Emerging Technology · FDA Regulatory Strategy

AI/ML SaMD Regulatory Strategy

By Andre D. Butler, Principal Consultant  ·  reviewed August 2026

FDA's approach to AI/ML Software as a Medical Device is built around a single idea: the algorithm keeps changing after clearance, so the regulatory plan has to account for that in advance. This guide covers how FDA classifies AI/ML SaMD, what a Predetermined Change Control Plan (PCCP) actually requires, and the practitioner-level decisions — predicate strategy, GMLP documentation, transparency labeling — that determine whether a submission clears cleanly or comes back with questions.

AI/ML SaMD Consultation
SaMD Risk Classification PCCP Development GMLP Documentation Adaptive Algorithm Strategy Post-Market Monitoring Plans

A Growing Category

A Regulatory Practice Built for AI/ML SaMD

The FDA's approach to AI/ML SaMD is rapidly evolving. The 2021 AI/ML Action Plan, the finalized Predetermined Change Control Plan (PCCP) guidance, and ongoing digital health guidance have introduced real complexity for device developers — complexity that sits on top of the standard 510(k), De Novo, and PMA frameworks, not in place of them. ADB specializes in helping AI-enabled medical device companies build compliant regulatory strategies from the ground up, including SaMD risk classification, pathway selection, and PCCP development for adaptive algorithms.

Scope of Work

What the Engagement Covers

🧠

SaMD Risk Classification Framework

Risk categorization built to IEC 62304 and ISO 13485, mapped to your device's intended use and clinical decision role.

📄

Software Function & Intended Use Analysis

FDA-facing analysis of what your software function actually does and how that determines regulatory classification.

💬

Pre-Submission (Q-Sub) Strategy

Structured Q-Sub strategy for AI/ML devices, built to get FDA's written feedback before you file.

🔄

PCCP Development

Predetermined Change Control Plan drafting — Description of Modifications, Modification Protocol, and Impact Assessment.

🛠️

Algorithm Change Protocol Design

The verification and validation methodology that governs how each planned modification gets implemented safely.

🎯

510(k) or De Novo Pathway Recommendation

Predicate strategy and pathway recommendation built around your algorithm's classification and change behavior.

🔒

Software-Specific Testing Strategy

Cybersecurity, usability, and V&V testing strategy scoped to a software-only device.

The Regulatory Framework

What Is AI/ML Software as a Medical Device (SaMD)?

AI/ML SaMD is software that uses artificial intelligence or machine learning to perform a medical function — diagnosis, treatment guidance, or clinical decision support — without being part of a hardware device. It's regulated as SaMD first: the fact that the underlying model uses AI or machine learning doesn't create a separate regulatory category, but it does introduce one problem standard software doesn't have — the algorithm's behavior can change after clearance as it's exposed to new data.

Classification

How Does FDA Classify AI/ML-Based SaMD?

Classification follows the same risk-based framework as any other software device — intended use and the software's role in a clinical decision determine device class, with higher-risk clinical decision support pushing toward Class II or III and a corresponding 510(k), De Novo, or PMA pathway. A locked algorithm is generally compared more directly to a fixed predicate; an adaptive algorithm's PCCP becomes part of the substantial equivalence argument itself, since the reviewer is clearing both the current algorithm state and the plan for how it changes.

PCCP Fundamentals

What Is a Predetermined Change Control Plan (PCCP)?

A PCCP is an FDA-reviewed plan, submitted with a device's marketing submission, that pre-specifies the anticipated modifications an AI/ML algorithm may undergo post-market and the methodology used to implement those changes without requiring a new submission for each one. It exists because FDA's traditional model — clear a device, then require a new submission for any significant change — doesn't fit an algorithm that's designed to keep learning.

PCCP Contents

What Does a PCCP Actually Contain?

FDA's finalized PCCP guidance structures a plan around three components: a Description of Modifications — often referred to on this site and elsewhere as the Software Pre-Specifications, or SPS — that names the specific planned changes and their bounds; an Impact Assessment that evaluates the benefits and risks each modification introduces, including what could go wrong if the modification behaves unexpectedly; and a Modification Protocol — the verification and validation methodology used to implement and confirm each change before it's deployed. All three have to be specific enough that FDA can evaluate them now, not just a promise to "test appropriately" later.

