The FDA and AI-Enabled Medical Devices
A radiologist opens the worklist and sees a chest CT already flagged by an AI tool: "suspicious nodule, right upper lobe, high confidence." Next to the flag is a small line that reads "FDA cleared." It is tempting to read those two words as a promise, that this tool is safe, that it is right, that a regulator has vouched for what it just told you about this patient. It is none of those things. FDA clearance is a narrow, specific, enormously important regulatory statement, and understanding exactly what it does and does not say is the difference between using an authorized tool wisely and hiding behind a label that was never designed to carry your clinical accountability.
The FDA Regulates AI as a Device, Not as a Colleague
The first thing to internalize is a category fact that surprises many clinicians: when an AI tool makes or informs a medical claim, the US Food and Drug Administration regulates it as a medical device, in the same legal family as a pacemaker, an infusion pump, or a blood-glucose meter. Most clinical AI falls under a specific subcategory called Software as a Medical Device, or SaMD, meaning software that performs a medical function on its own without being part of a physical device. An algorithm that reads a mammogram, scores a patient's sepsis risk, or measures an ejection fraction from an echo is, in the eyes of the law, a device that happens to be made of code. This framing matters because it tells you what kind of oversight exists and, just as importantly, where that oversight stops.
By early 2026 the FDA had authorized more than 1,350 AI/ML-enabled medical devices, a number that has roughly doubled since 2022. To feel the trajectory: the running total was about 950 in August 2024 and about 1,250 by July 2025. That is not a trickle, it is a flood, and it means the AI you encounter in imaging, cardiology, pathology, and increasingly the rest of medicine is very often a formally regulated device with a paper trail behind it. Treat that number as a number to verify, not a talisman: the count grows every quarter, and the point is not the exact figure but the scale. AI in clinical care is no longer experimental at the edges; it is a large, regulated, and rapidly expanding fleet of authorized products, and you are one of its operators.
One striking pattern inside that fleet is worth knowing because it shapes what you personally will meet first. Radiology dominates, accounting for roughly 74% of the AI/ML device authorizations in 2024. There are good reasons: imaging produces clean, digital, labeled data at enormous volume, the tasks (detect, measure, triage) are well defined, and the specialty already lives inside picture archiving systems that make an algorithm easy to plug in. So if you are a radiologist, an ED physician reading your own films, or a clinician who orders and acts on imaging, you are already the front line of regulated clinical AI, whether or not anyone told you so.
It helps to make the SaMD idea concrete, because clinicians often picture "device" as a physical object with a plug and a serial number. Walk a single shift. A hospitalist opens a chest radiograph and a colored box appears over a region the algorithm calls a possible pneumothorax: that box is a device. A nurse on telemetry sees an early-warning score climb from 3 to 7 driven by a proprietary deterioration model: that score is a device. A cardiologist reviews an ECG and the machine appends "consider atrial fibrillation" from a learned classifier: that phrase is a device. None of them look like a pacemaker, yet each one is software making or informing a medical claim, and each one carries a regulatory identity, an intended use, and a paper trail. Once you start seeing the devices hiding inside your ordinary screens, the question "who is accountable for that output" stops being abstract.
The counterexample sharpens the boundary. A general-purpose large language model that a clinician pastes a history into and asks for a differential is, in most current framings, not an FDA-authorized device: it was never submitted, never given an intended use, never reviewed for a medical claim. That does not make it safer. It makes it less accountable, an unregulated tool doing device-like work with none of the paper trail. So the presence of a clearance is not the thing that makes an output trustworthy, and the absence of one is not what makes it dangerous. What the clearance gives you is a defined claim you can hold the tool to. The verification burden is the same either way.
What Clearance Actually Means: Three Pathways and One Question
Not all FDA authorizations are equal, and the pathway a device took tells you something about how much scrutiny it received. There are three you should recognize by name, because they will appear in the tool's documentation and in any serious conversation about it.
