AI/ML SaMD, PCCP, and the Convergence of Drug-Device-Diagnostic Regulation
A rare-disease asset enters Phase 3 with a companion algorithm that selects which patients are likely to respond, and somewhere in the program plan a regulatory lead writes a sentence that quietly redefines the whole submission: the algorithm is a Software-as-a-Medical-Device that the drug now depends on. The moment that sentence is true, the program is no longer a drug program with a software accessory. It is a combination product, governed by a device regulatory framework the drug team has never operated, with a learning AI inside it that may continue to change after approval. This is the convergence that most pharma organizations are unprepared for, and it is arriving fastest precisely where AI is most valuable: in the diagnostics and patient-selection algorithms that increasingly decide who gets the drug. This lesson is for the Level 5 leader who has to see, before the program team does, that an AI capability has changed the regulatory nature of the product. It traces how the SaMD framework, the Predetermined Change Control Plan finalized in December 2024 and revised January 2025, and the FDA Office of Combination Products together reshape what drug development means when a learning algorithm becomes part of the product.
When an Algorithm Becomes a Medical Device
The first thing a leader has to internalize is the boundary that turns software into a regulated device. Software-as-a-Medical-Device is software intended to perform a medical purpose without being part of a hardware device, and the defining test is the intended use: software that diagnoses, treats, prevents, or informs a clinical decision about a specific patient is a device, while software that merely organizes information for a clinician to interpret usually is not. An AI that flags a literature article for a PV writer is not a SaMD. An AI that outputs a patient-specific probability of response that a clinician uses to decide whether to prescribe is heading directly into SaMD territory, because it is informing a clinical decision about a specific patient. The leader's job is to recognize this boundary while the product is still being designed, because the difference between an internal analytics tool and a regulated SaMD is not a matter of the technology; it is a matter of the claimed intended use, and intended use is something the organization controls and frequently stumbles into without noticing.
The reason this matters at the Level 5 altitude is that the categorization changes the entire regulatory machine that governs the asset. A drug is regulated under the new-drug or biologics framework with INDs, NDAs, and BLAs; a device is regulated under a separate framework with its own classification, its own premarket pathways, and its own quality system regulation. When an AI becomes the patient-selection arm of a therapy, the program suddenly has to satisfy both, and the two frameworks were not designed to interlock cleanly. The strategic error is to discover this late, when the software has already been built and validated as an internal tool and now has to be re-baselined as a regulated device under a quality system it never followed. The leader who sees the SaMD boundary early can architect the program so the algorithm is developed as a device from the start, which is dramatically cheaper than retrofitting device-grade controls onto an algorithm that was treated as a spreadsheet with ambitions.
The Companion Diagnostic the Drug Depends On
The sharpest version of this convergence is the companion diagnostic, the test or algorithm that is essential for the safe and effective use of the corresponding therapeutic. When a drug's label requires that patients be selected by a specific diagnostic, the diagnostic is not an accessory; it is a co-dependent product whose approval is linked to the drug's. Historically the companion diagnostic was an assay run in a lab. Increasingly it is an AI model that reads images, integrates multi-omic data, or scores a risk profile, which means the companion diagnostic is now frequently a SaMD, and frequently a learning one. This is the point of maximum convergence: a single therapeutic program now contains a drug, a device, and a diagnostic, each with its own regulatory pathway, bound together by a label claim that none of them can satisfy alone.
For the regulatory leader, the operational consequence is that the program must be planned as a coordinated co-development from the earliest stages, because the diagnostic's evidence and the drug's evidence have to support a single integrated claim. The clinical trial that establishes the drug's efficacy in the algorithm-selected population is simultaneously the trial that validates the algorithm's selection performance, and the two cannot be separated after the fact. If the algorithm is changed after the pivotal trial, the population it selects changes, and the drug's efficacy claim in that population is no longer supported by the trial that established it. This is why a learning AI inside a companion diagnostic is so consequential: an uncontrolled model update does not just change the diagnostic, it potentially invalidates the drug's label. The leader has to ensure the program treats the algorithm's change control as a drug-label-integrity issue, not a software-maintenance issue, which is precisely the gap the PCCP framework was built to close.
