The Food and Drug Administration is asking patients, clinicians, developers, researchers and manufacturers how it should regulate medical devices enabled by generative artificial intelligence. Unlike conventional predictive models that classify or estimate from inputs, generative systems can produce new text, images, audio or other content. The agency’s request for information is a fact-gathering step. It does not approve a specific device, authorize autonomous diagnosis or establish a binding final rule.
FDA wants evidence about premarket testing, human factors, transparency, cybersecurity and postmarket monitoring. A central question is how to evaluate outputs that may vary even when users provide similar inputs. Traditional performance averages may not capture rare but serious hallucinations, biased recommendations or confident language unsupported by clinical evidence. Developers may need scenario testing, traceable source information and clearly defined conditions under which a clinician must review or reject an output.
Change control is another hard problem. Generative models can be updated frequently, while medical-device law expects regulators and manufacturers to understand the version that was reviewed. FDA has previously developed predetermined change-control plans for some AI-enabled devices. The new request asks whether those tools can handle foundation-model updates, new training data, prompt changes and third-party dependencies without allowing a product to drift beyond its authorized use.
Privacy and security run through the entire lifecycle. Clinical prompts may contain protected health information, and model providers can introduce data-retention or remote-service risks. A device company cannot outsource responsibility simply because an external model produced the answer. Contracts, logs, access controls, validation records and incident reporting should reveal which model version ran, what data entered it and how a harmful output was handled.
Uncle Sibursam’s circuit check: confirmed are FDA’s public request and the issues it asks stakeholders to address. Claims that generative AI devices are now broadly approved are false. Disputed are how much explanation, reproducibility and human oversight regulators should require. Unknown are the final framework, comment synthesis and product-specific consequences. Expected next are public submissions, workshops or draft guidance. Innovation needs a socket, but medicine also needs a circuit breaker: the output must be testable, attributable and stoppable when it leaves the evidence. Commenters should distinguish consumer chatbots from regulated devices and support proposed safeguards with clinical data, failure examples and measurable acceptance criteria. Hospitals considering pilots should document supervision, escalation and downtime procedures before any output reaches a treatment decision. Patients should also be told when generated content materially contributes to care.
Sources
- U.S. Food and Drug Administration — FDA Seeks Public Feedback on Generative AI-Enabled Medical Devices (08-18-2026)
- U.S. Food and Drug Administration — Artificial Intelligence-Enabled Medical Devices (08-27-2026)