The most common is the 510(k) clearance. Here the manufacturer demonstrates that the new device is substantially equivalent to a device already legally on the market, called the predicate. The key word is equivalent, not superior and not independently proven safe from scratch. A 510(k) says, in effect, "this is close enough to something we already allowed that it can follow the same path." It is a real bar, but it is a comparative one, and the strength of the clearance is only as strong as the predicate it leans on and how honestly the comparison was made.
The second is De Novo authorization, used when a device is genuinely novel and low-to-moderate risk, with no suitable predicate to compare against. De Novo creates a new device category and a new set of controls, so a De Novo authorization generally reflects more original review than a routine 510(k). Many first-of-their-kind AI tools came through this path.
The third and most rigorous is Premarket Approval, or PMA, reserved for the highest-risk devices, typically those that sustain or support life or present a potential unreasonable risk of illness or injury. PMA demands the manufacturer affirmatively prove safety and effectiveness, usually with clinical data, and it is the closest thing to the exhaustive review a layperson imagines when they hear "FDA approved." Relatively few AI tools have taken this path, which itself tells you something about the risk tier most current clinical AI occupies. It is worth pausing on why the pathway label is useful to you at the bedside rather than a piece of regulatory trivia: it is a rough proxy for how much independent scrutiny stood behind the authorization, and therefore how much of the safety work still falls to you and your organization. A tool that squeaked through as substantially equivalent to an aging predicate has leaned on someone else's older evidence; a De Novo or PMA tool carried more of its own. Neither fact settles whether the tool works on your patients, but it tells you where to aim your questions.
The three pathways are easy to blur together, so hold them side by side. The distinction you most need is not the statutory citation but the question each one answers and, from that, how much of the safety work still lands on you.
| Pathway | The question it answers | What it leans on | What it means for you |
|---|---|---|---|
| 510(k) clearance | Is this substantially equivalent to a device already on the market? | A predicate device and the honesty of the comparison | Comparative, not proven from scratch; scrutinize the predicate chain and validate locally |
| De Novo | Is this novel, low-to-moderate risk, with no suitable predicate? | Original review that creates a new device category and controls | More original scrutiny than a routine 510(k), but still not local performance |
| PMA | Has the manufacturer affirmatively proven safety and effectiveness? | Clinical data for the highest-risk devices | The most rigorous bar, rare for AI, and still silent on your specific patients |
Notice the common thread in the last column. Whichever pathway a tool took, the review happened somewhere else, on someone else's data, before it ever met your population. The pathway tells you how much independent scrutiny stood behind the general claim. It never tells you how the tool behaves on your Tuesday.
FDA clearance answers one question: is this tool authorized for a defined intended use? It does not answer the question you actually care about at the bedside: is it right for my patient, in my workflow, today?
Hold onto that distinction, because it is the whole lesson compressed into a sentence. Whichever pathway a device took, the authorization is tied to a specific intended use: a defined task, a defined patient population, a defined kind of input data, and often a defined role (aid, triage, adjunct, not autonomous decision-maker). The clearance certifies that, for that narrow claim, the FDA saw enough evidence to allow the device on the market. It does not certify that the device is accurate on your specific patient, that it performs the same on your population as on the population it was tested on, or that it fits safely into the particular way your unit uses it. Clearance is a statement about a claim, not a guarantee about an outcome.
Reading the Intended Use Like a Contract
The intended-use statement is the most useful paragraph most clinicians never read. It is worth reading like a contract, because that is what it is: the boundary of the promise. Take a real-sounding example. A tool is cleared "to assist trained radiologists in detecting suspected large-vessel occlusions on non-contrast and CT-angiography images in adult patients, as a triage and notification aid, not for primary diagnosis." Four clauses do enormous work. "Assist trained radiologists" means the accountable reader is still in the loop. "Adult patients" means the pediatric case in front of you is outside the tested population. "CT-angiography images" means feeding it a different sequence is off-label. "Triage and notification aid, not for primary diagnosis" means if you let the absence of an alert reassure you into skipping your own read, you have used the tool in a role it was never authorized for. Every one of those clauses is a place where "FDA cleared" quietly stops applying, and none of them will announce themselves on the flashing box on your screen.
