meant to be built in from the earliest stages of development through to a device's decommissioning [s1]. To convey how a device behaves to the people using it, the guidance proposes an example "model card," a short standardised description of what a model does and where it applies [s1].
The second is postmarket performance monitoring [s1]. An AI model can degrade silently as the patients, scanners or clinical practices it meets drift away from the data it was trained on. The draft proposes recommendations addressing performance in the postmarket setting, and specifically asks for comment on using a performance monitoring plan as a means of risk mitigation [s1]. That reframes an AI device as something requiring ongoing surveillance rather than a one-time approval.
How it fits with the change-control rule
The lifecycle draft is one half of a pair. Six weeks earlier, in December 2024, the FDA finalised a separate guidance on the Predetermined Change Control Plan, or PCCP [s2]. A PCCP lets a manufacturer specify in advance the modifications it intends to make to an AI device and the methods it will use to implement and validate them, so that those pre-agreed changes can be made after clearance without a fresh marketing submission each time [s2].
Read together, the two documents are the scaffolding of the FDA's lifecycle approach: the PCCP guidance, now final, governs how an AI device may be updated after it is cleared, and the lifecycle draft governs what the original submission should contain in the first place [s1][s2]. The site's coverage of the predetermined change control plan sets out that final piece in more detail.
What it is, and is not
A guidance is not a regulation. The FDA's own notice states the draft, when finalised, will represent the agency's current thinking, does not establish any rights for any person, and is not binding on the FDA or the public, and that an alternative approach is acceptable if it meets the applicable statutes and regulations [s1]. It went out for public comment, which closed on 7 April 2025, and had not been finalised at the time of writing [s1]. So the specifics above describe where the agency is heading, not a rule already in force.
There is also a candid signal buried in the FDA's request for comment: it asks whether the recommended documentation is adequate for devices that use emerging technology such as generative AI [s1]. That the agency is asking the question is a reminder that the framework is being built around a technology still moving faster than the paperwork meant to govern it.
What to watch
Whether the guidance is finalised, and whether the demographic-performance and postmarket-monitoring expectations survive into the final text or are softened. How the FDA adapts the framework for generative AI, which its own consultation flags as an open problem. And whether, once finalised, these recommendations change what actually appears in submissions — because guidance shapes practice only to the extent that reviewers ask for it and companies supply it.
Sources
- [s1] Artificial Intelligence-Enabled Device Software Functions: Lifecycle Management and Marketing Submission Recommendations; Draft Guidance; Availability. Federal Register (FDA), 7 January 2025. https://www.federalregister.gov/documents/2025/01/07/2024-31543/artificial-intelligence-enabled-device-software-functions-lifecycle-management-and-marketing
- [s2] Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions; Final Guidance; Availability. Federal Register (FDA), 4 December 2024. https://www.federalregister.gov/documents/2024/12/04/2024-28361/marketing-submission-recommendations-for-a-predetermined-change-control-plan-for-artificial
Sources
- Artificial Intelligence-Enabled Device Software Functions: Lifecycle Management and Marketing Submission Recommendations; Draft Guidance for Industry and FDA Staff; Availability — Federal Register (U.S. Food and Drug Administration) , January 7, 2025
- Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions; Final Guidance; Availability — Federal Register (U.S. Food and Drug Administration) , December 4, 2024
How the FDA lets an AI device update itself without a new clearance
A predetermined change control plan is the FDA's answer to a model that keeps learning: pre-approve a bounded set of future changes, and the manufacturer can ship them without returning for a fresh review.
New US rules make certified health records reveal how their AI was built
A federal rule now requires certified electronic health records to publish a standard set of facts about each predictive algorithm they ship, including how it was validated and whether it was tested for fairness.
The EU AI Act makes most medical AI 'high-risk.' The hard part starts in 2027
Under Article 6, AI that is or sits inside a device already needing an independent safety check counts as high-risk. A 70-study review finds the trouble is overlap with existing device law.
The 'digital pill' that reports when you swallow it, and what it can't prove
Abilify MyCite embeds a sensor in an antipsychotic tablet to log each dose to an app. Nearly a decade on, its own FDA label still says it has not been shown to improve whether patients take their medicine.