Anjali Patel
Associate Editor
Loyola University Chicago School of Law, JD 2028
Imagine a patient suffering from sporadic unconsciousness is hooked up to a heart monitor. Suddenly, an irregular heart rhythm begins but is flagged almost instantaneously. The irregularity was not spotted by a cardiologist analyzing an EKG but rather by AI trained on millions of other heartbeats. That’s not a scene from the future. It’s already routine.
The FDA has authorized the marketing of over 1,500 AI-enabled medical devices in the United States. The first one dates back to 1995, but the number of devices has sharply increased since then and continues to do so. However, the main caveat for AI devices is that their software can change after authorization, but the FDA’s monitoring of those changes doesn’t. In light of this, the FDA needs stricter and more continuous regulation of AI-enabled medical devices.
Built for pacemakers, not algorithms
The FDA’s approval system is built around products, such as pacemakers, implants, or drugs. These products are checked thoroughly and approved by regulators before entering the market; thereafter, the product is meant to stay as is. AI doesn’t fit that mold.
The FDA sorts medical devices into three classes based on risk level: Class I—low risk, Class II—moderate risk, and Class III—high risk. Most AI devices land in Class II. Devices in this class are usually subject to premarket review under section 510(k) of the Federal Food, Drug, and Cosmetic Act. Instead of proving safety and effectiveness from ground zero, as high-risk Class III devices generally have to, manufacturers only have to show that their device is substantially equivalent to a device already on the market. Once proven, the FDA clears the device for sale, which is generally a faster and cheaper process than a full premarket approval.
Over the years, the FDA has tried to modernize its approach by allowing companies to submit predetermined change control plans, which describe how their AI devices might change over time. Congress has also taken notice. In its FY2026 appropriations, it required the FDA to assess its existing authorities and report back within 90 days on the statutory changes needed to oversee post-deployment performance of AI devices.
The FDA has since published a discussion paper and request for feedback on regulating generative AI-enabled devices. The paper touches on how the FDA’s Center for Devices and Radiological Health (CDRH) has recognized these challenges. The CDRH believes that to ensure the continued safety and effectiveness of generative AI devices, it might be necessary for premarket evidence to be complemented by postmarket results, meaning checking in on how devices work not just before they hit the market but after as well. In line with this, the CDRH’s discussion paper suggests possible postmarket approaches for generative AI devices, such as periodic re-benchmarking and sample-based clinician review, which would work like regular check-ins after a device reaches the market.
Oversight beyond the first green light
The FDA’s current regulatory approach falls short. As it stands, the FDA has not authorized any generative AI device for marketing. It has, however, granted a breakthrough device designation to RecovryAI for its patient-facing clinical AI chatbot tool designed to help patients in post-operative recovery. This is a notable step forward for AI, though a designation is not an authorization. Devices such as this present an array of risks: they can hallucinate, perform worse in real-world use than in testing, and operate with uncertain limits on what they are meant to be used for. Having AI complete simple tasks or answer routine recovery questions is one thing, but having it handle complex medical cases and diagnoses would be something entirely different.
Undoubtedly, there are many opinions on how to address this problem. Some say the FDA should adopt new regulations, requiring that AI devices be monitored well after initial authorization. Others say the current parameters work as is. Additionally, some industry groups want the FDA to use existing standards and a risk-based approach rather than instituting new postmarket monitoring standards.
Regardless of whether new statutory changes are required in the current model, something needs to change to address the unprecedented regulatory complication that accompanies AI devices. Without a shift, it is likely the current process will fail to properly screen devices. The FDA must set up a strong and continuous regulatory framework that includes mandatory postmarket monitoring protocols for technology the industry can only anticipate.