So the discipline is small and repeatable: when you meet a clinical AI tool, find its intended use and read it clause by clause, asking of each one, does my patient, my image, my role match what was authorized? Where the answer is no, you are not necessarily doing something wrong, but you are outside the tested claim, and the safety work is entirely yours.
The Predetermined Change Control Plan: How a Learning Model Stays Legal
Traditional devices do not change after they ship; a cleared infusion pump behaves the same on day one and day one thousand. AI is different, and this is where the FDA had to invent something new. Many AI models can be retrained and updated, and their behavior can shift as the manufacturer improves them or as they adapt to new data. Under the old rules, any significant change to a cleared device could require a whole new submission, which would make continuous improvement impossibly slow. So the FDA created the Predetermined Change Control Plan, or PCCP.
A PCCP lets a manufacturer pre-specify, at the time of authorization, exactly how the AI model may be updated after clearance, what kinds of changes, within what boundaries, validated by what methods, without needing a brand-new submission for each update. Think of it as a pre-approved envelope of allowed change. As long as the manufacturer stays inside that envelope and follows the plan they committed to, they can update the model and keep it current. The moment a proposed change falls outside the PCCP, something more substantial than what was pre-specified, a new regulatory review is triggered. The PCCP is genuinely clever regulation: it lets AI stay a living, improving product while keeping the changes bounded and accountable rather than silent and unlimited.
Why should a bedside clinician care about a document they will probably never read? Because it changes what "the version I validated" means. The tool your organization evaluated and trusted six months ago may have been updated, legitimately, under its PCCP, and its behavior may have shifted within the allowed envelope. This is the regulatory face of a phenomenon you will meet again as model drift: the tool you are using today is not necessarily identical to the tool that was studied in the paper you read. Knowing that a PCCP exists is knowing to ask, at the governance level, whether a given tool has changed since it was last validated locally, and whether your organization re-checks performance after updates rather than assuming the clearance carries forward untouched.
Picture how this goes wrong quietly. In March, a quality team validates a cleared deterioration model on twelve months of their own admissions and finds it performs well: it fires early enough to matter and rarely cries wolf. Everyone signs off. In September, the vendor pushes an update inside the PCCP, a legitimate retraining meant to reduce false alarms. Nobody at the hospital did anything wrong, and no new FDA submission was required, because the change stayed inside the pre-specified envelope. But the recalibration that trimmed false alarms also nudged the threshold, and on this hospital's particular case mix the model now fires a little later. No alert flashes to say "I am a different tool now." The only defense is a governance habit: treat "the vendor updated the model" as a trigger to re-check local performance, the same way you would re-check a lab analyzer after a reagent change. A PCCP is not a loophole. It is a promise that change will be bounded and documented, and it is an invitation for your side to watch the boundary.
A clearance is a snapshot. A PCCP means the tool is allowed to move inside a frame. If you never look again after the snapshot, you are trusting a picture of a thing that has since changed.
The Gap Clearance Does Not Close
Now we arrive at the heart of it, the gap between what the label promises and what you are accountable for. Picture the concrete case. A stroke-triage AI is FDA cleared to flag suspected large-vessel occlusions on CT angiography and alert the team faster. Its clearance rests on a validation dataset assembled by the manufacturer. Your hospital serves a patient population that differs from that dataset in age distribution, comorbidity mix, scanner model, and imaging protocol. The tool is fully, legitimately cleared. It is also, potentially, less accurate on your patients than on the ones it was tested on, and nothing about the clearance tells you where or how much. The FDA authorized a claim; it did not audit your Tuesday.