The PCCP: The Contract for a Learning Model
The Predetermined Change Control Plan is the regulatory innovation that makes a learning AI tractable inside a regulated product, and understanding it is the centerpiece of this lesson. The FDA finalized its PCCP guidance for AI-enabled device software functions on 19 December 2024, with a January 2025 revision, and it solves a specific problem: a traditional device is approved in a fixed state, but a learning model is valuable precisely because it changes, and you cannot file a new submission every time the model retrains. The PCCP resolves this by letting the sponsor specify, in advance and as part of the original authorization, exactly what the model is allowed to change, how it will change it, and how the impact will be assessed. It has three components: a description of the planned modifications, a modification protocol describing the methods and controls for making them, and an impact assessment of the benefits and risks of the planned changes. Approved together with the device, the PCCP becomes a pre-authorized envelope within which the model may update without a new marketing submission, while changes outside the envelope still require one.
The conceptual power of the PCCP is that it converts an unbounded learning system into a bounded, governed, and inspectable one, and this is exactly why industry is adopting the PCCP pattern far beyond formal SaMD. The same logic that governs a learning diagnostic governs any production AI in a regulated content workflow: declare in advance what the system may change, the protocol by which it changes, and how you will assess the impact, and you have converted a frightening black box into a defensible controlled process. A Level 5 leader uses the PCCP not only as the literal mechanism for a learning companion diagnostic, but as the mental model for governing every learning AI in the enterprise. The PCCP is the answer to the regulator's deepest worry about AI, which is not that it is wrong today but that it might become wrong tomorrow without anyone noticing. The PCCP makes tomorrow's changes a thing the sponsor pre-committed to and the regulator pre-reviewed, which is the only way a learning system and a regulatory framework can coexist.
The Office of Combination Products Playbook
When a product spans drug, device, and diagnostic, someone inside the FDA has to decide which center leads the review and how the pieces fit together, and that someone is the Office of Combination Products. A combination product is one composed of two or more regulated components, such as a drug plus a device, and the OCP assigns a lead center based on the product's primary mode of action: if the therapeutic effect is principally the drug's, the drug center leads, with the device and diagnostic reviewed in coordination. For the leader, the practical playbook starts with the primary-mode-of-action determination, because it sets which center is in charge, which framework dominates, and which expectations the program must center on. Getting this determination early, sometimes through a formal Request for Designation, removes the most expensive form of late-stage uncertainty: discovering after the pivotal trial that the agency views the product through a different lens than the sponsor planned for.
The combination-product reality reshapes the submission itself. The dossier must now coherently integrate drug content, device content, and the SaMD's documentation, including the PCCP, into a single reviewable package whose pieces cross-reference and do not contradict each other. The drug's clinical evidence has to align with the diagnostic's analytical and clinical validation; the device's quality system records have to coexist with the drug's; and the AI's change-control plan has to be legible to reviewers from multiple disciplines. This is a documentation and coordination challenge of a different order than a pure-drug NDA, and it is exactly where AI-native, structured-content authoring earns its keep, because a combination product is the case where a single fact must appear consistently across drug, device, and diagnostic sections authored by different teams. The leader's job is to ensure the organization has the cross-functional muscle and the structured-content backbone to assemble a combination-product dossier that reads as one coherent argument rather than three stapled-together submissions.
What This Changes About What Drug Development Means
Step back and the convergence redefines the boundaries of the discipline. Drug development used to end at the molecule and its label; now, when the label depends on an AI that selects patients, drug development includes the lifecycle management of a learning algorithm that may outlive the original approval and keep changing under a PCCP. The regulatory affairs function can no longer be purely a drug function; it has to hold device and diagnostic competency, or partner deeply with those who do. The quality system can no longer be purely a GMP system; it has to encompass the device quality system regulation and the software lifecycle. The clinical strategy can no longer treat the diagnostic as a logistics detail; it has to co-develop the diagnostic's validation inside the pivotal trial. Each of these is a structural change to how an organization is shaped, not a procedural tweak, and the leader who sees the convergence early gets to make these changes deliberately rather than under the pressure of a program that has already crossed the boundary unaware.