Regulatory Orientation

FDA's AI/ML Action Plan and Total Product Lifecycle Approach

FDA's 2021 AI/ML Action Plan describes FDA's regulatory approach and priorities for AI/ML SaMD — including the PCCP framework and Good Machine Learning Practice — but the binding requirements still flow through the existing 510(k), De Novo, and PMA pathways under the FD&C Act. The Action Plan's Total Product Lifecycle (TPLC) approach treats safety and effectiveness as something evaluated across the device's entire lifecycle — premarket review, PCCP-governed modifications, and post-market performance monitoring together — rather than as a single premarket determination.

Development Practice

Good Machine Learning Practice (GMLP): The Ten Guiding Principles

GMLP is a set of AI/ML-specific development practices — covering data management, model design, and performance monitoring — that FDA references as the quality foundation an AI/ML SaMD submission is expected to demonstrate.

1. Multi-Disciplinary Expertise Throughout the Lifecycle

Clinical, data science, statistics, and regulatory expertise are all represented in design and risk decisions — not siloed to one team.

2. Good Software Engineering & Security Practices

Standard software lifecycle discipline — configuration management, traceability, cybersecurity — still applies to the model pipeline.

3. Representative Clinical Study Data

Training and test populations reflect the intended-use population, including relevant demographic and clinical subgroups.

4. Training Data Independent of Test Data

Test sets are held out from training to produce a valid, non-inflated estimate of real-world performance.

5. Best-Available Reference Datasets

Ground-truth/reference standards are selected using the most rigorous method reasonably available for the clinical question.

6. Model Design Fits the Data and Intended Use

Model architecture and complexity are matched to the available data volume/quality and the device's actual clinical task.

7. Human-AI Team Performance

Performance is evaluated for the clinician-plus-algorithm workflow, not the algorithm in isolation.

8. Testing Under Clinically Relevant Conditions

Validation testing reflects the real clinical environment and edge cases the device will actually encounter.

9. Clear, Essential User Information

Labeling and user-facing outputs communicate what the algorithm does, its limitations, and how confident to be in its output.

10. Monitoring Deployed Models for Performance and Re-Training Risk

Real-world performance is tracked post-deployment, with a plan for what happens if performance drifts.

Adaptive vs. Locked

Adaptive vs. Locked Algorithms: What's the Difference?

A locked algorithm produces the same output every time for a given input and does not change after clearance. An adaptive algorithm continues to learn and update post-market — the specific case a PCCP is designed to manage. Most AI/ML SaMD devices on the market today are locked; adaptive, continuously-learning algorithms remain the harder, less common case, which is exactly why the PCCP framework matters most for that group.

Post-Clearance

Transparency and Labeling Expectations for AI/ML Devices

FDA's transparency expectations for AI/ML devices center on giving users — clinicians and, where relevant, patients — clear information about what the algorithm does, the population its training and test data represent, its performance characteristics, and its known limitations. This applies whether the algorithm is locked or governed by an approved PCCP; a PCCP doesn't reduce the labeling obligation, it just means the labeling has to account for the range of changes the algorithm is authorized to make.

Post-Market

Real-World Performance Monitoring After Clearance

Devices operating under a PCCP need a monitoring plan describing what real-world performance metrics are tracked, how performance drift is detected, and what triggers a corrective action or a determination that a modification has exceeded the PCCP's authorized bounds. This is where the Total Product Lifecycle approach becomes concrete — the monitoring plan is what lets FDA and the manufacturer confirm the algorithm is still performing the way the cleared submission said it would.

Applied · Practitioner Layer

Do You Need a PCCP? A Practical Decision Walkthrough

Not every AI/ML device needs one, and adding one you don't need slows your submission down for no benefit. Start with one question: will the algorithm's logic actually change after clearance based on new data, or is it locked at the version you're submitting? If it's locked, a PCCP has nothing to govern — any future change goes through a standard 510(k) supplement or new submission regardless, and a PCCP just adds upfront review scope.