This is the practical meaning of the phrase local validation, which becomes a major theme later in this program. A cleared tool is a candidate, not a conclusion. A responsible organization tests an authorized AI tool on its own representative patient data before trusting it, and monitors it afterward, precisely because clearance certifies a general claim and cannot certify local performance. The clearance gets the tool through the door. Whether it performs on your patients is a separate question that only local evidence can answer, and pretending clearance settles it is one of the quieter ways AI causes harm.
There is a second, even more important gap, and it is the one this whole program keeps returning to: clearance does not transfer clinical accountability. When you act on the output of an FDA-cleared AI tool, the clinical decision is still yours. If the stroke-triage AI misses an occlusion and you do too, "the tool was FDA cleared" is not a defense to a board, a plaintiff's attorney, a patient's family, or a Joint Commission surveyor. The clearance regulates the manufacturer's right to market a device; it does not regulate away your duty to exercise clinical judgment. The device is authorized to assist. You are still the one who decides, and the record still has to show that you did.
This cuts in a direction clinicians sometimes miss. The evolving standard of care is starting to run both ways. A clinician can be exposed for following a wrong AI recommendation that a reasonable reader should have caught, and, increasingly, for ignoring an accurate one when the tool flagged something the clinician then failed to work up. Neither the presence nor the absence of the flag settles your duty. What protects you is the same thing in both directions: a short, honest note showing you engaged with the output and exercised judgment. "AI flagged possible LVO; reviewed CTA, findings not confirmed on my read, no acute intervention, will reassess with clinical change" is worth more to your defense than any clearance number, because it shows a human looked and decided. The record is not paperwork. In a world of assistive AI, the record is the proof that accountability stayed where it belongs.
The Automation Bias Trap
There is a specific human failure mode that turns all of this from theory into a safety event, and it has a name: automation bias. It is the well-documented tendency to accept an authoritative-looking output under time pressure without the checking you would normally do. The word "cleared" makes it worse, because it dresses the output in a regulator's authority. Picture an ED at 2 a.m., the board full, a cleared triage AI returns "no large-vessel occlusion, low probability," and the exhausted clinician, half-reassured by the label, moves the scan down the pile. The occlusion was there. The tool was within its cleared intended use, and the clinician was within their duty to read the study, and the gap between those two facts is exactly where the patient fell. Clearance did not cause the miss. It lowered the clinician's guard. Naming automation bias is half of resisting it: when a cleared tool tells you the reassuring thing, that is precisely the moment to do your own read, not skip it.
A Worked Example: Reading a Clearance Honestly
Watch two clinicians meet the same tool and read its clearance in opposite ways. Both work in a cardiology practice that has just adopted an AI tool cleared to measure left-ventricular ejection fraction from echocardiogram images, intended as an aid to the interpreting physician.
The first clinician reads "FDA cleared" as a green light. When the AI reports an ejection fraction of 55%, he accepts it, drops it into the report, and moves on. He does not know which patient population the tool was validated on, whether that population resembles his elderly, multi-comorbid patients, whether the image quality on his older machine matches the validation conditions, or whether the clearance intended the number to be an aid he verifies or a value he adopts. He has treated a narrow regulatory authorization as a broad clinical guarantee, and on the day the tool over-reads a borderline study, he will have signed a number he never actually checked, into a record that is now his.
The second clinician reads the same two words as the start of a conversation, not the end of one. She knows clearance means the tool is authorized for a defined intended use, so she asks what that use actually is: an aid to interpretation, which means the accountable reader still confirms the measurement. She knows clearance does not certify local performance, so she is glad her group validated the tool on its own studies before going live and re-checks it periodically. When the AI reports 55%, she treats it as a well-supported draft: she glances at the images the measurement came from, confirms it is consistent with what she sees, and signs a number she has verified. If it had reported 55% on a study her eye read as severely reduced, she would have trusted her eye, looked harder, and documented why she disagreed. Same tool, same clearance, same output. One clinician is protected and so is the patient; the other is exposed and so is the patient. The difference is entirely in how the two words were read.