The talent and capability implications follow directly and are where the Level 5 leader spends real budget. The organization needs people who can read a SaMD classification, draft and defend a PCCP, navigate a primary-mode-of-action determination, and assemble a combination-product dossier, and these people are scarce because they sit at the intersection of drug, device, and AI competencies that historically lived in separate companies. The AI-aware regulatory roles that the horizon lesson named, the Submission AI Architect and the AI Validation Lead, here acquire a specific combination-product dimension: they must understand not just how to govern an AI, but how a governed AI fits a device framework that fits a drug submission. The leader's move is to build this competency before the first program needs it, because the first companion-diagnostic combination product is precisely the wrong moment to discover that no one in the regulatory function has ever filed a PCCP or coordinated with the Office of Combination Products. The convergence is coming through the door of patient-selection AI, and the organizations that prepared for it will move while the unprepared ones reclassify their software under deadline pressure.
The Leader's Early-Warning System
Because the cost of discovering the convergence late is so high, the most valuable thing a Level 5 leader can install is an early-warning system that flags a program crossing the SaMD boundary before the software is built. The trigger is always a claim, not a technology: the moment a program proposes that an algorithm will select, stratify, or decide for a specific patient in a way the label will reference, the program has likely created a SaMD and possibly a companion diagnostic, and it must be routed to the device and diagnostic expertise immediately. This is a governance-design problem the leader owns, because the program team that built the algorithm as an analytics tool has every incentive to keep treating it as one, and the reclassification that follows is unwelcome news that arrives most cheaply when it arrives early. A simple, well-placed gate in the development process, asking whether any AI output informs a patient-specific clinical decision the label will rely on, catches the convergence at the point where it is still cheap to manage.
The early-warning system also has to watch the learning dimension, because a model that is a fixed SaMD today can become a learning SaMD the moment someone decides it should retrain on post-market data, and that decision changes the regulatory obligations. The leader's standing rule is that no production AI inside a regulated product is allowed to learn without a PCCP or an equivalent pre-authorized change envelope, because an uncontrolled update is the single failure mode that can invalidate a label or trigger a finding. This is the through-line that connects the SaMD boundary, the PCCP, and the combination-product framework into one coherent leadership stance: see the boundary early, govern the learning with a pre-committed plan, and coordinate the drug, device, and diagnostic as one product from the start. The leader who holds that stance turns the convergence from a threat that ambushes programs into a capability that the organization can wield deliberately, which is exactly the difference between a Level 5 visionary and a function that is perpetually catching up to its own technology.
Key Takeaways
- The SaMD boundary is set by intended use, not technology, and the leader must see it early. Software that informs a clinical decision about a specific patient is a medical device; an internal analytics tool is not, and the difference is a claim the organization controls and frequently stumbles into. Catching the boundary while the algorithm is still being designed is dramatically cheaper than retrofitting device-grade controls onto a tool built as a spreadsheet with ambitions.
- A learning AI inside a companion diagnostic makes its change control a drug-label-integrity issue. When the label requires algorithm-selected patients, an uncontrolled model update changes the selected population and can invalidate the drug's efficacy claim, so the diagnostic and drug must be co-developed and the algorithm's validation must live inside the pivotal trial. This is the point of maximum convergence: one program containing a drug, a device, and a diagnostic bound by a single label claim.
- The PCCP, finalized 19 December 2024 and revised January 2025, is the contract that makes a learning model tractable. Its three parts, the description of modifications, the modification protocol, and the impact assessment, pre-authorize an envelope within which the model may update without a new submission. Industry is adopting the PCCP pattern far beyond formal SaMD as the mental model for governing any learning AI: declare what may change, how, and how impact is assessed.
- The FDA Office of Combination Products assigns the lead center by primary mode of action, and the determination should be made early. A combination product spanning drug, device, and diagnostic must integrate all three into one coherent, cross-referenced dossier including the PCCP, which is exactly where structured-content authoring earns its keep. Discovering the agency's lens late, after the pivotal trial, is the most expensive form of regulatory uncertainty.
- The convergence redefines drug development and demands an early-warning system the leader owns. Drug development now includes lifecycle management of a learning algorithm that may outlive the approval, so the regulatory, quality, and clinical functions must hold device and diagnostic competency. The standing rule is that no production AI inside a regulated product learns without a pre-authorized change envelope, and a simple gate asking whether any AI output informs a label-referenced patient decision catches the convergence while it is still cheap to manage.
Skill.re