If the algorithm is genuinely adaptive — retraining on new data, adjusting thresholds, expanding to new subpopulations — the question becomes whether you can specify those changes narrowly enough for FDA to evaluate now. A PCCP that says "we may retrain periodically" without bounding what retraining can and can't do is a PCCP FDA is likely to send back. It pays when your modification plan is specific: a defined retraining cadence, a defined performance floor the retrained model must clear, and a defined process for confirming that floor before deployment. It doesn't pay when the actual plan is "we'll figure out the changes as we go" — that isn't a plan FDA can authorize in advance, and it's better to submit the locked version now and file a traditional supplement when a real, specific change is ready.

Applied · Practitioner Layer

How AI Devices Actually Clear: Predicate Strategy in Practice

Predicate selection for an AI/ML device starts the same way it does for any 510(k) — same intended use, same technological characteristics, no new questions of safety or effectiveness. The complication is that the predicate pool for AI-specific functions is thinner than most device categories, and product-code selection matters more here than almost anywhere else: FDA product codes with an established history of AI/ML clearances (concentrated in radiological image analysis, cardiology rhythm detection, and a growing set of other decision-support categories) carry review-division familiarity that a novel code doesn't.

For a locked algorithm, the substantial equivalence argument is a fairly standard software SE comparison against the predicate's function and performance. For a device submitted with a PCCP, the SE argument has to do double duty — it has to establish equivalence for the algorithm as submitted, and it has to establish that the PCCP's bounded set of future modifications won't push the device outside the predicate comparison FDA is clearing today. That second piece is where a predicate strategy either holds up under review or comes back with a deficiency letter.

Applied · Practitioner Layer

Adaptive vs. Locked: The Regulatory Consequences

The table below is the practical version of the classification question above — what each choice actually costs you in submission burden and ongoing obligations.

DimensionLocked AlgorithmAdaptive Algorithm (PCCP-Governed)
Initial submission burdenStandard software SE package; no PCCP section required.Standard SE package plus Description of Modifications, Impact Assessment, and Modification Protocol — meaningfully more upfront work.
Cost of a future algorithm changeNew 510(k) supplement or submission for each material change.Changes within the PCCP's authorized bounds don't require a new submission — the cost is front-loaded into getting the PCCP approved.
Predicate/SE argumentDirect comparison to a fixed predicate.Comparison must also account for the full range of PCCP-authorized future states, not just the version submitted.
Post-market monitoring obligationStandard post-market surveillance; no algorithm-drift-specific plan required.A real-world performance monitoring plan tracking drift and confirming each modification stayed within its authorized bounds.
Best fitDevices where the model is stable and you don't expect to retrain on new data.Devices with a genuine, specific retraining or threshold-update roadmap you can bound in advance.

Applied · Practitioner Layer

GMLP Applied: What Reviewers Expect Per Principle

Naming the ten GMLP principles in a submission is not the same as demonstrating them — reviewers are looking for documentation, not a list. In practice, that means: a written data-provenance summary (not just an assertion) describing where training data came from and how population representativeness was assessed against your intended-use population (Principle 3); an explicit description of the train/test split methodology showing the two sets don't overlap (Principle 4); a documented rationale for why your model architecture fits your data volume and clinical task, not just a performance number (Principle 6); human-factors or usability data showing the clinician-plus-algorithm workflow was evaluated, not the algorithm's standalone accuracy alone (Principle 7); and — for any device with a PCCP — a monitoring plan document that operationalizes Principle 10, specifying the metrics tracked and the drift thresholds that trigger action. A submission that recites the ten principles without attaching the underlying evidence for each is the single most common way GMLP documentation falls short in practice.

Applied · Practitioner Layer

The AI Transparency and Labeling Section: What Compliant Looks Like

A compliant AI/ML labeling section reads less like marketing copy and more like a technical disclosure. It states the intended use in the same specific terms as the classification/predicate analysis (not a broader marketing description); it describes the population the training and test data represent, including any populations the device was not validated on; it states the device's performance characteristics against the reference standard used for validation, in terms a clinician can act on (not just an aggregate accuracy figure); it discloses known limitations and failure modes; and — for a PCCP-governed device — it describes the current authorized version and how a user would know if the algorithm's behavior has changed. The common failure mode is a labeling section that describes the algorithm's capabilities in general terms while omitting the specific population and performance-characteristic detail FDA's transparency expectations are actually asking for.