Notice what the second clinician did not do. She did not reject the tool, distrust it reflexively, or treat "FDA cleared" as meaningless. Clearance is real and valuable: it means a regulator reviewed a defined claim and found enough evidence to allow the product to market, which is genuinely more than an unregulated app can say. She simply held the label to its actual scope. That is the mature stance this lesson is teaching: not cynicism about clearance and not credulity about it, but calibration, knowing exactly what it certifies and exactly where your own judgment has to take over.
It is worth laying the two readings side by side, because the entire lesson lives in the contrast, and it is not a contrast of skill or seniority. Both clinicians are competent. The difference is a habit of mind.
| The same moment | Reads "cleared" as a guarantee | Reads "cleared" as a defined claim |
|---|---|---|
| AI reports EF 55% | Drops it into the report and signs | Glances at the images the measurement came from and confirms consistency |
| Number conflicts with the eye | Defers to the AI because it is cleared | Trusts the trained read, looks harder, documents the disagreement |
| Population and machine differ from the validation set | Never asks; assumes the label covers it | Relies on local validation her group ran before go-live |
| Tool was updated last quarter | Assumes it is the tool she trusted | Asks whether performance was re-checked after the update |
| Result in the record | An unverified value with her name on it | A verified value her judgment stands behind |
Same tool. Same clearance. Same output. Opposite exposure, for the clinician and for the patient. Nothing in the right-hand column requires regulatory expertise. It requires treating the label as the beginning of a question rather than the end of one.
How to Use This at the Bedside
You do not need to become a regulatory affairs specialist to put this to work. You need a short set of instincts that fire whenever you meet a clinical AI tool. First, when you see "FDA cleared" or "FDA authorized," read it as "authorized for a specific intended use," and find out what that use is: what task, what population, what input, and what role (aid, triage, adjunct). The intended use is the boundary of the promise. Second, ask which pathway and whether the tool was validated locally on patients like yours, and monitored after updates, because clearance certifies a general claim, not local performance. Third, remember the PCCP: the tool may have changed since it was last checked, so "we validated it once" is not the same as "it is still the tool we validated."
Fourth, and above all, keep the accountability where it belongs. The clearance is the manufacturer's; the clinical decision is yours; the record is the proof. An FDA-cleared tool that you used without verification produced an unverified output with your name on it, and the clearance will not shield you or, more importantly, help the patient. Used well, a cleared AI tool is a powerful, regulated assistant that has cleared a real bar. Used as a substitute for judgment, its clearance becomes a comfortable illusion. The label is a floor, never a ceiling, and never a replacement for the human who signs.
Key Takeaways
- The FDA regulates clinical AI as a medical device, most often as Software as a Medical Device (SaMD), and had authorized more than 1,350 AI/ML-enabled devices by early 2026 (about 950 in August 2024 and 1,250 by July 2025), a number to track, not to worship.
- Radiology dominates, at roughly 74% of 2024 authorizations, so imaging-facing clinicians are already the front line of regulated clinical AI.
- Three pathways carry different weight: 510(k) shows substantial equivalence to an existing predicate; De Novo authorizes a novel low-to-moderate-risk device; PMA demands affirmative proof of safety and effectiveness for the highest-risk devices.
- Clearance certifies a specific intended use (task, population, input, role). It does not certify accuracy on your patient, performance on your population, or fit in your workflow.
- A Predetermined Change Control Plan (PCCP) lets a manufacturer pre-specify how an AI model may be updated after clearance without a new submission; substantial changes outside the plan trigger new review, which is why the tool you use today may differ from the one last validated.
- Clearance does not transfer clinical accountability. "The tool was FDA cleared" is not a defense to a board, a plaintiff, a family, or a surveyor; you still decide and the record must prove it.
- A cleared tool is a candidate, not a conclusion: local validation on representative patients before deployment, and monitoring after, is what answers whether it works for the people you actually treat.
- The mature stance is calibration, not cynicism or credulity: know exactly what clearance certifies, hold it to that scope, and let your verified judgment carry everything past the boundary of the label.
Skill.re