Applied · Practitioner Layer

Engagement Structure and Timeline

AI/ML SaMD engagements are scoped individually — the driving variables are your device's classification pathway, whether a PCCP applies at all, and how much of the underlying regulatory groundwork (predicate research, clinical validation data, existing QMS documentation) already exists. A locked-algorithm 510(k) with no PCCP follows roughly the same timeline as any other software 510(k); adding a PCCP adds real time upfront — Description of Modifications, Impact Assessment, and Modification Protocol are each substantive documents, not boilerplate sections — in exchange for not re-filing on every future modification.

Natural Overlap

AI/ML Devices Are Usually Cyber Devices Too

Most connected AI/ML SaMD devices meet the definition of a "cyber device" under Section 524B — they have software, connect to the internet in some form, and contain technological characteristics that could be vulnerable to cybersecurity threats. If your device transmits data for model updates or retraining, or connects to a hospital network for inference, your PCCP strategy and your Section 524B cybersecurity submission need to be built together, not sequentially — an SBOM and threat model that doesn't account for how the algorithm updates itself is incomplete for a PCCP-governed device.

Frequently Asked Questions

AI/ML SaMD Regulatory Questions

What is a Predetermined Change Control Plan (PCCP) and when does FDA require one for an AI/ML medical device?

A PCCP is an FDA-reviewed plan submitted with a device's marketing submission that pre-specifies anticipated post-market modifications to an AI/ML algorithm and how they'll be implemented without a new submission for each change. FDA doesn't require one for every AI/ML device — only devices with a genuine adaptive component that will change post-market benefit from including one.

How does FDA classify Software as a Medical Device (SaMD) that uses AI or machine learning?

AI/ML-based SaMD is classified the same way as any other software device — by intended use and the role the software's output plays in a clinical decision, not by the fact that it uses AI. Higher-risk clinical decision support pushes toward Class II or III and a corresponding 510(k), De Novo, or PMA pathway.

What's the difference between an adaptive and a locked AI/ML algorithm for FDA purposes?

A locked algorithm produces the same output every time for a given input and doesn't change after clearance, so any modification requires a new submission or supplement. An adaptive algorithm continues to learn and update post-market — the specific case a PCCP is designed to manage.

What does Good Machine Learning Practice (GMLP) require for an AI/ML medical device?

GMLP is a set of ten AI/ML-specific development principles — covering data management, model design, human-AI team performance, and post-deployment monitoring — that FDA references as the quality foundation an AI/ML SaMD submission is expected to demonstrate. It's a framework FDA expects to see reflected in your documentation, not a checklist FDA certifies separately.

What transparency and labeling information does FDA expect for an AI/ML-enabled medical device?

FDA expects labeling that clearly communicates the device's intended use, performance characteristics, the population the training and test data represent, and any known limitations of the algorithm's outputs. This transparency expectation applies whether the algorithm is locked or governed by an approved PCCP.

Do I need a PCCP for my AI/ML device, or can I skip it?

You need a PCCP only if your algorithm will genuinely change after clearance based on new data — if your algorithm is locked at clearance and any future change would go through a standard submission anyway, a PCCP adds review burden without a matching benefit.

How much does AI/ML SaMD regulatory strategy cost?

AI/ML SaMD engagements are scoped individually based on your device's classification pathway, whether a PCCP applies, and how much regulatory groundwork already exists — book a consultation for a fee quote specific to your program.

Andre Butler

Led by Andre Butler, CQA, CCRP — 28+ years, 15+ FDA 510(k) clearances, 11 years on a Class III PMA program. Meet the team →

Not Sure Which Pathway Fits?

Book a Free 30-Minute Pathway Call

Talk through your device's classification and whether a PCCP applies before you commit to a submission strategy — no obligation.

Or call (888) 450-8607